Crypto World
Coinsbuy Announces $100K Reward After Sunday Security Breach
Crypto payments platform Coinsbuy says it has covered all client losses after wallets tied to the service were allegedly drained on Sunday. Blockchain investigator SpecterAnalyst reported that more than $7.9 million was moved out across Ethereum and TRON, with parts of the proceeds routed through exchanges and into Monero.
According to SpecterAnalyst’s Telegram post, the attacker initially began converting the stolen funds into Monero via exchange activity. The same report claimed ChangeNOW was involved in freezing a six-figure portion of the assets during the incident.
Key takeaways
- Coinsbuy confirmed an Aug. 9 security incident and stated affected client funds were fully covered from its own reserves.
- SpecterAnalyst alleged that attackers moved over $7.9 million across Ethereum and TRON, with additional steps to route value into Monero.
- Coinsbuy temporarily paused deposits and withdrawals, later restoring both services to normal operations.
- The platform offered a $100,000 reward for information leading to the identification of those responsible, with an extra bonus for help recovering the funds.
Alleged multi-chain drain and attempts to obscure proceeds
SpecterAnalyst’s report focused on on-chain activity tied to Coinsbuy-linked wallets. The investigator said the stolen funds were routed through multiple addresses and then moved onward into Monero through exchange interfaces, a strategy commonly associated with attempts to reduce traceability.
In the same Telegram post, SpecterAnalyst identified three addresses linked to the compromised funds—two on Ethereum and one on TRON—suggesting the attacker exploited access across more than one network rather than relying on a single chain or transfer pattern.
The alleged scale is central to why this case matters for the broader payments market: payments platforms typically sit at a crossroads between user custody, exchange-like routing, and business workflows. When that infrastructure is compromised, the incident can quickly ripple from a single compromised wallet into large cross-chain movements.
Coinsbuy response: coverage from reserves and operational restart
Coinsbuy acknowledged the incident in a statement shared with Cointelegraph. The company said unauthorized withdrawals affected several platform wallets, but that all affected client funds have been fully covered from its own reserves—meaning users were not expected to bear direct financial loss.
Coinsbuy also said the platform is back to normal operation, with deposits and withdrawals restored. SpecterAnalyst previously reported that Coinsbuy temporarily paused both deposits and withdrawals following the incident before reinstating service.
While Coinsbuy did not confirm or dispute the reported $7.9 million figure attributed by SpecterAnalyst, it did not provide additional technical details during the early stages of investigation. The company said it is still investigating and plans to disclose technical information only after its review is complete and findings are verified.
Freezing assistance and what remains unclear
SpecterAnalyst claimed that ChangeNOW helped freeze a six-figure portion of the assets during the incident. That point is important for investors and operators because it highlights how quickly counterparties can sometimes mitigate exposure once abnormal flows become apparent. At the same time, the overall timeline, the exact mechanism used by the attacker, and the full extent of assets that were frozen versus successfully moved were not fully substantiated in the publicly available reporting.
Coinsbuy’s statement did not detail the attack method or explain whether compromised keys, misconfigured permissions, or another failure mode was responsible. For readers, the key takeaway is that the public narrative currently rests on investigator tracing of blockchain activity and the platform’s assurance of coverage, rather than on confirmed technical findings.
Given that the platform is delaying technical disclosure until verification, what watchers should monitor next is whether Coinsbuy’s eventual investigation identifies the initial breach vector and whether it leads to changes in internal controls, monitoring, or custody procedures across its networks.
Incentives for information and possible recovery efforts
Beyond covering client funds, Coinsbuy said it offered a $100,000 reward for information that leads to identifying those responsible. The platform also indicated it would provide an additional bonus for help recovering stolen funds.
Rewards of this type can be a practical lever for incident response, especially when stolen assets are dispersed across exchanges and networks. They can also encourage third parties—such as analysts who can link wallets to identities or brokers who may have custody-relevant information—to share actionable details before assets become permanently difficult to trace.
For users of crypto payments infrastructure, the reward plus coverage stance provides some near-term stability, but it does not eliminate the longer-term concern that vulnerabilities in operational security can recur if root causes are not addressed. The most consequential follow-up will be whether Coinsbuy’s later disclosures point to structural weaknesses that can affect other platforms with similar architectures.
As Coinsbuy continues its investigation and refrains from releasing technical details for now, the next signals to watch are: any confirmed update on the attackers’ initial access method, whether additional funds beyond what was reportedly frozen can be recovered, and what operational or custody safeguards the company says it will change after verification.
You must be logged in to post a comment Login