×

Hackers Drain $8 Million From Coinsbuy Across Two Blockchains

Crypto payment processor Coinsbuy was drained of roughly $8 million in a security breach that spanned two separate blockchains, according to on-chain monitoring that first flagged the incident. The Coinsbuy hack marks another attack on a centralized crypto platform, though key details remain unconfirmed by the company.

The alert originated from blockchain security account BlockWatchdog, which reported the theft and its cross-chain scope in a post on X. As of publication, the loss figure and the exact mechanics of the exploit rest on that single monitoring source rather than an official statement. For related coverage, see DOJ Seizes $15M in USDT from North Korean Hackers.

Coinsbuy operates as a business-focused crypto payment gateway, offering wallets and settlement services for merchants, per its company site. That profile matters here: a payment processor holds funds and infrastructure connected to client transactions, which widens the potential impact of any breach. For related coverage, see Ethereum Surpasses 200 Million Non-Empty Wallets for the First Time.

Why a Two-Chain Exploit Complicates the Response

The reported attack did not stay confined to one network. A theft that moves across two blockchains forces defenders to track stolen assets on separate ledgers, each with its own explorers, bridges, and liquidity paths. For related coverage, see Marathon Digital Holdings Sells 23,093 Bitcoin for $1.6B in H1 2026.

Cross-chain movement typically makes tracing and recovery harder, because attackers can hop assets between networks to break the trail. That dynamic has featured in prior incidents, including a case where fake bridge messages let a hacker drain funds by abusing the connective tissue between chains.

For a payment platform tied to multiple chains, the attack surface scales with each supported network. More integrations mean more contracts, hot wallets, and signing systems that all need to hold, and any single weak point can expose funds across the stack.

What the Breach Means for Coinsbuy Users

The most immediate questions fall on customers: whether deposits are safe, whether withdrawals remain open, and whether reserves cover the shortfall. Until Coinsbuy issues a formal accounting, those answers are unresolved.

An eight-figure loss is large enough to raise user-protection and reserve concerns for any centralized service. Recovery efforts in comparable cases have sometimes involved law enforcement, as when the DOJ seized $15 million in USDT tied to North Korean hackers, showing that stolen crypto is not always permanently lost.

The episode reinforces the standard expectations placed on custodial platforms after a breach: transparent incident disclosure, a security audit of the affected systems, and clear guidance to users. It also echoes the broader pressure on centralized exchanges and processors, including situations where platforms wind down and tell customers to move funds, as with the Fireplace shutdown and migration notice.

Coinsbuy has not published a confirmed timeline, root-cause analysis, or reimbursement plan at the time of writing. This report will be updated if the company or independent investigators verify the scope of the loss.

Additional source references: source document 1.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.