1inch Aqua is a decentralized protocol for creating and managing custom liquidity positions with flexible strategies and advanced features.
| Target | Type | Severity |
|---|---|---|
https://github.com/1inch/aqua Copy src/*.sol src/libs/Balances.sol | Smart Contract | Critical |
https://github.com/1inch/swap-vm Copy src/*.sol src/routers/AquaSwapVMRouter.sol src/opcodes/AquaOpcodes.sol src/instructions/Balances.sol src/instructions/Controls.sol src/instructions/Decay.sol src/instructions/Extruction.sol src/instructions/Fee.sol src/instructions/PeggedSwap.sol src/instructions/XYCConcentrate.sol src/instructions/XYCSwap.sol src/libs/MakerTraits.sol src/libs/PeggedSwapMath.sol src/libs/TakerTraits.sol src/libs/VM.sol | Smart Contract | Critical |
https://github.com/1inch/solidity-utils/ Copy contracts/libraries/Calldata.sol contracts/libraries/CalldataPtr.sol contracts/libraries/Transient.sol contracts/libraries/TransientLock.sol contracts/mixins/Simulator.sol contracts/mixins/Multicall.sol | Smart Contract | Critical |
src/*.sol src/libs/Balances.sol
src/*.sol src/routers/AquaSwapVMRouter.sol src/opcodes/AquaOpcodes.sol src/instructions/Balances.sol src/instructions/Controls.sol src/instructions/Decay.sol src/instructions/Extruction.sol src/instructions/Fee.sol src/instructions/PeggedSwap.sol src/instructions/XYCConcentrate.sol src/instructions/XYCSwap.sol src/libs/MakerTraits.sol src/libs/PeggedSwapMath.sol src/libs/TakerTraits.sol src/libs/VM.sol
contracts/libraries/Calldata.sol contracts/libraries/CalldataPtr.sol contracts/libraries/Transient.sol contracts/libraries/TransientLock.sol contracts/mixins/Simulator.sol contracts/mixins/Multicall.sol
| Target | Type | Severity |
|---|---|---|
https://github.com/1inch/sdks Copy | SDK | Critical |
The following vulnerabilities are considered in-scope:
All in-scope vulnerability reports must include a Proof of Concept (PoC) that demonstrates real-world impact. Submissions without a PoC will not be considered.
Vulnerabilities identified in out-of-scope resources are generally not eligible for rewards unless they present a significant business risk, as determined at our sole discretion.
The following items are generally excluded from reward eligibility due to insufficient severity or lack of relevance to the program’s defined scope:
The following proposals are in scope for this program:
We invite contributors to submit thoughtful and constructive proposals. Each proposal should describe the rationale and expected impact, identify affected contracts or components, outline minimal tests and benchmarks, and, if relevant, note any migration considerations. A good PoC typically includes clear before/after evidence, a minimal reproducible example, and a brief implementation outline demonstrating how the change would be applied.
While we reserve the right to decline proposals, our aim is to encourage constructive discussion and contribution from the community.
The following proposals are out of scope for this program:
https://github.com/1inch/1inch-audits/tree/master
We value all valid reports that help us strengthen our security. To qualify for a monetary reward, the following eligibility conditions must be fulfilled: