T
iTokenly

Truebit Protocol hack — January 2026

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedJanuary 9, 2026
Target typeInfrastructure provider
Loss$26,400,000Published estimates range $26,000,000 to $26,600,000Price at time of incident
MethodContract logic errorInteger overflow in the getPurchasePrice function of Truebit's legacy TRU bonding-curve Purchase contract (0x764C64b2A09b09Acb100B80d8c505Aa6a0302EF2), written in a Solidity version predating automatic overflow checks. A sufficiently large requested token quantity caused an addition in the price calculation to wrap around and return a price of zero, letting the attacker mint TRU for no payment and sell it straight back to the curve for ether.
ChainsEthereum
OutcomeUnresolved

What happened

Truebit is a verification layer for off-chain computation whose TRU token could be minted and redeemed against an ether reserve through a bonding-curve contract deployed on Ethereum around 2021. On 8 January 2026 an attacker emptied that reserve.

The contract's getPurchasePrice function performed unchecked arithmetic in a legacy Solidity version predating automatic overflow protection. Passing a sufficiently large token quantity, which analysts give as an input of 240,442,509,453,545,333,947,284,131, caused an addition inside the price calculation to wrap around and return a purchase price of zero. The attacker minted TRU for no payment, immediately sold the tokens back to the same bonding curve for ether, and repeated the cycle several times inside a single transaction, removing 8,535.36 ETH.

Published dollar figures cluster between $26 million and $26.6 million. That spread reflects different ether marks on the day rather than any dispute over the quantity, which is fixed on-chain.

The vulnerable contract was roughly five years old, closed-source, and had not been kept under audit or monitoring; the published analyses are based on decompiled bytecode. TRU collapsed almost completely, from around $0.16 to a small fraction of a cent, once the freshly minted supply reached the market.

Truebit acknowledged the incident on X on 8 January, confirmed that a specific contract was affected and told users not to interact with it. The team said it was in contact with law enforcement. No full post-mortem, recovery or compensation plan had been published, and no suspect has been named.

Law enforcement

Truebit said it was cooperating with law enforcement; no agency, case or arrest has been named publicly.

On-chain references

Published so the figures above can be checked against the chain rather than taken from us. Victim addresses are never listed.

Transactions

  • 0xcd4755645595094a8ab984d0db7e3b4aabde72a5c87c4f176a030629c47fb014

Attacker addresses

  • 0x1De399967B206e446B4E9AeEb3Cb0A0991bF11b8

Sources

  1. QuillAuditsSecondary · retrieved 2026-08-01
  2. ExVulSecondary · retrieved 2026-08-01
  3. CoinCentralSecondary · retrieved 2026-08-01
  4. HalbornSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Truebit Protocol hack — January 2026", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/truebit-protocol
https://itokenly.com/hacks/truebit-protocol

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.