Highlights: Truebit Protocol lost $26.6M after attackers exploited an outdated smart contract flaw. The TRU token collapsed from $0.16 to near zero Highlights: Truebit Protocol lost $26.6M after attackers exploited an outdated smart contract flaw. The TRU token collapsed from $0.16 to near zero

Truebit Protocol Exploit Drains $26M as TRU Token Collapses to Zero

2026/01/09 18:38
4분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 crypto.news@mexc.com으로 연락주시기 바랍니다

Highlights:

  • Truebit Protocol lost $26.6M after attackers exploited an outdated smart contract flaw.
  • The TRU token collapsed from $0.16 to near zero within hours.
  • Legacy DeFi contracts continue attracting attackers seeking mispriced minting functions.

Truebit Protocol suffered a major security breach on Thursday that triggered one of 2026’s sharpest token collapses. On-chain data showed attackers drained about 8,535 ether, valued at $26.6 million. As a result, the TRU token plunged from $0.16 to near zero within hours, sparking widespread panic selling across the market.

The exploit targeted an outdated smart contract still connected to active liquidity pools. According to researchers, a pricing error let attackers mint TRU at zero cost. They repeatedly bought and sold tokens to extract ether directly from the protocol’s reserves. As a result, the rapid transactions bypassed early safeguards on the Ethereum network.

Truebit Protocol’s Exploit Mechanics and On-Chain Trail

The activity was flagged by blockchain experts when a single wallet received most of the funds. Cyvers reported the unusual behavior of transactions not corresponding to normal Truebit operations. In addition, its systems identified high-risk indicators with the attacker employing small builder bribes to gain block priority. The attacker thus made trades quickly across various blocks to achieve maximum extraction speed.

Additional investigation revealed that the attacker used a flawed minting function. Independent researcher Weilin Li traced the bug to a mispriced contract implemented five years prior. Since the code was still available, the attackers took advantage of old permissions that developers never retired during the previous network phases that are still connected to liquidity contracts today.

Li also suggested that there were two attackers involved in the exploit window. A single address captured approximately $26 million in Ether profits. The other address gained about $250,000 upon identifying the weakness. The activity further suggests opportunistic follow-on trading by observers of mempool data and interactions of contracts on the network-wide volatility that morning.

Protocol Response and Market Fallout

Truebit protocol acknowledged that it was aware of the security incident via a public statement. The team cautioned against interacting with the affected contract address. Meanwhile, the developers notified law enforcement and initiated internal investigations. However, they did not confirm any immediate contract pauses as investigations expanded in multiple jurisdictions with blockchain analytics partners.

Response in the market became rapid, with liquidity evaporating in the trading venues. TRU token dropped to almost zero value within hours as the selling pressure intensified. Moreover, the collapse erased years of market capitalization and left behind holders unable to exit positions amid thin order books and halted arbitrage flows in the face of extreme volatility conditions globally.

Increasing DeFi Exploits and Legacy Contract Risks

This incident contributes to the expanding list of decentralized finance hacks. Security firms noted that attackers are targeting more forgotten permissions on older contracts. With protocols evolving, legacy code has been a frequent vulnerability. Audits often trail behind older deployments, allowing mispriced logic embedded years ago to go unnoticed.

Similar exploits have been observed in major protocols recently. Balancer suffered a loss of more than $120 million due to a rounding error. Bunni and Nemo also reported contract drains, adding momentum to increasing security pressures throughout the sector.

Meanwhile, stablecoin neobank Kontigo recently experienced a wallet breach, draining more than 340,000 USDC from affected users. Kontigo, however, responded promptly by issuing full reimbursements. Moreover, Trust Wallet suffered a separate breach linked to its Chrome extension, whereby hackers drained about $7 million from unsuspecting users.

eToro Platform

Best Crypto Exchange

  • Over 90 top cryptos to trade
  • Regulated by top-tier entities
  • User-friendly trading app
  • 30+ million users
9.9
Visit eToro

eToro is a multi-asset investment platform. The value of your investments may go up or down. Your capital is at risk. Don’t invest unless you’re prepared to lose all the money you invest. This is a high-risk investment, and you should not expect to be protected if something goes wrong.

시장 기회
트루파이토큰 로고
트루파이토큰 가격(TRU)
$0.007742
$0.007742$0.007742
-0.74%
USD
트루파이토큰 (TRU) 실시간 가격 차트
면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, crypto.news@mexc.com으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

USD1 Genesis: 0 Fees + 12% APR

USD1 Genesis: 0 Fees + 12% APRUSD1 Genesis: 0 Fees + 12% APR

New users: stake for up to 600% APR. Limited time!