A wallet linked to the Trusted Volumes exploit has returned 1,122 ETH to the protocol’s inventory, partially reversing losses from a May attack that drained about $5.9 million. On-chain activity suggests the funds were not fully recovered, with the attacker apparently keeping roughly $2 million in ETH in what looks like a bounty-style arrangement.
Attack tied to RFQ swap proxy flaw
The incident began on May 7, when Trusted Volumes was exploited through a vulnerability in its RFQ swap proxy. According to the source report, the attacker used a signature-check bypass to drain approximately $5.9 million in assets from the protocol.
The newly returned 1,122 ETH marks the most concrete development since the exploit. The transfer was sent back to protocol inventory from a wallet tied to the attack, reducing at least part of the damage caused by the breach.
Partial return, not full recovery
The recovery does not amount to a complete reimbursement. Based on the on-chain picture described in the report, the attacker appears to have retained another large portion of the stolen funds, estimated at around $2 million in ETH.
That has led to the episode being viewed less as a straightforward recovery and more as a settlement of the kind sometimes seen in decentralized finance. In such cases, an attacker returns part of the funds while keeping a share that effectively functions as a bounty, even if no formal process is visible on-chain.
A familiar DeFi pattern
The outcome reflects a recurring dynamic in crypto security incidents. Rather than ending through a conventional legal process, exploits in decentralized finance often move into a public and informal phase shaped by wallet tracking, on-chain analysis and pressure from the broader market.
Projects facing losses may prefer a partial recovery over the risk of losing everything permanently. At the same time, attacker behavior varies widely. Some wallets return funds, some move assets through mixers or exchanges, and others keep the proceeds without further contact.
Damage reduced, uncertainty remains
For Trusted Volumes, the return of 1,122 ETH is a meaningful recovery because it lowers the scale of the loss. But it does not erase the underlying security failure or settle all questions around the incident.
The exploit itself was tied to a smart contract weakness, and the report notes that any longer-term resolution depends on how the protocol addresses that flaw and rebuilds confidence. A partial return can improve the immediate balance sheet, but it does not by itself show that the broader fallout is over.
The case fits a broader pattern in DeFi, where exploit aftermaths are often resolved through ad hoc on-chain outcomes rather than clear legal enforcement. In this instance, the return of funds offers some relief, while the attacker’s apparent retention of roughly $2 million underlines how incomplete those resolutions can be.
Source: www.newsbtc.com