Attack Detected on 1inch-Affiliated Liquidity Provider, Approximately $5.87 Million Drained
⚡ What Happened
A vulnerability was reportedly exploited in the infrastructure of "TrustedVolumes," a liquidity provider affiliated with DEX aggregator 1inch, resulting in an estimated outflow of approximately $5.87 million (roughly ¥880 million). Security firm Blockaid announced on May 7 that it had detected an ongoing attack. Attacks on DeFi's infrastructure layer exploit vulnerabilities in third-party layers rather than the protocol itself, potentially affecting the trustworthiness of the entire ecosystem. The official response from 1inch and TrustedVolumes and the determination of the full extent of damages are now the focus.
A key aspect of this attack is that it targeted the third-party infrastructure layer responsible for liquidity provision, rather than the DEX aggregator itself. Since the 2022 Wormhole bridge hack ($320 million) and the 2023 Curve Finance exploit, a pattern has become established in DeFi where "peripheral infrastructure rather than the protocol itself" becomes the target of attacks. While the estimated $5.87 million in damages is mid-range for a DeFi hack, 1inch is one of the largest DEX aggregators, and damage to trust in the liquidity provider layer could ripple through to routing efficiency and slippage. The fact that security firm Blockaid detected the attack demonstrates the maturation of real-time monitoring infrastructure, though it may not have been able to completely prevent the attack from progressing. DeFi's "composability" structurally carries supply chain attack risks as the trade-off for convenience, and there is a high probability that incidents of this kind will continue to recur.
🔍 Reporting has not clearly distinguished the impact on the 1inch protocol itself, but the liquidity provider's vulnerability exists in a layer that 1inch's routing algorithm depends on—meaning the explanation that "the core protocol is unaffected" is technically accurate but practically indistinguishable from the user's perspective. The fact that TrustedVolumes, a relatively low-profile provider, was targeted illustrates where the "weak links" in the DeFi ecosystem lie. Additionally, the estimated $5.87 million is a sufficient incentive for the attacker, yet also falls within a range where white-hat bug bounty negotiations could potentially succeed. Note that the damage amount is currently an estimate and may change as investigations proceed.
📰 Source: NewEconomy
🧭 Why This Is Moving Now
domain=crypto
🔮 Next Scenarios
🎯 Incentive Map
| Player | True Incentive | Underlying Weakness | Predicted Action |
|---|---|---|---|
| 1inch (Protocol Operator) | Minimize brand damage and prevent TVL outflows. Wants to clearly separate responsibility between itself and the liquidity provider | The contradiction of being unable to fully manage complex ecosystem dependencies while wanting to project "safety" to users | Swiftly review its relationship with TrustedVolumes and announce enhanced audits. Reluctant on victim compensation but may consider partial reimbursement depending on community pressure |
| Attacker | Maximize profit. The estimated $5.87 million is a launderable amount via mixers and bridges, but the attacker is also aware of tracking risks | Complete anonymization is difficult due to on-chain transparency. Also has the option of gaining legitimate profit through bug bounty negotiations | In the short term, will attempt to move funds via mixers and cross-chain bridges, but may agree to partial return negotiations if tracking pressure increases |
| Blockaid (Security Firm) | Showcase its detection capabilities and establish its position in the DeFi security market | Vulnerable to criticism that detection did not translate to full prevention of the attack. Will be evaluated on the accuracy of its post-incident analysis | Publish a detailed post-mortem report and intensify marketing of its real-time defense solutions |
⚠️ Pre-Mortem — Conditions Under Which This Prediction Fails
- If the attacker is a white hat and early fund return is achieved through bug bounty negotiations (precedent exists in DeFi with cases like Euler Finance)
- If on-chain tracking leads to fund freezes and recovery via CEXs proceeds faster than expected
- If the actual damage amount is significantly smaller than initially reported and is automatically covered by protocol insurance
Fear-Setting / When this prediction fails
- This probability fails if the attacker returns funds within 48 hours as a white-hat, as seen in the Euler Finance case (March 2023).
- This probability fails if on-chain forensics quickly identify the attacker and law enforcement freezes funds at centralized exchanges within the 14-day window.
- This probability fails if TrustedVolumes had undisclosed insurance coverage that enables rapid reimbursement announced as 'recovery'.
Hit Condition: HIT if 1inch or TrustedVolumes officially announces the recovery of more than 50% of the drained funds or a negotiated agreement with the attacker by May 21, 2026
Resolution Date: 2026-05-21
Read more
Toranpu Cai Pan Suo Nidui Chu Suru Fa Yan Zui Gao Cai Guan Shui Wei Xian Pan Jue Gayao Rasusan Quan Nojun Heng
U.S. Supreme Court judged that the customs duty under Trump's IEEPA (International Emergency Economic Authority Act) was different from the US Supreme Court's 6 to 3, and over $13.4 billion was covered. Trump said, “We have to deal with the court”, and openly attack two judges appointed by ourselves
Ri Ben No Zi Zhu Fang Wei Fa An Zhan Hou 80Nian Noan Quan Bao Zhang Tabugabeng Rerugou Zao Li Xue
FASTRead 1 minute The Japanese government submitted the draft of the Defense Force Enhancement Law to the National Assembly is the pro。。 of the largest security paradigm shift since the establishment of the Peace Const。tion in 。. As the structural changes in the U.S.-China confrontation, nuclear threats in
Deepening of Russian-Iranian Military Cooperation — “Double-front pressure” structure
FASTRead 1 minute President Zeleスキー’s afflicted military cooperation between Russia and Iran to demonstrate that the Ukrainian War has evolved into a “two-front pressure” system that works structurally with the Middle East, rather than just European regional disputes. If this cooperation is established, the west side of the security
Gao Shi Shou Xiang No Ji Shu Zi Yuan Wai Jiao Ji Zhong Ri Ri Ben Gaaienerugidi Zheng Xue Nojie Jie Dian Womu Zhi Sugou Zao Zhuan Huan
FASTRead 1 minute Prime Minister Takaichi met with the Minister of Economy, Trade and Industry, Minister of Economy, Trade and Industry, Minister of Economy, Trade and Industry. This is a strategic signal positioning Japan at the intersection of three mega-trends: AI defense technology, energy security, and European regunry. ── ───────── * • On March
本サイトの記事は情報提供・教育目的のみであり、投資助言ではありません。記載されたシナリオと確率は分析者の見解であり、将来の結果を保証するものではありません。過去の予測精度は将来の精度を保証しません。特定の金融商品の売買を推奨していません。投資判断は読者自身の責任で行ってください。 This content is for informational and educational purposes only and does not constitute investment advice. Scenarios and probabilities are analytical opinions, not guarantees of future outcomes. Past prediction accuracy does not guarantee future accuracy. We do not recommend buying or selling any specific financial instruments.
予測トラッカーを見る View Prediction Track Record