1inch has released its first bi-annual bug bounty report, detailing vulnerabilities uncovered in its Aqua protocol before and around its public launch, including one high-severity flaw that could have allowed a malicious taker to redirect or steal maker funds.
The H1 2026 review, published in collaboration with HackenProof, covers 472 reports submitted by 217 security researchers between January and June.
The report highlights nine vulnerabilities that earned bounty payouts, including one high-severity issue, one medium-severity flaw and seven low-severity findings, with eight detailed publicly.
Aqua launched publicly in July as 1inch’s shared-liquidity layer, but its bug bounty had already been running during the first half of the year, giving researchers early access to review its smart contracts, SwapVM execution engine and software development kit.
High-severity flaw exposed fund-redirection risk
The most serious issue covered in the report involved a mismatch in how MakerTraits hook flags were encoded and interpreted during execution.
According to the report, researcher Z3rco demonstrated that a malicious taker could craft the hook encoding in a way that altered transaction execution and redirected maker funds during a swap. The finding included a working proof of concept showing potential fund loss and became the program’s only high-severity payout for the period.
Researchers also uncovered a medium-severity flaw in Aqua’s concentrated-liquidity logic, where an inverted scale formula could move a price range in the wrong direction after swaps and gradually create arbitrage opportunities against maker positions.
Several lower-severity findings targeted other parts of SwapVM, including Dutch auction logic that failed to decay prices correctly, a strategy-hash collision capable of triggering a global reentrancy lock and disrupting atomic routing, and a TWAP unit mismatch that could allow an entire stream to be drained in one transaction.
Other bugs involved incorrect storage offsets in decay calculations and a gas-compensation mechanism that mixed gas units with token amounts.
Bug bounty activity stretches beyond Aqua
The Aqua review forms part of a broader security program spanning six 1inch products.
Across Aqua, Smart Contract, Wallet, Web, Business and Infrastructure programs, researchers submitted 1,055 reports during the period, with 32 resulting in payouts. Aqua accounted for the largest number of reports at 472 and drew 217 participating researchers.
The report said the identified Aqua vulnerabilities have since been resolved, with fixes applied across SwapVM and related SDK components.
For DeFi protocols increasingly handling complex trading logic onchain, the findings underline how small implementation errors in pricing, execution and accounting can translate into direct financial or operational risk long before they become visible to users.




