EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

TrustedVolumes reaches a settlement with hackers, recovers $2 million in ETH

2026-07-19 00:16:11
Bookmark

Hackers related to the TrustedVolumes attack returned 1,122.12 ETH, worth approximately US$2.07 million.

A hacker linked to the attack on TrustedVolumes, a liquidity parser integrated into 1inch Fusion, in May this year, has returned 1,122.12 Ethereum (ETH), worth approximately US$2.07 million. The settlement, which came more than two months after the attack, reflects the growing trend of direct negotiations between DeFi projects and attackers.

Settlement returns half of the stolen ETH

According to Defimon Alerts, the funds transferred accounted for about half of the stolen assets in the original breach. As part of the negotiated vulnerability bounty, the attacker allegedly retained an equal amount of ETH. At the time of return, the price of ether is approximately US$1843.

Both TrustedVolumes and the hacker confirmed the agreement through on-chain messages. Information showed that negotiations had been completed and encouraged other attackers involved in the incident to contact the company to seek the possibility of further settlement.

More than two months after the $5.8 million attack, an attacker returned 1122 ETH pieces worth $2 million. Both parties confirmed that the funds had been returned, the hacker accepted the vulnerability reward and publicly invited other participants in the incident to contact.

TrustedVolumes expressed its willingness to constructively communicate about the vulnerability bounty immediately after the attack and maintained this position in recent exchanges.

TrustedVolumes attack details

TrustedVolumes operates as a parser in the 1-inch Fusion Request for Quotation (RFC) market, providing liquidity for token redemption. On May 7, the system was compromised, resulting in withdrawals of approximately $5.87 million, which was later estimated to total $6.7 million, including all asset values and related losses.

According to cybersecurity company Blockaid, the attackers stole a variety of assets, including 1291 WETH, 1.26 million USDC, 206,282 million USDTs and 16.93 WBTC. The breach was traced to a specific resolver contract and the RFC proxy address on Ethereum. Etherscan tags the main attacker's wallets as the TrustedVolumes attack address.

Investigation showed that the vulnerability was not caused by a stolen key or undisclosed vulnerability, but an access control flaw. Blockchain security company Halborn has discovered that a public function allows anyone to register as an authorized order signer, allowing attackers to make unauthorized transfers from approved funds. Blockaid detected the attack in real time and confirmed that 1inch's entire infrastructure and end-user funds were not affected.

Details of stolen assets

WETH: 1291
USDC: 1.26 million
USDT: 206,282 million
WBTC: 16.93

Increased reliance on negotiations in DeFi attacks

The rapid settlement of the TrustedVolumes case reflects a broader strategic shift in decentralized finance. Faced with hacking attacks, more and more projects are choosing to negotiate to recover funds rather than relying solely on law enforcement or lengthy legal processes.

Analysts point out that while this approach can lead to quick resolutions, it could also inadvertently encourage more attacks if cybercriminals view negotiations as a predictable outcome. TRM Labs reported that approximately 150 crypto fraud incidents resulted in $2.87 billion in losses in 2025, but advances in forensic tracking technology have increased recovery rates. It is worth noting that in the TrustedVolumes incident, companies such as Blockaid, CertiK and SlowMist quickly identified and tracked the movements of stolen assets, providing the security team with leverage in subsequent negotiations.

The settlement only resolved part of the theft issue. The attacker who returned 1122.12 ETH kept the remaining amount as a vulnerability bounty, while the status of other stolen assets remained in the balance. Future progress in recovery may depend on whether other attackers choose to negotiate or continue to transfer funds, which will test the dynamic balance between blockchain transparency and incentives for reconciliation.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP