🚨 GoPlus Security Alert:
B2B crypto payment processor
@coinsbuycom had associated wallets drained on Ethereum + TRON for ~$7.9M.
Attacker then laundered via Monero/XMR, routing through CEXs including ChangeNOW / FixedFloat / BingX.
1. Coinsbuy’s X has been dormant since 2020, but their developer docs keep getting updates:
2. Attack pattern fits hot-wallet private key or admin privilege compromise.
In the 2026-07-10 release notes they just fixed:
“Fixed transportation transfers being confirmed without verifying the collected amount against the deposits actually received on the node — a mismatch now raises an incident instead of silently overstating the Locked in node balance and causing false insufficient funds errors later.”
Doesn’t directly prove the root cause of this drain, but shows how complex their transfer / node / fund-consolidation logic is — high-risk surfaces on both ops and accounting layers.
3. Attacker addresses:
0x4d1bEF2Fe998B3E3C4029EF9EA6A0534d95661d3
0x66790b54B891e2ebdef58a15B969Ff6fb4374b17
TVpX9xCzrj6KHeNhhDJoqjzEqFMxdgubGR
h/t:
@SpecterAnalyst ’s Telegram channel