Truebit Exploit Drains About $26 Million in Ether as TRU Crashes More Than 99%

Truebit Exploit Drains About $26 Million in Ether as TRU Crashes More Than 99%

N
News Editor 01
2026-07-24 08:35:17
Truebit disclosed a smart-contract security incident tied to about 8,535 ETH in losses, while TRU fell more than 99% as the market reacted to the breach.

Truebit’s TRU token collapsed by more than 99% after the project disclosed a security incident linked to roughly 8,535 ETH in losses, worth about $26.6 million at the time, according to on-chain analysts.

In a post on X, Truebit said it had identified “an incident of security involving one or more malicious actors” connected to a smart-contract address. The team said it was in contact with law enforcement and was taking available measures after the breach, but had not released a detailed technical post-mortem by the time of publication. While the contract address highlighted by Truebit showed only small amounts of stolen Ether, blockchain trackers including Lookonchain pointed to a wider trail of fund movements and said the total crypto taken in the attack exceeded $26 million.

TRU price fell from around $0.16 to near zero

Data from Nansen showed TRU dropping from about $0.16 to an all-time low near $0.0000000029 as reports of the exploit spread. The immediate selloff reflected how quickly traders repriced the token once the breach became public. At that stage, it was still unclear what triggered the exploit or whether user funds held on the protocol were directly exposed, and the source material noted that Truebit had not responded to a media request for comment.

December also brought a Flow counterfeit-token attack

The Truebit incident came after several other security failures in December. On Dec. 27, 2025, the Flow Foundation said an attacker had exploited a vulnerability in the Flow network to counterfeit tokens and extract about $3.9 million. In its technical post-mortem, Flow said no existing user balances were accessed or compromised. The attack duplicated assets rather than touching legitimate holdings. Validators coordinated a network halt within about six hours of the first malicious transaction, and most counterfeit assets were later frozen on-chain or recovered and destroyed with help from exchanges.

Trust Wallet confirmed losses tied to a malicious extension build

Trust Wallet also disclosed a serious issue involving its Chrome browser extension. The company said version 2.68 included malicious code that allowed an attacker to access sensitive wallet data and drain user funds, leading to estimated losses of around $7 million. Users were told to update to version 2.69, and the company started a reimbursement process while warning about fake compensation forms and impersonated support accounts. CEO Eowyn Chen said the malicious build was most likely published externally through the Chrome Web Store API key, bypassing the company’s standard release checks.

Monthly losses dropped even as major cases kept surfacing

PeckShield data showed total losses from hacks and exploits across the crypto sector fell to about $76 million in December, down from roughly $194 million in November. The aggregate figure moved lower, but the month still included several high-profile incidents that drew attention across the market.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.