TrustedVolumes, a liquidity provider and resolver in 1inch's Fusion ecosystem, was drained on Ethereum on May 7 through a custom RFQ proxy that confused signer validation with actual authorization. The attacker used a permissionless signer registration path, a check against the wrong address, and broken replay protection to pull 1,291 WETH, 206,282 USDT, 16.94 WBTC, and 1.27M USDC in one transaction. The on-chain loss priced around $5.87M, while TrustedVolumes' own post-exploit accounting put it closer to $6.7M.

TLDR by @Benthic

More coverage

Explore the topic

More on trustedvolumes

Comments