Token Collapse: From $0.166 to Near Zero
On January 8, 2026, the native token of Truebit — a verification and orchestration layer for tokenized assets — suffered a catastrophic exploit. The TRU token, which had been trading around $0.1663 prior to the attack, crashed by 99.95% to $0.00005417 by 3 p.m. EST. The sudden collapse erased nearly the entire market value of the token within hours.
The Anatomy of the Attack
Blockchain security firm Cyvers Alerts first detected the anomaly, flagging a suspicious on-chain transaction. According to its report, a single address received approximately 8,535 ETH (worth about $26 million at the time) through a transaction labeled “Truebit Protocol: Purchase.” The activity was flagged based on behavioral risk indicators in Cyvers’ detection models.
Preliminary investigations revealed that the exploit targeted a mispriced minting function in the protocol’s purchase contract. This flaw, embedded in a contract deployed roughly five years ago, allowed attackers to mint and purchase TRU tokens at a fraction of their market value. Social media analyst Weilin Li commented, “It seems old contracts are getting more ‘popular’ among attackers now.”
Team Response and Ongoing Investigation
Hours after the crash, Truebit acknowledged the incident via X (formerly Twitter). The team issued a safety warning, urging users to avoid interacting with the affected smart contract until further notice. Truebit confirmed it has engaged law enforcement authorities and is taking steps to mitigate the damage. Importantly, the protocol’s statement corroborated Li’s findings that two separate attackers may have been involved in the exploit, potentially increasing the complexity of recovery efforts.
Broader Implications for DeFi
The attack wiped out millions in value for TRU holders and drained significant liquidity from associated pools. It serves as a stark reminder of the risks posed by legacy smart contracts, especially those that have not undergone rigorous re-auditing or updates. Truebit’s role as a verification layer for tokenized assets makes this breach particularly concerning for the wider DeFi ecosystem, highlighting the need for continuous security monitoring and contract upgrades.

