
An on-chain settlement confirms one exploiter returned part of the May haul while retaining a similar amount as a bug bounty, leaving the broader recovery from losses of up to $6.7 million unresolved.
Trusted Volumes' attacker returned 1,122.12 ETH worth about $2.07 million in a partial recovery from the May exploit, while retaining a similar amount under a negotiated bug bounty settlement that both sides confirmed in on-chain messages. The transfer came more than two months after the breach, which initially drained about $5.87 million and was later estimated by the protocol at roughly $6.7 million after asset-value changes and related losses. The incident hit TrustedVolumes' role as a resolver in the 1inch Fusion request-for-quote market rather than 1inch's core infrastructure or user funds. Blockaid said the stolen assets included 1,291 WETH, 1.26 million USDC, 206,282 USDT and 16.93 WBTC, and security researchers traced the exploit to a custom RFQ proxy contract and an access-control flaw that let attackers register themselves as authorized order signers. Halborn said the weakness stemmed from a public function, allowing unauthorized orders to move funds already approved to the proxy. TrustedVolumes had signaled shortly after the hack that it was open to a bug bounty and a mutually acceptable resolution. The latest settlement underscores a growing DeFi pattern in which victims try to recover funds through direct negotiation rather than relying only on law enforcement or court action, even as that approach raises concerns that attackers may see post-hack settlements as a viable exit route.