TrustedVolumes exploit drains $6.7M from 1inch liquidity provider

1INCH-0.02%
ETH0.33%
WBTC0.91%
USDC0.01%

TrustedVolumes, a liquidity provider and market maker for decentralized exchange aggregator 1inch, is suffering an ongoing attack that has drained approximately $6.7 million in funds, according to reports from blockchain security firm Blockaid and TrustedVolumes itself. Blockaid initially flagged the exploit on Wednesday as affecting TrustedVolumes' resolver contract on the Ethereum blockchain, with the company providing an updated loss figure on Thursday and indicating consideration of a bug bounty to address the situation. 1inch confirmed that its systems, infrastructure, and user funds remain unaffected.

Initial Blockaid Report

Blockaid reported that the initial drained amount was approximately $5.87 million, comprised of 1,291.16 WETH, 206,282 USDT, 16.939 WBTC, and 1,268,771 USDC. According to Blockaid, the attacker is the same entity responsible for the March 2025 exploit of 1inch Fusion V1, which drained around $5 million. However, Blockaid noted that the ongoing attack involves a different vulnerability related to a TrustedVolumes-controlled custom RFQ (request for quote) swap proxy.

TrustedVolumes Response

TrustedVolumes confirmed the exploit on Thursday, updating the loss amount to approximately $6.7 million. The company indicated it will consider a bug bounty as a potential solution to address the situation.

1inch Statement

1inch released a statement clarifying that there is no impact on its systems, infrastructure, or user funds. "TrustedVolumes operate independently as a liquidity provider, used by multiple protocols across the industry, and are not exclusive to 1inch," the statement said. "We continue to monitor the situation and are actively assisting where appropriate alongside relevant security parties."

Broader DeFi Security Context

Attacks on DeFi participants have surged significantly in recent weeks. According to data from DefiLlama, a total of $635.2 million was stolen in hacks and exploits in April 2025, marking the largest monthly sum since February 2025, when hackers stole nearly $1.5 billion from Bybit. Recent major exploits include a $285 million social engineering attack on Drift and a $293 million exploit on Kelp DAO. The attack on TrustedVolumes marks the fifth major exploit since the beginning of May.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
GateUser-bc27b40cvip
· 05-09 13:15
Steadfast HODL💎
View OriginalReply0
Snowshoesvip
· 05-07 20:08
Just charge forward 👊
View OriginalReply0
BetweenBidAndAskvip
· 05-07 16:39
On-chain security, the tuition keeps getting more expensive; when will the project teams finally graduate?
View OriginalReply0
Abcos7vip
· 05-07 09:40
2026 GOGOGO 👊
Reply0
GateUser-c44b371bvip
· 05-07 08:15
Is the 1inch aggregator ecosystem still causing issues? Do users still dare to use it?
View OriginalReply0
GovernanceVotingvip
· 05-07 08:10
Blockaid's warning this time was quite quick, but speed doesn't help—money has already flown away.
View OriginalReply0
MidnightReconcilervip
· 05-07 08:10
Once again, LP has been hacked. When will the security debt of DeFi finally be paid off?
View OriginalReply0
GateUser-634ae966vip
· 05-07 07:57
5.87 million is a heavy blow to TrustedVolumes, as market maker capital is their lifeblood.
View OriginalReply0