Truebit Protocol Exploited for $26M, TRU Token Crashes 99.95%

Truebit Protocol Exploited for $26M, TRU Token Crashes 99.95%

N
News Editor 01
2026-07-09 00:34:15
On Jan. 8, an exploit targeting a mispriced minting function in an old Truebit contract led to a $26 million loss and a 99.95% collapse in the TRU token price. The team warned users and engaged law enforcement.
TruebitTRU tokensmart contract exploitsecurity breachprice crash

On Jan. 8, the native token of the Truebit protocol, TRU, suffered a catastrophic 99.95% price drop after a hacker exploited a vulnerability in a purchase contract deployed roughly five years ago. Trading at approximately $0.1663 before the breach, TRU fell to $0.00005417 within hours, nearly wiping out its entire market value.

Anatomy of the Attack

Blockchain security firm Cyvers Alerts detected the anomalous transaction, reporting that a single address siphoned about 8,535 ETH (worth an estimated $26 million) through a transaction labeled “Truebit Protocol: Purchase.” The firm flagged the activity based on behavioral risk indicators in its detection models. Initial investigations reveal that the exploit targeted a mispriced minting function within the protocol’s purchase contract, allowing the attacker to mint and sell TRU tokens at a fraction of their fair market price. Social media analyst Weilin Li noted that the compromised contract had been deployed five years ago, remarking, “It seems old contracts are getting more ‘popular’ among attackers now.”

Response and Ongoing Investigation

Hours after the crash, the Truebit team acknowledged the incident on X (formerly Twitter) and issued a safety warning, urging users to avoid interacting with the affected smart contract until further notice. The protocol confirmed it has engaged law enforcement and is taking steps to mitigate the damage. In its statement, Truebit also hinted at the possibility that two separate attackers were involved, aligning with Li’s earlier findings.

Market Impact and Broader Implications

The sudden collapse of TRU has sent shockwaves through the crypto community. As a verification and orchestration layer for tokenized assets, Truebit relied on its native token for network security and incentivization. The exploit underscores the persistent risks of legacy smart contracts in an ecosystem where code ages without adequate maintenance. Security experts are urging all projects using similar purchase or minting functions to audit their logic immediately and consider implementing circuit breakers to prevent such losses.

Truebit has not yet disclosed a recovery plan for affected holders, but community members are calling for transparent post-mortems and potential compensation. Meanwhile, this incident serves as a stark reminder that even years-old contracts can become ticking time bombs if left unpatched. As DeFi activity continues to grow, attackers are increasingly targeting overlooked vulnerabilities in older codebases.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.