Cryip
  • Home
  • News
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
  • Events
No Result
View All Result
Cryip
  • Home
  • News
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
  • Events
No Result
View All Result
Cryip
No Result
View All Result
Home News Security & Hacks

TrustedVolumes Exploited for $5.87 Million in Ethereum Hack as Repeat Attacker Returns

TrustedVolumes, a 1inch market maker, suffered a $5.87 million Ethereum exploit after attackers abused flaws in its custom RFQ swap infrastructure.

Saravana Kumar Mahendran by Saravana Kumar Mahendran
May 7, 2026
in Security & Hacks
0 0
TrustedVolumes Exploit
Share on FacebookShare on Twitter
MakeCryipCryippreferred onGoogle

A significant exploit has hit TrustedVolumes, a key liquidity provider and resolver for the leading DEX aggregator 1inch. The attack occurred in the early hours of May 7, draining approximately $5.87 million in crypto assets. The attacker quickly consolidated the stolen funds into roughly 2,513 ETH.

This incident is particularly concerning because it involves the same operator responsible for the March 2025 hack on 1inch’s Fusion V1, which also affected TrustedVolumes. The TrustedVolumes team has publicly confirmed the exploit. While most funds were returned in the previous case, this time the vulnerability lies in a different component – a custom RFQ (Request for Quote) swap proxy contract controlled by TrustedVolumes.

#PeckShieldAlert @trustedvolumes has been exploited for ~$5.9M, including $3.02M $ETH,$1.37M $WBTC & 1.47M stablecoins, the exploiter has swapped the stolen funds for 2.513K $ETH pic.twitter.com/HZ1LGlZJcC

— PeckShieldAlert (@PeckShieldAlert) May 7, 2026

What Exactly Happened

According to real-time alerts from blockchain security firms Blockaid and PeckShield, the attacker exploited TrustedVolumes’ resolver contract at 0x9bA0CF1588E1DFA905eC948F7FE5104dD40EDa31 through a custom RFQ swap proxy contract (0xeEeEEe53033F7227d488ae83a27Bc9A9D5051756).

Key details of the exploit:

  • Exploiter Address: 0xC3EBDdEa4f69df717a8f5c89e7cF20C1c0389100
  • Primary Exploit Transaction: 0xc5c61b3ac39d854773b9dc34bd0cdbc8b5bbf75f18551802a0b5881fcb990513

Stolen Assets:

  • 1,291.16 WETH (approx. $3.02 million)
  • 16.939 WBTC (approx. $1.37 million)
  • 1,268,771 USDC + 206,282 USDT (approx. $1.47 million)

The attacker leveraged a flaw in the custom proxy that allowed unauthorized draining of funds from the resolver. Within hours, all assets were swapped into ETH.

Why This Exploit Stands Out

TrustedVolumes is a key liquidity provider and resolver deeply integrated into 1inch’s RFQ and Fusion ecosystem. Resolvers are critical for efficiently filling large orders with competitive pricing. When such an important infrastructure provider is compromised, it raises serious questions about the security of intent-based trading systems and custom proxy implementations across DeFi.

This event adds to a growing list of sophisticated DeFi exploits already seen in 2026. Recently, the crypto community also witnessed the $1.78M Moonwell exploit, which highlighted how insecure smart contract practices and rushed development workflows can create dangerous attack surfaces for protocols handling user funds. Both incidents reinforce the growing concern that even experienced DeFi teams remain vulnerable when custom contract logic and privileged permissions are not continuously stress-tested.

The most alarming aspect here is the repeat attacker pattern. The same actor who exploited an outdated Fusion V1 component in March 2025 has now returned, targeting a different but related custom implementation. This indicates a sophisticated, patient operator who actively researches and monitors specific targets.

It serves as a clear reminder: A single past hack does not make any team “battle-tested.” Instead, it can place them on a dedicated attacker’s watchlist for future opportunities.

Impact and Practical Advice

End-user funds on 1inch itself appear safe, as the exploit was limited to TrustedVolumes’ own controlled resolver contracts. However, users who have interacted with TrustedVolumes or used 1inch Fusion routes are strongly advised to revoke approvals immediately via tools like Revoke.cash.

Short-term market reaction may include temporary nervousness around the $1INCH token and RFQ-related liquidity. TrustedVolumes has acknowledged the exploit and is expected to offer a bug bounty, similar to the previous incident.

Key Lessons for the Crypto Community

  • Custom proxy contracts and elevated permissions remain high-risk areas even in audited systems.
  • Real-time security monitoring tools can significantly limit damage.
  • Regular approval revocation is essential hygiene in DeFi.
  • Teams with previous incidents must maintain ongoing heightened security vigilance.

This story is still developing. On-chain movements of the stolen ETH will be closely watched in the coming hours.

In the fast-moving world of DeFi, assuming any protocol is “trusted” by name alone has repeatedly proven risky. Stay vigilant, monitor your wallet permissions, and treat every smart contract interaction with caution.

Disclaimer: Cryip is an independent media and research outlet providing news, data, and analysis on the cryptocurrency industry. Content is for informational and research purposes only and does not constitute financial, legal, tax, or investment advice. Cryptocurrency markets are volatile and past performance is not indicative of future results. References to specific assets, platforms, or incidents are for journalistic purposes only and do not imply endorsement, and readers assume full responsibility for their decisions.
Tags: Crypto Hacks

Related Posts

JaredFromSubway.eth MEV Bot Drained of $7.5 Million in Sophisticated Approval Exploit on Ethereum
Security & Hacks

JaredFromSubway.eth MEV Bot Drained of $7.5 Million in Sophisticated Approval Exploit on Ethereum

by Saravana Kumar Mahendran
June 22, 2026

Ethereum's most prominent sandwich MEV bot, JaredFromSubway.eth, lost more than $7.5 million in an exploit on June 20, 2026. The...

Read moreDetails
Taiko Bridge Exploit

Taiko Bridge Exploit Drains $1.7 Million in Chain State Verification Breach

June 22, 2026
Axelar Network Disables Secret Network IBC Bridge Following $4.67 Million Exploit

Axelar Network Disables Secret Network IBC Bridge Following $4.67 Million Exploit

June 20, 2026
Aztec Private Rollup Bridge Loses $2.2 Million in Latest Exploit

Aztec Private Rollup Bridge Hit Again as Attackers Drain $2.2 Million

June 18, 2026
RetoSwap Suspends Trading Following Second Exploit in Haveno Protocol

RetoSwap Suspends Trading Following Second Exploit in Haveno Protocol

June 17, 2026
Humanity Protocol to Replace Compromised $H Tokens With New ERC-20 Airdrop

Humanity Protocol to Replace Compromised $H Tokens With New ERC-20 Airdrop

June 16, 2026
Thetanuts Finance Hit by $2.1M Exploit as Legacy Ethereum Vault Flaw Resurfaces

Thetanuts Finance Hit by $2.1M Exploit as Legacy Ethereum Vault Flaw Resurfaces

June 16, 2026
Next Post
OpenTrade Raises $17 Million as Stablecoin Infrastructure Investment Accelerates

OpenTrade Raises $17 Million as Stablecoin Infrastructure Investment Accelerates

Recommended

  • All
  • News
KG Inicis Partners With Solana to Explore Stablecoin Payment Infrastructure in South Korea

KG Inicis Partners With Solana to Explore Stablecoin Payment Infrastructure in South Korea

June 23, 2026
Ethereum Foundation Cuts 54 Jobs, Reorganizes Into Seven Clusters

Ethereum Foundation Cuts 54 Jobs, Reduces Workforce by 20%

June 23, 2026 - Updated on June 24, 2026
THORChain Resumes Trading After $10.7 Million Exploit, Restores Cross-Chain Swaps

THORChain Resumes Trading After $10.7 Million Exploit, Restores Cross-Chain Swaps

June 23, 2026
Chinese Fentanyl Network Suspected of Running Multi-Million Dollar Zksync.jp Crypto Scam in Japan

Chinese Fentanyl Network Suspected of Running Multi-Million Dollar Zksync.jp Crypto Scam in Japan

June 23, 2026
KG Inicis Partners With Solana to Explore Stablecoin Payment Infrastructure in South Korea

KG Inicis Partners With Solana to Explore Stablecoin Payment Infrastructure in South Korea

June 23, 2026
Ethereum Foundation Cuts 54 Jobs, Reorganizes Into Seven Clusters

Ethereum Foundation Cuts 54 Jobs, Reduces Workforce by 20%

June 23, 2026 - Updated on June 24, 2026
Bitcoin Price Analysis: BTC Falls to $62K as Bears Target Key Support Levels

Bitcoin Price Analysis: BTC Falls to $62K as Bears Target Key Support Levels

June 23, 2026
THORChain Resumes Trading After $10.7 Million Exploit, Restores Cross-Chain Swaps

THORChain Resumes Trading After $10.7 Million Exploit, Restores Cross-Chain Swaps

June 23, 2026

Cryip focuses on crypto research and on-chain analysis, supported by coverage of markets, regulation, security events, and blockchain ecosystems.

Recent Posts

  • KG Inicis Partners With Solana to Explore Stablecoin Payment Infrastructure in South Korea
  • Ethereum Foundation Cuts 54 Jobs, Reduces Workforce by 20%
  • Bitcoin Price Analysis: BTC Falls to $62K as Bears Target Key Support Levels

Categories

  • AI × Crypto
  • Data & Dashboards
  • DeFi Basics
  • Investing Basics
  • Market & Price
  • Market Updates
  • On-Chain Analysis
  • OpSec
  • Policy & Regulation
  • Post Mortems
  • Press Release
  • Reports
  • Scams & Fraud
  • Security & Hacks
  • Stablecoins
  • Tokenomics
  • VC & Funding
  • Wallets & Custody

Company

  • About Us
  • Contact Us
  • Editorial Standards & Integrity
  • Our Team
  • Privacy Policy
  • Review Methodology
  • Terms and Conditions
  • Trust, Disclosures & Independence

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Home
  • News
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
  • Events

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.