Castlecrypto.Gg TrustedVolumes Exploit Drains $6.7M from DeFi Liquidity Provider
Article Content
- •TrustedVolumes lost approximately $6.7 million due to an exploit on May 7, 2026.
- •The attacker exploited a vulnerability in a custom RFQ swap proxy, allowing unauthorized fund drainage.
- •1inch confirmed no impact on its systems, distancing itself from the exploit linked to TrustedVolumes.
TrustedVolumes, a liquidity provider for DeFi protocols, suffered an exploit on May 7, 2026, leading to the theft of approximately $6.7 million in crypto assets. The attacker exploited a vulnerability in a custom request-for-quote (RFQ) swap proxy, allowing them to register as an approved order signer and drain funds. The stolen assets included 1,291 WETH, 206,282 USDT, 16.93 WBTC, and 1.26 million USDC, with the funds spread across three wallets. Blockchain security firms Blockaid and CertiK confirmed the attack and linked it to the same perpetrator behind the March 2025 1inch Fusion V1 exploit, although a different vulnerability was exploited this time. TrustedVolumes has expressed willingness to negotiate a bug bounty with the attacker. Despite the incident, 1inch clarified that its systems remain unaffected, emphasizing the independent operation of TrustedVolumes. The exploit is part of a troubling trend in DeFi, with multiple breaches reported in early May 2026.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (17)
Following this threat?
Track 1inch in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…