Wallets linked to the B2B crypto payments processor Coinsbuy were drained of more than $7.9 million across Ethereum and TRON beginning around 13:00 UTC on August 9. The unusual outflows were first flagged publicly by the investigator SpecterAnalyst.
Coinsbuy paused deposits and withdrawals following the incident and has since resumed services. It is the largest reported crypto theft of August so far.
Two Chains at Once Narrows the Diagnosis
Ethereum and TRON share no code, no virtual machine and no consensus. An exploit in an Ethereum smart contract cannot touch a TRON wallet, and vice versa. When funds leave both simultaneously, most hypotheses die immediately.
What survives:
- Hot wallet private keys were compromised. A payments processor typically manages keys for multiple chains from one operational system. Compromise that system and every chain it touches drains at once.
- Administrative privileges were escalated. If withdrawals route through an internal approval layer, an attacker with sufficient access can trigger legitimate-looking outbound transfers on every supported network.
Both live in the same place: the operator's infrastructure, not the blockchain. Multiple investigators reached the same conclusion for the same reason.
Why Payment Processors Are Structurally Exposed
A B2B crypto processor cannot use the defence that protects everyone else, which is cold storage. Its product is settling merchant payments quickly across many chains, which requires signing keys that are online, automated and reachable by the systems that trigger payouts.
The design constraint is real. It also means the attack surface is permanently larger than a custodian's, and the mitigation is limited to operational float management: keeping hot balances small and sweeping to cold storage frequently. $7.9 million sitting in reachable wallets is the number that turned an infrastructure compromise into a material loss.
Where the Money Went
The funds were routed through multiple exchanges and converted into Monero, the standard playbook for making blockchain forensics stop working. ChangeNOW reportedly froze a six-figure amount linked to the stolen funds before it moved further.
That freeze is a fraction of the total and it illustrates the recovery arithmetic in these incidents. Once funds reach a privacy chain, tracing degrades sharply. The only reliable interception points are the regulated venues the attacker has to pass through, and each of those has to act within minutes to matter.
Every large theft this year has ended the same way: the chain records everything, the attacker converts to something that does not, and recovery becomes a question of how fast a compliance team moved.
The Month's Running Tally
Coinsbuy is the third distinct infrastructure failure in under two weeks:
- The Coldcard hardware wallet entropy flaw, with tracked losses between $110 million and $130 million
- The BTCPay Server LND credential exploit that drained merchant Lightning nodes before the advisory went public
- This cross-chain hot wallet drain
Three different products, three different user bases, one common failure class. None involved breaking cryptography. All three involved credentials, configuration or key custody at the layer above the protocol. 2026 has now recorded more than $1.2 billion in losses across upwards of 276 incidents.
What to Watch
- Whether Coinsbuy publishes a technical post-mortem identifying the entry point, which investigators are still searching for
- Any further exchange freezes beyond the ChangeNOW six-figure amount
- Whether merchants using Coinsbuy face settlement delays or losses, which determines the real blast radius
- Whether the funds converted to Monero surface anywhere traceable, which historically they do not
- Whether other multi-chain payment processors publish hot wallet policy changes in response
If you use a payments processor or an exchange to hold operational crypto balances, the exposure is the balance itself, and it is a number you set. The merchants affected here were not hacked. Their processor was, and the funds involved were theirs. Knowing what sits with third parties, on which chains, at any given moment is the only part of this you actually control.
Koinlytics