EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

TrustedVolumes attacker returns 1,122 ETH, retains $2 million reward

2026-07-19 00:16:34
Bookmark

Settlement agreement promotes asset recovery, hackers return more than a thousand Ethereum

More than two months after the attack on TrustedVolumes, a liquidity parser within the 1inch Fusion ecosystem, one of the attackers has returned 1,122.12 ETH via Ethereum transfer. The amount recovered this time accounted for approximately $5.8 million in stolen assets, marking that the settlement negotiated by the two parties once again exceeded the lengthy asset recovery process. According to reports, the hacker retained the corresponding amount after negotiation as part of the vulnerability bounty. When the agreement was reached, the price of Ethereum was approximately US$1,843, so the total value recovered was approximately US$2.07 million, which explains why the incident is often referred to as a "US$2 million recovery case."

The significance of the settlement is not determined by its size, but reflects a growing trend in the decentralized finance space: more institutions are choosing to negotiate with attackers rather than relying solely on law enforcement or lengthy litigation. While this approach may work faster, it also raises concerns that blackmailers may view vulnerability bounty negotiations as a regular means of evading capture rather than an exception.

The two sides posted a message on the chain confirming the settlement: "We have finalized negotiations with the original attacker." The message added that the attacker "returned the funds and received a vulnerability bounty" and encouraged any remaining attackers to contact through designated email addresses. TrustedVolumes hinted at the strategy immediately after the attack, saying the company was willing to constructively communicate about "vulnerability bounties and mutually acceptable solutions."

The beginning and end of the May attack

TrustedVolumes runs as a parser in the 1inch Fusion environment, maintaining the quote request market and providing liquidity for token redemption when needed. On May 7, the parser was attacked and approximately $5.87 million in digital assets were extracted in an Ethereum transaction. According to subsequent data from the agreement, after taking into account the value of assets and related losses, the total loss may reach approximately US$6.7 million.

According to safety analysis, the total loss was US$5.87 million, including 1,291 WETH, 1.26 million USDC, 206,282 USDT and 16.93 WBTC. The address of the attacked resolver contract has been confirmed and the attack is associated with a customized RFC proxy contract. The main attacker's wallet address has been marked by Etherscan as a TrustedVolumes exploit address. Cybersecurity researchers found that the attack used methods that were highly similar to the March 2025 hacking attack involving the 1inch Fusion V1 system.

Investigators determined that the attack originated from an access control vulnerability and not a private key leak or unknown vulnerability. Because of the existence of a public function, anyone can register as an authorization order signer. The attacker then approved the unauthorized order and diverted funds that had been authorized for the agency contract. The security company identified the vulnerability when the attack occurred and noted that neither 1inch's infrastructure nor user funds were affected.

Trade-offs of incentive mechanisms

The settlement illustrates the challenges facing the decentralized financial industry. Negotiating and recovering stolen funds is often preferable to facing a lengthy and unpredictable investigation that may result in nothing. However, such settlements can create a financial incentive: criminals believe they can steal money and then negotiate huge rewards. With the continuous advancement of blockchain forensic technology, computational theft cases have become increasingly complex. Research shows that cryptocurrency scams looted $2.87 billion in about 150 incidents in 2025, but at the same time investigators have been quite successful in tracking stolen cryptocurrencies and money laundering paths. For example, in the TrustedVolumes case, multiple security companies were able to monitor attacks as they occurred and track how hackers converted stolen goods into ETH, which partly contributed to the uneasiness of criminals before reaching a deal.

The case was only partially resolved through settlement. An attacker returned 1,122.12 ETH (approximately US$2.07 million), but retained the same amount as the reward for the vulnerability in the proposal. The recovery of the remaining stolen funds may be achieved through future settlement or money laundering, which will become an important indicator for future hackers to weigh the risks of blockchain security tracking with the possibility of negotiating an escape.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP