
Wallets tied to crypto payments platform Coinsbuy were reportedly drained of more than $7.9 million in funds spanning Ethereum and TRON on Sunday, according to blockchain investigator SpecterAnalyst.
In a Telegram post, SpecterAnalyst said the attacker began routing the stolen assets into Monero via exchanges. The investigator also reported that ChangeNOW helped freeze a six-figure portion of the funds during the incident.
Key takeaways
- SpecterAnalyst alleges attackers moved stolen Ethereum and TRON funds into Monero through exchanges.
- ChangeNOW is reported to have frozen part of the assets, reducing what the attacker could immediately keep.
- Coinsbuy paused deposits and withdrawals after the incident, then restored both services.
- Coinsbuy says it covered all affected client funds from its own reserves, without client losses.
- The company offered a $100,000 reward for information identifying the responsible parties.
Reported theft and fund movement
SpecterAnalyst’s report claims the compromise involved multiple wallet addresses connected to Coinsbuy. The investigator identified three addresses associated with the stolen activity: two Ethereum addresses and one TRON address.
Rather than leaving the funds on-chain, the alleged operator reportedly initiated transfers aimed at increasing privacy. SpecterAnalyst stated that the attacker routed the proceeds into Monero through exchanges, a path commonly used in laundering attempts where the goal is to obscure fund trails across networks.
The investigator further indicated that ChangeNOW played a role in limiting the damage by freezing a portion of the stolen assets—described as a six-figure amount—after the incident began.
Coinsbuy confirms incident and compensates clients
Coinsbuy acknowledged the security incident in a statement shared with Cointelegraph, saying unauthorized withdrawals affected several platform wallets. The company said the impact was handled internally: all affected client funds were “fully covered… from our own reserves,” according to Coinsbuy’s statement, meaning users did not suffer financial losses.
Coinsbuy also stated that operations were restored and that the platform is “back to operating normally,” with deposits and withdrawals available again. In the immediate aftermath of the reported hack, the platform had temporarily paused those functions, a step that typically aims to stop further outflows while incident response teams assess wallet activity and implement controls.
While SpecterAnalyst reported a theft of more than $7.9 million, Coinsbuy did not confirm or dispute that figure. The company said it is investigating the event, but will refrain from disclosing technical details until the investigation is complete and its findings have been verified.
Reward program and what to watch next
Beyond compensating users, Coinsbuy said it is offering a $100,000 reward for information that leads to identification of those responsible. It also added that there would be an additional bonus for help recovering the stolen funds.
For affected users and monitoring communities, the most important open questions now center on how the compromise occurred and what controls failed—or were circumvented. Coinsbuy’s decision not to publish technical details yet means observers will need to watch for later disclosures that can clarify whether this was primarily a custody issue, an operational security lapse, a smart contract problem (if applicable), or something else entirely.
Given SpecterAnalyst’s claim that stolen funds were moved toward Monero via exchanges, the timeline for additional enforcement and tracing will likely depend on how quickly exchanges and compliance partners can identify related transactions and block further conversion or withdrawal routes. The reported freezing of a portion of funds highlights that intervention can matter during the early hours of such incidents, but it does not automatically indicate how much remains recoverable.
How this fits the broader crypto payments risk picture
Incidents like this underscore a persistent challenge for crypto payments and custody-adjacent businesses: even when clients are made whole, platform wallets become an attractive target because they concentrate balances, enable faster movement, and can provide an immediate payout surface if access controls are breached.
Coinsbuy’s statement that it covered client funds from reserves is a useful data point for users evaluating risk around payment providers—compensation reduces direct losses, but it still signals that operational disruptions can happen and that recovery efforts may be complex. The temporary halt in deposits and withdrawals also reflects the standard incident-response pattern: contain outflows, assess exposure, and then reopen services once systems are deemed stable.
Investors and builders in the sector may also want to pay attention to what controls Coinsbuy says it will improve later. The lack of technical disclosure right now makes it difficult to assess whether similar weaknesses could affect other platforms using comparable wallet management, exchange integrations, or withdrawal workflows.
Next, readers should look for updates from Coinsbuy’s investigation—especially any verified technical findings—and for additional reporting on whether more of the stolen funds can be traced, frozen, or recovered as the laundering path into Monero and off-chain exchange activity unfolds.
https://www.cryptobreaking.com/coinsbuy-launches-100k-bounty-after/?utm_source=blogger%20&utm_medium=social_auto&utm_campaign=Coinsbuy%20Launches%20$100K%20Bounty%20After%20Sunday%20Security%20Breach%20
Comments
Post a Comment