Truflation Hack

Reported loss $5.2M
Private Key Compromised (Malware)

What happened

On 25 September 2024 an attacker drained about $5.2 million from Truflation, a Coinbase Ventures-backed inflation data project, after malware gave them access to the private keys behind its treasury multisig and several team members' personal wallets. ZachXBT estimated the loss at about $5.23 million and Cyvers at $4.95 million. The Ethereum wallets lost about $3.89 million in TRUF, $1.07 million in ETH and $236,000 in DAI, with roughly $100,000 more taken on seven other chains. Truflation said no customer or staking funds were compromised, though staking was disabled and liquidity on DEXs was reduced while it responded.

Truflation's CEO said the malware was likely planted on a computer during the Token2049 conference in Singapore. The treasury used multisig wallets, but the attacker collected enough signer keys to control them. The attacker swapped 1.37 million DAI for 500 ETH and sent it to the eXch exchange. Truflation worked with law enforcement, offered a $500,000 bounty on-chain for the funds' return with a deadline of 08:00 UTC on 28 September, then opened the bounty to anyone who could identify the hacker. No contact came. On 28 October 2024 Truflation announced a TRUF token migration designed to cancel out the value of the tokens the attacker held.

How it happened

  1. Malware infected a computer used by the Truflation team, which the CEO said was likely compromised during the Token2049 conference.
  2. The malware exposed private keys for the project's treasury multisig and for team members' personal wallets. The attacker obtained enough multisig signer keys to move treasury funds.
  3. On 25 September 2024 the attacker transferred TRUF, ETH and DAI out of the Ethereum wallets and about $100,000 more from seven other chains, around $5.2 million in total.
  4. The attacker swapped 1.37 million DAI for 500 ETH and sent it to the eXch exchange. Truflation named 0xb1cf7880351e6d16313c03a6686b4c8a5ba6372a as the address holding most of the stolen funds.
  5. Truflation offered a $500,000 bounty, got no reply, and later migrated TRUF to a new token so the attacker's stolen TRUF would lose its value.

Protocol details

Classification Infrastructure / Social Engineering / CeFi
Protocol Type Exploit/Access control
Protocol links Website @truflation

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.