T
iTokenly

TrustedVolumes hack — May 2026

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedMay 7, 2026
Target typeOther
Loss$6,700,000Published estimates range $5,870,000 to $6,700,000Price at time of incident
Recovered$2,000,000
MethodAccess control flawTrustedVolumes' custom request-for-quote swap proxy exposed a public registerAllowedOrderSigner function with no access control. The attacker deployed a contract that called it during construction to add their own externally owned account to the allowlist of authorised order signers, then submitted fill-order calls carrying orders signed by that key. Two further defects compounded it: the signature was validated against the order's receiver field while tokens were pulled from a separately controlled inventory field, so authorisation and asset source were never bound together; and replay protection read fill status from one storage location but wrote it to another, so orders were never marked consumed and the same order could be filled repeatedly. The vault also held unlimited token approvals to the proxy, so the whole market-making inventory was reachable once the forged orders were accepted.
ChainsEthereum
Attributed toUnidentified attacker; security firm Blockaid linked the wallet to the March 2025 exploit of a 1inch Fusion V1 resolver, in which TrustedVolumes was itself reported to be the main victim.Suspected
OutcomePartially recovered

What happened

On 7 May 2026 an attacker drained the market-making inventory of TrustedVolumes, a firm that quotes prices and fills signed request-for-quote orders as a resolver for 1inch and other protocols. The assets taken were about 1,291 WETH, 16.94 WBTC, 206,282 USDT and 1.27 million USDC, moved across roughly 85 transactions on Ethereum. TrustedVolumes put the total at about $6.7 million, above the initial estimates published by security researchers, one of which was around $5.87 million.

The flaw was in TrustedVolumes' own RFQ swap proxy rather than in 1inch's contracts. The implementation contract exposed a public function for registering allowed order signers with no access control. The attacker deployed a contract that called it in its constructor to register their own address as an authorised signer, then submitted orders signed by that key. The fill path checked the signature against the allowlist but never checked that the signer owned what was being transferred, so the forged orders released TrustedVolumes' inventory. Verichains and Halborn both described it as an access-control failure rather than a cryptographic one.

1inch said its own systems and user funds were unaffected, noting that TrustedVolumes operates independently as a liquidity provider used by multiple protocols. TrustedVolumes said it was open to discussing a bug bounty and a mutually acceptable resolution.

On 18 July 2026 the attacker returned 1,122 ETH, worth roughly $2 million, and retained a similar amount as a self-declared bounty. TrustedVolumes had not publicly confirmed accepting those terms at the time of reporting. Blockaid linked the attacker's wallet to the March 2025 exploit of a 1inch Fusion V1 resolver, a separate earlier incident.

Sources

  1. VerichainsSecondary · retrieved 2026-08-01
  2. HalbornSecondary · retrieved 2026-08-01
  3. crypto.newsSecondary · retrieved 2026-08-01
  4. NewsBTC via TradingViewSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "TrustedVolumes hack — May 2026", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/trustedvolumes
https://itokenly.com/hacks/trustedvolumes

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.