Truebit $26M Exploit: Overflow Bug Lets Cheap TRU Mint Now!!

Integer overflow in Truebit's Solidity 0.6.10 Purchase contract let attacker mint ~$26M TRU for near‑zero cost, plunging the token price ~99%

  • An attacker exploited a smart-contract bug to mint about $26 million worth of TRU tokens at almost no cost.
  • The flaw stemmed from integer overflow in the Purchase contract, which reduced price calculations to near zero.
  • The contract used Solidity 0.6.10, which lacked built-in overflow checks, causing silent wraparound on uint256 overflow.
  • Security firm SlowMist published a detailed post-mortem of the incident.
  • Industry data show smart-contract bugs were the top attack vector in 2025, while phishing and account compromises remained major threats.

An attacker exploited a smart-contract logic error in the offline computation protocol Truebit, minting roughly $26 million in TRU tokens at almost no cost and triggering a roughly 99% crash in the TRU price. The incident occurred on the protocol’s deployed contracts, and the vulnerability let the attacker drain contract reserves by creating large token amounts without paying the required ETH.

- Advertisement -

Security firm SlowMist published a detailed analysis explaining the root cause. “Due to a lack of overflow protection in an integer addition operation, the Purchase contract of Truebit Protocol produced an incorrect result when calculating the amount of ETH required to mint TRU tokens,” the report said. That error caused price calculations to be “erroneously reduced to zero,” enabling near-free minting.

The contract was compiled with Solidity 0.6.10, a version that did not include built-in overflow checks. Calculations that exceeded the maximum uint256 value triggered a “silent overflow” and could “wrap around a small value near zero.” The exploit leveraged this wraparound to subvert the purchase logic.

The incident highlights ongoing risks in established projects; Truebit launched on the Ethereum mainnet in April 2021. Separately, AI agents have demonstrated the ability to find smart-contract flaws: a research paper reported AI-discovered exploits valued at $4.6 million during testing.

Broader industry data from SlowMist’s 2025 report show smart-contract vulnerabilities were the largest attack vector that year, with 56 incidents and 30.5% of exploits. Account compromises numbered 50 incidents (24%), and private key leaks accounted for 8.5%. Phishing remained costly: security firm CertiK recorded $722 million stolen across 248 phishing incidents in 2025, down 38% from about $1 billion the prior year. For a related video, see this coverage clip.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Bitcoin ETF Boomers Hold Strong Amid 40% Price Plunge

Bitcoin has fallen over 40% from recent highs, yet only 6.6% of assets have...

Musk Denies Starlink Phone, Confirms Other Plans

Elon Musk denied SpaceX is developing a phone, contradicting recent rumors.The Starlink division generated...

Intel Defies Tech Slump as AI, GPU Plans Fuel Rebound

Intel stock has shown relative resilience, dropping only slightly during a broader tech sell-off.The...

BitMine’s $8B ETH Loss: Tom Lee Says It’s “A Feature”

BitMine Immersion Technologies holds over 4.29 million ETH worth $16.4 billion, approximately 3.5% of...

Alphabet Stock Dips 2.5% Despite Strong Earnings Amid AI Spend Worries

Alphabet (GOOGL) stock fell 2.5% Thursday, extending a five-day slide to 4% despite a...
- Advertisement -

Must Read

The Best Bitcoin Casinos of 2025: An Expert’s Data-Driven Guide

Key TakeawaysA Deep Dive into the Top Bitcoin Casinos of 2025Bitcoin Casino Comparison Table1. Stake.com: Best for Variety & Integrated Sports Betting2. BC.Game: Best...
🔥 #AD Get 20% OFF any new 12 month hosting plan from Hostinger. Click here!