1inch Launches Biannual Bug Bounty Transparency Reports With HackenProof
Key Takeaways
- •1inch Network has introduced a biannual bug bounty reporting series in partnership with HackenProof, with the first edition covering the Aqua program and first-half 2026 bounty activity.
- •1inch's six primary HackenProof bug bounty programs received 1,055 submissions in the first half of 2026, resulting in 32 validated payouts, a validation rate of roughly 3 percent.
- •The Aqua program drew the highest engagement of the six programs, with 472 reports from 217 researchers and nine vulnerabilities qualifying for rewards, including one high-severity issue.
- •All vulnerabilities identified through the Aqua bug bounty program, spanning logic inconsistencies, unit mismatches, execution edge cases, and tooling problems, have been remediated.
- •Aqua, 1inch's shared liquidity layer, surpassed $100 million in transaction volume within weeks of its public launch.

1inch Network has introduced a biannual bug bounty reporting series developed in partnership with HackenProof, a platform that connects crypto projects with white-hat security researchers, with the inaugural edition examining the Aqua program and bounty activity across the first half of 2026.
The rise of institutional-grade decentralized finance marks a significant expansion for the industry, as traditional financial institutions increasingly participate in the digital asset market. Establishing trust, however, continues to present a substantial challenge, and security incidents have drained billions of dollars from the crypto sector in recent years. In response, 1inch has pursued a range of transparency and security measures, including a recently updated second edition of its Risk Management Whitepaper, ISO and SOC 2 certifications, and the newly introduced biannual bug bounty report series.
Each installment of the series will examine a specific program or operational domain, giving the community broader context about operational mechanisms and potential vulnerability areas. The publications will also include supplementary technical details designed to help security researchers optimize their contributions to the ecosystem. While smart contract audits are routinely published across DeFi, itemized disclosure of bounty submissions and payout statistics remains comparatively uncommon; under the biannual schedule, a second edition covering the second half of 2026 is set to follow.
First-Half 2026 Bug Bounty Activity
During the first half of 2026, 1inch's six primary HackenProof bug bounty programs collectively received 1,055 submissions from security researchers, resulting in 32 validated payouts distributed across various severity classifications. That equates to a validation rate of roughly 3 percent, in line with crowdsourced security programs generally, where many reports turn out to be duplicates, out of scope, or below severity thresholds.
The 1inch Smart Contract program generated 267 reports from 122 researchers, yielding three paid findings. The 1inch Wallet program produced 85 reports from 67 researchers, with six resulting in compensation. The 1inch Web initiative received 68 reports from 45 researchers, leading to one paid report. The 1inch Business program accounted for 111 reports from 89 researchers, with nine validated payouts, while the 1inch Infrastructure program drew 52 reports from 45 researchers, producing four paid findings.
The Aqua program attracted the highest engagement of the six, with 472 reports submitted by 217 researchers, nine of which received rewards.
Aqua Program: Security Architecture for Shared Liquidity
The initial report provides a comprehensive analysis of Aqua, 1inch's recently introduced shared liquidity layer, which the company describes as the first of its kind. Since its public launch, Aqua has demonstrated rapid adoption, exceeding $100 million in transaction volume within weeks. The platform's security foundation was established through extensive pre-launch scrutiny, with its HackenProof bug bounty program attracting substantial researcher attention and contributing to product security from inception.
The Aqua Bug Bounty program recorded significant community participation, with 472 submissions from 217 researchers addressing vulnerabilities across multiple severity levels. Nine vulnerabilities qualified for rewards during this reporting period, encompassing one high-severity issue alongside several medium- and low-severity findings. The identified issues included logic inconsistencies, unit mismatches, execution edge cases, and tooling-related problems. All reported vulnerabilities have since been remediated, enhancing protocol stability and security.
"Institutional-grade DeFi requires proactively adopting standards that go past what is prescribed," Sergej Kunz, co-founder of 1inch, said in a written statement. "The industry needs to go beyond the minimum to ensure products are secure and reliable. With Aqua, as with all our products, we put multiple layers of checks and testing in place from the start, and bug bounties are a key part of that approach," he added.
"Aqua's approach to security highlights the value of making security an ongoing part of product development," said Alex Horlan, CTO of HackenProof, in a written statement. "Its bug bounty program provides continuous visibility into potential security risks as the product evolves, helping the team strengthen the protocol and reduce the likelihood of costly security incidents," he added.