Key Takeaways
- Coinsbuy lost more than $8M across Ethereum and TRON in an August 9, 2026 hack.
- The attacker laundered part of the funds into Monero.
- Details circulating in the media have not been officially confirmed.
- Multi-sig wallets, cold storage, withdrawal limits, and real-time monitoring are the strongest defenses against similar attacks.
On August 9, 2026, wallets linked to crypto payment processor Coinsbuy were drained of more than $8 million across Ethereum and TRON. The attacker started moving the stolen funds into Monero (XMR) shortly after, routing them through several exchange services in an attempt to break the on-chain trail. Here's what's known so far, and how to protect your own funds from similar attacks.
Coinsbuy Hack: What Happened
Coinsbuy is a crypto payment processor. Around 13:00 UTC on August 9, on-chain investigator Specter Analyst flagged unusual outflows from wallets:

Two Ethereum addresses and one TRON address were identified as the main destinations of the stolen funds.
Coinsbuy temporarily suspended deposits and withdrawals as a precaution while it assessed the breach, then restored both services a few hours later.
Investigators say the pattern points to compromised wallet keys or admin-level access on Coinsbuy's side rather than any flaw in the Ethereum or TRON networks themselves. The exact attack vector hasn't been confirmed publicly.
Coinsbuy Hack at a Glance
| Detail | Info |
|---|---|
| Date | August 9, 2026, ~13:00 UTC |
| Chains affected | Ethereum, TRON |
| Amount reportedly stolen | $8M+ |
| Laundering method | Conversion into Monero (XMR) via multiple exchanges |
The story moved fast across crypto Twitter/X as security researchers and outlets picked it up within hours of the drain.
Several media outlets have reported that a substantial amount of funds associated with the incident was stopped while passing through ChangeNOW infrastructure. Our AML team is actively working on the case and cooperating with the relevant parties and authorities.



