Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
1inch Liquidity Provider TrustedVolumes Exploited for $6.7 Million
00

1inch Liquidity Provider TrustedVolumes Exploited for $6.7 Million

May 7, 2026

TrustedVolumes, a 1inch liquidity provider and market maker, was exploited on May 7, 2026, draining $6.7 million in wrapped assets and stablecoins from the Ethereum network. Blockchain analysts believe the same hacker behind the March 2025 1inch Fusion V1 attack that netted $5 million executed this breach. The exploit was one of five major DeFi breaches in early May 2026, totaling over $8 million in losses.

TrustedVolumes exploit details

  • ▪TrustedVolumes is considering a bug bounty in response to the hack
  • ▪The TrustedVolumes exploit drained 1,291.16 WETH, 206,282 USDT, 16.939 WBTC, and 1,268,771 USDC, totaling $5.87 million
  • ▪The TrustedVolumes exploit drained approximately $6.7 million in wrapped assets and stablecoins
  • ▪TrustedVolumes, a 1inch liquidity provider and market maker, was exploited on the Ethereum network on May 7, 2026

Attack methodology

  • ▪The TrustedVolumes vulnerability exploited a custom RFQ (request-for-quote) swap proxy controlled by TrustedVolumes at address 0xeEeEEe53033F7227d488ae83a
  • ▪The exploiter wallet 0xC3EBDdEa4f69df717a8f5c89e7cF20C1c0389100 executed the primary transaction in the TrustedVolumes attack
  • ▪The TrustedVolumes attack targeted the resolver contract at address 0x9bA0CF1588E1DFA905eC948F7FE5104dD40EDa31
  • ▪The TrustedVolumes hacker aggregated all drained assets into 2,513 ETH via internal swapping using a custom proxy

Connection to previous hacks

  • ▪Blockchain analysts believe the same hacker who executed the March 2025 hack on 1inch Fusion V1, netting around $5 million, is behind the TrustedVolumes attack
  • ▪The flaw leveraged in the TrustedVolumes attack is completely different from the one exploited during the March 2025 1inch Fusion V1 incident, targeting TrustedVolumes' unique RFQ system rather than the Fusion V1 codebase

May 2026 DeFi breach wave

  • ▪Five major DeFi breaches occurred within the first days of May 2026, totaling losses exceeding $8 million
  • ▪Henrik Jannsen, a Bisq contributor, released a comprehensive reimbursement plan on GitHub for victims to receive compensation mainly in Bitcoin, with BSQ as the secondary option
  • ▪Ekubo protocol lost $1.4 million (17 WBTC) on May 5, 2026, due to an improper access-control vulnerability in its router module
  • ▪April 2026 saw an unprecedented $625-$635 million theft across 28-30 DeFi attacks
  • ▪The Ekubo attacker performed 85 fast transactions, funneling the stolen funds through DeFi platforms connected via Velora before swapping some for USDC, DAI, and ETH
  • ▪SmartCredit protocol was attacked on May 4, 2026, with a flash loan attack extracting $72,000 through malicious use of the borrowing mechanism
  • ▪Bisq was attacked on May 1, 2026, using the Bisq V1 client exploit, resulting in a loss of $858,000
  • ▪Hackers drained approximately $8.23 million from investors in May 2026
  • ▪Sharwa.Finance was attacked on May 1, 2026, with attackers draining $32,850 through oracle price manipulation

2 sources

Coinpedia
1inch Liquidity Provider Trusted Volumes Exploited for $5.87 Million
View source article
Cryptopolitan
DeFi attacker steals $6.7M from 1inch market maker
View source article

Story comments

Loading comments…

Related Projects

1inch

Topics

Crypto hacksSmart contract vulnerabilityDeFiDecentralized exchange (DEX)