A new cyberattack has struck the decentralized finance (DeFi) ecosystem, resulting in a major security breach at Trusted Volumes, a trading protocol. Approximately $5.9 million was reported stolen, including significant amounts of Ethereum ($ETH), Wrapped Bitcoin (WBTC), and stablecoins.
Technical cause and details of the exploit
According to blockchain security companies SlowMist and PeckShield, the attack exploited a critical flaw in the protocol’s signature verification code. This allowed the attacker to bypass essential authorization checks and create fraudulent trading orders.
Trusted Volumes operates as a DeFi trading protocol using a Request for Quote (RFQ) architecture. Unlike conventional automated market maker (AMM) models, orders in this system are exchanged directly between parties and require digital signature approval from both sides. Flawless operation of the cryptographic signature verification mechanism is crucial for transactional security.