T
iTokenly

Truflation hack — September 2024

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedSeptember 25, 2024
Target typeInfrastructure provider
Loss$5,200,000Published estimates range $4,600,000 to $5,330,000Price at time of incident
MethodPrivate key compromiseMalware planted on a team machine harvested the private keys to Truflation's treasury multisignature wallet and to personal wallets, which the attacker then used to move the balances out. The chief executive said the infection most likely occurred during the Token2049 conference in Singapore.
ChainsEthereum
OutcomeUnresolved

What happened

Truflation, which publishes on-chain inflation and real-world economic data, confirmed on 25 September 2024 that its wallets had been emptied by an attacker who obtained the private keys through malware.

Chief executive Stefan Rust said the malware was most likely planted on a machine during the Token2049 conference in Singapore earlier that month, and that his own personal account was among those compromised. The keys covered the project's treasury multisignature wallet and personal wallets. Wallet data compiled by Zapper and cited in contemporaneous reporting put the Ethereum-side losses at about $3.89 million in the project's own TRUF token, $1.07 million in ETH and roughly $236,000 in DAI, with about $100,000 more taken across seven other chains.

Estimates of the total differ and the figure is contested. The on-chain investigator ZachXBT put it at about $5.2 million. The security firm Cyvers was quoted at $4.95 million in one account and $4.6 million in another. The largest single component was Truflation's own token, valued at its pre-incident market price, so the realisable value of what was taken was lower than the headline number.

Truflation said no customer funds and no staked funds were affected. It posted an on-chain message offering the attacker a $500,000 bounty for the return of the funds, which was refused, and later published a clearinghouse page offering the same $500,000 for return of the funds, identification of the attacker, or information leading to a conviction. Truflation traced 1.37 million DAI being swapped for 500 ETH and sent to the eXch exchange. As of its final update on 23 October 2024 nothing had been recovered and the attacker had not been identified.

Sources

  1. TruflationPrimary · retrieved 2026-08-01
  2. CointelegraphSecondary · retrieved 2026-08-01
  3. YellowSecondary · retrieved 2026-08-01
  4. HalbornSecondary · retrieved 2026-08-01

Official post-mortem: https://truflation.com/blog/truflation-bounty-clearinghouse

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Truflation hack — September 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/truflation
https://itokenly.com/hacks/truflation

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.