{"id":427253,"date":"2026-05-14T10:56:30","date_gmt":"2026-05-14T05:26:30","guid":{"rendered":"https:\/\/dripp.zone\/news\/hacker-actively-laundering-stolen-crypto-after-exploiting-liquidity-provider-for-6700000-peckshield-crypto-news\/"},"modified":"2026-05-14T12:21:59","modified_gmt":"2026-05-14T06:51:59","slug":"hacker-actively-laundering-stolen-crypto-after-exploiting-liquidity-provider-for-6700000-peckshield-crypto-news-2","status":"publish","type":"post","link":"https:\/\/dripp.zone\/news\/hacker-actively-laundering-stolen-crypto-after-exploiting-liquidity-provider-for-6700000-peckshield-crypto-news-2\/","title":{"rendered":"Hacker Actively Laundering Stolen Crypto After Exploiting Liquidity Provider for $6,700,000: PeckShield &#8211; Crypto News"},"content":{"rendered":"<p><\/p>\n<div>\n<p>A hacker has started laundering digital assets that were part of the $6.7 million theft from the liquidity provider TrustedVolumes, says cybersecurity firm PeckShield.<\/p>\n<p>PeckShield <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/x.com\/PeckShieldAlert\/status\/2053726382061195737\" rel=\"noopener\" target=\"_blank\">says<\/a> that new data shows the hacker has started moving hundreds of thousands of dollars worth of Ethereum (<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/dailyhodl.com\/currencies\/ethereum\/\" rel=\"noopener\" target=\"_blank\">ETH<\/a>).<\/p>\n<p><em>\u201cThe TrustedVolumes exploiter has laundered $278,000 in stolen funds so far: they deposited 10.2 ETH ($23,600) to TornadoCash and laundered 110 ETH ($250,000) via THORChain to BTC; they also attempted to deposit 0.5 ETH to Railgun but changed their mind and sent it back. TrustedVolumes was exploited for ~$6.7 million on May 7th.\u201d <\/em><\/p>\n<p>TrustedVolumes <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/x.com\/trustedvolumes\/status\/2052235435292910005\" rel=\"noopener\" target=\"_blank\">says<\/a> that it is willing to negotiate a resolution with the hacker. The firm also lists three wallet addresses with two holding approximately $3 million and one $700,000 worth of the stolen crypto assets.<\/p>\n<p><em>\u201cWe were recently exploited\u2026<\/em><\/p>\n<p><em>We are open to constructive communication regarding a bug bounty and a mutually acceptable resolution.\u201d <\/em><\/p>\n<p>Blockchain security firm QuillAudits <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.quillaudits.com\/blog\/hack-analysis\/trustedvolumes-rfq-hack\" rel=\"noopener\" target=\"_blank\">says<\/a> that the hacker was able to drain millions in a single transaction by exploiting a design flaw in the platform\u2019s custom order-settlement system.<\/p>\n<p><em>\u201cTrustedVolumes operates as a 1inch market maker and resolver, providing on-chain liquidity through a custom Request-for-Quote (RFQ) proxy\u2026 <\/em><\/p>\n<p><em>In an RFQ model, a maker pre-signs orders, quoting a specific price for a specific token pair. A taker presents that signed quote to the settlement contract, which verifies the signature and executes the swap atomically.The system relies on three guarantees working in concert, the maker must have authorized who can sign orders on its behalf, each signed order must be filled only once (replay protection), and the token source for the fill must be the authenticated maker\u2019s own inventory, not an arbitrary third-party address. <\/em><\/p>\n<p><em>In the TrustedVolumes implementation, all three guarantees failed simultaneously, and the attacker exploited them in a single composed transaction.\u201d<\/em><\/p>\n<p><em><span style=\"font-size: 13pt;\">Follow us on <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/x.com\/TheDailyHodl\" target=\"_blank\" rel=\"noopener\">X<\/a>, <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.facebook.com\/thedailyhodl\/\" target=\"_blank\" rel=\"noopener\">Facebook<\/a> and <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/t.me\/thedailyhodl\" target=\"_blank\" rel=\"noopener\">Telegram<\/a><\/span><\/em><br \/>\n<br \/>\n<em><span style=\"font-size: 13pt;\">Don&#8217;t Miss a Beat \u2013 <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/dailyhodl.com\/join-the-daily-hodl-email-list\/\" target=\"_blank\" rel=\"noopener\">Subscribe<\/a> to get email alerts delivered directly to your inbox <\/span><\/em><br \/>\n<br \/>\n<em><span style=\"font-size: 13pt;\">Surf <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/dailyhodl.com\/daily-hodl-mix\">The Daily Hodl Mix<\/a><\/span><\/em><br \/>\n<\/p>\n<div class=\"hideinamp\">\n<p>&#038;nbsp<\/p>\n<h6>Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any assets including cryptocurrencies, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.<\/h6>\n<\/div>\n<p><span style=\"font-size: 10pt;\"><em>Generated Image: Midjourney<\/em><\/span><\/p>\n<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>A hacker has started laundering digital assets that were part of the $6.7 million theft from the liquidity provider TrustedVolumes, says cybersecurity firm PeckShield. PeckShield says that new data shows the hacker has started moving hundreds of thousands of dollars worth of Ethereum (ETH). \u201cThe TrustedVolumes exploiter has laundered $278,000 in stolen funds so far: [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":427258,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[173],"tags":[201,248,251,246,257,255,250,252,247,253,249,256,254],"class_list":["post-427253","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-others","tag-blockchain","tag-bsc","tag-chainlink","tag-coin","tag-cryptocurrency","tag-gta","tag-looks-rare","tag-oracle","tag-polygon","tag-quickswap","tag-safe-moon","tag-wallet","tag-wordpress"],"_links":{"self":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/427253","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/comments?post=427253"}],"version-history":[{"count":1,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/427253\/revisions"}],"predecessor-version":[{"id":427260,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/427253\/revisions\/427260"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/media\/427258"}],"wp:attachment":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/media?parent=427253"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/categories?post=427253"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/tags?post=427253"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}