On Jan. 8, 2026, the Truebit protocol's native token (TRU) crashed 99.95% to near-zero after hackers exploited a vulnerability, draining approximately $26 million in digital assets. Security firm Cyvers Alerts detected the anomaly when a single address siphoned roughly 8,535 ETH via a transaction labeled "Truebit Protocol: Purchase."
Anatomy of the Attack
Market data shows TRU was trading near $0.1663 before the breach, then collapsed to $0.00005417 by 3 p.m. EST. Cyvers reported that the attack resulted in a total loss of about $26 million. Preliminary investigations revealed that the exploit targeted a mispriced minting function within the protocol's purchase contract, deployed roughly five years ago. Social media analyst Weilin Li remarked, "It seems old contracts are getting more 'popular' among attackers now."
Hours after the crash, Truebit acknowledged the incident via X (formerly Twitter), issuing a safety warning and advising users to avoid interacting with the affected smart contract. The team confirmed it has engaged law enforcement and is taking steps to mitigate damage. The statement also hinted that two separate attackers may have been involved.
Community and Response
The incident underscores the risks of legacy smart contracts in DeFi. Truebit is collaborating with security experts to recover funds and patch vulnerabilities. Investors are urged to monitor official channels and refrain from interacting with the compromised contract addresses. Analysts emphasize the need for projects to conduct regular audits and updates of older contracts.

