Skip to content
DeFi Platform TrustedVolumes Hit by $6.7M Exploit

DeFi Platform TrustedVolumes Hit by $6.7M Exploit

Decrypt.Co May 7, 2026

TrustedVolumes, a liquidity provider used by multiple DeFi protocols, was hit by an exploit that has so far drained around $6.7 million in funds.

Blockchain analytics firm Blockaid's exploit detection system identified the victim contract as TrustedVolumes' resolver on Ethereum , with the attacker extracting approximately 1,291 WETH, 206,282 USDT , 16.93 WBTC , and 1.26 million USDC .

The firm flagged the exploiter as the same operator behind the March 2025 1inch Fusion V1 incident , leveraging a different vulnerability, this time in a TrustedVolumes-controlled custom RFQ swap proxy.

An RFQ, or request-for-quote, swap proxy is a contract that handles price quotes and token swaps between a market maker and traders.

TrustedVolumes confirmed the breach, publishing three wallet addresses holding the stolen funds, approximately $3 million, $3 million, and $700,000, and said it was "open to constructive communication regarding a bug bounty and a mutually acceptable resolution."

Hakan Unal, senior security operations lead at crypto security firm Cyvers, told Decrypt the root cause was a combination of “permissionless signer registration, broken replay protection, and an unvalidated transfer source field.”

The flaws let the attacker act as a trusted signer and drain victims without valid authorization, with funds routed through high-risk no-KYC exchange ChangeNow before being swapped to ETH, he added.

“The damage could have been far greater,” Unal said. “With replay protection nonfunctional, the attacker could have potentially drained additional approved accounts repeatedly.”

Decrypt has reached out to TrustedVolumes for .

DeFi aggregator 1inch pushed back after reports linked the platform directly to the breach, framing it as an attack on the protocol itself.

“We can confirm that neither 1inch nor any of the 1inch protocols are involved,” 1inch tweeted . “There is no impact on 1inch systems, infrastructure or user funds.”

“From a vetting and monitoring perspective, we are working alongside our security partners to understand the specifics of how this exploit occurred, and we will be incorporating any relevant findings into our ongoing security and integration processes,” a 1inch spokesperson told Decrypt .

If a provider is “unavailable or compromised, others continue to serve users without disruption,” with this “built-in redundancy” a core design principle that “functioned exactly as intended in this case,” the spokesperson added.

“While it is true that 1inch uses TrustedVolumes as a resolver, we are one of many. The framing of this story is ultimately confusing and harmful,” 1inch co-founder Sergej Kunz tweeted .

“What’s striking the TrustedVolumes incident is that the same attacker struck twice, months apart, against different contracts,” Nick Harris, founder and CEO of crypto asset recovery platform CryptoCare, told Decrypt , describing the perpetrator as a “patient, targeted operator” rather than an opportunistic hacker. He warned that surviving an exploit doesn’t necessarily close the risk but may instead “open a new one.”

The TrustedVolumes exploit follows a brutal stretch for DeFi, with North Korean hackers draining $285 million from Drift Protocol and Kelp DAO losing $293 million in an attack it blamed on compromised LayerZero infrastructure.

The Kelp hack has since spilled into a U.S. federal court, where Aave is fighting to unblock $71 million in frozen user funds on Arbitrum.

Arbitrum DAO passed a governance vote on Thursday approving the release of roughly $70 million in frozen ETH to a coordinated recovery effort aimed at making victims of the Kelp DAO rsETH exploit whole, though a U.S. federal court order could still block the transfer. The proposal, co-authored by Aave Labs, KelpDAO, LayerZero, EtherFi, and Compound, passed with 182.2 million votes in favor, 90.96%, against negligible opposition. The 30,765.67 ETH was frozen by the Arbitrum Security Council...

Australia's financial intelligence unit AUSTRAC has launched two targeted supervisory campaigns into the country's virtual assets sector as landmark anti-money laundering reforms take effect. "AUSTRAC is checking how well crypto businesses in Australia are managing money-laundering risks, ahead of major new laws coming into force," said the regulator’s Chief Executive Officer Brendan Thomas in a statement. We’re conducting 2 supervisory campaigns aimed at Australia’s virtual assets sector. We’r...

Another crypto project is leaving blockchain interoperability protocol LayerZero after the fallout from the $292 million Kelp DAO exploit intensified scrutiny around cross-chain bridge security. In an announcement Thursday, Solv Protocol said it is migrating the infrastructure that powers more than $700 million in tokenized Bitcoin from LayerZero to Chainlink’s Cross-Chain Interoperability Protocol (CCIP), following what it described as a broader security review of cross-chain systems. The prot...

This website or its third-party tools use cookies. By clicking the accept button, you agree to the use of cookies.

Extracted Entities