Crypto Hackers Drain Over $36M From Protocols Using Unverified Contracts

Source Newsbtc

A crypto hacker who drained $26 million from Ethereum-based protocol Truebit in January had likely practiced the technique on smaller targets first, according to blockchain analytics firm Chainalysis.

A Contract Left Exposed For Years

The Truebit exploit was the largest of four incidents Chainalysis identified in a new report covering the past six months. Together, those attacks — targeting Truebit, Trusted Volumes, Aperture Finance, and Ekubo — account for roughly $37 million in losses, all traced back to contracts whose source code had never been publicly verified on blockchain explorers.

The Truebit contract had been sitting on Ethereum since 2021. It was compiled using Solidity v0.5.3, a version released before automatic overflow protections became standard. An attacker found an integer overflow flaw inside its bonding curve mechanism and used it to mint large quantities of tokens at minimal cost before converting them to ETH.

Why Closed Code Creates Open Risk

Verified contracts get reviewed. Bug bounty hunters read them. Independent researchers flag problems before attackers do. Unverified contracts get none of that scrutiny, and many bug bounty programs specifically exclude them from coverage — meaning vulnerabilities can sit untouched for years while millions of dollars flow through the affected code.

That gap is what Chainalysis says attackers are now exploiting. Each of the four compromised contracts lacked publicly available source code. Attackers worked instead from decompiled bytecode, converting raw on-chain code into readable output using tools like Dedaub, Heimdall, and Panoramix.

Once decompiled, the code can be fed into AI systems capable of spotting reentrancy flaws, arithmetic errors, and access-control weaknesses at a scale no human reviewer could match.

The $36.7 million figure is a fraction of total DeFi losses during the same period — Chainalysis puts the broader six-month theft total above $1 billion. But the firm argues the unverified contract problem could grow as automated analysis tools become cheaper and easier to use, allowing attackers to scan large numbers of dormant contracts and rank them by exploitability.

The Vulnerabilities Varied, But The Pattern Did Not

Across the four incidents, the specific bugs differed. Reports indicate weaknesses ranged from integer overflow and access-control failures to input-validation errors and identity verification flaws.

What they shared was the same protection gap: no public source code, no external review, and no real-time monitoring in place to catch abnormal activity before the funds were gone.

Chainalysis is recommending that protocols treat source-code verification as a baseline requirement for any contract holding user assets.

The firm also says audits and bug bounty coverage should extend to implementation contracts sitting behind proxy structures — components that often go unreviewed even when the front-facing contract is verified.

Featured image from CybersecAsia, chart from TradingView

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
Apple to use Google's Nvidia processors for planned Siri revampTech giant Apple is furthering plans to power its Siri assistant revamp using Nvidia’s Blackwell B200 processors hosted in Google’s data centers, which points to a U-turn from the company’s regular strategy of having control over its entire tech stack. The announcement is expected to come alongside a preview of iOS 27 and the initial...
Author  Cryptopolitan
Jun 05, Fri
Tech giant Apple is furthering plans to power its Siri assistant revamp using Nvidia’s Blackwell B200 processors hosted in Google’s data centers, which points to a U-turn from the company’s regular strategy of having control over its entire tech stack. The announcement is expected to come alongside a preview of iOS 27 and the initial...
placeholder
Super Micro stock plunges after plans for $7 billion capital raise to fund AI backlogGlobal leader in AI and computing, Super Micro Computer (SMCI) has had its shares fall by about 10% in after-hours trading on Tuesday after the server maker announced plans to raise $7 billion in new financing to fund its growing AI hardware backlog. The capital raise involves two phases, with the initial phase being an...
Author  Cryptopolitan
Yesterday 02: 51
Global leader in AI and computing, Super Micro Computer (SMCI) has had its shares fall by about 10% in after-hours trading on Tuesday after the server maker announced plans to raise $7 billion in new financing to fund its growing AI hardware backlog. The capital raise involves two phases, with the initial phase being an...
placeholder
Disciplined Retail Traders Could Beat the S&P 500, NYSE Veteran Tuchman SaysDisciplined retail traders who follow the rules could probably beat the S&P 500, according to Peter Tuchman, the longest-serving floor trader at the New York Stock Exchange.The 40-year veteran, who tr
Author  Beincrypto
2 hours ago
Disciplined retail traders who follow the rules could probably beat the S&P 500, according to Peter Tuchman, the longest-serving floor trader at the New York Stock Exchange.The 40-year veteran, who tr
placeholder
SpaceX IPO Can Pump $100 Billion Into Google’s Alphabet StockThe SpaceX IPO, the largest listing in history, is set to price this week, with Alphabet (GOOGL) stock fresh off a 12.67% slide from its May 18 record.The debut turns a decade-old bet worth close to $
Author  Beincrypto
2 hours ago
The SpaceX IPO, the largest listing in history, is set to price this week, with Alphabet (GOOGL) stock fresh off a 12.67% slide from its May 18 record.The debut turns a decade-old bet worth close to $
placeholder
Elizabeth Warren pushes SEC to delay SpaceX IPO as valuation debate intensifiesSen. Elizabeth Warren (D-Mass.), in yet another attack on big tech, has called on the SEC to delay SpaceX’s planned initial public offering.  Wall Street was already having arguments over whether or not a $1.75 trillion price tag can be justified, and now Senator Warren has intervened just days before SpaceX is set to begin...
Author  Cryptopolitan
2 hours ago
Sen. Elizabeth Warren (D-Mass.), in yet another attack on big tech, has called on the SEC to delay SpaceX’s planned initial public offering.  Wall Street was already having arguments over whether or not a $1.75 trillion price tag can be justified, and now Senator Warren has intervened just days before SpaceX is set to begin...
goTop
quote