TrustedVolumes Hack

Reported loss $6.7M
Ethereum
Unauthorized order-signer registration

What happened

On May 7, 2026, TrustedVolumes, an independent liquidity provider and 1inch Fusion resolver, was exploited on Ethereum. The attacker abused an authorization flaw in the resolver's custom RFQ path, allowing an attacker-controlled signer relationship to settle orders against pre-approved resolver balances. On-chain analysis of the principal transaction shows approximately $5.87 million in WETH, USDT, WBTC, and USDC was taken; TrustedVolumes later described the broader incident as about $6.7 million.

Technical root cause

A public signer-registration function allowed an untrusted party to become an approved order signer. Authorization for RFQ settlement must bind signer registration to the account whose funds can be committed, restrict registration to an authorized administrator or cryptographic consent path, and validate maker, signer, and balance ownership together at settlement.

How it happened

TrustedVolumes’ RFQ flow used an allow-list for order signers, but the registration path did not bind that authorization to a trusted resolver-controlled identity. The attacker registered a signer they controlled, created orders whose maker and signer relationship satisfied the flawed authorization check, and settled them against a third party’s pre-approved token balances. The principal exploit transaction executed on Ethereum on May 7.

The differing $5.87 million and $6.7 million figures describe the observed principal transaction and TrustedVolumes’ later incident-wide estimate, respectively; they should not be combined into a single loss total.

Protocol details

Classification Access Control / RFQ Authorization
Protocol Type Exploit/Other
Implementation language Solidity
Protocol links Website @trustedvolumes

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.