According to TrustedVolumes, 1inch, and security researchers, a flaw in a custom RFQ swap proxy led to about $6.7 million in losses, while 1inch states its systems, infrastructure, and user funds were unaffected.
TrustedVolumes, a 1inch-linked but independently operating liquidity provider and market maker, said about $6.7 million was stolen in a smart contract exploit tied to a vulnerability in its custom RFQ swap proxy. Security researchers including PeckShield, Blockaid, and Humphrey said the attacker bypassed authorization checks through flawed signature validation and a publicly accessible signer-registration function, enabling forged trading orders. Earlier estimates put losses at about $5.87 million before TrustedVolumes updated the figure to roughly $6.7 million. Stolen assets reportedly included WETH, WBTC, USDT, and USDC, and the funds were distributed across three addresses. TrustedVolumes said it is open to bug bounty talks, while 1inch said in a May 7 statement that TrustedVolumes is an independent liquidity provider used by multiple protocols and that the incident did not affect 1inch’s systems, infrastructure, operations, or user funds. Reports also linked the attacker to the March 2025 1inch Fusion V1 Settlement contract exploit that previously affected TrustedVolumes.