Loss Exceeding $26 Million: Analysis of Truebit Protocol Security Incident and Tracking of Stolen Funds Flow

marsbitPubblicato 2026-01-09Pubblicato ultima volta 2026-01-09

Introduzione

On January 9, the Truebit Protocol suffered an attack resulting in a loss of 8,535.36 ETH (approximately $26.4 million) due to an exploit in a five-year-old unaudited and unopen-sourced contract. The attack involved a suspected arithmetic logic flaw, possibly due to integer truncation, in an unverified function (0xa0296215). The attacker repeatedly called this function with a minimal msg.value to mint a large number of TRU tokens, which were then burned to withdraw ETH from the contract’s reserves. According to Beosin’s analysis, the stolen funds—totaling 8,535.36 ETH—were primarily transferred to two addresses: 0xd12f6e0fa7fbf4e3a1c7996e3f0dd26ab9031a60 (holding 4,267.09 ETH) and 0x273589ca3713e7becf42069f9fb3f0c164ce850a (holding 4,001 ETH). The attacker’s address (0x6c8ec8f14be7c01672d31cfa5f2cefeab2562b50) still retains 267.71 ETH. All related addresses have been flagged as high-risk by Beosin KYT. The incident underscores the importance of security audits, contract upgrades, and incorporating emergency pause mechanisms and modern Solidity safety features to mitigate risks in legacy smart contracts.

Author: Beosin

In the early hours of January 9, an unopen-sourced contract deployed by Truebit Protocol 5 years ago was attacked, resulting in a loss of 8,535.36 ETH (worth approximately $26.4 million). The Beosin security team conducted an analysis of the vulnerability and fund tracking for this security incident and shares the results as follows:

Attack Technique Analysis

For this incident, we take the most significant attack transaction as the analysis subject, with the transaction hash: 0xcd4755645595094a8ab984d0db7e3b4aabde72a5c87c4f176a030629c47fb014

1. The attacker calls getPurchasePrice() to obtain the price

2. Subsequently calls the flawed function 0xa0296215(), setting the msg.value extremely low

Since the contract is not open-source, it is inferred from the decompiled code that this function has an arithmetic logic vulnerability, such as integer truncation issues, allowing the attacker to successfully mint a large number of TRU tokens.

3. The attacker "sells back" the minted tokens to the contract through the burn function, extracting a large amount of ETH from the contract reserves.

This process is repeated 4 more times, with the msg.value increasing each time, until almost all ETH in the contract is extracted.

Stolen Funds Tracking

Based on on-chain transaction data, Beosin conducted a detailed fund tracking through its blockchain on-chain investigation and tracking platform, BeosinTrace, and shares the results as follows:

Currently, the stolen 8,535.36 ETH, after transfers, are mostly held in 0xd12f6e0fa7fbf4e3a1c7996e3f0dd26ab9031a60 and 0x273589ca3713e7becf42069f9fb3f0c164ce850a.

Among them, address 0xd12f holds 4,267.09 ETH, and address 0x2735 holds 4,001 ETH. The address from which the attacker initiated the attack (0x6c8ec8f14be7c01672d31cfa5f2cefeab2562b50) still holds 267.71 ETH. There have been no further fund transfers from these three addresses yet.

Stolen Funds Flow Analysis Diagram by Beosin Trace

The above addresses have been marked as high-risk addresses by Beosin KYT. Taking the attacker's address as an example:

Beosin KYT

Conclusion

This stolen fund incident involves an unopen-sourced smart contract from 5 years ago. For such contracts, the project team should upgrade the contract, introduce emergency pause functions, parameter limitations, and new Solidity security features. Furthermore, security audits remain an essential step for contracts. Through security audits, Web3 enterprises can comprehensively detect smart contract code, identify and fix potential vulnerabilities, and enhance contract security.

*Beosin will provide a complete analysis report of all fund flows and address risks for this incident. Welcome to request it via the official email [email protected].

Domande pertinenti

QWhat was the total amount of ETH stolen in the Truebit Protocol security incident?

A8,535.36 ETH, valued at approximately $26.4 million.

QWhich function did the attacker call to exploit the vulnerability in the unopened contract?

AThe attacker called the function 0xa0296215() with a very small msg.value to exploit an arithmetic logic vulnerability, likely due to integer truncation issues.

QHow did the attacker convert the fraudulently minted TRU tokens into ETH?

AThe attacker used the burn function to 'sell back' the minted TRU tokens to the contract, extracting a large amount of ETH from the contract reserves.

QWhat are the two main addresses where the stolen ETH is currently held?

AThe majority of the stolen ETH is held in addresses 0xd12f6e0fa7fbf4e3a1c7996e3f0dd26ab9031a60 (4,267.09 ETH) and 0x273589ca3713e7becf42069f9fb3f0c164ce850a (4,001 ETH).

QWhat security measures does Beosin recommend to prevent such incidents?

ABeosin recommends upgrading the contract to include emergency pause functions, parameter limits, and new Solidity security features, as well as conducting thorough security audits to detect and fix potential vulnerabilities.

Letture associate

Different Choices After the Plunge: Institutions Buy the Dip, Traders Shift to US Stocks

Title: Diverging Strategies After the Crash: Institutions Buying the Dip, Traders Shifting to US Stocks Following a sharp decline where Bitcoin briefly fell below $60,000 on June 6th, market sentiment remains "extreme fear" despite a partial recovery. This has led to varied responses from major market participants. Several institutional figures and analysts present a cautiously optimistic long-term view for Bitcoin. Glassnode's co-founder identifies $46k-$54k as a probable key bottom range based on historical on-chain models, while a Standard Chartered executive suggests the bottom is nearly formed. Strive's CEO points to Bitcoin touching its 200-week moving average as a historically reliable buy signal. Analysts highlight metrics like MVRV ratio and the "Power Law" model indicating Bitcoin is in an extremely undervalued zone. Conversely, some traders are exiting the crypto space. One trader cited a more attractive risk/reward profile and deeper research opportunities in US stocks, particularly with AI-related equities outperforming and capital rotating away from crypto. This shift is partly attributed to perceived ongoing risks, including those related to Strategy's Bitcoin sales. Market prediction data suggests a high probability (72%) of Bitcoin falling below $55,000, but lower odds for a deeper crash below $35k-$40k. The overall picture is one of division: institutions and long-term analysts see a accumulating opportunity, while some active traders are seeking alpha elsewhere amidst the volatility and shifting capital flows.

marsbit44 min fa

Different Choices After the Plunge: Institutions Buy the Dip, Traders Shift to US Stocks

marsbit44 min fa

Tech Stocks in the Midst of Deleveraging: Rather Than Rushing to Buy the Dip, Wait for the Macro Environment to Stabilize First

"Technology Stocks in Deleveraging Phase: Wait for Macro Stability Before Buying the Dip" The current sell-off in tech/AI stocks is primarily driven by macro headwinds, not a breakdown in AI fundamentals. After a parabolic rise, the market faced a perfect storm: an overcrowded trade, a massive SpaceX IPO draining liquidity, pre-CPI/PPI/FOMC hedging, and strong jobs data renewing "higher-for-longer" rate fears. This triggered a concentrated deleveraging in hot tech names. Key historical context: Unlike the December 2023 sell-off focused on AI capex returns, the current correction centers on the "denominator" – rising concerns over rates, inflation, the Fed, geopolitics, and liquidity. Leading memory stocks like Micron have seen ~20% pullbacks, significant but not yet at panic levels seen in March. The intense selling wave may be largely over, but a quick V-shaped recovery is unlikely. The market will likely churn in high volatility, awaiting clarity. The immediate catalyst needed for a sustainable reversal is a "stop-bleeding" signal from macro conditions. This doesn't require a major positive shock (like the April Iran ceasefire), but simply a halt to further deterioration: CPI not surprising hotter, Treasury yields stabilizing, the Fed not turning more hawkish, and post-SpaceX IPO liquidity easing. Once macro pressure plateaus, the intact AI investment thesis – centered on persistent compute/memory shortages and accelerating commercialization – can quickly regain market focus. The strategy is clear: prioritize monitoring macro stabilization over rushing to bottom-fish individual AI stories. Patience is key.

marsbit51 min fa

Tech Stocks in the Midst of Deleveraging: Rather Than Rushing to Buy the Dip, Wait for the Macro Environment to Stabilize First

marsbit51 min fa

South Korean Stocks Plunge, Global Funds Liquidate: Has the Semiconductor Fundamentals Really Changed?

South Korean stocks experienced their sharpest decline of the year, with the KOSPI index plunging nearly 9% on Monday, triggering a market circuit breaker. Leading semiconductor firms Samsung Electronics and SK Hynix were heavily sold off, raising questions about whether the AI-driven bull market has reached an inflection point. This sell-off was largely triggered by a significant drop in the U.S. semiconductor sector late last week. Concurrently, NVIDIA CEO Jensen Huang visited Seoul over the weekend, meeting with top executives from SK Group, Samsung, LG, and NAVER. He announced a new multi-year partnership with SK Hynix to co-develop next-generation memory products for AI data centers. Huang emphasized that AI infrastructure build-out remains in its early stages, creating a stark contrast between market panic and ongoing, strengthened industry collaboration. The article argues that South Korea has become one of the most sensitive markets for global AI-related capital flows, functioning like a large AI memory ETF due to the heavy weighting of its chipmakers. The current market turmoil reflects a shift in investor focus: from simply betting on overall AI growth to scrutinizing which companies will actually capture the profits from that growth. This "profit pool reassessment" phase is causing high volatility based on supply chain news and earnings guidance. Ultimately, the direction of the Korean market will be determined by external factors—NVIDIA's orders, HBM supply-demand dynamics, and capital expenditures from cloud service providers—rather than domestic conditions. The disconnect between sharp price corrections and continued strong signals from the industry core leaves the market at a crossroads, awaiting clearer data on the durability of AI infrastructure demand.

marsbit1 h fa

South Korean Stocks Plunge, Global Funds Liquidate: Has the Semiconductor Fundamentals Really Changed?

marsbit1 h fa

Trump in Talks with AI Companies Over Profit Sharing, A Narrative Pressure of Industrial Revolution Scale Begins

In recent AI market discussions, a new dimension beyond growth and profits has emerged: the question of how the immense wealth potentially generated by AI should be shared with the wider public. Triggered by reports of White House officials discussing "voluntary equity transfers" with top AI firms, similar to models like Alaska's Permanent Fund, the conversation focuses on public wealth funds. OpenAI's own whitepaper proposes such funds, allowing households without direct tech stock ownership to benefit from AI gains. More radical proposals, like Bernie Sanders' call for high public equity stakes and board seats, represent an extreme end of the spectrum. Currently, these are early-stage policy probes, not enacted laws. OpenAI's initiative is seen as an attempt to secure "social license" for its future expansion, mitigating risks of public backlash, stricter regulation, or anti-trust actions as AI's economic impact grows. The core market implication is the introduction of a "policy discount" to AI valuations, particularly for private model companies like OpenAI, Anthropic, and xAI. Investors must now consider not just future earnings but also what portion might be allocated to public mechanisms. The impact varies greatly based on the mechanism. A small, voluntary transfer of non-voting economic rights (e.g., 5%) acts as a quantifiable long-term cost. Government acquisition of economic rights via warrants tied to support differs from direct equity with governance power. The most disruptive scenario would be forced high-percentage public ownership affecting control and innovation incentives. Key signals to watch include whether other AI companies follow suit, if the White House formalizes proposals, related disclosures in future IPO documents, and any market price reactions. For now, this represents a shift from pricing pure AI growth to pricing its potential distribution. A manageable, voluntary economic share is akin to an insurance cost for societal acceptance, while a forced shift toward control and governance would fundamentally alter valuation logic.

marsbit1 h fa

Trump in Talks with AI Companies Over Profit Sharing, A Narrative Pressure of Industrial Revolution Scale Begins

marsbit1 h fa

From Record Highs to a Two-Week Low: Why Did AI Concept Stocks Suddenly Pull Back?

From Record Highs to Two-Week Lows: Why Did AI Stocks Suddenly Pull Back? U.S. stock indices, led by the tech-heavy Nasdaq 100, fell sharply to two-week lows. This marked a reversal from earlier in the week when AI infrastructure and semiconductor stocks had propelled major indices to record highs. Investors are rotating out of these previously high-flying tech sectors into other areas. The sell-off was driven by profit-taking and concerns that the AI rally had become overextended, exacerbated by chipmaker Broadcom's sales outlook falling short of lofty market expectations. The decline accelerated following a stronger-than-expected U.S. May nonfarm payrolls report, which showed 172,000 jobs added versus an estimated 88,000. This data sparked a jump in bond yields, with the 10-year Treasury yield rising to 4.553%, as it reinforced market speculation that the Federal Reserve's next move could be a rate hike rather than a cut. Globally, equities also declined, with European and Asian markets falling. Within the U.S. market, chip and AI-related stocks like Super Micro Computer and Arm Holdings led the losses, dropping over 7%. Cryptocurrency-linked stocks and mining shares also fell sharply amid drops in Bitcoin and commodity prices. While the overall Q1 earnings season remained solid, with 83% of S&P 500 companies beating estimates, the weakness was concentrated in tech. Excluding the tech sector, Q1 earnings growth was around 3%, the weakest in two years.

marsbit1 h fa

From Record Highs to a Two-Week Low: Why Did AI Concept Stocks Suddenly Pull Back?

marsbit1 h fa

Trading

Spot
Futures
活动图片