EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Unexpected development in the aftermath of the DeFi attack: hackers return millions

2026-07-19 00:16:12
Bookmark

Unexpected twist after the DeFi attack: Hackers return millions of dollars in assets

An unexpected twist has occurred following a major security breach in the decentralized finance (DeFi) space. Hackers who launched an attack in May against TrustedVolumes, a key player in the 1inch Fusion ecosystem, have returned 1,122.12 ETH pieces worth approximately $2.07 million. The return occurred more than two months after the incident, highlighting a new trend of DeFi platforms and hackers increasingly negotiating directly to resolve such vulnerability attacks.

Why only half of the stolen ETH was returned?

The funds returned accounted for approximately half of the stolen assets. Allegedly, the hackers retained the same amount of ETH in the form of a negotiated vulnerability reward. Defimon Alerts confirmed that the settlement occurred when the Ethereum price was approximately $1,843. TrustedVolumes and the hacker confirmed the agreement through on-chain information, marking the end of negotiations between the two parties, and invited other people involved in the attack to contact the company for possible further negotiations.

More than two months after the attack that caused US$5.8 million in damage, one of the attackers returned 1,122 ETH pieces worth approximately US$2 million. Both parties confirmed that the funds had been returned, the hacker accepted the vulnerability reward, and publicly invited other participants in the incident to take the initiative to contact.

Since the security breach occurred, TrustedVolumes has expressed its willingness to engage in a constructive dialogue about the breach, and has even reminded potential attackers of this proposal again in recent communications.

Why was TrustedVolumes hacked?

TrustedVolumes is the liquidity parser in the 1inch Fusion quote request market and is responsible for efficient token redemption. The May 7 attack resulted in the theft of approximately $5.87 million in assets, and the estimate was later revised to $6.7 million. Blockaid's cybersecurity experts found that the breach involved a variety of digital assets, including a large number of WETH, USDC, USDT and WBTC.

Further investigation revealed that the attack was related to negligence in access control rather than stolen keys or undisclosed system flaws. Halborn's analysis revealed a public function that could be leveraged that allows unauthorized users to register as order signers, thereby facilitating illegal money transfers. Blockaid confirmed that despite the attack, 1inch's entire system and other user funds were not affected.

  • An exploit resulted in unauthorized access, triggering major theft.
  • After negotiation, the hacker returned 1,122.12 ETH pieces.
  • Negotiations with the hackers took more than two months to end.
  • TrustedVolumes provides vulnerability bounties to engage constructively with hackers.

The settlement case highlights a shift in DeFi's approach to vulnerability attacks, with direct negotiations becoming increasingly common as project parties want to resolve issues faster than traditional legal approaches. However, this strategy of quick reconciliation has also raised concerns; some security experts believe it could encourage future attacks if hackers expect negotiations. According to TRM Labs, losses caused by cryptocurrency fraud in 2025 have reached US$2.87 billion. In this context, advances in digital forensics by companies such as Blockaid, CertiK and SlowMist are critical to tracking and negotiating asset recovery. Despite these advances, many incidents remain unresolved, and only part of the stolen assets have been recovered in this case. Future recovery efforts will likely depend on continued dialogue or decisive action on remaining perpetrators.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP