Truebit Protocol was hit by a major security breach after attackers exploited a pricing flaw in its Purchase smart contract, draining 8,535 ETH, worth about $26 million according to the report. The incident was dated January 8, 2026. In the aftermath, the TRU token fell 99.99%, pushing its market price close to zero.
Purchase contract flaw let attackers mint TRU cheaply
The affected contract was identified as 0x764C64b2A09b09Acb100B80d8c505Aa6a0302EF2. Based on the source material, the bug sat in the contract’s pricing logic, allowing attackers to mint TRU tokens for almost no cost in ETH. They could then sell the newly minted tokens and pull large amounts of value out of the protocol. The report also mentioned a separate, smaller attack that took roughly $250,000.
The article described the breach as one of the largest DeFi hacks recorded in 2026. Some of the stolen funds were said to have moved through Tornado Cash, an apparent attempt to obscure the trail.
Cyvers and Forta flagged suspicious activity quickly
Blockchain security firm Cyvers Alerts detected the abnormal transfers in real time and labeled them suspicious. Forta also identified the exploit soon after. That put immediate attention on the scale of the loss and on the security controls around the compromised contract.
After confirming the breach, Truebit advised users to stop interacting with the affected contract. The team also said it was working with law enforcement to trace the attackers, with updates being shared through official channels as the investigation continued.
TRU price crash reignites audit concerns
The token reaction was severe and immediate. According to the cited 24-hour market data, TRU dropped 99.99%, moving from normal trading levels to almost worthless within a very short period. Holders were left facing a near-total collapse in token value.
Discussion in the community also turned to contract review practices. The source said Truebit had no officially recorded audit for the affected contract, despite using the slogan “Don’t just trust, verify”. In this case, the exploit showed how a single pricing weakness in a DeFi contract could turn into a protocol-wide loss before the market had time to react.

