Truebit’s TRU token nearly collapsed on Thursday after an exploit drained about 8,535 ETH from the protocol’s reserves, worth roughly $26.6 million at the time. Following the breach, TRU fell as much as 99.9% as liquidity dried up and holders rushed for the exit.
Truebit, an Ethereum-based verification and computation project, said it was aware of a security incident involving one or more malicious actors. The team said it was in contact with law enforcement and was taking steps to respond. At the time of publication, the protocol had not released a full post-mortem and had not confirmed whether the affected contracts were paused.
An old contract appears to be at the center of the attack
Lookonchain estimated the loss at 8,535 ETH. Researcher Weilin Li said the exploit likely came from a flaw in an older smart contract deployed around five years ago. In that contract, a minting function could return a purchase price of zero for an unusually large TRU buy.
That pricing error let the attacker acquire TRU at almost no cost, then sell the tokens straight back into the bonding-curve reserve and pull out ether. Independent onchain researcher “n0b0dy” described the pattern as repeated buy-and-sell loops. As the reserve balance shifted, the mispricing kept working in the attacker’s favor, allowing the pool to be drained over time. The wallet involved reportedly paid a small builder bribe to get transactions prioritized.
Liquidity vanished as the reserve was drained
The market reaction was immediate. TRU suffered a near-total collapse once the exploit hit the reserve backing the token, and available liquidity thinned out fast. The move was tied not just to panic selling but to the reserve mechanism itself: as ETH was extracted from the bonding curve, the token lost the support that had been anchoring its market.
The incident adds to a familiar risk in DeFi. Even when current protocol code has been updated, legacy deployments can stay exposed for years. If those older contracts still hold value or remain connected to reserve assets, forgotten pricing logic can turn into a live attack path.

