Coinsbuy offers $100K bounty after reported $7.9M hack

Coinmama
Blockonomics


Coinsbuy has offered a $100,000 reward for information identifying those behind unauthorized withdrawals that reportedly drained more than $7.9 million from its Ethereum and TRON wallets.

Summary

  • Coinsbuy offered a $100,000 identification bounty and an additional asset-recovery bonus.
  • The company said all affected client funds were covered using its reserves.
  • Investigators traced stolen assets through exchanges, with some funds reportedly converted into Monero.
  • Coinsbuy restored deposits and withdrawals but has not disclosed the attack method.

Coinsbuy launches $100K identification bounty

Coinsbuy announced the reward after confirming that unauthorized withdrawals affected several platform wallets on Aug. 9. The Panama-incorporated crypto payments company did not confirm or dispute the $7.9 million loss estimated by blockchain investigators.

The $100,000 reward will go to anyone who provides information leading to the identification of those responsible. Coinsbuy also promised an additional, unspecified bonus for assistance in recovering the stolen assets.

coinbase

Coinsbuy said it is investigating the incident but will withhold technical details until its findings are complete and independently verified. No suspect or attack method has been publicly identified.

Blockchain investigator SpecterAnalyst initially reported that Coinsbuy-linked wallets lost more than $7.9 million across Ethereum and TRON at around 13:00 UTC on Sunday.

PeckShield later traced parts of the funds through ChangeNOW, FixedFloat, and BingX. ChangeNOW reportedly froze a six-figure amount before it could be moved further.

Coinsbuy covers affected customer balances

Coinsbuy temporarily suspended deposits and withdrawals after detecting the activity. Both services have since resumed, and the company said the platform is operating normally.

“All affected client funds have been fully covered by Coinsbuy from our own reserves, so our users have not experienced any financial losses.”

The company added that all services were fully available. Separate reporting indicated that Coinsbuy replenished the affected wallets to within 0.05% of their balances before the incident within 24 hours.

Around 282 ETH, valued at approximately $542,000 at the time, remained unmoved across five addresses in the latest reported on-chain review. Coinsbuy has not disclosed how much of the remaining cryptocurrency has been recovered or frozen.

The attacker reportedly routed portions of the assets through exchanges for conversion into Monero (XMR), a privacy-focused cryptocurrency that makes subsequent fund tracing more difficult.

Bounty follows other crypto recovery offers

Coinsbuy’s fixed identification reward differs from the percentage-based vulnerability bounties sometimes offered directly to exploiters in exchange for returning stolen assets.

In July, a TrustedVolumes attacker returned about $2 million in Ethereum while retaining another $2 million as a self-declared bounty. TrustedVolumes had previously invited the attacker to negotiate a vulnerability reward and return the funds.

Coinsbuy’s offer instead targets information that could identify those responsible, while providing a separate bonus for recovery assistance. The company has not published eligibility rules, a deadline, or payment terms for the reward.

The incident comes after crypto platforms lost approximately $110 million to hacks in July, according to Immunefi. The security platform also reported that confirmed and paid bug reports increased by 18% during the month.

Coinsbuy has not disclosed the attack vector

GoPlus Security said the cross-chain withdrawals appeared consistent with compromised hot-wallet keys or administrator access. This assessment remains unconfirmed, and moving funds across Ethereum and TRON does not, by itself, establish how the attacker entered Coinsbuy’s systems.

No U.S. authority has publicly announced involvement in the Coinsbuy investigation. However, a recent Bybit case showed that affected platforms may use American courts to obtain records and freeze assets passing through services with U.S. connections. Bybit recently secured U.S. court support to trace stolen funds from its $1.5 billion breach.

Coinsbuy said it would disclose further technical information only after completing and verifying its investigation. Until then, the reported loss, precise attack vector, and amount recovered remain unresolved.



Source link

Paxful

Be the first to comment

Leave a Reply

Your email address will not be published.


*