The post $26M Truebit Hack Was Smart Contract Exploit: Analysis appeared on BitcoinEthereumNews.com. A $26 million exploit of the offline computation protocol TruebitThe post $26M Truebit Hack Was Smart Contract Exploit: Analysis appeared on BitcoinEthereumNews.com. A $26 million exploit of the offline computation protocol Truebit

$26M Truebit Hack Was Smart Contract Exploit: Analysis

A $26 million exploit of the offline computation protocol Truebit stemmed from a smart-contract flaw that allowed an attacker to mint tokens at near-zero cost, highlighting persistent security risks even in long-running blockchain projects.

Truebit suffered the $26 million exploit that resulted in a 99% crash for the Truebit (TRU) token, Cointelegraph reported on Friday.

The attacker abused a loophole in the protocol’s smart-contract logic, which enabled them to mint “massive amounts of tokens without paying any ETH,” according to blockchain security company SlowMist, which published a post-mortem analysis on Tuesday.

“Due to a lack of overflow protection in an integer addition operation, the Purchase contract of Truebit Protocol produced an incorrect result when calculating the amount of ETH required to mint TRU tokens,” SlowMist said.

The smart contract’s price calculations were then “erroneously reduced to zero,” enabling the attacker to drain the contract’s reserves by minting $26 million worth of tokens “at nearly no cost,” the post mortem said.

Since the contract was compiled with Solidity 0.6.10, the prior version didn’t include built-in overflow checks, which caused calculations exceeding the maximum value of “uint256” to result in a “silent overflow,” causing the result to “wrap around a small value near zero.”

Truebit exploit post-mortem analysis. Source: SlowMist

Related: Fake MetaMask 2FA security checks lure users into sharing recovery phrases

The exploit shows that even the more established protocols are threatened by hackers. Truebit was launched on the Ethereum mainnet almost five years ago in April 2021.

Smart-contract security attracted interest at the end of last year, when an Anthropic study revealed that commercially available artificial intelligence (AI) agents had found $4.6 million worth of smart contract exploits.

Anthropic’s Claude Opus 4.5, Claude Sonnet 4.5 and OpenAI’s GPT-5 collectively developed exploits worth $4.6 million when tested on smart contracts, according to a research paper released by the AI company’s red team, dedicated to discovering code vulnerabilities before malicious actors can find them.

Chart of AI exploiting revenue from simulations. Source: Anthropic

Related: Bitcoin investor loses retirement fund in AI-fueled romance scam

Smart-contract bugs largest attack vector of 2025

Smart-contract vulnerabilities were the largest attack vector for the cryptocurrency industry in 2025, with 56 cybersecurity incidents, while account compromises ranked second with 50 incidents, according to SlowMist’s year-end report.

Contract vulnerabilities accounted for 30.5% of all the crypto exploits in 2025, while hacked X accounts accounted for 24% and private key leaks for 8.5% in third place.

Distribution of causes for security incidents in 2025. Source: SlowMist

Meanwhile, other hackers are switching strategies from protocol hacks to exploiting weak links in onchain human behavior.

Crypto phishing scams emerged as the second-largest threat of 2025, costing crypto investors a cumulative $722 million across 248 incidents, according to blockchain security platform CertiK.

Crypto phishing attacks are social engineering schemes that don’t require hacking code. Instead, attackers share fraudulent links to steal victims’ sensitive information, such as the private keys to crypto wallets.

Still, investors are becoming more aware of this threat, as the $722 million was 38% less than the $1 billion stolen through phishing scams in 2024.

Magazine: Meet the onchain crypto detectives fighting crime better than the cops

Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently. Read our Editorial Policy https://cointelegraph.com/editorial-policy

Source: https://cointelegraph.com/news/26m-truebit-hack-smart-contract-vulnerability?utm_source=rss_feed&utm_medium=feed&utm_campaign=rss_partner_inbound

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Is Putnam Global Technology A (PGTAX) a strong mutual fund pick right now?

Is Putnam Global Technology A (PGTAX) a strong mutual fund pick right now?

The post Is Putnam Global Technology A (PGTAX) a strong mutual fund pick right now? appeared on BitcoinEthereumNews.com. On the lookout for a Sector – Tech fund? Starting with Putnam Global Technology A (PGTAX – Free Report) should not be a possibility at this time. PGTAX possesses a Zacks Mutual Fund Rank of 4 (Sell), which is based on various forecasting factors like size, cost, and past performance. Objective We note that PGTAX is a Sector – Tech option, and this area is loaded with many options. Found in a wide number of industries such as semiconductors, software, internet, and networking, tech companies are everywhere. Thus, Sector – Tech mutual funds that invest in technology let investors own a stake in a notoriously volatile sector, but with a much more diversified approach. History of fund/manager Putnam Funds is based in Canton, MA, and is the manager of PGTAX. The Putnam Global Technology A made its debut in January of 2009 and PGTAX has managed to accumulate roughly $650.01 million in assets, as of the most recently available information. The fund is currently managed by Di Yao who has been in charge of the fund since December of 2012. Performance Obviously, what investors are looking for in these funds is strong performance relative to their peers. PGTAX has a 5-year annualized total return of 14.46%, and is in the middle third among its category peers. But if you are looking for a shorter time frame, it is also worth looking at its 3-year annualized total return of 27.02%, which places it in the middle third during this time-frame. It is important to note that the product’s returns may not reflect all its expenses. Any fees not reflected would lower the returns. Total returns do not reflect the fund’s [%] sale charge. If sales charges were included, total returns would have been lower. When looking at a fund’s performance, it…
Share
BitcoinEthereumNews2025/09/18 04:05
The whale "pension-usdt.eth" has reduced its ETH long positions by 10,000 coins, and its futures account has made a profit of $4.18 million in the past day.

The whale "pension-usdt.eth" has reduced its ETH long positions by 10,000 coins, and its futures account has made a profit of $4.18 million in the past day.

PANews reported on January 14th that, according to Hyperbot data monitoring, the whale "pension-usdt.eth" reduced its ETH long positions by 10,000 ETH in the past
Share
PANews2026/01/14 13:45
Senator Warren Tells OCC to Stop World Liberty Bank Review Amid Trump Ties

Senator Warren Tells OCC to Stop World Liberty Bank Review Amid Trump Ties

The post Senator Warren Tells OCC to Stop World Liberty Bank Review Amid Trump Ties appeared on BitcoinEthereumNews.com. U.S. Senator Elizabeth Warren has called
Share
BitcoinEthereumNews2026/01/14 12:55