Imagine someone taking your wallet, returning half of its contents, and claiming the rest is a ‘fee’ for proving how easy it was to steal. That is essentially the situation TrustedVolumes currently faces. The hacker who drained its funds in May has just returned 1,122 ETH - roughly $2 million - while keeping another estimated $2 million as a self-styled ‘bounty’.
What makes this case unusual: as of this writing, TrustedVolumes has never officially confirmed agreeing to the unilaterally proposed bounty terms.
Anatomy of a Signed Robbery
The exploit unfolded on May 7, 2026, initially draining around $5.87 million from contracts controlled by TrustedVolumes, a liquidity provider and market maker. Security firm Blockaid identified the stolen assets: 1,291.16 WETH, 206,282 USDT, 16.939 WBTC, and 1.27 million USDC. PeckShield later reported that the hacker swapped all the tokens and consolidated the proceeds into roughly 2,513 ETH.
The vulnerability stemmed from TrustedVolumes’ custom request-for-quote (RFQ) system running on 1inch infrastructure. This system was used to quote token prices and execute signed trades directly from their own inventory. Verichains discovered a public function completely devoid of access controls - a loophole that allowed the attacker to register their own address as an authorized ‘order signer’. With that status, they could construct transactions that appeared legitimate to the proxy system, then instruct the proxy to siphon WETH, WBTC, USDT, and USDC straight from the inventory vault. Verichains also uncovered a mismatch between the address verified for authorization and the address actually supplying the tokens, alongside a replay protection mechanism that failed to record orders properly.
Crucially, although TrustedVolumes provided liquidity via 1inch, the attack did not breach 1inch’s core aggregation contracts or standard user swap routes. Blockaid emphasized that the hacker targeted TrustedVolumes’ custom Ethereum resolver setup rather than regular 1inch channels - a reassuring distinction for millions of everyday 1inch users.
When the ‘Refund’ Shrinks on Its Own
There is further irony in the return. The combined value of the returned funds is now lower than the initial loss, as the price of ETH has dropped since May - when the stolen assets were first converted into ETH. This means that despite the hacker’s ‘generosity’ in returning half, the victim still absorbs the deficit caused by market volatility.
TrustedVolumes responded in guarded terms. The firm offered discussions regarding a ‘vulnerability bounty’ and a mutually beneficial resolution, inviting the hacker to initiate constructive dialogue. However, the official statement made no mention of any proposed bounty figure - leaving the impression that the reward’s size was dictated entirely by the party responsible for the theft.
A Recurring Pattern
Blockaid linked the hacker’s wallet to a March 2025 Fusion V1 exploit. Notably, the May 2026 attack leveraged a different security flaw specific to TrustedVolumes’ custom proxy - signaling that the same perpetrator continues hunting for fresh weaknesses from one target to the next.
The case highlights an increasingly common dilemma in DeFi: the line between a ‘malicious hacker’ and a ‘white hat demanding compensation’ blurs when perpetrators unilaterally set their own fee - holding victim funds as collateral. For everyday users, the takeaway is less about the technicalities of RFQs or resolvers and more about an enduring principle: protocols managing substantial funds must audit down to the most trivial functions, as a single function missing access controls is all it takes to swing the doors wide open.
Reported via crypto.news.
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




