The post $26M Truebit Hack Was Smart Contract Exploit: Analysis appeared on BitcoinEthereumNews.com. A $26 million exploit of the offline computation protocol TruebitThe post $26M Truebit Hack Was Smart Contract Exploit: Analysis appeared on BitcoinEthereumNews.com. A $26 million exploit of the offline computation protocol Truebit

$26M Truebit Hack Was Smart Contract Exploit: Analysis

A $26 million exploit of the offline computation protocol Truebit stemmed from a smart-contract flaw that allowed an attacker to mint tokens at near-zero cost, highlighting persistent security risks even in long-running blockchain projects.

Truebit suffered the $26 million exploit that resulted in a 99% crash for the Truebit (TRU) token, Cointelegraph reported on Friday.

The attacker abused a loophole in the protocol’s smart-contract logic, which enabled them to mint “massive amounts of tokens without paying any ETH,” according to blockchain security company SlowMist, which published a post-mortem analysis on Tuesday.

“Due to a lack of overflow protection in an integer addition operation, the Purchase contract of Truebit Protocol produced an incorrect result when calculating the amount of ETH required to mint TRU tokens,” SlowMist said.

The smart contract’s price calculations were then “erroneously reduced to zero,” enabling the attacker to drain the contract’s reserves by minting $26 million worth of tokens “at nearly no cost,” the post mortem said.

Since the contract was compiled with Solidity 0.6.10, the prior version didn’t include built-in overflow checks, which caused calculations exceeding the maximum value of “uint256” to result in a “silent overflow,” causing the result to “wrap around a small value near zero.”

Truebit exploit post-mortem analysis. Source: SlowMist

Related: Fake MetaMask 2FA security checks lure users into sharing recovery phrases

The exploit shows that even the more established protocols are threatened by hackers. Truebit was launched on the Ethereum mainnet almost five years ago in April 2021.

Smart-contract security attracted interest at the end of last year, when an Anthropic study revealed that commercially available artificial intelligence (AI) agents had found $4.6 million worth of smart contract exploits.

Anthropic’s Claude Opus 4.5, Claude Sonnet 4.5 and OpenAI’s GPT-5 collectively developed exploits worth $4.6 million when tested on smart contracts, according to a research paper released by the AI company’s red team, dedicated to discovering code vulnerabilities before malicious actors can find them.

Chart of AI exploiting revenue from simulations. Source: Anthropic

Related: Bitcoin investor loses retirement fund in AI-fueled romance scam

Smart-contract bugs largest attack vector of 2025

Smart-contract vulnerabilities were the largest attack vector for the cryptocurrency industry in 2025, with 56 cybersecurity incidents, while account compromises ranked second with 50 incidents, according to SlowMist’s year-end report.

Contract vulnerabilities accounted for 30.5% of all the crypto exploits in 2025, while hacked X accounts accounted for 24% and private key leaks for 8.5% in third place.

Distribution of causes for security incidents in 2025. Source: SlowMist

Meanwhile, other hackers are switching strategies from protocol hacks to exploiting weak links in onchain human behavior.

Crypto phishing scams emerged as the second-largest threat of 2025, costing crypto investors a cumulative $722 million across 248 incidents, according to blockchain security platform CertiK.

Crypto phishing attacks are social engineering schemes that don’t require hacking code. Instead, attackers share fraudulent links to steal victims’ sensitive information, such as the private keys to crypto wallets.

Still, investors are becoming more aware of this threat, as the $722 million was 38% less than the $1 billion stolen through phishing scams in 2024.

Magazine: Meet the onchain crypto detectives fighting crime better than the cops

Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently. Read our Editorial Policy https://cointelegraph.com/editorial-policy

Source: https://cointelegraph.com/news/26m-truebit-hack-smart-contract-vulnerability?utm_source=rss_feed&utm_medium=feed&utm_campaign=rss_partner_inbound

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

What NFT Paris Cancellation Reveals About the NFT Market in 2026

What NFT Paris Cancellation Reveals About the NFT Market in 2026

The post What NFT Paris Cancellation Reveals About the NFT Market in 2026 appeared on BitcoinEthereumNews.com. Key takeaways NFT Paris’ cancellation highlights
Share
BitcoinEthereumNews2026/01/14 14:01
United States Building Permits Change dipped from previous -2.8% to -3.7% in August

United States Building Permits Change dipped from previous -2.8% to -3.7% in August

The post United States Building Permits Change dipped from previous -2.8% to -3.7% in August appeared on BitcoinEthereumNews.com. Information on these pages contains forward-looking statements that involve risks and uncertainties. Markets and instruments profiled on this page are for informational purposes only and should not in any way come across as a recommendation to buy or sell in these assets. You should do your own thorough research before making any investment decisions. FXStreet does not in any way guarantee that this information is free from mistakes, errors, or material misstatements. It also does not guarantee that this information is of a timely nature. Investing in Open Markets involves a great deal of risk, including the loss of all or a portion of your investment, as well as emotional distress. All risks, losses and costs associated with investing, including total loss of principal, are your responsibility. The views and opinions expressed in this article are those of the authors and do not necessarily reflect the official policy or position of FXStreet nor its advertisers. The author will not be held responsible for information that is found at the end of links posted on this page. If not otherwise explicitly mentioned in the body of the article, at the time of writing, the author has no position in any stock mentioned in this article and no business relationship with any company mentioned. The author has not received compensation for writing this article, other than from FXStreet. FXStreet and the author do not provide personalized recommendations. The author makes no representations as to the accuracy, completeness, or suitability of this information. FXStreet and the author will not be liable for any errors, omissions or any losses, injuries or damages arising from this information and its display or use. Errors and omissions excepted. The author and FXStreet are not registered investment advisors and nothing in this article is intended…
Share
BitcoinEthereumNews2025/09/18 02:20
Top 5 Crypto to Buy Now: Last 3 Days to Avail 22,300% ROI With APEMARS

Top 5 Crypto to Buy Now: Last 3 Days to Avail 22,300% ROI With APEMARS

Looking for the top 5 crypto in today’s market? Here’s a kid-simple, news-style listicle on APEMARS ($APRZ) Stage 3 BANANA BOOST and four major coins, XLM, BCH,
Share
CoinLive2026/01/14 14:15