Close Menu
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
What's Hot

AAVE Price Prediction: Smart Money Loading at $90 — Is a Break to $96 Next?

July 20, 2026

BigCommerce Powered by Commerce Scores 24/24 Total Medals in 2026 Paradigm B2B Combine Midmarket and Enterprise Editions for Fourth Consecutive Year

July 20, 2026

Tungsten Miner Soars After Billionaire Forrest Takes 17% Stake

July 20, 2026
Facebook X (Twitter) Instagram
Recession Profit AlertsRecession Profit Alerts
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
Recession Profit AlertsRecession Profit Alerts
Home»Security»TrustedVolumes attacker returns $2M, keeps another $2M as bounty
Security

TrustedVolumes attacker returns $2M, keeps another $2M as bounty

July 19, 2026No Comments3 Mins Read

A TrustedVolumes attacker has returned 1,122 $ETH worth about $2 million while keeping another $2 million as a self-declared bounty.

According to Com Feed monitoring, the Ethereum transfer represents a partial recovery from the May exploit, which initially drained about $5.87 million from a contract controlled by the liquidity provider. The attacker has retained roughly the same dollar amount as the returned funds, labeling it a bounty.

⚠️ JUST IN: The TrustedVolumes exploiter has returned 1,122 $ETH ($2M+

The original exploit resulted in more than $5.8M being stolen. The exploiter has now returned around $2M while retaining another $2M as a “bounty” pic.twitter.com/HJSdx4i4Or

— Com Feed (@thecomfeed) July 18, 2026

At the time of writing, TrustedVolumes had not formally confirmed that it had accepted the attacker’s bounty terms.

Partial repayment recovers only part of the stolen funds

TrustedVolumes disclosed in May that the total loss had reached roughly $6.7 million, exceeding the initial estimate reported by security researchers. The company said at that time the stolen assets were held across three addresses containing approximately $3 million, $3 million, and $700,000.

Seeking to recover the assets, TrustedVolumes offered to discuss a vulnerability bounty and what it called a mutually acceptable solution. The liquidity provider also invited the attacker to begin constructive communication, though its statement did not specify a proposed bounty rate.

Before the stolen tokens were consolidated, Blockaid identified 1,291.16 WETH, 206,282 $USDT, 16.939 WBTC, and 1.27 million $USDC among the drained assets. PeckShield later reported that the attacker exchanged the tokens and gathered the proceeds into about 2,513 $ETH.

See also  Galaxy and Sharplink Launch $125M DeFi Yield Fund Targeting Institutional-Grade Returns

The returned 1,122 $ETH was worth about $2 million at the time of writing, while Com Feed valued the attacker’s retained bounty at a similar amount. The combined dollar value is lower than the original loss because $ETH has fallen since the May exploit, when the stolen assets were converted into the cryptocurrency.

Custom TrustedVolumes proxy caused the security breach

As previously reported by crypto.news, Blockaid traced the May 7 attack to a custom request-for-quote swap proxy operated by TrustedVolumes. According to the security firm, the attacker targeted the company’s Ethereum resolver setup rather than a regular 1inch swap route.

TrustedVolumes used the RFQ system to quote token prices and complete signed trades from its inventory. Verichains found that a public function lacked access controls, allowing the attacker to register an address as an approved order signer and create transactions that appeared valid to the proxy.

During the same transaction, the attacker directed the proxy to pull WETH, WBTC, $USDT, and $USDC from the TrustedVolumes inventory vault. Verichains also identified a mismatch between the address checked for authorization and the address supplying the tokens, while faulty replay protection failed to record orders correctly.

Although the affected market maker supplied liquidity through 1inch, the attack did not compromise 1inch’s core aggregation contracts or standard user routes, according to 1inch’s account of the incident. Blockaid linked the wallet to the March 2025 Fusion V1 exploit but reported that the May attack used a different flaw tied to TrustedVolumes’ custom proxy.



Source link

attacker Bounty returns TrustedVolumes

Related Posts

UK turns delayed wallet identification into a 14-year criminal risk for crypto firms

July 20, 2026

Ethereum Developer Consensys Denies User Data Was Compromised

July 20, 2026

Crypto malware in 8 Steam games steals tokens after leaving trail to Uber Eats deliveries

July 20, 2026

US Court Seizes XRP and Bitcoin Portfolios Worth $8.3 Million From Cyber Negotiator

July 20, 2026
Top Posts

Bitcoin lenders say institutions want crypto credit to look more like TradFi

May 7, 2026

US Scientists Crack Superconductor Code – Zero Energy Loss Moves Closer To Reality

April 8, 2026

Military Conflicts Haven’t Derailed The Long-Term Growth Of Stocks

October 28, 2023

Type above and press Enter to search. Press Esc to cancel.