{"id":43690,"date":"2026-05-09T18:22:13","date_gmt":"2026-05-09T18:22:13","guid":{"rendered":"https:\/\/financialrush.com\/?p=43690"},"modified":"2026-05-09T18:22:13","modified_gmt":"2026-05-09T18:22:13","slug":"hacker-drains-5-9m-from-ethereum-liquidity-provider-trustedvolumes","status":"publish","type":"post","link":"https:\/\/financialrush.com\/?p=43690","title":{"rendered":"Hacker Drains $5.9M From Ethereum Liquidity Provider TrustedVolumes"},"content":{"rendered":"<p> \n<br \/><\/p>\n<div>\n<p>&#13;<br \/>\n\t\t\t\t\t\t\t\t\tEarly reports framed the incident as a 1inch exploit, but the protocol clarified that it was not compromised and no user funds were affected.\t\t\t\t\t\t\t\t<\/p>\n<\/p><\/div>\n<div>\n<p>TrustedVolumes, a liquidity provider on the Ethereum blockchain, lost about $5.9 million in funds to a hacker on Thursday.<\/p>\n<p>The attacker was able to exploit a vulnerability within the custom trading system used by the platform and managed to withdraw the funds, which included ETH, WBTC, as well as USDT and USDC stablecoins.<\/p>\n<h2 id=\"what-happened\">What Happened<\/h2>\n<p>According to blockchain security firm Blockaid, which <a href=\"https:\/\/x.com\/blockaid_\/status\/2052198320420819089?s=20\" target=\"_blank\">caught<\/a> the exploit as it was happening, the stolen funds included 1,291 WETH, around 16.9 WBTC, roughly 206,000 USDT, and just under 1.27 million USDC.<\/p>\n<p>The attack worked by abusing a design flaw in TrustedVolumes\u2019 custom order-settlement system, known as a Request for Quote (RFQ) proxy.<\/p>\n<p>GoPlus Security posted a breakdown <a href=\"https:\/\/x.com\/GoPlusSecurity\/status\/2052281656615297057?s=20\" target=\"_blank\">showing<\/a> that the attacker registered themselves as an authorized \u201corder signer\u201d using a function called \u201cregisterAllowedOrderSigner()\u201d that was publicly accessible.<\/p>\n<p>The function allows anyone to designate their own address as a valid signer for trades they controlled, and while normally that would be harmless enough, the settlement function had a separate problem: it checked authorization against one address while actually pulling funds from a different one.<\/p>\n<p>As detailed in a technical report <a href=\"https:\/\/github.com\/DarkNavySecurity\/web3-exploit-analysis\/blob\/main\/reports\/trustedvolumes-rfq-proxy-drain\/report.md\" target=\"_blank\">posted<\/a> by security researcher Defi Nerd, the attacker used that gap to execute four drain transactions against the TrustedVolumes resolver contract, which had previously given the proxy permission to move its tokens.<\/p>\n<h3 id=\"you-may-also-like\" class=\"heading-4\">You may also like:<\/h3>\n<p>According to them, each time, the proxy pulled assets from the resolver and sent only a single raw USDC unit back. Then the attacker converted the stolen WETH back into ETH and forwarded everything to their own wallet.<\/p>\n<p>TrustedVolumes confirmed the exploit and publicly posted three wallet addresses holding the stolen funds, asking the hacker to get in touch about a \u201cbug bounty and a mutually acceptable resolution.\u201d<\/p>\n<h2 id=\"1inch-distances-itself-as-defi-hacks-continue\">1inch Distances Itself as DeFi Hacks Continue<\/h2>\n<p>Because TrustedVolumes functions as a liquidity provider and market maker on 1inch, some early reports framed the incident as a 1inch exploit.<\/p>\n<p>However, that is not accurate, and both 1inch and Blockaid put out statements <a href=\"https:\/\/x.com\/1inch\/status\/2052288374451339544?s=20\" target=\"_blank\">clarifying<\/a> that the protocol itself was not compromised and no user funds on 1inch were affected.\u00a0TrustedVolumes operates independently across multiple platforms, not exclusively on 1inch.<\/p>\n<p>The attack occurred during an especially difficult period for the DeFi ecosystem since it followed a catastrophic month of April, where more than $650 million worth of crypto was <a href=\"https:\/\/cryptopotato.com\/kelpdao-and-drift-lead-devastating-650m-crypto-hack-wave-of-april\/\">stolen<\/a> from different projects.<\/p>\n<p>KelpDAO and Drift Protocol were the most affected, having $292 million and $285.2 million taken away from them.<\/p>\n<p>So at $5.9 million, this latest exploit is smaller in scale. But the technical sophistication of the approach, deploying a helper contract, abusing self-service signer registration, and exploiting a maker\/funding-source mismatch in a single transaction, puts it in a different category from a simple bug or misconfiguration.<\/p>\n<p><!-- CONTENT END 1 --><\/p><\/div>\n\n<br \/><a href=\"https:\/\/cryptopotato.com\/hacker-drains-5-9m-from-ethereum-liquidity-provider-trustedvolumes\/\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"&#13; Early reports framed the incident as a 1inch exploit, but the protocol clarified that it was not&hellip;\n","protected":false},"author":2,"featured_media":3932,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[13],"tags":[],"class_list":["post-43690","post","type-post","status-publish","format-standard","has-post-thumbnail","category-crypto","cs-entry","cs-video-wrap"],"_links":{"self":[{"href":"https:\/\/financialrush.com\/index.php?rest_route=\/wp\/v2\/posts\/43690","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/financialrush.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/financialrush.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/financialrush.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/financialrush.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=43690"}],"version-history":[{"count":0,"href":"https:\/\/financialrush.com\/index.php?rest_route=\/wp\/v2\/posts\/43690\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/financialrush.com\/index.php?rest_route=\/wp\/v2\/media\/3932"}],"wp:attachment":[{"href":"https:\/\/financialrush.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=43690"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/financialrush.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=43690"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/financialrush.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=43690"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}