According to BlockWatchdog, another 282.2 ETH, worth about $542,000 at the time of the attack, remained untouched across five addresses.
Hours after the theft, Coinsbuy replenished the affected wallets, with BlockWatchdog reporting that around $3.93 million was returned to the same 10 addresses, with seven deposits matching the amounts originally stolen to within 0.05%.
“That only makes sense if the team does not believe the private keys leaked,” BlockWatchdog wrote. “An address is a key: nobody tops up a compromised wallet with seven figures twice in one night. Whatever was taken over on 9 August sat above the keys—the withdrawal path that uses them.”
While the exact attack vector is unknown, BlockWatchdog said the attacker may have gained access to Coinsbuy’s withdrawal system.
“Nothing on-chain shows how the withdrawal path was reached—the refill argues against key theft, it does not name what replaced it,” they wrote. “No attribution either: zero address overlap with the Triple-A attacker of 24 July, and a different laundering habit.”
BlockWatchdog found no address overlap with the attacker behind the July 24 Triple-A hack and noted different laundering patterns.
Coinsbuy had not publicly explained how the attacker gained access at the time of BlockWatchdog’s analysis.
Coinsbuy did not immediately respond to a request for comment by Decrypt.


















