Status DataClose notification

1inch Bug Bounty Report: Aqua Edition, H1 2026

Alex Horlan
Alex Horlan
СТО HackenProof

DeFi protocols move billions daily. Every on-chain swap depends on blockchain security that leaves no room for error. Focused on 1inch Aqua, this H1 2026 Bug Bounty Report provides a comprehensive breakdown of what 217 security researchers uncovered across smart contracts, SwapVM, and the SDK.

Although Aqua launched publicly in July 2026, its bug bounty program had already been active during H1, giving researchers early access to review the protocol. Pricing and swap logic run on SwapVM, a programmable on-chain execution engine. Tokens stay in the maker’s wallet. Strategies are opcode programs that SwapVM runs during quote and swap.

SwapVM can encode Dutch auctions that decay price over time, concentrated-liquidity curves, dynamic fee models and other instruction programs. This level of programmability makes security review crucial.

That's why 1inch runs a public bug bounty program on Aqua.

Not because we assume errors, but because the best way to harden a protocol this complex is to invite the world's sharpest eyes to look for what you missed.


H1 2026: The Numbers

Between January and June 2026, 217 security researchers submitted 472 reports in response to the Aqua bug bounty. That's a remarkable level of engagement for a young program - a testament both to the protocol's technical depth and to the community's appetite for serious smart contract research.

Of those reports, 9 were paid and formally resolved. Eight paid findings are detailed in this report.


H1 2026 Bug Bounty Report: What Researchers Found

Finding 1 — Inverted Scale Formula in Concentrated Liquidity

Researcher: nathan47 | Severity: 🟡 Medium

A sign error can be a goldmine for attackers.

Deep inside Aqua's concentrated liquidity engine, nathan47 found exactly that: the scale update formula was inverted. Instead of tightening the price range after a swap, the formula moved it in the opposite direction, steadily breaking the AMM's core invariant with every trade. Over time, the drift created a systematic arbitrage window against maker positions. The bug was hiding in plain sight behind correct-looking code.

🔧 Fix: swap-vm PR #82 «[PT1-396] fixed concentrate» (XYCConcentrate rewritten in stateless-model); additional changes — #105, #113, #114

________________________________________________________________________________________________________________________________________________

Findings 2 & 3 — Dutch Auction Decay Bug: uint32 Truncation and Non-Functional Balance Instructions

Researchers: Bz & Xmanuel | Severity: 🔵 Low (×2)

Dutch auctions are elegant: the price starts high and decays over time until a taker fills the order. It's a classic mechanism for efficient price discovery. But it just... didn't work.

Xmanuel discovered that decayFactor was declared as a uint32 - but the calculation expected a 1e18-scaled fixed-point number. The truncation was silent and total. Every decay curve became a flat line.

Bz went deeper and found that both balance instructions for Dutch auctions - _dutchAuctionBalanceIn1D and _dutchAuctionBalanceOut1D - were non-functional. Makers who thought they were posting time-weighted price discovery orders were actually posting static limit orders, exposed to adverse selection for the order's entire lifetime.

Two separate researchers. Two separate angles. One broken feature - fully exposed.

🔧 Fix commit: https://github.com/1inch/swap-vm/pull/25/changes

________________________________________________________________________________________________________________________________________________

Finding 4 — Strategy Hash Collision Triggering Global Reentrancy Lock

Researcher: mayoo0x0 | Severity: 🔵 Low

Reentrancy locks exist to prevent one of DeFi's oldest attack vectors. But what happens when two completely different makers end up with the same strategy hash?

mayoo0x0 traced a scenario where a hash collision between distinct makers' strategies would trigger the global reentrancy lock — effectively blocking atomic routing for Aqua Apps entirely. No funds stolen directly. Just a hard stop, mid-execution. In a system where atomicity is the guarantee, a DoS like this could be a serious reliability failure.

🔧 Awareness commit: 13434dc (25 Feb) / PR #85 «added doc about orderHash collisions»

________________________________________________________________________________________________________________________________________________

Finding 5 — MakerTraits Hook Flag Mismatch Enabling Fund Redirection

Researcher: Z3rco | Severity: 🟠 High

Z3rco identified a mismatch in how MakerTraits hook flags are encoded versus how they're interpreted during execution. By carefully crafting the hook encoding, a malicious taker could manipulate transaction execution - redirecting or outright stealing maker funds during an otherwise normal-looking swap. With a working proof of concept demonstrating real fund loss, this earned the program's only High-severity payout of H1.

It's a reminder that in a programmable swap engine, the boundary between "configuration" and "code" is thin - and every serialization boundary is a potential attack surface.

🔧 Fix commit: https://github.com/1inch/sdks/pull/32

________________________________________________________________________________________________________________________________________________

Finding 6 — TWAP Unit Mismatch Allowing Full Stream Drain

Researcher: dantehrani | Severity: 🔵 Low

TWAP orders exist to pace liquidity over time - to sell gradually rather than all at once. The mechanism relies on a cap: you can't drain more than your allotted share in a given window.

dantehrani found that the cap was comparing amountIn against available amountOut. Two different units, two different tokens, being compared directly. The result: a determined taker could drain the entire TWAP stream in a single transaction, bypassing the rate-limiting entirely.

🔧 Fix commit: https://github.com/1inch/swap-vm/pull/105

Note: The issue was technically out of scope, but the researcher still received a bounty.

________________________________________________________________________________________________________________________________________________

Findings 7 & 8 — Storage Slot Offset Bug and Gas Unit Mismatch in Fee Machinery

Researcher: Jugger63 | Severity: 🔵 Low (x2)

Jugger63 closed out the paid findings with a sharp pair of low-level catches in Aqua's fee and decay machinery.

First: the Decay._decayXD function had an offset direction bug. Decay state was being written to one storage slot and read from a completely different one. Every decay calculation was operating on stale or zero data, silently corrupting strategy behavior over time - the kind of bug that's nearly invisible in unit tests but damaging in production.

Second: the gas compensation calculation in BaseFeeAdjuster's ExactIn path was mixing incompatible units - gas units against token amounts. The adjustment was orders of magnitude off, making the entire gas compensation mechanism effectively dead code.

🔧 Fix commit: https://github.com/1inch/swap-vm/pull/70


Acknowledged Contributions

Not every valid finding comes with a bounty, but we are thankful for every researcher who made a contribution. These are the names on the board. Behind them are 217 researchers who took the time to read the code, understand the protocol, and try to find what could go wrong. Every report - even the ones marked Out of Scope or Duplicate - is an extra pair of eyes supporting the 1inch team.

HackenProof and 1inch Aqua H1 2026 bug bounty report overview showing 472 reports received, 217 unique researchers, and 9 paid reports: 1 High, 1 Medium, and 7 Low. The graphic also lists eight top researchers and their paid reports and best severity.

1inch Smart Contract

  • Total reports received: 267
  • Unique participating researchers: 122
  • Paid reports: 3 paid

1inch Wallet

  • Total reports received: 85
  • Unique participating researchers: 67
  • Paid reports: 6 paid

1inch Web

  • Total reports received: 68
  • Unique participating researchers: 45
  • Paid reports: 1 paid

1inch Business

  • Total reports received: 111
  • Unique participating researchers: 89
  • Paid reports: 9 paid

1inch Infrastructure

  • Total reports received: 52
  • Unique participating researchers: 45
  • Paid reports: 4 paid

Start Hunting on 1inch Aqua Bug Bounty Program

Aqua is the shared liquidity layer. SwapVM, the programmable engine it runs on, is exactly the kind of code that rewards deep review: a custom VM running concentrated liquidity and Dutch auctions in production.

Audited by OpenZeppelin, Hexens and Decurity; the bounty covers what audits might miss.

Critical vulnerabilities pay up to $100,000. The code is public. The scope is clear.

Program link: 1inch Aqua

Security doesn't happen by accident. It happens because people like you show up.


Frequently Asked Questions

What bug bounty programs does 1inch run on HackenProof?

1inch runs six bug bounty programs on HackenProof: Aqua, Smart Contract, Wallet, Web, Business and Infrastructure.

How many findings received payouts in the 1inch Aqua bug bounty program during H1 2026?

9 reports were paid out across 1 High, 1 Medium, and 7 Low severity findings.Eight of these findings are publicly detailed in this report. 472 total reports were submitted by 217 unique researchers between January and June 2026.

Can I participate in the 1inch Aqua bug bounty program?

Yes. The program is open on HackenProof. The scope, reward structure, and submission guidelines are publicly available at hackenproof.com/programs/1inch-aqua.

Share article:
More topics:

Read more on HackenProof Blog