Two DeFi exploits drained $7.3M and an FBI-led international operation restrained $701M in scam-center crypto, May 4–10. Weekly breakdown by Recoveris.
This week’s Recoveris report covers TrustedVolumes’ $5.87M loss through an access-control flaw in a custom RFQ swap proxy used by 1inch Fusion, a coordinated international takedown that restrained $701M in cryptocurrency and dismantled nine scam compounds, and Ekubo Protocol’s $1.4M WBTC drain via an EVM v2 router callback exploit.
TrustedVolumes – ~$5.87M | May 7, 2026 | Smart Contract / Access Control
TrustedVolumes, a Request-for-Quote liquidity provider used by 1inch Fusion and other DeFi protocols, was drained of approximately $5.87M from its Ethereum custom RFQ swap proxy. The attacker exploited a publicly accessible function that permitted permissionless registration as an authorized order signer, then combined that with broken replay protection and an unvalidated transferSource field to impersonate a trusted signer and route withdrawals to three attacker-controlled addresses. Stolen assets included 1,291 WETH, 16.93 WBTC, 1.27M USDC, and 206,000 USDT. 1inch confirmed its protocol, infrastructure, and user funds were not affected.
Access-control failures in resolver and market-maker infrastructure are a recurring weak point in DeFi composability. When a protocol delegates execution to a third-party signer or proxy, every assumption about that signer’s identity must be enforced inside the contract. A missing validation step or an open registration function transfers full extraction authority to whoever finds it. Blockaid attributed the operator to the same actor behind the March 2025 1inch Fusion V1 incident, suggesting a pattern of opportunistic exploitation targeted at the resolver layer rather than the core protocol.
TrustedVolumes published the three exploiter wallet addresses on disclosure and offered constructive communication regarding a bug bounty and a mutually acceptable resolution. When stolen funds remain consolidated across a small number of attacker-controlled wallets in the hours after an exploit, freezing requests to centralized off-ramps and stablecoin issuers can preserve recovery optionality before the funds enter mixers or cross-chain bridges.
Sources: The Block, CoinPedia, Decrypt, Cointelegraph
Global Scam Center Crackdown – $701M restrained | May 4–8, 2026 | Cross-Border Enforcement
A coordinated operation led by the UAE’s Dubai Police, in partnership with the U.S. FBI and the Chinese Ministry of Public Security, restrained over $701M in cryptocurrency, arrested 276 individuals, and dismantled nine scam compounds. The operation also seized a Telegram recruitment channel used to traffick victims into Cambodian scam centers and took down 503 fake investment websites. Six defendants, including alleged compound managers and recruiters, were charged in the U.S. District Court for the Southern District of California with federal fraud and money-laundering offenses.
Investment-scam compounds, often described as pig butchering operations, depend on a tightly integrated pipeline: trafficked operators inside the compound, fake brokerage front-ends that mirror legitimate exchange interfaces, and laundering rails that move victim deposits through stablecoins, OTC desks, and offshore VASPs. Dismantling nine compounds simultaneously interrupts that pipeline at its source and generates intelligence opportunities downstream as seized devices and chat logs surface compound-to-launderer relationships.
For VASPs, law firms, and institutions representing affected victims, coordinated enforcement actions of this scale generate evidentiary records and clearer attribution paths for individual recovery cases tied to the same compound infrastructure. The FBI noted that Operation Level Up has now notified approximately 9,000 victims and saved an estimated $562M as of April 2026. Identifying victims linked to the seized infrastructure and surfacing freezing opportunities at receiving exchanges remains the operational priority.
Sources: DOJ press release, The Hacker News, The Daily Hodl, Bitdefender
Ekubo Protocol – ~$1.4M | May 5, 2026 | Smart Contract / Approval-Based Exploit
Attackers exploited an access-control flaw in Ekubo’s EVM v2 swap router on Ethereum, specifically in the IPayer.pay callback that allowed the attacker to control the payer, token, and amount fields. The attacker chained roughly 85 rapid transactions to drain WBTC from wallets that had previously granted token approvals to the affected router contract. The primary victim lost approximately 17 WBTC, which was converted to WETH and DAI. Ekubo’s Starknet deployment and core liquidity providers were not affected.
Approval-based exploits weaponize the persistence of token allowances rather than the contract being drained directly. When users grant a router permission to spend their tokens, that permission remains active even after the router is compromised, turning every previously approved address into a draining vector. The attack class is well documented and is effectively only mitigated by users actively revoking approvals to deprecated or compromised contracts.
Ekubo issued user warnings to revoke approvals to the affected router shortly after the exploit was detected. For users who held WBTC and other approved assets in wallets connected to Ekubo’s EVM router, immediate revocation is the only on-chain remediation. The attacker’s conversion path through WETH and DAI on-chain provides a clear forensic trail that supports off-ramp interception requests at downstream exchanges.
Sources: The Block, Bankless, FinanceFeeds
Post-Incident Developments | Prior Weeks
Two prior-week incidents saw material in-window movement on recovery and accountability.
The Kelp DAO / LayerZero / Aave $292M exploit (April 18) accelerated through court and protocol channels. On May 5, Aave LLC filed an emergency motion in the Southern District of New York to vacate a restraining notice that had frozen approximately $71M in ETH tied to the rsETH exploit, filed by judgment creditors of the DPRK seeking attachment. On May 9, Judge Margaret Garnett modified the freeze to allow Arbitrum governance to vote on transferring the ETH to an Aave-controlled wallet while preserving the terrorism creditors’ legal claims. The same day, LayerZero publicly admitted it made a mistake in approving a 1/1 DVN configuration for high-value transactions and committed to migrating all default pathways to 5/5 verifiers (or no less than 3/3 where DVN availability is limited). Solv Protocol announced migration of over $700M in tokenized BTC infrastructure away from LayerZero in response.
Drift Protocol announced a recovery plan on May 5 for users affected by the April 1 DPRK-linked exploit that drained $295M. The plan introduces recovery tokens representing $1 of verified loss each, backed by a recovery pool starting at approximately $3.8M and projected to reach roughly $151M through exchange revenue, up to $127.5M from Tether tied to performance milestones, and up to $20M from partner contributions. A Q2 2026 protocol relaunch is planned.
Sources: CoinDesk – Aave motion, CoinDesk – Garnett ruling, CoinDesk – LayerZero admission, CoinDesk – Drift recovery plan
If your platform or users have been affected by recent exploits, immediate forensic intervention is critical to tracing and freezing assets before they reach obfuscation services.