Loss Exceeding $26 Million: Analysis of Truebit Protocol Security Incident and Tracking of Stolen Funds Flow

marsbitОпубліковано о 2026-01-09Востаннє оновлено о 2026-01-09

Анотація

On January 9, the Truebit Protocol suffered an attack resulting in a loss of 8,535.36 ETH (approximately $26.4 million) due to an exploit in a five-year-old unaudited and unopen-sourced contract. The attack involved a suspected arithmetic logic flaw, possibly due to integer truncation, in an unverified function (0xa0296215). The attacker repeatedly called this function with a minimal msg.value to mint a large number of TRU tokens, which were then burned to withdraw ETH from the contract’s reserves. According to Beosin’s analysis, the stolen funds—totaling 8,535.36 ETH—were primarily transferred to two addresses: 0xd12f6e0fa7fbf4e3a1c7996e3f0dd26ab9031a60 (holding 4,267.09 ETH) and 0x273589ca3713e7becf42069f9fb3f0c164ce850a (holding 4,001 ETH). The attacker’s address (0x6c8ec8f14be7c01672d31cfa5f2cefeab2562b50) still retains 267.71 ETH. All related addresses have been flagged as high-risk by Beosin KYT. The incident underscores the importance of security audits, contract upgrades, and incorporating emergency pause mechanisms and modern Solidity safety features to mitigate risks in legacy smart contracts.

Author: Beosin

In the early hours of January 9, an unopen-sourced contract deployed by Truebit Protocol 5 years ago was attacked, resulting in a loss of 8,535.36 ETH (worth approximately $26.4 million). The Beosin security team conducted an analysis of the vulnerability and fund tracking for this security incident and shares the results as follows:

Attack Technique Analysis

For this incident, we take the most significant attack transaction as the analysis subject, with the transaction hash: 0xcd4755645595094a8ab984d0db7e3b4aabde72a5c87c4f176a030629c47fb014

1. The attacker calls getPurchasePrice() to obtain the price

2. Subsequently calls the flawed function 0xa0296215(), setting the msg.value extremely low

Since the contract is not open-source, it is inferred from the decompiled code that this function has an arithmetic logic vulnerability, such as integer truncation issues, allowing the attacker to successfully mint a large number of TRU tokens.

3. The attacker "sells back" the minted tokens to the contract through the burn function, extracting a large amount of ETH from the contract reserves.

This process is repeated 4 more times, with the msg.value increasing each time, until almost all ETH in the contract is extracted.

Stolen Funds Tracking

Based on on-chain transaction data, Beosin conducted a detailed fund tracking through its blockchain on-chain investigation and tracking platform, BeosinTrace, and shares the results as follows:

Currently, the stolen 8,535.36 ETH, after transfers, are mostly held in 0xd12f6e0fa7fbf4e3a1c7996e3f0dd26ab9031a60 and 0x273589ca3713e7becf42069f9fb3f0c164ce850a.

Among them, address 0xd12f holds 4,267.09 ETH, and address 0x2735 holds 4,001 ETH. The address from which the attacker initiated the attack (0x6c8ec8f14be7c01672d31cfa5f2cefeab2562b50) still holds 267.71 ETH. There have been no further fund transfers from these three addresses yet.

Stolen Funds Flow Analysis Diagram by Beosin Trace

The above addresses have been marked as high-risk addresses by Beosin KYT. Taking the attacker's address as an example:

Beosin KYT

Conclusion

This stolen fund incident involves an unopen-sourced smart contract from 5 years ago. For such contracts, the project team should upgrade the contract, introduce emergency pause functions, parameter limitations, and new Solidity security features. Furthermore, security audits remain an essential step for contracts. Through security audits, Web3 enterprises can comprehensively detect smart contract code, identify and fix potential vulnerabilities, and enhance contract security.

*Beosin will provide a complete analysis report of all fund flows and address risks for this incident. Welcome to request it via the official email [email protected].

Пов'язані питання

QWhat was the total amount of ETH stolen in the Truebit Protocol security incident?

A8,535.36 ETH, valued at approximately $26.4 million.

QWhich function did the attacker call to exploit the vulnerability in the unopened contract?

AThe attacker called the function 0xa0296215() with a very small msg.value to exploit an arithmetic logic vulnerability, likely due to integer truncation issues.

QHow did the attacker convert the fraudulently minted TRU tokens into ETH?

AThe attacker used the burn function to 'sell back' the minted TRU tokens to the contract, extracting a large amount of ETH from the contract reserves.

QWhat are the two main addresses where the stolen ETH is currently held?

AThe majority of the stolen ETH is held in addresses 0xd12f6e0fa7fbf4e3a1c7996e3f0dd26ab9031a60 (4,267.09 ETH) and 0x273589ca3713e7becf42069f9fb3f0c164ce850a (4,001 ETH).

QWhat security measures does Beosin recommend to prevent such incidents?

ABeosin recommends upgrading the contract to include emergency pause functions, parameter limits, and new Solidity security features, as well as conducting thorough security audits to detect and fix potential vulnerabilities.

Пов'язані матеріали

Saeed Al-Marri: How Tokenization Unlocks New Opportunities for Shipping Funds

Said Al-Marri: How Tokenization Opens New Opportunities for Shipping Funds For centuries, commercial shipping has been a capital-intensive asset class limited to institutional funds and shipping dynasties. Said bin Saleh Al-Marri, CEO of Ethra Invest and Ethra Ship, aims to break down these barriers by combining Real World Asset (RWA) tokenization with conservative private equity principles. This bridges decentralized finance (DeFi) with the physical realities of global trade. Tokenization allows fractional ownership of ships on a blockchain, giving smaller investors access to previously inaccessible markets. However, Al-Marri warns it is not a regulatory loophole or a cure for asset illiquidity. The core physical risks are isolated in Special Purpose Vehicles (SPVs) for qualified investors. While tokenization enhances transparency and ownership record-keeping, Al-Marri stresses that a liquid secondary market depends on transparent asset valuation and must not interfere with ship operations managed by professionals. Regarding legal enforcement, smart contracts cannot physically seize a ship. Legal recourse still relies on traditional maritime courts, ship mortgages, and flag state laws, with blockchain records needing to mirror legal ownership in the SPV perfectly. Beyond ownership, the industry faces administrative hurdles like paper-based bills of lading. Al-Marri argues the bottleneck is legal and operational standardization, not technology. He advocates for a hybrid model combining digital trade documents and programmable settlements with support from regulated financial institutions, rather than a full crypto replacement for tools like Letters of Credit. A major challenge is decarbonizing the global fleet by 2050. Transitioning to green fuels requires massive upfront investment. Al-Marri emphasizes a conservative, holistic approach to underwriting these projects, evaluating technology, fuel availability, safety, and resale value. Investments must be justified under conservative forecasts, not just optimistic ones. By combining pragmatic risk management with digital infrastructure, leaders like Al-Marri show that the evolution of maritime finance is about mobilizing capital to build a modernized and sustainable global fleet, not just putting ships on a blockchain.

cryptonews.ru15 хв тому

Saeed Al-Marri: How Tokenization Unlocks New Opportunities for Shipping Funds

cryptonews.ru15 хв тому

Six Years Later, UNI Finally Welcomes Its Own "Buyback Bull"

After years of debate, Uniswap's UNI token has finally entered a 'buyback bull' phase following the long-awaited activation of its fee-switch mechanism. The UNIfication proposal, executed in December 2025, redirected a portion of protocol fees from select pools and Unichain sequencer revenue into a treasury (TokenJar) dedicated to buying back and permanently burning UNI. Initial market reaction was muted due to modest early burn rates. A significant shift occurred in July 2026 with the launch of Robinhood Chain. Uniswap's immediate deployment there skyrocketed trading volume, making it a top fee-generator. Subsequently, governance votes extended the fee mechanism to v4 pools and Robinhood Chain, causing protocol revenue to nearly triple. Daily funds directed to UNI burns rose sharply, with Robinhood Chain contributing over half. This transitioned UNI's narrative from a governance token to a cash-flow asset backed by a perpetual automatic buyer. UNI's price, which had languished around $2.30 in early June, nearly doubled to approach $4.60 by late July. Analysts credit this to the tangible cash flow from fees rather than mere speculation. Unlike many newer projects where buybacks are offset by large investor unlocks, UNI's six-year history has resulted in a widely distributed and relatively clean supply, allowing the buyback pressure to effectively impact the secondary market. The key test will be whether trading activity, particularly on Robinhood Chain, sustains after its initial gas subsidies expire.

marsbit21 хв тому

Six Years Later, UNI Finally Welcomes Its Own "Buyback Bull"

marsbit21 хв тому

Only 153 Venture Capital Firms Invested in July: Is the Crypto VC Industry Experiencing a 'Mass Extinction'?

In July 2026, only 153 unique venture capital firms participated in disclosed crypto funding rounds, marking the lowest monthly count since November 2020. This figure represents an 87% decline from the peak of 1,177 firms in 2022. Overall, the first seven months of 2026 saw crypto projects raise approximately $11.78 billion across 481 rounds. This crypto VC contraction contrasts sharply with the broader venture capital landscape, where global VC investment reached a record $560.4 billion in H1 2026, heavily fueled by major AI company financings. This shift in capital allocation has drawn funds away from the crypto sector. Within crypto, funding is highly concentrated. Trading platforms, prediction markets, and payment sectors absorbed 53% of the total capital. While early-stage deals remain frequent, the largest sums flow to a few late-stage rounds and mergers & acquisitions, which surged to $7.23 billion in Q2 2026. The market is consolidating around top funds like a16z crypto and Dragonfly, which successfully raised new multi-billion dollar funds, while many smaller firms have retreated. Analysts describe this as a "great extinction" for crypto VCs, where capital is becoming more selective, favoring proven business models and assets over early-stage speculation. This raises the bar for project quality, funding efficiency, and viable exit paths.

marsbit41 хв тому

Only 153 Venture Capital Firms Invested in July: Is the Crypto VC Industry Experiencing a 'Mass Extinction'?

marsbit41 хв тому

Торгівля

Спот
活动图片