The $8 million drain of Coinsbuy across TRON and Ethereum marks the latest case where a single on-chain footprint ties two blockchain networks into one attack narrative. According to the original report , forensic analysis has connected the exploitation of the exchange to one actor, with the stolen funds primarily routed through the non-custodial platform FixedFloat.
The attack, which unfolded early on 10 August 2026, siphoned assets from wallets operating on both TRON and Ethereum. On-chain data shows the attacker rapidly dispersed tokens into a chain of intermediary addresses before funnelling them toward FixedFloat swap contracts. The ability to link the two disparate chains in real time suggests a level of orchestration that is becoming more common as cross-chain infrastructure grows.
Linking Two Chains to One Actor
Forensic firms traced the movement of funds and discovered that identical behavior patterns and overlapping address clusters appeared on both networks almost simultaneously. The entity behind the drain did not rely on a single-chain exploit but rather executed a synchronized assault, moving assets between TRON’s USDT liquidity and Ethereum-based tokens before converging on a single exit route. Such coordination implies deep familiarity with how these blockchains handle contract interactions and bridging mechanisms.
Both TRON and Ethereum continue to rank among the top blockchains by developer activity, as highlighted in a recent analysis of on-chain development metrics . High activity often means more surface area for exploits, especially when exchanges integrate multiple networks without isolating risk. In Coinsbuy’s case, the exposure was amplified because the attacker could hit two distinct user pools at once without triggering immediate cross-chain alarms.
FixedFloat Becomes a Recurring Laundering Conduit
FixedFloat operates as an instant, non-custodial exchange that does not require KYC for small-value swaps. That design has repeatedly drawn funds from hacks because assets can be automatically swapped without human approval delays. The service has appeared in the aftermath of several other exchange breaches over the last two years, making it a persistent challenge for investigators.
Unlike centralized exchanges that can freeze assets upon request, FixedFloat’s structure offers limited recourse once transactions settle. In the Coinsbuy incident, the majority of the drained $8 million had already been processed through the platform before the exploit became publicly known, leaving little opportunity to intercept the funds. The speed at which the attacker moved the assets—within hours—suggests pre-programmed scripts and a clear exit plan.
Unanswered Questions Around the Attack Vector
The precise method used to compromise Coinsbuy remains unknown. No official disclosure has confirmed whether the breach involved a private key leak, a smart contract vulnerability, a rogue insider, or a manipulation of the exchange’s internal hot wallet management. Forensic firms have only been able to map the outflow, not the intrusion point.
This gap matters because exchanges often fix a specific technical hole after a hack, leaving other weak spots untouched. Without knowing how the attacker gained initial access, users and platform operators are left guessing whether similar vectors exist on other networks or services. The TRON and Ethereum ecosystems share some cross-chain protocols, and the possibility of a bridge-related exploit has not been ruled out.
Broader Exchange Security Under Scrutiny
Centralized exchanges continue to experience multi-million dollar losses despite years of maturing security practices. The Coinsbuy event adds to a series of 2026 incidents where attackers exploited the friction between different blockchain architectures. Regulators in several jurisdictions have begun to demand stricter proof-of-reserves and real-time monitoring of exchange wallets, but enforcement remains inconsistent.
For Coinsbuy users, the immediate impact may include suspended withdrawals while the exchange assesses the damage and works with law enforcement. Whether any portion of the funds can be recovered depends heavily on whether the attacker’s identity can be tied to a centralized off-ramp, a task made harder when FixedFloat serves as the initial mixer. The absence of a clear recovery path leaves affected customers exposed, and the exchange’s reputation will hinge on how transparently it handles the aftermath.
The use of two blockchains in a single, attributable attack also signals a maturation of hostile operational tradecraft. Attackers are moving beyond opportunistic single-chain drains to planned multi-network campaigns that exploit the blind spots between ecosystems. For security teams, this raises the cost of monitoring and defense, because a comprehensive view now requires correlating data across multiple ledgers in near real time.


