Crypto Hackers Drain Over $36M From Protocols Using Unverified Contracts
Narrative Analysis: Name Calling

A crypto hacker who drained 26 million from Ethereum-based protocol Truebit in January had likely practiced the technique on smaller targets first, according to blockchain analytics firm Chainalysis. Related Reading: The Bitcoin Rally Has A Problem: Demand Is Drying Up A Contract Left Exposed For Years The Truebit exploit was the largest of four incidents Chainalysis identified in a new report covering the past six months. Together, those attacks — targeting Truebit, Trusted Volumes, Aperture Finance, and Ekubo — account for roughly 37 million in losses, all traced back to contracts whose source code had never been publicly verified on blockchain explorers. The Truebit contract had been sitting on Ethereum since 2021. It was compiled using Solidity v0.5.3, a version released before automatic overflow protections became standard. An attacker found an integer overflow flaw inside its bonding curve mechanism and used it to mint large quantities of tokens at minimal cost before converting them to ETH. Why Closed Code Creates Open Risk Verified contracts get reviewed. Bug bounty hunters read them. Independent researchers flag problems before attackers do. Unverified contracts get none of that scrutiny, and many bug bounty programs specifically exclude them from coverage — meaning vulnerabilities can sit untouched for years while millions of dollars flow through the affected code. That gap is what Chainalysis says attackers are now exploiting. Each of the four compromised contracts lacked publicly available source code. Attackers worked instead from decompiled bytecode, converting raw on-chain code into readable output using tools like Dedaub, Heimdall, and Panoramix. Once decompiled, the code can be fed into AI systems capable of spotting reentrancy flaws, arithmetic errors, and access-control weaknesses at a scale no human reviewer could match. The 36.7 million figure is a fraction of total DeFi losses during the same period — Chainalysis puts the broader six-month theft total above 1 billion. But the firm argues the unverified contract problem could grow as automated analysis tools become cheaper and easier to use, allowing attackers to scan large numbers of dormant contracts and rank them by exploitability. The Vulnerabilities Varied, But The Pattern Did Not Across the four incidents, the specific bugs differed. Reports indicate weaknesses ranged from integer overflow and access-control failures to input-validation errors and identity verification flaws. Related Reading: A 400 Billion Shiba Inu Surprise: Whale Wallet Springs Back To Life What they shared was the same protection gap: no public source code, no external review, and no real-time monitoring in place to catch abnormal activity before the funds were gone. Chainalysis is recommending that protocols treat source-code verification as a baseline requirement for any contract holding user assets. The firm also says audits and bug bounty coverage should extend to implementation contracts sitting behind proxy structures — components that often go unreviewed even when the front-facing contract is verified. Featured image from CybersecAsia, chart from TradingView
Narrative Intelligence Brief
This article was published by NewsBTC, a source frequently categorized with a center bias based in United Kingdom. Our narrative intelligence engine continuously monitors coverage from this outlet to track framing, bias, and rhetorical patterns. In this specific piece, our systems detected the potential use of the "Name Calling" technique. This narrative approach is often used to shape reader perception by highlighting specific emotional or rhetorical angles. By understanding the editorial perspective of NewsBTC, readers can better contextualize the information presented and compare it across our broader media matrix to find the real narrative.
Explore related topics: Stay informed with Real Narrative News as we track unfolding stories. Dive deeper into our coverage of pivotal topics including nba finals, strikes iran, coupe monde, hormuz, taylor swift, fifa cup, middle east, spacex ipo, guerre moyenorient, and iran war. Our intelligence streams continuously monitor these keywords to bring you unbiased analysis and real-time updates on topics like "Crypto Hackers Drain Over $36M From Protocols Using Unverified Contracts".
More from NewsBTC
June 11, 2026
Bitcoin Whales Bought The $60K Dip As Retail Capitulated – Over 11,000 BTC Leave Exchanges
June 11, 2026
Ethereum Price Could Spark A Fresh Upswing While Above $1,550
June 11, 2026
Bitcoin Price Hovers Above $60K As Traders Search For Direction
June 11, 2026
Crypto Hackers Drain Over $36M From Protocols Using Unverified Contracts
June 11, 2026
Three Wallets Withdraw $122M In Ethereum From FalconX And Kraken: Is Tom Lee Buying Again?
Reliability Insights
P
Technique: Name Calling
System analysis detected use of specific narrative techniques in this piece.Analysis Methodology
This narrative analysis was generated using the CoDataLab Global Intelligence Engine. Our proprietary AI scans thousands of cross-border sources to identify sentiment patterns, framing techniques, and potential media bias. While AI provides the data-driven foundation, our objective is to empower readers with additional context beyond the standard headline.The content displayed above is a structured summary designed for rapid information processing. For the full original report, please visit the source outlet.More Coverage
Discussion