Trusted Volumes, a DeFi trading protocol, was hit by an exploit that drained $5.9 million in crypto assets, according to blockchain security firms SlowMist and PeckShield. The stolen funds included 1,291 ETH, 16.94 WBTC, 1.26 million USDC, and 206,000 USDT. SlowMist estimated the ETH at about $3.02 million and the WBTC at about $1.37 million.
Signature verification flaw opened the door
The attack was traced to a critical weakness in the protocol’s signature verification code. Security researchers said the flaw allowed the attacker to bypass required authorization checks and generate fraudulent trading orders. Trusted Volumes runs on an RFQ (Request for Quote) model rather than a conventional AMM structure, which means orders are exchanged directly between parties and rely on digital signatures from both sides.
That design makes signature verification a core security control. The report said a logical bug in the protocol’s fillOrder function severely weakened those protections and left the platform exposed to manipulation.
Stolen funds moved through decentralized exchanges
After the exploit, the attacker quickly routed the stolen assets through decentralized exchanges in an effort to make tracking harder. Blockchain records linked the stolen stablecoins and WBTC balances to several exchange addresses. The source material did not identify those addresses by name, and it did not say whether any of the funds had been frozen or recovered.
Protocol built around decentralized quote-based trading
Trusted Volumes is described as a DeFi protocol for decentralized trading that lets users exchange price quotes directly. The model is intended to move price discovery for over-the-counter style trading into a decentralized setting. In that structure, secure asset access depends on reliable signature checks before user approvals can be acted on.
Audit focus returns to protocol-level security
The incident has put attention back on persistent security weaknesses across DeFi protocols. Security experts cited in the report said protocol-level signature verification algorithms need regular and thorough audits. Users who still hold assets on the platform now face elevated risk, and analysts advised reviewing technical documentation and security reports carefully before granting large approvals.
Trusted Volumes is continuing its investigation and is checking for any additional vulnerabilities.

