The attack exploited a flaw in an older smart contract, allowing the attacker to buy TRU at no cost and sell it back to extract ether.