Koinlytics

A Payments Processor Lost $7.9M on Two Chains at Once and That Rules Out Most Causes

Aug 9, 2026ETHTRXXMRsecurityexploitspaymentshot-walletstron
Wallets tied to crypto payments platform Coinsbuy were drained of more than $7.9 million across Ethereum and TRON starting around 13:00 UTC on August 9. Simultaneous activity on two unrelated chains points to key compromise rather than a contract exploit.

Wallets linked to the B2B crypto payments processor Coinsbuy were drained of more than $7.9 million across Ethereum and TRON beginning around 13:00 UTC on August 9. The unusual outflows were first flagged publicly by the investigator SpecterAnalyst.

Coinsbuy paused deposits and withdrawals following the incident and has since resumed services. It is the largest reported crypto theft of August so far.

Two Chains at Once Narrows the Diagnosis

Ethereum and TRON share no code, no virtual machine and no consensus. An exploit in an Ethereum smart contract cannot touch a TRON wallet, and vice versa. When funds leave both simultaneously, most hypotheses die immediately.

What survives:

Both live in the same place: the operator's infrastructure, not the blockchain. Multiple investigators reached the same conclusion for the same reason.

Why Payment Processors Are Structurally Exposed

A B2B crypto processor cannot use the defence that protects everyone else, which is cold storage. Its product is settling merchant payments quickly across many chains, which requires signing keys that are online, automated and reachable by the systems that trigger payouts.

The design constraint is real. It also means the attack surface is permanently larger than a custodian's, and the mitigation is limited to operational float management: keeping hot balances small and sweeping to cold storage frequently. $7.9 million sitting in reachable wallets is the number that turned an infrastructure compromise into a material loss.

Where the Money Went

The funds were routed through multiple exchanges and converted into Monero, the standard playbook for making blockchain forensics stop working. ChangeNOW reportedly froze a six-figure amount linked to the stolen funds before it moved further.

That freeze is a fraction of the total and it illustrates the recovery arithmetic in these incidents. Once funds reach a privacy chain, tracing degrades sharply. The only reliable interception points are the regulated venues the attacker has to pass through, and each of those has to act within minutes to matter.

Every large theft this year has ended the same way: the chain records everything, the attacker converts to something that does not, and recovery becomes a question of how fast a compliance team moved.

The Month's Running Tally

Coinsbuy is the third distinct infrastructure failure in under two weeks:

Three different products, three different user bases, one common failure class. None involved breaking cryptography. All three involved credentials, configuration or key custody at the layer above the protocol. 2026 has now recorded more than $1.2 billion in losses across upwards of 276 incidents.

What to Watch

If you use a payments processor or an exchange to hold operational crypto balances, the exposure is the balance itself, and it is a number you set. The merchants affected here were not hacked. Their processor was, and the funds involved were theirs. Knowing what sits with third parties, on which chains, at any given moment is the only part of this you actually control.

Powered by Koinlytics · Portfolio and DeFi analytics that see what others miss.

See every headline that moves your bag.

Koinlytics Market Intel is live inside the app. Track your portfolio, LPs and impermanent loss while the news breaks.

Join Koinlytics