Author: Beosin In the early hours of January 9th, a closed-source contract deployed by Truebit Protocol five years prior was attacked, resulting in a loss of 8,Author: Beosin In the early hours of January 9th, a closed-source contract deployed by Truebit Protocol five years prior was attacked, resulting in a loss of 8,

Truebit Protocol security incident analysis and traceability of stolen funds, resulting in losses exceeding $26 million.

2026/01/09 18:40

Author: Beosin

In the early hours of January 9th, a closed-source contract deployed by Truebit Protocol five years prior was attacked, resulting in a loss of 8,535.36 ETH (worth approximately $26.4 million). The Beosin security team conducted a vulnerability and fund tracking analysis of this security incident and shares the results below:

Attack Method Analysis

We will analyze the most significant attack transaction in this incident, with the transaction hash: 0xcd4755645595094a8ab984d0db7e3b4aabde72a5c87c4f176a030629c47fb014

1. The attacker calls getPurchasePrice() to obtain the price.

2. Subsequently, the flawed function 0xa0296215() is called, and the msg.value is set to an extremely small value.

Since the contract is not open source, it is inferred from the decompiled code that the function has an arithmetic logic vulnerability, such as a problem with integer truncation, which allowed the attacker to successfully mint a large number of TRU tokens.

3. The attacker used the burn function to "sell back" the minted tokens to the contract, extracting a large amount of ETH from the contract's reserves.

This process is repeated four more times, with the msg.value increasing each time, until almost all the ETH in the contract has been extracted.

Stolen Funds Tracking

Based on on-chain transaction data, Beosin conducted a detailed fund tracking through its blockchain on-chain investigation and tracking platform, BeosinTrace, and shared the results as follows:

Currently, the stolen 8,535.36 ETH has been transferred, with the vast majority stored at 0xd12f6e0fa7fbf4e3a1c7996e3f0dd26ab9031a60 and 0x273589ca3713e7becf42069f9fb3f0c164ce850a.

Address 0xd12f holds 4,267.09 ETH, and address 0x2735 holds 4,001 ETH. The address from which the attacker launched the attack (0x6c8ec8f14be7c01672d31cfa5f2cefeab2562b50) still holds 267.71 ETH. No further fund transfers have been made from these three addresses.

Analysis chart of stolen funds flow by Beosin Trace

All the addresses listed above have been flagged as high-risk by Beosin KYT. For example, consider the attacker's address:

Beosin KYT

Conclusion

The stolen funds involved smart contracts that were not open-sourced five years ago. For such contracts, project teams should upgrade them, introducing emergency pauses, parameter restrictions, and the security features of the latest Solidity versions. Furthermore, security auditing remains an essential part of contract management. Through security audits, Web3 companies can comprehensively examine smart contract code, identify and fix potential vulnerabilities, and improve contract security.

*Beosin will provide a complete analysis report on all fund flows and address risks. You are welcome to request it via the official email address support@beosin.com.

Market Opportunity
Ethereum Logo
Ethereum Price(ETH)
$3,158.56
$3,158.56$3,158.56
+1.29%
USD
Ethereum (ETH) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Is Doge Losing Steam As Traders Choose Pepeto For The Best Crypto Investment?

Is Doge Losing Steam As Traders Choose Pepeto For The Best Crypto Investment?

The post Is Doge Losing Steam As Traders Choose Pepeto For The Best Crypto Investment? appeared on BitcoinEthereumNews.com. Crypto News 17 September 2025 | 17:39 Is dogecoin really fading? As traders hunt the best crypto to buy now and weigh 2025 picks, Dogecoin (DOGE) still owns the meme coin spotlight, yet upside looks capped, today’s Dogecoin price prediction says as much. Attention is shifting to projects that blend culture with real on-chain tools. Buyers searching “best crypto to buy now” want shipped products, audits, and transparent tokenomics. That frames the true matchup: dogecoin vs. Pepeto. Enter Pepeto (PEPETO), an Ethereum-based memecoin with working rails: PepetoSwap, a zero-fee DEX, plus Pepeto Bridge for smooth cross-chain moves. By fusing story with tools people can use now, and speaking directly to crypto presale 2025 demand, Pepeto puts utility, clarity, and distribution in front. In a market where legacy meme coin leaders risk drifting on sentiment, Pepeto’s execution gives it a real seat in the “best crypto to buy now” debate. First, a quick look at why dogecoin may be losing altitude. Dogecoin Price Prediction: Is Doge Really Fading? Remember when dogecoin made crypto feel simple? In 2013, DOGE turned a meme into money and a loose forum into a movement. A decade on, the nonstop momentum has cooled; the backdrop is different, and the market is far more selective. With DOGE circling ~$0.268, the tape reads bearish-to-neutral for the next few weeks: hold the $0.26 shelf on daily closes and expect choppy range-trading toward $0.29–$0.30 where rallies keep stalling; lose $0.26 decisively and momentum often bleeds into $0.245 with risk of a deeper probe toward $0.22–$0.21; reclaim $0.30 on a clean daily close and the downside bias is likely neutralized, opening room for a squeeze into the low-$0.30s. Source: CoinMarketcap / TradingView Beyond the dogecoin price prediction, DOGE still centers on payments and lacks native smart contracts; ZK-proof verification is proposed,…
Share
BitcoinEthereumNews2025/09/18 00:14
CME Group to launch options on XRP and SOL futures

CME Group to launch options on XRP and SOL futures

The post CME Group to launch options on XRP and SOL futures appeared on BitcoinEthereumNews.com. CME Group will offer options based on the derivative markets on Solana (SOL) and XRP. The new markets will open on October 13, after regulatory approval.  CME Group will expand its crypto products with options on the futures markets of Solana (SOL) and XRP. The futures market will start on October 13, after regulatory review and approval.  The options will allow the trading of MicroSol, XRP, and MicroXRP futures, with expiry dates available every business day, monthly, and quarterly. The new products will be added to the existing BTC and ETH options markets. ‘The launch of these options contracts builds on the significant growth and increasing liquidity we have seen across our suite of Solana and XRP futures,’ said Giovanni Vicioso, CME Group Global Head of Cryptocurrency Products. The options contracts will have two main sizes, tracking the futures contracts. The new market will be suitable for sophisticated institutional traders, as well as active individual traders. The addition of options markets singles out XRP and SOL as liquid enough to offer the potential to bet on a market direction.  The options on futures arrive a few months after the launch of SOL futures. Both SOL and XRP had peak volumes in August, though XRP activity has slowed down in September. XRP and SOL options to tap both institutions and active traders Crypto options are one of the indicators of market attitudes, with XRP and SOL receiving a new way to gauge sentiment. The contracts will be supported by the Cumberland team.  ‘As one of the biggest liquidity providers in the ecosystem, the Cumberland team is excited to support CME Group’s continued expansion of crypto offerings,’ said Roman Makarov, Head of Cumberland Options Trading at DRW. ‘The launch of options on Solana and XRP futures is the latest example of the…
Share
BitcoinEthereumNews2025/09/18 00:56
Lindy AI vs. SuperCool: Task Automation vs. Autonomous Creation

Lindy AI vs. SuperCool: Task Automation vs. Autonomous Creation

Lindy AI and SuperCool are both AI-powered platforms designed to help people get work done faster, but they operate at very different layers of the AI ecosystem
Share
AI Journal2026/01/12 12:37