The 1inch ecosystem comprises interconnected smart contracts that aggregate liquidity from various decentralized exchanges to execute optimal token swaps.
| Target | Type | Severity |
|---|---|---|
https://github.com/1inch/limit-order-protocol Copy Limit order protocol | Smart Contract | Critical |
https://github.com/1inch/fusion-protocol Copy Limit order settlement | Smart Contract | Critical |
https://github.com/1inch/token-plugins Copy Token-plugins | Smart Contract | Critical |
https://github.com/1inch/farming Copy Farming contracts | Smart Contract | Critical |
https://github.com/1inch/delegating Copy Delegating contracts | Smart Contract | Critical |
https://github.com/1inch/cross-chain-swap Copy | Smart Contract | Critical |
https://github.com/1inch/solana-crosschain-protocol Copy | Smart Contract | Critical |
https://github.com/1inch/solana-fusion Copy | Smart Contract | Critical |
Limit order protocol
Limit order settlement
Token-plugins
Farming contracts
Delegating contracts
The following vulnerabilities are considered in-scope:
All in-scope vulnerability reports must include a Proof of Concept (PoC) that demonstrates real-world impact. Submissions without a PoC will not be considered.
Vulnerabilities identified in out-of-scope resources are generally not eligible for rewards unless they present a significant business risk, as determined at our sole discretion.
The following items are generally excluded from reward eligibility due to insufficient severity or lack of relevance to the program’s defined scope:
https://github.com/1inch/1inch-audits/tree/master
We value all valid reports that help us strengthen our security. To qualify for a monetary reward, the following eligibility conditions must be fulfilled: