Coinsbuy told its users it had made them whole. Within hours of an $8 million drain on August 9, the payment processor pushed a wave of deposits back into the emptied wallets and said the affected balances were replenished.
On-chain, the refund tells a narrower story. Roughly $3.93 million landed back, about half of what left. The other half is still gone, and the way it left points at Coinsbuy's own plumbing rather than a leaked key.
The theft hit two chains at once. On Tron, eight wallets gave up more than 6 million USDT. On Ethereum, three more wallets lost 1.89 million USDT and 77 ETH. The attacker opened with a 5 USDT test transfer on Tron, confirmed the path was live, then moved the rest in coordinated pulls. That choreography is what makes the private-key explanation hard to accept.
The refill is the tell
Blockchain investigator BlockWatchdog flagged the detail the headlines skimmed. Coinsbuy topped several compromised wallets back up with seven-figure sums during the same night the attacker was draining them. "An address is a key: nobody tops up a compromised wallet with seven figures twice in one night," the firm noted. If the keys were in a stranger's hands, refunding those exact addresses would just hand the thief a second payday.
The behavior fits a compromised withdrawal system, where the platform still holds the keys but the machinery that authorizes payouts was turned against it. That is a different failure from the single stolen key that drained a MiCA-licensed stablecoin, and it is the internal weakness that crypto's move past pure code exploits keeps exposing.
Where the missing half went
The seven refunded deposits matched the original stolen amounts to within 0.05 percent, which is why the restored total lands so cleanly near four million. The remainder followed a laundering script. Monitoring firm Specter tracked the funds routing toward Monero, funneled through one or more exchanges before the privacy-coin conversion. ChangeNOW froze a six-figure sum in transit, a small fraction and a familiar pattern for anyone who watched the Kelp exploiter move nine figures through mixers. Freezing funds mid-flight works when a venue cooperates fast, the way Arbitrum reached into a hacker's wallet, but Monero shuts that door once the swap clears.
A bad year for the cashier's desk
Coinsbuy has restored services and posted a $100,000 bounty for information on the attackers, plus a bonus tied to recovery. It arrives inside a theft spree that has crossed $972 million this year, on exchange infrastructure that keeps buckling in public. Users who watched BitMart reopen withdrawals for only 58 wallets have learned to read "replenished" carefully. The Coinsbuy refund was real. It was also partial, and until the company explains how its withdrawal system got turned, the safer read is that the cashier's desk, not the vault, is where this went wrong.