TrustedVolumes Confirms $6.7 Million Crypto Attack and Opens Bug Bounty Talks

According to TrustedVolumes, 1inch, and security researchers, a flaw in a custom RFQ swap proxy led to about $6.7 million in losses, while 1inch states its systems, infrastructure, and user funds were unaffected.

USDT
USDC
WBTC

Fact Check
The claim is directly confirmed by Blockaid's own official X account (@blockaid_) in two posts published on 2026-05-07 (URLs: https://x.com/blockaid_/status/2052198320420819089 and https://x.com/blockaid_/status/2052195192305045571). Both posts precisely match every element of the claim: the victim (TrustedVolumes resolver, a 1inch market maker), the chain (Ethereum), the total loss (~$5.87M), and the specific assets drained (Wrapped Ether/WETH, Tether/USDT, Wrapped Bitcoin/WBTC, and USD Coin/USDC). The PANewsLab article independently corroborates the same details. No conflicting evidence was found. The only minor caveat is that the claim describes the event as 'active' at time of reporting, which is consistent with Blockaid's own language ('on-going exploit').
Summary

TrustedVolumes, a 1inch-linked but independently operating liquidity provider and market maker, said about $6.7 million was stolen in a smart contract exploit tied to a vulnerability in its custom RFQ swap proxy. Security researchers including PeckShield, Blockaid, and Humphrey said the attacker bypassed authorization checks through flawed signature validation and a publicly accessible signer-registration function, enabling forged trading orders. Earlier estimates put losses at about $5.87 million before TrustedVolumes updated the figure to roughly $6.7 million. Stolen assets reportedly included WETH, WBTC, USDT, and USDC, and the funds were distributed across three addresses. TrustedVolumes said it is open to bug bounty talks, while 1inch said in a May 7 statement that TrustedVolumes is an independent liquidity provider used by multiple protocols and that the incident did not affect 1inch’s systems, infrastructure, operations, or user funds. Reports also linked the attacker to the March 2025 1inch Fusion V1 Settlement contract exploit that previously affected TrustedVolumes.

Terms & Concepts
  • RFQ: Short for request for quote, a trading workflow in which a participant requests a price from liquidity providers before executing a swap.
  • Smart contract exploit: An attack that abuses a flaw in blockchain-based code to bypass intended rules and move or steal funds.
  • Bug bounty: A reward or negotiated payment offered for responsibly disclosing a vulnerability or returning exploited funds after a hack.