It has been revealed that Coinsbuy, a cryptocurrency payment processor and exchange, has suffered a large-scale hacking incident.
The attackers are believed to have illegally withdrawn approximately $8 million (around 1.27 billion yen) across multiple blockchain networks, attempting to execute sophisticated money laundering schemes.
The fraudulent outflow was detected on August 9, 2026 (Sunday). According to analyses by blockchain research firm BlockWatchdog and others, the attackers first executed a small test transfer of 5 USDT on the Tron network. Immediately after confirming that there were no issues, they drained over 6 million USDT from eight Tron wallets managed by Coinsbuy all at once.
The damage was not limited to Tron; it also spread to Ethereum. From three wallets, 1.89 million USDT and 77 ETH were stolen. The total damage across the two different chains amounts to approximately $7.9 to $8 million (around 1.257 billion to 1.27 billion yen).
To evade tracking of the stolen assets, the attackers initiated a rapid and complex money laundering process.
Ultimately, the attackers proceeded to convert the stolen funds into Monero (Monero/XMR), a cryptocurrency known for its high anonymity and difficulty in tracking. However, it has been reported that ChangeNOW detected suspicious fund movements and successfully froze assets worth hundreds of thousands of dollars before they could be drained.
Coinsbuy temporarily halted deposits and withdrawals immediately after the incident, but later resumed services. Although the company has not released a technical post-mortem analysis, they stated in interviews that "while unauthorized withdrawals occurred from multiple wallets, the issue has been contained."
Notably, Coinsbuy replenished approximately $3.93 million (around 620 million yen) of its own funds to the same ten affected wallets just hours after the outflow. Experts point out that if the private keys themselves had been stolen, it would be highly unusual to deposit large amounts of funds back into the same address. This response suggests that the breach likely involved the "withdrawal permissions" or "vulnerabilities in the authentication process" rather than the private keys themselves.
Coinsbuy announced that "all funds of affected users have been fully compensated from the company's own resources, and no direct financial damage has occurred to customers." The company has now returned to normal operational status.
They are conducting a thorough internal investigation to clarify the full details of the incident and have expressed their intention to pay a "$100,000 reward" to anyone providing information that leads to the identification of the perpetrators. Additionally, they are preparing extra rewards for collaborators who contribute to the recovery of the drained funds.
This incident at Coinsbuy occurred amid increasing security threats across the entire cryptocurrency industry.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.


























Today’s WEEX TradFi Daily Brief covers pressure from NVIDIA-related AI financing news, energy sector leadership driven by stronger oil prices, and the U.S. after-hours earnings lineup to help you quickly capture stock-token trading opportunities.



