Moderate risk — battle-tested aggregator with 15+ audits, but third-party routing and recent infrastructure incidents keep it from a higher grade
Risk Breakdown
Top Risks
March 2025 buffer overflow in deprecated Fusion v1 allowed $5M drain; October 2024 supply chain attack on Lottie Player library compromised frontend ($768K). Two separate incidents within 6 months indicate infrastructure security gaps.
DEX aggregation routes through third-party protocols whose security is outside 1inch's control, inheriting risks from every liquidity source in the routing path.
Fusion+ cross-chain intent execution depends on relayer availability; during volatile markets resolvers may abandon in-flight swaps, causing failed transactions.
Frequently Asked Questions
Is 1inch safe to use?
What are the main risks of using 1inch?
What is 1inch's risk score breakdown?
How does 1inch compare to other DEX protocols?
Has 1inch ever been hacked or exploited?
Incident History
Get risk alerts before it's too late
Weekly grade changes, downgrade alerts, and new protocol risk findings. Free.