Refreshed 3h ago· updates every 6h

TrustedVolumes (1inch) (2026) — Crypto Hack

Not Recovered
May 7, 2026·
Ethereum
Amount Stolen
$6.7M
1,291 WETH, 16.9 WBTC, 206,282 USDT, 1,268,771 USDC (~2,513 ETH)
Recovered
$0

A public function in TrustedVolumes' resolver contract let anyone become an authorized order signer, draining $6.7M in 85 rapid transactions via old approvals.

Summary

A public function in TrustedVolumes' resolver contract let anyone become an authorized order signer, draining $6.7M in 85 rapid transactions via old approvals.

How It Was Compromised — Smart Contract Exploit via Attacker exploited a public function in TrustedVolumes resolver contract that allowed anyone to register themselves as an 'Allowed Order Signer.' Used old token approvals to drain funds through ~85 rapid transactions. Stolen: 1,291 WETH, 16.9 WBTC, 206,282 USDT, 1,268,771 USDC. Funds converted to ~2,513 ETH. Note: 1inch protocol itself was NOT compromised — only TrustedVolumes' own contract. Same attacker as March 2025 1inch Fusion V1 hack.

Smart Contract ExploitAttacker exploited a public function in TrustedVolumes resolver contract that allowed anyone to register themselves as an 'Allowed Order Signer.' Used old token approvals to drain funds through ~85 rapid transactions. Stolen: 1,291 WETH, 16.9 WBTC, 206,282 USDT, 1,268,771 USDC. Funds converted to ~2,513 ETH. Note: 1inch protocol itself was NOT compromised — only TrustedVolumes' own contract. Same attacker as March 2025 1inch Fusion V1 hack.

On May 7 2026, TrustedVolumes — a 1inch liquidity provider — lost $6.7M when an attacker exploited a critical access control flaw in its resolver contract. A public function allowed any address to register itself as an 'Allowed Order Signer,' bypassing the intended access controls. The attacker leveraged users' existing (old) token approvals granted to the TrustedVolumes contract to drain funds across approximately 85 rapid transactions. Stolen assets included 1,291 WETH, 16.9 WBTC, 206,282 USDT, and 1,268,771 USDC. The 1inch protocol itself was not compromised — only TrustedVolumes' own contract. Security researchers noted the same attacker was responsible for the March 2025 1inch Fusion V1 exploit, suggesting a repeat sophisticated actor. Funds were converted to approximately 2,513 ETH.

Fund Flow & Laundering Analysis

Funds converted to approximately 2,513 ETH and dispersed across three attacker-controlled wallets on Ethereum. No mixer usage confirmed as of reporting date.

Related Incidents

For educational and transparency purposes only. Not financial advice. Data compiled from public sources and may contain approximations.