Blockchain security firm Blockaid reported an ongoing exploit against TrustedVolumes, a DeFi liquidity provider and resolver widely used in the 1inch ecosystem, that drained roughly $5.87 million in crypto assets from an Ethereum resolver contract, with on‑chain patterns linked to the operator behind the March 2025 1inch Fusion V1 incident. Blockaid said the attacker targeted a TrustedVolumes-controlled RFQ swap resolver (not core 1inch contracts), siphoning assets including WETH, USDT, WBTC and USDC into attacker-controlled addresses while the exploit was still active at the time of detection. TrustedVolumes later confirmed it had been exploited and identified three Ethereum addresses collectively holding about $6.7 million in stolen funds, a higher figure than Blockaid’s initial $5.87 million estimate, reflecting additional movements after the first alert. Security analyses attribute the incident to a vulnerability in TrustedVolumes’ RFQ swap proxy / resolver authorization logic, where insufficient access control around order-signing permissions allowed the attacker to authorize malicious trades and drain liquidity. In response to media reports initially framing the incident as a 1inch hack, 1inch Network publicly stressed that neither its protocols, infrastructure, nor user funds were compromised, describing TrustedVolumes as an independent market maker and liquidity provider used by multiple DeFi platforms rather than an official 1inch protocol component. Blockaid further linked the attacker’s on‑chain fingerprint to the March 2025 1inch Fusion V1 exploit, which had targeted a third‑party resolver integrated with 1inch’s Fusion settlement, although the firm emphasized that the TrustedVolumes incident relied on a different vulnerability. The case underscores the systemic risk posed by third‑party resolvers and liquidity providers embedded in DEX aggregation stacks: even when core protocol contracts remain secure, bugs in external market makers’ RFQ or resolver logic can result in multimillion‑dollar losses and reputational spillover for the protocols that route order flow to them. "entities":["TrustedVolumes","1inch Network","1inch Fusion V1","Blockaid","Ethereum","WETH","USDT","USDC","WBTC","Fusion V1 incident (March 2025)","TrustedVolumes RFQ swap proxy / resolver","Sergej Kunz"]}`

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on $USDC

Comments