TrustedVolumes suffers $5.87M DeFi exploit—funds swapped to ETH

TrustedVolumes, a 1inch liquidity provider, lost $5.87M in a breach exploiting a contract vulnerability. The attacker used token approvals to steal funds, which were swapped to ETH. The exploit may still be active.

TrustedVolumes, a liquidity provider for the 1inch decentralized exchange aggregator, has suffered a major security breach. Approximately $5.87 million in assets—including WETH, USDT, WBTC, and USDC—were stolen after an attacker exploited a vulnerability in the resolver contract on Ethereum. This allowed the attacker to register as an authorized order signer and execute unauthorized transfers by leveraging existing token approvals. Blockchain security firms such as Blockaid, CertiK, SlowMist, and PeckShield have confirmed the incident. They warn that the exploit may still be ongoing, raising concerns about further potential losses. The stolen assets were quickly converted to Ethereum and split between two wallet addresses. Preliminary investigations suggest the attacker may be linked to a previous exploit of 1inch Fusion V1 in March 2025, though the vulnerabilities differ. This breach highlights persistent risks in DeFi, especially those related to unlimited token approvals and smart contract weaknesses.

Related Tokens

Related News