A five-year-old vulnerability in Truebit’s TRU token contract enabled a single attacker to mint near-free tokens and drain millions in ETH.