Truebit Hacker Launders Millions in ETH

The attacker behind the Truebit Protocol exploit has laundered over 8,500 ETH through Tornado Cash after abusing a smart contract flaw. The incident caused a near-total collapse of the TRU token and significant losses for investors, marking the first major DeFi hack of 2026.

Truebit Hacker Launders Millions in ETH

The hacker responsible for the attack on the Truebit Protocol has successfully laundered all of the stolen funds. On-chain data shows that 8,535 ETH, worth approximately $26 million, was transferred through the Tornado Cash mixer. The activity was identified and documented by analysts at Lookonchain.

The exploit occurred on January 8, 2026, when the attacker took advantage of an integer overflow vulnerability in an outdated smart contract. This flaw allowed them to mint enormous amounts of TRU tokens at almost no cost. The attacker then sold these tokens back to the protocol, rapidly draining its liquidity.

This incident represents the first major DeFi security breach of 2026, with devastating consequences for the project. The price of the TRU token collapsed by more than 99.9%, effectively erasing the value of investors’ holdings.

In response, the Truebit team confirmed the breach and warned users against interacting with the compromised contract. They also announced cooperation with law enforcement authorities and initiated a full protocol audit to determine the scope of the damage and assess any potential recovery options.

Blockchain security firms have linked the wallet used in this attack to a previous hack targeting the Sparkle Protocol, suggesting that the perpetrator is an experienced and well-prepared actor.

Share