Skip to content
TrustedVolumes Market Maker Suffers $5.87 Million Exploit

TrustedVolumes Market Maker Suffers $5.87 Million Exploit

Castlecrypto.Gg • May 7, 2026

A critical third-party market maker has recently suffered a multi-million dollar security breach. According to data published by blockchain security firm Blockaid, an active exploit targets the TrustedVolumes resolver contract deployed on the Ethereum mainnet.

🚨 Blockaid’s exploit detection system has identified an on-going exploit on TrustedVolumes (1inch market maker / resolver, @trustedvolumes ). Chain: Ethereum

Victim contract: TrustedVolumes resolver — 0x9bA0CF1588E1DFA905eC948F7FE5104dD40EDa31

— Blockaid (@blockaid_) May 7, 2026

The breach entered through a vulnerability within the custom Request for Quote (RFQ) swap proxy used by the market maker allowed the attacker to bypass the contract’s security parameters.

As a result of the breach, around $5.87 million of the market maker’s assets have been extracted by the attacker. The assets stolen by the attacker consisted of heavy allocations of WETH, USDT, WBTC, and USDC tokens.

The researchers behind the TrustedVolumes smart contract breach have confirmed through their investigation that the entity behind the attack is the same entity behind the $3 million 1inch Fusion V1 exploit in March 2025. However, the current attack used a different vulnerability in the smart contract.

More News: Flow Network Neutralizes $3.9M Exploit After Sophisticated Token Counterfeiting Attack

As the trustedVolumes protocol is a third-party resolver for the 1inch protocol, the smart contract breach initially caused concern for the 1inch protocol. However, 1inch quickly announced its findings to mitigate the market panic.

No 1inch protocols or entities were involved in the attack. They confirmed the attack was limited to the external TrustedVolumes smart contract resolver. As a result, all 1inch protocols and users remain secure from the attack.

Although 1inch has not been compromised, this incident highlights the risks of the current structure of the DeFi sector and how third-party market makers can be targeted and exploited by hackers.

More News: KelpDAO Suffers $290M Exploit as LayerZero Attributes Attack to Lazarus Group

For more information on stablecoin adoption and blockchain innovation globally, keep checking Castlecrypto News.

Extracted Entities