1inch
Swap Aggregator — DEX aggregator and limit-order protocol. TVL not applicable — volume metric.
AI review
AI assessment
updated 4h ago·Claude (preview)·preview1inch is a swap aggregator protocol. 3 of 16 risk feeds in the registry report on it. 1 sourced incident on record. No material change has been detected in the current window.
- Governance: 1inch DAO (1INCH); treasury Safe 7/12 (0x7951…1c07) with a 72-hour timelock governance
- 3 of 16 feeds report on 1inch. coverage
- Most recent recorded event: Deprecated Fusion v1 resolver exploit. incident
AI-generated summary of facts already in this registry — not a Rails assessment, not a risk score, and not a ranking. Per the project charter, the registry never produces its own composite risk judgement. Verify every point against the linked sources below. This is an illustrative preview of a proposed feature; the content is not live.
Feeds
How feeds see it
Seen through 2 of 4 methodology lenses (rating, monitoring). A neutral view of who is looking and how — not a risk judgement.
Multi-dimension registry: Control, Exit, Autonomy, Open Access, Verifiability via LLM consensus.
View sourcePosition-management tooling: live loan-health / safety-ratio tracking and automated liquidation protection for leveraged positions.
View sourceAn early DeFi Safety review exists (PQR id 17); confirm it is current and read the score on the live page.
View sourceDecentralization maturity: who controls keys, upgrades, and admin powers. Stage 0–2 framework.
Protocol risk research and parameter recommendations; collateral and governance risk.
Quantitative on-chain risk dashboards for lending markets: liquidations, collateral health, exposure.
Vault-level risk monitoring for Morpho curators: allocation risk and curator behavior.
Institutional-grade credit-risk ratings for DeFi protocols and borrowers. Credora by RedStone; GraphQL API + on-chain attestations (EAS).
Independent risk rating for DeFi vaults; 300+ subscores across 85+ mechanisms. Open-source.
Deterministic vault risk scoring across 700+ vaults: asset quality, code maturity, governance. Open methodology (public API, CLI, MCP server).
Vault analytics and risk-adjusted yield across 50+ protocols; exploits, concentration, risk-adjusted APY. Paid structured API.
Real-time risk scores for DeFi liquidity pools: risk metrics, TVL, APY, security grades.
DAO governance-capture risk: delegate/voting-power concentration, cost-to-attack vs. treasury value, and proposal/power-shift monitoring across major DAOs. Open-source.
Risk ratings (A–F) decomposed into protocol, asset, chain, and pool risk across DeFi yield pools. Open whitepaper methodology. (Standalone product migrated into YO Protocol in 2026 — ratings shown are pre-migration samples.)
Agent-based economic simulation: insolvency prevention, parameter optimization, and risk-scenario analysis for lending markets.
Edge risk oracles and economic-risk dashboards: real-time parameter automation and scenario stress for lending markets (active on Aave, GMX, Pendle).
Governance
Governance at a glance
- Governance
- DAO (on-chain)
- Timelock
- 72 hours
- Core contracts
- Immutable
Structural facts, distilled from the sourced control records below — neutral capabilities, not a risk score. Multisig threshold and signer count are fetched live via the Safe API.
| Governance | |
| Upgradeability | |
| Admin control | |
| Aggregation |
Incidents
A calldata bug in an obsolete Fusion v1 settlement contract was exploited to drain ~$5M from a market-maker/resolver — not 1inch core or end-user funds. Most funds were returned after a bug-bounty negotiation.
Material risk events, presented verbatim from cited sources — not a Rails assessment.
Audits
| Auditor | Date | Scope | |
|---|---|---|---|
| OpenZeppelin | 2021-12 | Limit Order Protocol v2 | Report |
| OpenZeppelin | 2023-11 | Aggregation Protocol (Router V6) diff audit | Report |
| OpenZeppelin | 2024-05 | Limit Order + Aggregation diff audit | Report |
| Decurity | 2023 | Aggregation Router v6 + Limit Order v4 | Report |
Representative public audits, attributed and linked to source — not a Rails assessment, and not a completeness or safety guarantee.