TrustedVolumes Loses $6.7 Million in Exploit; 1inch Says It Was Unaffected
TrustedVolumes is an independent market maker that provides liquidity and resolves request-for-quote orders for decentralized finance protocols including 1inch Fusion. The incident highlights how permission flaws in a third-party resolver’s custom contracts can put approved tokens at risk even when those contracts are not part of an aggregator’s core systems. It also raised concerns about the security of 1inch users’ assets.
On May 7, 2026, TrustedVolumes confirmed that its Ethereum resolver had been exploited for about $6.7 million. The attacker used a public function to register as an authorized signer and then transferred the tokens. The stolen funds were held across three Ethereum addresses, with about $3 million in each of two addresses and about $700,000 in the third. 1inch said the same day that its protocol, infrastructure and user funds were unaffected.
All Coverage
2 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →