Truebit accounted for the biggest loss at $26 million, with Chainalysis warning that decompiled bytecode and AI-assisted analysis are making older, unverified contracts easier to exploit.
Protocols with unverified source code lost about $36.7 million over the past six months, Chainalysis said, citing attacks on Truebit, Trusted Volumes, Aperture Finance, and Ekubo. The largest incident was the January exploit of Ethereum-based protocol Truebit, where an attacker drained $26 million from a contract deployed in 2021 and compiled with Solidity v0.5.3, exploiting an integer overflow in its bonding curve to mint tokens cheaply before converting them to ETH. Chainalysis said all four compromised contracts lacked publicly verified source code, allowing vulnerabilities to persist without broader external review or bug bounty scrutiny. The firm said attackers decompiled on-chain bytecode with tools including Dedaub, Heimdall, and Panoramix, and warned that AI systems can then be used to detect flaws such as reentrancy, arithmetic, access-control, input-validation and identity-verification weaknesses at scale. While the losses are a small share of the more than $1 billion in DeFi thefts Chainalysis tracked over the same six-month period, the firm said the risk could grow as automated analysis becomes cheaper and recommended source-code verification, broader audits and bug bounty coverage for contracts holding user assets, including implementation contracts behind proxy structures.