Crypto Hackers Drain Over $36M From Protocols Using Unverified Contracts

Source Newsbtc

A crypto hacker who drained $26 million from Ethereum-based protocol Truebit in January had likely practiced the technique on smaller targets first, according to blockchain analytics firm Chainalysis.

A Contract Left Exposed For Years

The Truebit exploit was the largest of four incidents Chainalysis identified in a new report covering the past six months. Together, those attacks — targeting Truebit, Trusted Volumes, Aperture Finance, and Ekubo — account for roughly $37 million in losses, all traced back to contracts whose source code had never been publicly verified on blockchain explorers.

The Truebit contract had been sitting on Ethereum since 2021. It was compiled using Solidity v0.5.3, a version released before automatic overflow protections became standard. An attacker found an integer overflow flaw inside its bonding curve mechanism and used it to mint large quantities of tokens at minimal cost before converting them to ETH.

Why Closed Code Creates Open Risk

Verified contracts get reviewed. Bug bounty hunters read them. Independent researchers flag problems before attackers do. Unverified contracts get none of that scrutiny, and many bug bounty programs specifically exclude them from coverage — meaning vulnerabilities can sit untouched for years while millions of dollars flow through the affected code.

That gap is what Chainalysis says attackers are now exploiting. Each of the four compromised contracts lacked publicly available source code. Attackers worked instead from decompiled bytecode, converting raw on-chain code into readable output using tools like Dedaub, Heimdall, and Panoramix.

Once decompiled, the code can be fed into AI systems capable of spotting reentrancy flaws, arithmetic errors, and access-control weaknesses at a scale no human reviewer could match.

The $36.7 million figure is a fraction of total DeFi losses during the same period — Chainalysis puts the broader six-month theft total above $1 billion. But the firm argues the unverified contract problem could grow as automated analysis tools become cheaper and easier to use, allowing attackers to scan large numbers of dormant contracts and rank them by exploitability.

The Vulnerabilities Varied, But The Pattern Did Not

Across the four incidents, the specific bugs differed. Reports indicate weaknesses ranged from integer overflow and access-control failures to input-validation errors and identity verification flaws.

What they shared was the same protection gap: no public source code, no external review, and no real-time monitoring in place to catch abnormal activity before the funds were gone.

Chainalysis is recommending that protocols treat source-code verification as a baseline requirement for any contract holding user assets.

The firm also says audits and bug bounty coverage should extend to implementation contracts sitting behind proxy structures — components that often go unreviewed even when the front-facing contract is verified.

Featured image from CybersecAsia, chart from TradingView

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
Gold price declines amid risk-on sentiment despite Fed rate cut expectationsGold price (XAU/USD) continues with its struggle to find acceptance above the $3,400 mark and attracts heavy selling during the Asian session on Monday.
Author  FXStreet
Aug 11, 2025
Gold price (XAU/USD) continues with its struggle to find acceptance above the $3,400 mark and attracts heavy selling during the Asian session on Monday.
placeholder
EUR/USD Price Forecast: Keeps bullish vibe above 1.1600 despite France’s deepening political crisisThe EUR/USD pair loses ground to near 1.1620 during the early European session on Monday.
Author  FXStreet
Oct 27, 2025
The EUR/USD pair loses ground to near 1.1620 during the early European session on Monday.
placeholder
ECB Policy Outlook for 2026: What It Could Mean for the Euro’s Next MoveWith the ECB likely holding rates steady at 2.15% and the Fed potentially extending cuts into 2026, EUR/USD may test 1.20 if Eurozone growth proves resilient, but weaker growth and an ECB pivot could pull the pair back toward 1.13 and potentially 1.10.
Author  Mitrade
Dec 26, 2025
With the ECB likely holding rates steady at 2.15% and the Fed potentially extending cuts into 2026, EUR/USD may test 1.20 if Eurozone growth proves resilient, but weaker growth and an ECB pivot could pull the pair back toward 1.13 and potentially 1.10.
placeholder
Gold plummets below $4,200 as US‑Iran tensions spur hawkish rate bets ahead of US CPIGold (XAU/USD) extends the recent breakdown momentum below a technically significant 200-day Simple Moving Average (SMA) and drops to a fresh low since March 23, further below the $4,200 mark during the Asian session on Wednesday.
Author  FXStreet
20 hours ago
Gold (XAU/USD) extends the recent breakdown momentum below a technically significant 200-day Simple Moving Average (SMA) and drops to a fresh low since March 23, further below the $4,200 mark during the Asian session on Wednesday.
placeholder
BTC Hovers Near 60,000 Mark After Plunge. US May CPI Set to Be Revealed, How Is Wall Street Betting?Bitcoin's rebound falters as the U.S.-Iran conflict and CPI data likely sustain downward pressure.On June 10, escalating U.S.-Iran tensions put the already fragile crypto market to the te
Author  TradingKey
18 hours ago
Bitcoin's rebound falters as the U.S.-Iran conflict and CPI data likely sustain downward pressure.On June 10, escalating U.S.-Iran tensions put the already fragile crypto market to the te
goTop
quote