TrustedVolumes exploit drains roughly $5.87 million from 1inch resolver
Security & Exploits ·
The attacker behind March's 1inch Fusion V1 incident appears to have struck again, this time against market maker TrustedVolumes.
TrustedVolumes, described as a 1inch market maker and resolver, was reportedly hit by an exploit that has extracted approximately $5.87 million so far, according to a post from researcher Vladimir S.. The extracted funds break down as 1,291.16 WETH, 206,282 USDT, 16.939 WBTC, and 1,268,771 USDC. The report credits security firm Blockaid with flagging the activity, and Blockaid's own post corroborates that the exploit was ongoing at the time of disclosure.
Notably, the same attacker is said to be responsible for the March-2025 1inch Fusion V1 incident, an earlier exploit that drained about $5 million, according to corroborating reporting in the cluster. If accurate, this would mark a repeat targeting of 1inch-linked infrastructure by the same actor, though the exact mechanism connecting the two incidents has not been detailed in the material available.
The Block also reported on the exploit, placing the loss at approximately $6 million, broadly consistent with the $5.87 million figure cited elsewhere in the cluster. Multiple accounts describe the draining as having been in progress at the time of reporting, with the total figure characterized as the amount extracted "so far" rather than a final tally.
As a market maker and resolver within the 1inch ecosystem, TrustedVolumes would typically hold liquidity used to facilitate trades, meaning the exploited funds were reportedly drawn from operational reserves rather than user deposits directly, though the material does not specify the precise vulnerability exploited or how the attacker gained access.
What remains unresolved includes the final total extracted, whether the draining has been stopped, the specific technical vector used, and whether any funds can be recovered or frozen. It is also unclear whether 1inch or TrustedVolumes has issued an official statement, or what connection, if any, exists between the wallet addresses used in this incident and those from the March Fusion V1 exploit. Four distinct sources are tracking the story as it develops.