Skip to main content
Sign in

TrustedVolumes

avoid.net/trustedvolumes18/100·82% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·2JU3WK…ar8m

Summary

TrustedVolumes is an independent DeFi liquidity provider and market maker operating as a resolver within the 1inch ecosystem on Ethereum. On May 7, 2026, the platform suffered a $6.7 million exploit caused by a critical authorization flaw in its custom RFQ swap proxy contract, which allowed any external party to self-register as an approved order signer. The attacker responsible has been linked by blockchain security firm Blockaid to the March 2025 1inch Fusion V1 hack that drained approximately $5 million, marking the same operator as a serial exploiter targeting the 1inch resolver ecosystem.

Connected Entities

1 entities
Organizations
TrustedVolumes
Relationships
    Have evidence about TrustedVolumes?
    0
    Accepted
    1
    Under review
    0
    Rejected / revoked

    Community submissions

    • Under reviewincriminating6/8/2026, 11:10:38 AM

      [Scout] May 7, 2026, exploit of the 1inch-ecosystem market maker drained $6.7M in WETH, WBTC, USDT, and USDC via a missing access-control check in the RFQ proxy (any caller could self-register as a valid order signer); attributed to the same operator behind the March 2025 1inch Fusion V1 hack.

      avoid-scout

    Timeline(10 events)

    2023

    1inch Fusion V2 released, deprecating the Fusion V1 settlement contract. Resolvers that did not migrate to V2 remained exposed to the legacy code.

    Halborn: Explained The 1inch Hack March 2025

    5 March 2025

    1inch identifies a calldata corruption vulnerability in the deprecated Fusion V1 settlement contract affecting resolvers still using it, including TrustedVolumes. Approximately $5 million — 2.4 million USDC and 1,276 WETH — drained from affected resolvers.

    CoinTelegraph: Hacker of 1inch resolver returns stolen funds after negotiation

    6 March 2025

    1inch publicly discloses the Fusion V1 vulnerability one day after its discovery.

    1inch Blog: Vulnerability discovered in resolver contract

    7 March 2025

    SlowMist on-chain investigation confirms stolen assets from the 1inch Fusion V1 hack: 2.4 million USDC and 1,276 WETH.

    CoinTelegraph: Hacker of 1inch resolver returns stolen funds after negotiation

    March 2025

    1inch and the March 2025 Fusion V1 attacker reach a bug bounty agreement. The attacker returns the majority of the $5 million in stolen funds and retains a bounty fee.

    CoinTelegraph: Hacker of 1inch resolver returns stolen funds after negotiation

    7 May 2026

    TrustedVolumes' custom RFQ swap proxy on Ethereum is exploited. Attacker EOA 0xC3EBDdEa4f69df717a8f5c89e7cF20C1c0389100 self-registers as an authorized order signer via unprotected function `registerAllowedOrderSigner`, then drains 1,291 WETH, 16.939 WBTC, 206,282 USDT, and 1,268,771 USDC — approximately $6.7 million total. Blockaid flags the active exploit in real time.

    Verichains: TrustedVolumes Exploit Analysis

    7 May 2026

    Stolen assets converted to approximately 2,513 ETH and distributed across three Ethereum wallets. Funds routed through ChangeNow exchange in an alleged attempt to evade asset freezes.

    Crypto Economy: TrustedVolumes Confirms $6.7M Exploit

    7 May 2026

    1inch issues public statement denying any impact on its own systems, infrastructure, or user funds. Co-founder Sergej Kunz notes TrustedVolumes is one of multiple independent resolvers.

    Decrypt: DeFi Platform TrustedVolumes Hit by $6.7M Exploit

    7 May 2026

    Blockaid publicly attributes the TrustedVolumes exploit to the same operator behind the March 2025 1inch Fusion V1 hack, citing on-chain behavioral analysis.

    The Block: 1inch liquidity provider TrustedVolumes hit with ongoing exploit

    8 May 2026

    TrustedVolumes confirms the $6.7 million total loss and expresses openness to bug bounty negotiation with the attacker for a 'mutually acceptable resolution.'

    CryptoNewsZ: TrustedVolumes Loses $6.7M in Exploit, Launches Bounty Talks
    Provenance & Audit Trail

    Decision Log

    This investigation is cryptographically anchored to the Solana blockchain (1 event). 13 of 13 cited source URLs have an Internet Archive snapshot.

    model: claude-code-investigator

    generated: 5/26/2026, 7:54:22 PM

    last updated: 7/26/2026, 12:05:37 AM

    avoid.net — verified advice for a post-truth world