$36M Drained via Unverified Contracts: Chainalysis Flags Truebit as Largest

Truebit lost $26 million in a January 2026 exploit against its unverified TRU purchase and minting smart contract. Unverified smart contracts drove at

Share
$36M Drained via Unverified Contracts: Chainalysis Flags Truebit as Largest

Hero: A digital visualization of shadowed hackers targeting glowing unverified smart contract code on a blockchain ledger, with red alert icons and data streams leaking from DeFi protocol interfaces

Summary

  • Truebit lost $26 million in a January 2026 exploit against its unverified TRU purchase and minting smart contract.
  • Unverified smart contracts drove at least $36.7 million in total DeFi losses across four incidents over six months.
  • The Chainalysis 2026 Crypto Crime Report identifies these contracts as a growing attack vector in DeFi exploits.

Truebit lost $26 million in January 2026. Hackers drained its unverified TRU purchase and minting smart contract. Halborn confirmed the flaw.

The theft fits a wider pattern. Attackers now target unverified contracts across DeFi. Chainalysis documented the trend in its latest report.

Context

Unverified smart contracts let anyone call functions before audits occur. Weaknesses stay exposed. Chainalysis tracks the rising number of hits in its 2026 Crypto Crime Report.

Four incidents struck Truebit, Trusted Volumes, Aperture Finance, and Ekubo. Losses reached nearly $37 million inside six months. None of the contracts carried public verification.

Details

Halborn traced the Truebit attack to faulty logic inside the purchase contract. One transaction emptied the funds. The other three protocols suffered the same style of unauthorized mint or withdrawal.

Chainalysis connects unverified contracts to at least $36.7 million in losses. AI tools speed up flaw discovery in live code. Aggregated reports put the four-event total near $37 million.

"Unverified smart contracts linked to at least $36.7M in losses."

, Chainalysis (Source)

Impersonation scams on social media add noise around these events. On-chain records still match the contract-loss totals.

Outlook

Teams and users should verify contracts on public explorers before any interaction. Chainalysis will keep watching whether verification lowers exploit success rates.