Trusted Volumes attacker returns 1,122 ETH, keeps about $2 million bounty

Trusted Volumes attacker returns 1,122 ETH, keeps about $2 million bounty

An on-chain settlement confirms one exploiter returned part of the May haul while retaining a similar amount as a bug bounty, leaving the broader recovery from losses of up to $6.7 million unresolved.

ETH
USDT
USDC

Fact Check
Six independent crypto news outlets (CoinCu, BlockBeats, ChainCatcher, Binance Square, Odaily, and KuCoin per search) report identical details: 1,122 ETH returned (~$2M) with roughly $2M retained as a de facto bounty, from an original ~$5.8M exploit. CoinCu cites the specific Etherscan return transaction and the Trusted Volumes address, and multiple outlets trace back to on-chain trackers (DefimonAlerts/thecomfeed). The consistency of figures and on-chain references across independent sources strongly supports the claim, though the Etherscan transaction and original X posts could not be directly verified in this run.
Summary

Trusted Volumes' attacker returned 1,122.12 ETH worth about $2.07 million in a partial recovery from the May exploit, while retaining a similar amount under a negotiated bug bounty settlement that both sides confirmed in on-chain messages. The transfer came more than two months after the breach, which initially drained about $5.87 million and was later estimated by the protocol at roughly $6.7 million after asset-value changes and related losses. The incident hit TrustedVolumes' role as a resolver in the 1inch Fusion request-for-quote market rather than 1inch's core infrastructure or user funds. Blockaid said the stolen assets included 1,291 WETH, 1.26 million USDC, 206,282 USDT and 16.93 WBTC, and security researchers traced the exploit to a custom RFQ proxy contract and an access-control flaw that let attackers register themselves as authorized order signers. Halborn said the weakness stemmed from a public function, allowing unauthorized orders to move funds already approved to the proxy. TrustedVolumes had signaled shortly after the hack that it was open to a bug bounty and a mutually acceptable resolution. The latest settlement underscores a growing DeFi pattern in which victims try to recover funds through direct negotiation rather than relying only on law enforcement or court action, even as that approach raises concerns that attackers may see post-hack settlements as a viable exit route.

Terms & Concepts
  • bug bounty: A payment or retained share of funds offered in exchange for disclosing a flaw or returning assets tied to an exploit.
  • request-for-quote market: A trading model in which liquidity providers submit quoted prices for swaps rather than relying solely on open order books.
  • access-control flaw: A security weakness that allows unauthorized users to gain permissions or perform restricted actions in a system.