OAK — OnChain Attack Knowledge

Worked example · 2026-08

Coinsbuy — a B2B payment processor's Ethereum and TRON wallets emptied in the same hour, the signature of one signing infrastructure rather than two compromises — Coinsbuy (Ethereum, TRON) — 2026-08-09

Loss
more than $7.9M, drained from wallets associated with Coinsbuy across Ethereum and TRON in a coordinated sequence beginning around 13:00 UTC on 2026-08-09. The largest single crypto loss reported in August 2026 up to that date. Proceeds were routed through multiple exchanges and converted into Monero; ChangeNOW reportedly froze a six-figure amount linked to the stolen funds. Coinsbuy paused deposits and withdrawals and later resumed service.
OAK Techniques observed
OAK-T11.011 (Multi-chain Key-store Co-location — primary, inferred from the extraction pattern rather than from any disclosed forensic finding. Simultaneous outflows across two chains with independent address formats, signing schemes, and node infrastructure is the diagnostic signature of one compromised signing layer serving both, not of two separate intrusions. Multiple investigators reading the same pattern reached the same conclusion — hot-wallet private keys or elevated administrative privileges rather than a smart-contract exploit. See techniques/T11.011-multi-chain-key-store-co-location.md). OAK-T5.001 (Hard Drain — the on-chain manifestation). OAK-T7.002 (CEX Deposit Layering — proceeds pushed through multiple exchanges and instant-swap services including ChangeNOW, FixedFloat and BingX). OAK-T7.005 (Privacy-Chain Hops — conversion into Monero to break the on-chain trail before freezes could take effect). The initial access vector is not established. Neither Coinsbuy nor any investigator has published how the keys or privileges were obtained, so no T15.x entry-point Technique is recorded — the honest boundary of the public record is "the signing layer was under attacker control", not how it got there.
Attribution
pseudonymous. No named individual or group and no link to a tracked OAK actor. Detection is credited to on-chain investigator SpecterAnalyst, who flagged unusual outflows on Telegram. The laundering pattern — rapid fan-out through instant-exchange services into Monero — is common to a wide range of operators and is not, on its own, an attribution signal. OAK records no state-actor or group inference here; the superficially similar 2023 Alphapo payment-processor compromise carries one, and that similarity is not evidence.
Key teaching point
"Multi-chain" is a product claim; whether the keys are also multi-chain is an architecture question, and only the second one determines blast radius. Ethereum and TRON share no addressing scheme, no client, and no operational tooling — an attacker who compromised each independently would have had to do two different jobs and would almost certainly have shown two different timelines. One hour, both chains, is the pattern of a single signing environment with a shared key store. For any operator holding customer funds across chains, the reusable control is architectural and unglamorous: per-chain key isolation, so that one compromised signer bounds the loss to one chain's float, plus withdrawal thresholds that make a full-float move require an approval path that a stolen key alone cannot satisfy. The second lesson is about who the victim actually is. Coinsbuy is a B2B processor serving merchants and exchanges — the entities whose balances sat in those wallets were businesses that had made a vendor-selection decision, not a custody decision, and most of them had no way to audit the custody architecture they had implicitly adopted. Counterparty custody due diligence is the control that lives on their side of the boundary, and it is almost never exercised.

Summary

Coinsbuy is a B2B cryptocurrency payment processor serving businesses, merchants, and exchanges. On 2026-08-09, starting around 13:00 UTC, wallets associated with the platform began emitting unusual outflows on Ethereum and TRON at the same time. On-chain investigator SpecterAnalyst flagged the activity on Telegram; the total exceeded $7.9M.

Coinsbuy paused deposits and withdrawals and subsequently resumed services. No smart-contract exploit was identified. Multiple investigators observed that simultaneous drains across two structurally unrelated chains point to compromise of hot-wallet private keys or elevated administrative privileges in the platform's own signing infrastructure rather than to a flaw in any deployed contract.

Proceeds were moved quickly. Funds were routed through multiple exchanges and pushed into Monero using instant-swap services — ChangeNOW, FixedFloat and BingX appear in public reporting — an offramp pattern designed to break the on-chain trail before freeze requests could propagate. ChangeNOW reportedly froze a six-figure amount connected to the funds; no other freeze totals have been published.

At the time, this was the largest reported crypto loss of August 2026, and it sat inside a week that also produced the Coreum bridge drain, the Oraichain unauthorised mint, and the Harmony mint incident.

Timeline (UTC)

When Event OAK ref
(standing) Coinsbuy operates hot wallets on Ethereum and TRON; the extraction pattern implies their signing key material shared one infrastructure layer (standing T11.011 surface)
(pre-event) Initial access obtained — vector never disclosed (not established)
2026-08-09 ~13:00 Coordinated outflows begin from Coinsbuy-associated wallets on Ethereum and TRON simultaneously T11.011 → T5.001
2026-08-09 SpecterAnalyst flags the unusual outflows on Telegram; total passes $7.9M (external detection)
2026-08-09 Coinsbuy pauses deposits and withdrawals M34
2026-08-09 onward Proceeds routed through multiple exchanges and swapped into Monero via ChangeNOW, FixedFloat and BingX T7.002 → T7.005
2026-08-09 onward ChangeNOW reportedly freezes a six-figure amount tied to the stolen funds M41
post-event Coinsbuy resumes services; no root-cause disclosure, no reimbursement terms published (operator response)

What defenders observed

  • Pre-event (co-location is visible in the incident, not before it). The clearest evidence that key material was shared is the drain itself. That is exactly why the control must be architectural: an operator cannot detect co-location at runtime, only inventory it at design time. The question to ask before an incident is "if one signing environment falls, how many chains' float leaves?" (M37).
  • Pre-event (hot-float sizing is the real loss-limiting control). Whatever the entry vector, the ceiling on this incident was set by how much sat in hot wallets. Cold-majority custody with rate-limited replenishment converts a total hot-float loss into a bounded one, and it is the only mitigation that works regardless of how the keys were obtained (M19, M38).
  • At-event (simultaneous cross-chain outflow is a high-quality alert). Two chains, one hour, no contract interaction. For any operator with multi-chain float, a correlation alarm on near-simultaneous outflows across unrelated chains is cheap, has almost no false-positive population in normal operations, and fires on the exact minute this began (M39).
  • Detection (an outsider on Telegram was first). The initial public signal came from an independent investigator, not from the processor's own monitoring. That ordering recurs across the July–August 2026 cohort and is worth stating plainly: external watchers are currently outperforming operator telemetry, and operators should treat that as a finding about their instrumentation.
  • Response (the laundering path was chosen against the freeze clock). Fan-out through instant-swap services into Monero is a race: every hop before the freeze requests land is a hop that cannot be reversed. The six-figure ChangeNOW freeze against a $7.9M loss is the honest measure of how that race went (M41, M43).
  • Response (silence about root cause is itself a data point). Service resumed without a published cause, so the merchants and exchanges whose balances were held cannot evaluate whether the condition that produced the loss still exists. For a B2B processor this is a materially different disclosure obligation than for a retail product, and the absence is the observation.

Public references

Discussion

Coinsbuy is a textbook T11.011 case precisely because nothing about the mechanism was disclosed and the Technique is still legible. The classification does not rest on a postmortem; it rests on the shape of the outflow. Ethereum and TRON have different address formats, different signing libraries, different node software, and different operational tooling. An attacker compromising them separately would face two distinct jobs and would almost certainly leave two distinct timelines. One hour across both is the signature of a shared signing layer, and OAK records it as inferred from pattern rather than confirmed by disclosure — a distinction contributors should preserve, because it is the difference between reading evidence and importing an assumption.

The comparison worth drawing is to Alphapo (2023-07), another payment processor whose multi-chain hot wallets emptied at once. The structural lesson repeats: payment processors concentrate other people's money in hot infrastructure by the nature of the business — funds must be spendable on demand — and that makes hot-float sizing, not perimeter hardening, the load-bearing control. What does not carry over is attribution. Alphapo is attributed; Coinsbuy is not, and the laundering pattern here is common to a wide population of operators. Contributors should resist the pull of the adjacent case: similar victim profile and similar extraction shape are not attribution evidence, and OAK's per-item attribution-strength labels exist specifically to stop that inference from propagating.

The last point is about who carries the risk. Merchants and exchanges using a processor are making a vendor decision; the custody architecture behind that decision is invisible to them and rarely covered by any assurance they receive. Until a processor publishes how it isolates keys per chain, how much float sits hot, and what approval path a full-float withdrawal must clear, its customers are accepting an unpriced concentration risk. That is a due-diligence question with a concrete list of answers, and this incident is a good argument for asking it before selecting a processor rather than after reading about one.

Techniques demonstrated (4)