A hacker involved in the Trusted Volumes exploit has returned 1,122 ETH to the protocol, resolving part of a security incident that began with a vulnerability affecting the blockchain infrastructure platform. The attacker retains approximately $2 million worth of cryptocurrency as what appears to be a negotiated bounty or retained proceeds from the exploit.
The Trusted Volumes incident involved a vulnerability that allowed the attacker to drain funds from the protocol. After the exploit was discovered, negotiations between the attacker and the protocol’s team reportedly led to an agreement under which a portion of the stolen funds would be returned while the attacker kept the remainder.
This pattern follows a common trajectory in crypto security incidents, where attackers return a majority of stolen funds in exchange for being allowed to keep a portion as a “white hat” bounty. The arrangement avoids lengthy legal proceedings and provides some recovery for affected users, though it remains controversial within the industry.
The 1,122 ETH returned represents a significant portion of the stolen funds, though the precise total amount taken in the exploit has not been fully disclosed. The protocol’s team has stated that they will work to distribute the returned funds to affected users.
The incident adds to a growing list of security breaches in the crypto sector in 2026. According to CertiK’s mid-year report, web3 security incidents cost the industry over $1.31 billion in the first half of 2026, a 28 percent increase year-over-year when excluding the baseline impact of the Bybit hack.
This article was adapted from NewsBTC. Read the original here.
