Settlement agreement promotes asset recovery, hackers return more than a thousand Ethereum
More than two months after the attack on TrustedVolumes, a liquidity parser within the 1inch Fusion ecosystem, one of the attackers has returned 1,122.12 ETH via Ethereum transfer. The amount recovered this time accounted for approximately $5.8 million in stolen assets, marking that the settlement negotiated by the two parties once again exceeded the lengthy asset recovery process. According to reports, the hacker retained the corresponding amount after negotiation as part of the vulnerability bounty. When the agreement was reached, the price of Ethereum was approximately US$1,843, so the total value recovered was approximately US$2.07 million, which explains why the incident is often referred to as a "US$2 million recovery case."
The significance of the settlement is not determined by its size, but reflects a growing trend in the decentralized finance space: more institutions are choosing to negotiate with attackers rather than relying solely on law enforcement or lengthy litigation. While this approach may work faster, it also raises concerns that blackmailers may view vulnerability bounty negotiations as a regular means of evading capture rather than an exception.
The two sides posted a message on the chain confirming the settlement: "We have finalized negotiations with the original attacker." The message added that the attacker "returned the funds and received a vulnerability bounty" and encouraged any remaining attackers to contact through designated email addresses. TrustedVolumes hinted at the strategy immediately after the attack, saying the company was willing to constructively communicate about "vulnerability bounties and mutually acceptable solutions."
The beginning and end of the May attack
TrustedVolumes runs as a parser in the 1inch Fusion environment, maintaining the quote request market and providing liquidity for token redemption when needed. On May 7, the parser was attacked and approximately $5.87 million in digital assets were extracted in an Ethereum transaction. According to subsequent data from the agreement, after taking into account the value of assets and related losses, the total loss may reach approximately US$6.7 million.
According to safety analysis, the total loss was US$5.87 million, including 1,291 WETH, 1.26 million USDC, 206,282 USDT and 16.93 WBTC. The address of the attacked resolver contract has been confirmed and the attack is associated with a customized RFC proxy contract. The main attacker's wallet address has been marked by Etherscan as a TrustedVolumes exploit address. Cybersecurity researchers found that the attack used methods that were highly similar to the March 2025 hacking attack involving the 1inch Fusion V1 system.
Investigators determined that the attack originated from an access control vulnerability and not a private key leak or unknown vulnerability. Because of the existence of a public function, anyone can register as an authorization order signer. The attacker then approved the unauthorized order and diverted funds that had been authorized for the agency contract. The security company identified the vulnerability when the attack occurred and noted that neither 1inch's infrastructure nor user funds were affected.
Trade-offs of incentive mechanisms
The settlement illustrates the challenges facing the decentralized financial industry. Negotiating and recovering stolen funds is often preferable to facing a lengthy and unpredictable investigation that may result in nothing. However, such settlements can create a financial incentive: criminals believe they can steal money and then negotiate huge rewards. With the continuous advancement of blockchain forensic technology, computational theft cases have become increasingly complex. Research shows that cryptocurrency scams looted $2.87 billion in about 150 incidents in 2025, but at the same time investigators have been quite successful in tracking stolen cryptocurrencies and money laundering paths. For example, in the TrustedVolumes case, multiple security companies were able to monitor attacks as they occurred and track how hackers converted stolen goods into ETH, which partly contributed to the uneasiness of criminals before reaching a deal.
The case was only partially resolved through settlement. An attacker returned 1,122.12 ETH (approximately US$2.07 million), but retained the same amount as the reward for the vulnerability in the proposal. The recovery of the remaining stolen funds may be achieved through future settlement or money laundering, which will become an important indicator for future hackers to weigh the risks of blockchain security tracking with the possibility of negotiating an escape.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
ETH
WBTC