The party responsible for the TrustedVolumes vulnerability attack has returned 1,122 ETH, worth approximately US$2 million at current prices. On-chain monitoring confirmed that the transfer was related to the incident on May 7, 2026 and was a partial repayment. This is also the latest development in the original vulnerability attack of TrustedVolumes, when stolen assets were converted to approximately 2,513 ETH. TrustedVolumes reported total losses of approximately $6.7 million. A preliminary security assessment put the damage at approximately US$5.87 million, including 1,291.16 WETH, 206,282 USDT, 16.939 WBTC and approximately 1.27 million USDC stolen from project inventory.
Latest News: TrustedVolumes vulnerability attackers have returned 1,122 ETH (worth more than $2 million). The original attack resulted in the theft of more than $5.8 million. The attackers have now returned approximately $2 million while retaining approximately $2 million as a "bounty." pic.twitter.com/HJSdx4i4Or Com Feed (@thecomfeed) July 18, 2026. The return was based on a settlement message requiring the return of exactly 1,122 ETH. Return address: 0xb6f28ed0f919a12822fe 78f6d610e5e09a6fe450. The main attacker's association address: 0xC3EBDdEa4f69 df717a8f5 c89 e7cF20C1c 0389100.
The attacker kept assets of comparable value and called the rest a bounty. TrustedVolumes has not announced the full terms of the settlement or directly confirmed the final reward amount. After the attack, the project expressed its willingness to constructively communicate about the vulnerability bounty and mutually acceptable solutions.
The bounty proposal has also been used in other cryptocurrency recovery operations, such as the BC.GAME hack, where the platform offered a reward of $500,000 for reliable information that could identify the attacker. Unlike recovery cases where security researchers received formal approval for rewards (such as the $1.84 million rescue operation at Foom.cash), the amount retained in this case was only unilaterally referred to as a "bounty" by the attacker.
Customizing the RFC agent causes vulnerability
Security researchers attributed the incident to TrustedVolumes 'custom Request for Quotation (RFC) exchange agent. Weaknesses in access control and authorization allow attackers to register an approved order signer and submit malicious orders against project inventory. The contract uses the recipient field of the order to check authorization, but transfers tokens from the inventory address. Researchers also found ineffective replay protection. Together, these vulnerabilities allow attackers to steal multiple assets in a single transaction.
1inch systems are not affected
The vulnerable RFC agents and inventory contracts are controlled by TrustedVolumes and are not part of 1inch's core aggregation infrastructure. 1inch said its protocols, systems and user funds were not affected. The event was targeted at TrustedVolumes 'independent market-making settings rather than regular redemption through 1inch. The transfer of 1,122 ETH confirmed partial recovery from the May attack. However, TrustedVolumes has not publicly disclosed how the retention amount is calculated or whether it believes a settlement has been reached.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
ETH
WBTC