Truebit $26M Exploit: Overflow Bug Lets Cheap TRU Mint Now!!

Integer overflow in Truebit's Solidity 0.6.10 Purchase contract let attacker mint ~$26M TRU for near‑zero cost, plunging the token price ~99%

  • An attacker exploited a smart-contract bug to mint about $26 million worth of TRU tokens at almost no cost.
  • The flaw stemmed from integer overflow in the Purchase contract, which reduced price calculations to near zero.
  • The contract used Solidity 0.6.10, which lacked built-in overflow checks, causing silent wraparound on uint256 overflow.
  • Security firm SlowMist published a detailed post-mortem of the incident.
  • Industry data show smart-contract bugs were the top attack vector in 2025, while phishing and account compromises remained major threats.

An attacker exploited a smart-contract logic error in the offline computation protocol Truebit, minting roughly $26 million in TRU tokens at almost no cost and triggering a roughly 99% crash in the TRU price. The incident occurred on the protocol’s deployed contracts, and the vulnerability let the attacker drain contract reserves by creating large token amounts without paying the required ETH.

- Advertisement -

Security firm SlowMist published a detailed analysis explaining the root cause. “Due to a lack of overflow protection in an integer addition operation, the Purchase contract of Truebit Protocol produced an incorrect result when calculating the amount of ETH required to mint TRU tokens,” the report said. That error caused price calculations to be “erroneously reduced to zero,” enabling near-free minting.

The contract was compiled with Solidity 0.6.10, a version that did not include built-in overflow checks. Calculations that exceeded the maximum uint256 value triggered a “silent overflow” and could “wrap around a small value near zero.” The exploit leveraged this wraparound to subvert the purchase logic.

The incident highlights ongoing risks in established projects; Truebit launched on the Ethereum mainnet in April 2021. Separately, AI agents have demonstrated the ability to find smart-contract flaws: a research paper reported AI-discovered exploits valued at $4.6 million during testing.

Broader industry data from SlowMist’s 2025 report show smart-contract vulnerabilities were the largest attack vector that year, with 56 incidents and 30.5% of exploits. Account compromises numbered 50 incidents (24%), and private key leaks accounted for 8.5%. Phishing remained costly: security firm CertiK recorded $722 million stolen across 248 phishing incidents in 2025, down 38% from about $1 billion the prior year. For a related video, see this coverage clip.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Bitcoin Rally Lifts MSTR, CRCL, COIN

Bitcoin's rally toward $69,000 on Wednesday fueled a jump in related equities like Coinbase...

Ethereum Leads Top 10 Crypto Recovery with 8.7% Daily Rally

Ethereum has posted significant gains, rallying 8.7% on the daily charts and now ranking...

ETHZilla rebrands as Forum Markets, pivots from crypto

ETHZilla will rebrand to Forum Markets and trade as FRMM on Nasdaq in early...

Buterin: Ethereum Block Times Could Drop To 2 Seconds

Ethereum co-founder Vitalik Buterin has elaborated on a bold new roadmap aiming to dramatically...

How Wall Street Bitcoin ETFs Weaken Spot Price Link

Bitcoin ETF share creation/redemption by authorized participants does not require immediate Bitcoin purchases or...

Must Read

26 Best Investment Audiobooks on Audible

Looking to expand your financial knowledge? Me too..When I first started investing, I was completely lost. There were so many terms, strategies, and theories...
🔥 #AD Get 20% OFF any new 12 month hosting plan from Hostinger. Click here!