Liquidity provider TrustedVolumes lost $6.7 million in a DeFi exploit linked to a custom RFQ proxy, though 1inch confirms its core protocols remain secure. TheLiquidity provider TrustedVolumes lost $6.7 million in a DeFi exploit linked to a custom RFQ proxy, though 1inch confirms its core protocols remain secure. The

1inch Resolver TrustedVolumes Drained for $6.7M in Ethereum Exploit

2026/05/12 00:47
3분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 [email protected]으로 연락주시기 바랍니다

TrustedVolumes, a prominent market maker and resolver for 1inch Fusion, was exploited for $6.7 million on Thursday. The attacker abused a publicly accessible function to register as an authorized order signer, bypassing traditional security checks. 1inch Network clarified that its core aggregation protocols and user funds remain unaffected by the third-party breach.

Liquidity provider TrustedVolumes, a key market maker and resolver utilized by 1inch Fusion, confirmed on Thursday that it was drained of approximately $6.7 million in an exploit on the Ethereum network. The incident marks the fifth major DeFi exploit since the beginning of May, following a period of record-high losses for the decentralized finance sector. The breach was first flagged by Web3 security firm Blockaid, which identified an ongoing attack targeting a custom request-for-quote (RFQ) swap proxy controlled by TrustedVolumes. According to security analysts, the vulnerability stemmed from a public function within the proxy contract that lacked proper permission modifiers. This allowed the attacker to self-register as an “authorized order signer,” granting them the ability to execute malicious trades and siphon assets. The stolen funds, which included Wrapped Ether (WETH), USDT, Wrapped Bitcoin (WBTC), and USDC, were quickly converted into 2,513 ETH and distributed across three separate Ethereum addresses. CertiK noted that the attacker leveraged existing token approvals previously granted by users to the vulnerable resolver, highlighting the persistent risks of long-standing unlimited approvals in DeFi. In response to the incident, 1inch Network issued a statement distancing its core infrastructure from the exploit. “Neither 1inch nor any of the 1inch protocols are involved,” the platform stated, emphasizing that TrustedVolumes operates as an independent liquidity provider used by multiple protocols. 1inch co-founder Sergej Kunz described the framing of the event as a protocol-level breach as “misleading” and “harmful.” Security researchers have linked the attacker to the March 2025 exploit of the 1inch Fusion V1 resolver, which saw a similar loss of $5 million. While the actor appears to be the same entity, Blockaid clarified that the technical nature of the vulnerability differs from the previous year’s incident. TrustedVolumes has expressed a willingness to engage in “constructive communication” with the exploiter, floating the possibility of a bug bounty in exchange for the return of the funds. The attack comes on the heels of a disastrous April for DeFi security, which saw over $635 million lost to various hacks and exploits. Disclaimer: This article is for informational purposes only and does not constitute advice of any kind. Readers should conduct their own research before making any decisions.

The post 1inch Resolver TrustedVolumes Drained for $6.7M in Ethereum Exploit appeared first on Cryptopress.

시장 기회
1인치 네트워크 로고
1인치 네트워크 가격(1INCH)
$0.09232
$0.09232$0.09232
+1.75%
USD
1인치 네트워크 (1INCH) 실시간 가격 차트
면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, [email protected]으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

No Chart Skills? Still Profit

No Chart Skills? Still ProfitNo Chart Skills? Still Profit

Copy top traders in 3s with auto trading!