1inch releases a biannual bug bounty report via HackenProof

In the first half of this year, over a thousand reports were submitted across six bug bounty programs, helping us to uncover vulnerabilities.
What does it take to build trust in institutional-grade DeFi? Transparency is a big part of the answer.
As traditional finance moves further on-chain, security and trust remain critical barriers to adoption. We have been working to address that challenge through initiatives including the second edition of its Risk Management Whitepaper, ISO 27001 certification and SOC 2 (Type 1) attestation.
Now, we are taking another step with the launch of a biannual bug bounty report, created in collaboration with HackenProof. The first report, released today, focuses on the 1inch Aqua bug bounty program and activity in H1 2026.
“Institutional-grade DeFi requires proactively adopting standards that go past what is prescribed,” comments Sergej Kunz, co-founder of 1inch. “The industry needs to go beyond the minimum to ensure products are secure and reliable. With Aqua, as with all our products, we put multiple layers of checks and testing in place from the start, and bug bounties are a key part of that approach.”
“Aqua’s approach to security highlights the value of making security an ongoing part of product development. Its bug bounty program provides continuous visibility into potential security risks as the product evolves, helping the team strengthen the protocol and reduce the likelihood of costly security incidents,” said Alex Horlan, CTO of HackenProof.
1inch bug bounty programs H1 2026
Across 1inch’s six core HackenProof bug bounty programs, 1,055 reports were submitted by security researchers in the January to June period. Of those reports, 32 resulted in payouts across different severity levels.
1inch Smart Contract: 267 reports from 122 security researchers - 3 paid reports
1inch Wallet: 85 reports from 67 security researchers - 6 paid reports
1inch Web: 68 reports from 45 security researchers - 1 paid report
1inch Business: 111 reports from 89 security researchers - 9 paid reports
1inch Infrastructure: 52 reports from 45 security researchers - 4 paid reports
1inch Aqua: 472 reports from 217 security researchers - 9 paid reports
Focus on 1inch Aqua
A separate in-depth report is focused on 1inch Aqua, our recently launched first-of-its-kind shared liquidity layer. Aqua has grown rapidly since being made public, surpassing $100 million in volume within a matter of weeks. However, its success and security weren’t built overnight. Its HackenProof bug bounty program saw a huge amount of interest and contributed greatly to the product's security from day one.
The Aqua bug bounty program saw high engagement from the security community, with 472 submissions received from 217 researchers, covering a range of vulnerabilities at different levels of severity.
A total of 9 vulnerabilities have been rewarded, including one high-severity vulnerability, as well as a number of medium and low-severity vulnerabilities. These included logic inconsistencies, unit mismatches, execution edge cases and tooling-related issues. As with all the vulnerabilities, these have now been resolved, adding to the stability and security of the protocol.
For more 1inch news and updates subscribe to our newsletter
Disclaimer: This content is for general information purposes only and does not constitute financial, investment, tax, or legal advice and is not a recommendation to buy or sell any particular digital asset or to employ any specific investment strategy.
