1inch Aqua security: 8 independent audits, all public

1inch Aqua security: 8 independent audits, all public

1inch Aqua was built around self-custody, so its security depends heavily on the smart contracts that make shared liquidity possible. These contracts have been heavily audited by top crypto security firms.

How do you secure a liquidity layer that never takes custody of users' funds? 

In 1inch Aqua, LP’s tokens remain in the wallet and move only when a swap executes. That makes the integrity of the underlying contracts critical.

So Aqua and its underlying SwapVM engine went through multiple independent audits before launch. Eight leading external security teams reviewed different parts of the system, giving the code several rounds of scrutiny and making the findings available for anyone to inspect. 

All the reports are publicly available - you'll find them linked below

What was the security process for 1inch Aqua?

  • Internal review by the 1inch security team
  • AI-assisted pre-audit with SavantChat (link to existing blog post or Link the SavantChat pre-audit blog post)
  • Eight independent audit firms on the contracts - the same core scope, each going deep on a different layer
  • A separate application-level audit of the frontend and backend
  • An ongoing bug bounty program

Across the eight reports, auditors raised roughly 190 findings. Every critical finding was fixed before launch; the rest were fixed or explicitly acknowledged with documented reasoning, and re-tested on updated code.

Who audited 1inch Aqua?

Each team reviewed the same core codebase - the Aqua contracts, the SwapVM engine and the supporting libraries - and each went deep on a different layer of it. These are links to their reports:

What do audits mean - and what don't they?

An audit is not a guarantee. It is an independent, expert attempt to break the system before anyone else can. Findings raised during these reviews were resolved or explicitly accepted with documented reasoning, and every report is public, so anyone can check that work.

On top of the contract reviews, Aqua swaps are filled by resolvers, independent counterparties that complete an onboarding and verification process, with access conditions enforced on-chain at swap time.

Security doesn't stop at launch

Audits are part of an ongoing process: new versions go through the same review cycle, the bug bounty program stays open, and a dedicated incident response process is in place. 1inch has also adopted the SEAL Whitehat Safe Harbor Agreement through 1inch DAO governance (1IP-104), enabling qualified whitehats to intervene during active exploits.

Read all eight audit reports and explore 1inch Aqua

Disclaimer: This content is provided for informational purposes only. Nothing in this material constitutes financial, investment, legal, or tax advice, or a recommendation to enter into any transaction. Interacting with Aqua involves risk, including the possible loss of all funds involved.