A hacker who drained roughly $5.9 million from the Trusted Volumes protocol earlier this month has sent back 1,122 ETH — but kept about $2 million as a de facto bounty. The partial return, confirmed through on-chain data from Etherscan, comes after the May 7 exploit that used a signature-check bypass in the protocol's RFQ swap proxy.
How the exploit worked
The attacker found a vulnerability in the smart contract that handles request-for-quote swaps. By bypassing the signature verification step, they were able to drain funds from the protocol in a single transaction. On-chain records show the stolen assets were moved quickly, but the hacker's wallet was publicly tracked from the start — a common dynamic in DeFi incidents where legal recourse is limited.
The partial recovery and bounty
Trusted Volumes got back 1,122 ETH, but that's only part of what was taken. The attacker kept roughly $2 million worth of crypto, effectively acting as a bounty for finding the bug. This kind of settlement — negotiate, return some, keep some — has become a pattern in decentralized finance. Without a central authority to freeze funds, protocols often have to bargain with the people who broke in.
What comes next for Trusted Volumes
The protocol hasn't been made whole, and users are waiting for answers. Trusted Volumes needs to provide a clear post-mortem explaining exactly how the signature check failed and what's being done to prevent a repeat. Restoring trust after a $5.9 million hole isn't going to happen on its own. The community will be watching for that report — and for any further movement from the hacker's wallet.




