Coinsbuy $7.9M Cross-Chain Hack Spotlights Ongoing Crypto Infrastructure Exploits
Coinsbuy wallets lost roughly $7.9 million across Ethereum and TRON on August 9 in a reported crypto wallet exploit. The payment provider responded with a

Summary
- Coinsbuy wallets lost roughly $7.9 million across Ethereum and TRON on August 9 in a reported crypto wallet exploit.
- The payment provider responded with a $100,000 bounty and full coverage of client losses during its investigation.
- BTCPay Server issued an urgent patch to version 2.4.2 after active exploitation of a flaw exposing LND credentials.
Coinsbuy lost roughly $7.9 million on August 9. Attackers drained wallets on Ethereum and TRON at once. On-chain trackers watched the funds head toward Monero.
This incident fits a larger pattern. Payment services keep getting hit.
Context
Crypto payment services face targeted exploits that drain hot wallets holding customer assets. The Coinsbuy incident follows similar drains reported at other firms this year. These attacks often combine technical weaknesses with rapid fund movement across chains to complicate tracing.
The TRON Ethereum drain highlights risks in multi-chain operations where providers maintain balances on separate networks. On-chain analysts noted the funds' conversion path shortly after the August 9 transfers. Such patterns reduce visibility once assets reach privacy-focused chains.
Details
Coinsbuy announced a $100,000 bounty and stated it would cover all client losses while the probe continues. Security teams are examining the breach vectors that allowed simultaneous access on two blockchains. Investigators from multiple firms have published wallet addresses tied to the outflows.
"Coinsbuy offers a $100000 bounty after a reported $7.9 million wallet hack, while covering client losses and investigating the breach."
, On-chain reports
BTCPay Server released version 2.4.2 to close a critical flaw that exposed Lightning Network Daemon credentials. Attackers had already stolen funds from unpatched merchant instances before the patch. The project urged all operators to update immediately.
The BTCPay Server vulnerability affected all prior versions and allowed direct credential theft. Merchants running older releases remained exposed until the fix deployed. Limited scope to unpatched instances has so far contained broader fallout.
Crypto payment infrastructure faces ongoing exploit risks that demand rapid patching and transparent response. The Coinsbuy hack and BTCPay Server vulnerability together show how single points of failure can affect multiple chains and user bases at once.
What comes next is continued on-chain monitoring of the Monero-laundered funds and verification that all BTCPay Server instances have applied the 2.4.2 update. Payment providers will likely accelerate audits of cross-chain wallet controls.