A market-making “solver” integrated with 1inch, TrustedVolumes, was exploited on Ethereum for roughly 1,291 WETH, 1.27M USDC, 206k USDT and 16.9 WBTC (about $5.9–6.7 million depending on price estimates) after an attacker abused a flaw in TrustedVolumes’ own Request-for-Quote (RFQ) swap proxy, not in 1inch’s core protocol. Blockchain security firm Blockaid detected the exploit in real time and linked it to a vulnerability in TrustedVolumes’ custom order-settlement system, where a publicly accessible function allowed the attacker to register themselves as an authorized order signer and then drain assets from a resolver contract that had previously granted token approvals. The stolen assets were taken from TrustedVolumes’ infrastructure and resolver funds, not from end users of 1inch, Uniswap, or other integrated protocols, and 1inch publicly clarified that its own contracts, systems, and user funds were unaffected. According to post-incident reporting, the attacker used the unprotected registerAllowedOrderSigner (or equivalent allowlist-management) function to add their address to the signer allowlist, then created seemingly valid RFQ orders that the proxy treated as authorized while pulling tokens from TrustedVolumes’ resolver wallets, ultimately converting the loot into ETH and distributing it across multiple addresses. TrustedVolumes confirmed the incident, shared the main addresses holding the funds, and indicated willingness to negotiate a bug-bounty-style resolution, while security researchers noted that this RFQ proxy vulnerability is distinct from, though possibly operated by the same actor as, the March 2025 1inch Fusion v1 resolver incident. This incident is significant because it shows that off-protocol market-making and solver infrastructure can be a critical point of failure in DeFi even when core protocol contracts are secure and audited. The hack underscores systemic risks around custom RFQ/settlement proxies, signature/allowlist management, and broadly trusted liquidity providers that operate across multiple front-ends and aggregators; a single access-control mistake in such infrastructure can have multi-million-dollar impact and be misinterpreted by markets as a protocol-level exploit. It also continues a pattern of attackers targeting specialized components around 1inch and other DEX ecosystems, reinforcing the need for rigorous audits and monitoring not only of protocol contracts but also of third-party resolvers, solvers, and market-making tooling.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on $ETH

Comments