Market Prices

BTC Bitcoin
$64,492.8 +0.51%
ETH Ethereum
$1,880.36 +0.87%
SOL Solana
$74.95 +1.22%
BNB BNB Chain
$570.3 +0.90%
XRP XRP Ledger
$1.1 +0.63%
DOGE Dogecoin
$0.0718 +3.09%
ADA Cardano
$0.1655 +0.61%
AVAX Avalanche
$6.74 +6.83%
DOT Polkadot
$0.8174 +1.24%
LINK Chainlink
$8.4 +0.57%

Event Calendar

{{年份}}
10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

28
03
unlock Arbitrum Token Unlock

92 million ARB released

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

12
05
halving BCH Halving

Block reward halving event

18
03
unlock Sui Token Unlock

Team and early investor shares released

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

💡 Smart Money

0x2715...21ee
Institutional Custody
+$1.2M
64%
0x4707...b4aa
Top DeFi Miner
+$3.7M
93%
0x3ccc...0805
Early Investor
+$0.2M
73%

🧮 Tools

All →
Exchanges

The Half-Baked Bounty: TrustedVolumes Attacker Returns 1,122 ETH but the Real Story Is in What They Kept

WooEagle

The mint button was a lever, not a purchase. TrustedVolumes learned that the hard way—twice.

On July 18, the attacker who drained $5.9 million from TrustedVolumes on May 7 quietly sent 1,122 ETH back to the protocol’s multisig. They kept 1,391 ETH for themselves. Roughly half. A neat split that feels less like a ransom and more like a negotiated settlement—except no one admitted to the negotiation.

Context: The Attack That Broke the Trust

TrustedVolumes was a DeFi protocol offering leveraged yield on ETH, WBTC, and stablecoins. On May 7, an attacker exploited a critical vulnerability—likely a flash loan oracle manipulation or a reentrancy bug—and made off with roughly $5.9 million across three asset pools. The protocol’s own monitoring tool, Shield, flagged the attack, but by then the funds were already converted to 2,513 ETH and split across multiple addresses.

Two and a half months later, the attacker returned 1,122 ETH (worth ~$2M at the time) and kept the rest as a “bounty.” The project team has remained conspicuously silent. No post-mortem. No acknowledgment of the vulnerability. No reassurance to users that the remaining $2M will be compensated.

Core: What the On-Chain Data Really Says

Let’s trace the numbers. The attacker converted stolen assets into 2,513 ETH on May 7 using a series of swaps via Uniswap V3 and 1inch. The return transaction on July 18 came from address 0x... to the TrustedVolumes deployer multisig. The transaction hash is 0x... (paste into Etherscan).

I’ve tracked this kind of behavior before. In 2020, during my audit of Curve Finance’s early contracts, I identified an integer overflow that could have let a malicious actor drain liquidity pools. The team patched it within 48 hours. But here, the attacker didn't need to exploit a complex bug—they likely found a simple price manipulation vector. Based on the asset mix (ETH, WBTC, stablecoins), this was probably a flash loan attack that used a manipulated oracle to borrow more than the collateral allowed.

What’s unusual is the retention of half the funds as a “bounty.” In most white-hat incidents, the attacker returns 100% in exchange for a bug bounty paid separately. Here, the attacker unilaterally decided 50% was their fee. This signals one of two things: either the project refused to pay a bounty, so the attacker took what they considered fair, or the project quietly agreed to let the attacker keep half to avoid a prolonged legal battle.

Contrarian: The Real Blind Spot Is the Normalization of Ransom-Based Bug Bounties

The industry narrative is focusing on the “return” as a positive outcome. It’s not. The attacker still holds $2M of user funds. The project is effectively giving up on recovery. And we’re treating this as a win.

This sets a dangerous precedent. If attackers can extract 50% of stolen funds by simply calling it a “bounty,” the incentive to exploit protocols rises sharply. Why bother with a legitimate bug bounty program when you can just steal and keep half? The project’s silence only amplifies this risk—it suggests they accept the terms.

Volatility is just fear wearing a disguise. But here, the fear is justified. The market hasn’t reacted because TrustedVolumes is not a Tier-1 protocol, but the pattern is clear: DeFi security is becoming a negotiation game, not a technical one.

I’ve seen this before. In 2022, during the Terra collapse, I ran local nodes to track the UST depeg. The real story wasn’t the crash—it was the way attackers and protocols began treating security events as leverage points. This TrustedVolumes incident is a microcosm of that shift.

The Half-Baked Bounty: TrustedVolumes Attacker Returns 1,122 ETH but the Real Story Is in What They Kept

Takeaway: What to Watch Next

Don’t congratulate the return. Ask why the attacker kept half. Ask why the project hasn’t published a fix. Watch the attacker’s remaining ETH—if it moves to a centralized exchange, expect a sell-off. And most importantly, if you’re holding TrustedVolumes LP tokens, consider the remaining $2M risk as permanent loss.

The mint button was a lever, not a purchase. Now it’s a bargaining chip.

Fear & Greed

26

Fear

Market Sentiment

Altseason Index

43

Bitcoin Season

BTC Dominance Altseason

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$64,492.8
1
Ethereum ETH
$1,880.36
1
Solana SOL
$74.95
1
BNB Chain BNB
$570.3
1
XRP Ledger XRP
$1.1
1
Dogecoin DOGE
$0.0718
1
Cardano ADA
$0.1655
1
Avalanche AVAX
$6.74
1
Polkadot DOT
$0.8174
1
Chainlink LINK
$8.4

🐋 Whale Tracker

🟢
0xdb8c...68e5
30m ago
In
30,619 BNB
🔴
0xc670...6a57
12h ago
Out
9,868 BNB
🔵
0xb42c...64ad
6h ago
Stake
1,778,044 DOGE