Swap on Monad, one of the fastest EVM chains, move assets cross-chain without a bridge, provide liquidity through Aqua and access Monad through every 1inch API.
Fast chains need fast, efficient trading infrastructure. That is why 1inch has integrated Monad, a high-performance EVM chain built around 300ms blocks, 600ms finality and fees at fractions of a cent.
What is Monad?Monad combines full EVM compatibility with a design built for high throughput. The network targets up to 10,000 transactions per second, with transactions confirming in under a second. And it already has significant DeFi activity.
As of early September, Monad held around $956 mln in TVL, while daily DEX volume ranged from roughly $200 mln to $340 mln, according to DefiLlama. Daily active addresses stood at around 22,000-27,000.
Aggregation, however, still represents only a small part of that activity. Aggregators routed around $4.6 mln-$11 mln per day, or roughly 2%-3% of total DEX volume. Some activity may be boosted by bots and incentives, but the network has already developed a sizable trading ecosystem.
Now, 1inch brings its routing and execution infrastructure to that market.
With Monad support, you can swap assets on the network directly through the 1inch dApp or 1inch Wallet.
Intent-based swaps let you specify the outcome you want while competing resolvers fill the order. For users, that means no gas fees and built-in MEV protection.
Monad already supports a broad range of assets, including:
MON and wrapped MON (WMON)Stablecoins including USDC, USDT0, AUSD, USDe and GHOMajor assets including WETH, WBTC, cbBTC and wstETHMonad ecosystem assets such as aprMON, sMON, gMON, APR and CHOGNative USDC, available through Circle CCTP, also provides a familiar stablecoin route for capital moving into and around the ecosystem.
Move assets to Monad without a bridgeGetting onto a new chain traditionally means finding a bridge, moving assets across and then opening another interface to make the trade you actually wanted.
1inch cross-chain swaps remove those extra steps.
You can swap an asset on another supported network directly for an asset on Monad in one cross-chain transaction. There is no need to interact with a traditional bridge, and the process remains self-custodial end to end.
That makes Monad accessible not only to traders already active there, but also to existing 1inch users looking to move liquidity onto the network.
One more chain, one connected DeFi experienceMonad is built around speed. 1inch makes that speed accessible across a broader DeFi environment.
Whether you are trading directly on Monad, moving assets there from another chain, providing liquidity through Aqua or adding Monad to an application through 1inch APIs, the network is now part of the same 1inch experience.
Explore Monad on 1inch.
Disclaimer: This content is provided for informational purposes only. Nothing in this material constitutes financial, investment, legal or tax advice, or a recommendation to enter into any transaction. Providing liquidity involves risk, including the possible loss of all funds involved. Fees are not guaranteed.
More than $500 mln in swap volume has now gone through 1inch Aqua. Every fill came directly from liquidity providers’ wallets: their tokens stayed in their wallets until the moment a swap actually filled.
What does $500 mln in swap volume look like when the liquidity was never deposited into a pool?
That is now more than a theoretical question. In early September, 1inch Aqua passed $500 mln in cumulative swap volume, according to Dune, marking a new milestone for its shared liquidity model. As of publication date, the cumulative swap volume stood at just over $520 mln.
The important part is not just the number. It is how those swaps happened.
Across that entire $500 mln, LPs did not first transfer their tokens into an Aqua pool or vault. Their assets remained in their wallets until individual swaps filled. Only then did the relevant tokens move as part of the transaction.
From launch to $500 mln1inch Aqua officially launched on July 28, 2026, following a developer release in November 2025. It was built around a different approach to DeFi liquidity: instead of requiring capital to be deposited into isolated pools, Aqua lets the same wallet balance support multiple liquidity positions.
Adoption started quickly. Soon after its public launch, Aqua passed $100 mln in swap volume. Now cumulative volume has crossed $500 mln, with roughly 4,500 open positions held by just under 600 LPs.
That growth provides an increasingly substantial real-world test of Aqua’s core idea: liquidity can remain self-custodial and still be available for swaps.
$500 mln without depositing liquidityTraditional AMMs normally require an LP to transfer tokens into a smart-contract pool before traders can use them.
Aqua removes that deposit-and-withdraw cycle. When an LP creates an Aqua position, the tokens stay in the LP’s wallet. Aqua receives permission to access the relevant balance under the position’s conditions, but the assets are not transferred in advance. They move only when a swap fills.
So the $500 mln milestone represents more than $500 mln in swaps routed through Aqua. It represents $500 mln in swap volume filled against liquidity that remained in LP wallets right up until the swap filled.
For every individual fill, the liquidity was there when it was needed - but it did not have to sit inside a pool waiting to be used.
The same balance can do moreKeeping liquidity in the wallet also enables Aqua’s second defining feature: shared liquidity.
With a conventional pool model, capital allocated to one position generally cannot simultaneously back another. An LP who wants exposure to several strategies has to divide the available assets among them.
Aqua positions can instead reference the same approved wallet balance. One balance can therefore support multiple positions without being split into separate deposits.
The actual wallet balance remains the limit. Aqua does not multiply the LP’s assets or create leverage simply because several positions can reference them.
This makes the liquidity more flexible. Capital that is not being used by one position can still be available to another.
Liquidity moves only when the swap doesAqua’s architecture changes a basic assumption behind liquidity provision.
Liquidity does not need to be moved somewhere first in order to become available for trading.
Instead, the position defines when and how the LP is willing to trade. The assets remain in the wallet until those conditions are met. When a swap fills, the relevant tokens move as part of the atomic transaction.
More than $500 mln in swap volume has now passed through that model.
And through every dollar of it, the same principle held: liquidity stayed with the LP until there was an actual swap to fill.
Explore 1inch Aqua and discover shared, self-custodial liquidity.
Disclaimer: This content is provided for informational purposes only. Nothing in this material constitutes financial, investment, legal or tax advice, or a recommendation to enter into any transaction. Interacting with Aqua involves risk, including the possible loss of all funds involved. Fees are not guaranteed.
Major blockchains are processing more activity while transactions get cheaper. For developers, the combination could open the door to a new generation of applications built around frequent, low-cost onchain interactions.
Blockchains are getting busier just as using them gets cheaper. For developers, that combination could matter more than token prices.
In Q2 2026, the Ethereum L1 processed 203.9 mln transactions, up 68% from 121.1 mln a year earlier, while the average transaction cost fell from $1.08 to $0.31. Solana handled 9.8 bln non-vote transactions, up from 8.9 bln, as average costs dropped from $0.03 to just $0.005. Avalanche went further still, processing roughly four times as many transactions as a year earlier, according to Bitwise’s Q3 2026 Staking Report.
This signal is hard to ignore. More activity shows that people are using blockchain infrastructure, while lower costs make entirely new types of high-volume applications practical to build.
“This growth in onchain activity is a real indicator that blockchain technology is relevant and valuable despite market conditions,” says Tanner Moore, Developer Relations Engineer at 1inch. “Builders working on these networks today will be well-positioned when the markets recover.”
More activity, lower costsHistorically, rising blockchain usage often came with a painful trade-off: congestion.
More transactions meant more competition for limited blockspace, pushing fees higher. Applications that required frequent transactions could quickly become too expensive to use.
Blockchain infrastructure has been moving in the opposite direction. Networks have been expanding capacity so that more activity does not necessarily mean higher costs.
Ethereum is a good example. Bitwise found that its mainnet throughput rose from about 15 transactions per second in Q2 2025 to 26 a year later after increases to the block gas limit. Ethereum’s broader scaling roadmap has also pushed activity toward rollups and made data availability cheaper. Ethereum.org estimates that current rollups can already be around 5-20 times cheaper than Ethereum Layer 1, with further scaling improvements planned.
Bitwise describes lower network revenue alongside higher activity as one of the main themes of the quarter. The report argues that the decline in fees largely reflects protocol design: networks are deliberately making blockspace cheaper and more abundant rather than simply seeing demand disappear.
That distinction matters for developers. Lower fees combined with growing activity mean blockchains can support applications that would have struggled economically only a few years ago.
Builders can look beyond token pricesCrypto development has always moved alongside market cycles. Rising prices attract capital and attention. Falling prices can create the impression that the underlying technology is also losing relevance.
Network activity tells a different story. For Tanner, growing usage during a weaker market is a particularly useful signal for builders. People continue to transact even when speculation around token prices is less favorable.
The opportunity for developers is therefore not necessarily to wait for the next market cycle. It is to build while the infrastructure is becoming capable of supporting more demanding products.
“If you look back at almost all of the breakout applications on Ethereum, you will find the founders were working hard on their ideas during bear markets and they were focused on making applications that solved user needs. Investor sentiment is still important, but being positioned correctly before the next market upswing is where the hockey stick growth usually happens,” Tanner says.
The economics of an application can change significantly when the cost of each interaction falls. Features that once needed to minimize onchain transactions can become viable with much higher transaction frequency.
High-volume apps become more viableThe clearest example is perpetual futures.
Perps require a very different kind of blockchain infrastructure from an application where a user makes one transaction occasionally. Trading applications can involve frequent orders, position changes, liquidations and other interactions. Low transaction costs and high throughput are therefore central to making the experience practical.
Perp DEX growth shows what becomes possible as infrastructure improves. CoinGecko found that decentralized perpetual exchange volume grew 346% in 2025 to $6.7 trn. In the first four months of 2026, the top 12 perp DEXs averaged $611.57 bln in monthly trading volume, up from an average of $531.65 bln in 2025.
“Apps that rely on very high transaction volume are cheaper and more viable than ever,” Tanner says. “The popularity of perps is an obvious example.”
The same principle can extend beyond trading. Games, payments, social applications, automated agents and other products can all require large numbers of small onchain actions. When every action is expensive, developers have to design around the blockchain’s limitations. When blockspace becomes abundant and inexpensive, they have more room to design around what users actually need.
A lower cost per transaction therefore does more than make existing applications cheaper. It expands the range of applications developers can realistically build.
Cheaper blockspace changes what you can buildDevelopers once had to assume that every onchain interaction was scarce and potentially expensive. That assumption is becoming less reliable.
Ethereum’s recent upgrades have increased capacity and reduced costs, while Solana continues to operate around a fee model designed for high-throughput applications. Other networks are pursuing similar goals.
The change does not mean scalability problems are solved. Networks still have different trade-offs, congestion can return during demand spikes and applications still need to optimize execution carefully. Financial applications also remain subject to applicable regulatory requirements, whatever the infrastructure costs.
But the direction matters. More activity alongside cheaper transactions suggests that blockchain infrastructure is moving toward a point where developers can build products around frequent onchain interactions rather than treating every transaction as an expensive event.
For Tanner, that makes the current environment an opportunity.
The applications that benefit most from cheaper blockspace may not simply be cheaper versions of today’s DeFi products. They could be products that previously did not make economic sense to build onchain at all.
And the developers experimenting with those models now may be the ones best positioned when the next wave of users arrives.
For 1inch news and updates subscribe to our newsletter
Disclaimer: This content is for general information purposes only and does not constitute financial, investment, tax, or legal advice and is not a recommendation to buy or sell any particular digital asset or to employ any specific investment strategy.
Ethereum gas fees can make or break a trade. This guide explains what they are, why they change and how to reduce gas costs.
Want to swap tokens, mint an NFT or interact with a DeFi protocol on Ethereum? Before your transaction can go through, you need to pay a gas fee. Understanding how gas works can help you choose the right time to transact and avoid paying more than necessary.
Ethereum transactions are usually priced across different speed tiers, often shown as Slow, Standard and Fast.
Slow targets cheaper inclusion when timing is not urgent. Standard aims for normal confirmation speed. Fast increases the priority fee when faster inclusion matters.
A practical model:
Slow: target inclusion in around 12 blocks
Standard: target inclusion in around 3 blocks
Fast: target inclusion in around 1 block
Gwei is the unit used to price gas. One gwei equals 0.000000001 ETH.
The USD cost of a transaction depends on the current gas price, ETH price and estimated gas used by the selected transaction type. Fast gas is worth paying when execution risk is higher than the gas cost. A liquidation, volatile token swap or time-sensitive mint may justify a higher fee. Waiting makes sense when the transaction is not urgent. Portfolio rebalancing, approvals and routine transfers can often wait for a cheaper hour.
What makes ETH gas fees moveEthereum gas changes because blockspace has limited capacity. Traders, bots, apps and protocols compete for the same space. Four factors matter most.
Base fee: The base fee is the minimum cost required for inclusion. Ethereum adjusts the base fee based on how full previous blocks were.
Priority fee: The priority fee is the tip paid to encourage faster inclusion. A higher priority fee can help during congestion.
Gas used: Different transactions consume different amounts of gas. A simple ETH transfer is lighter than a token swap or NFT mint.
Mempool congestion: Gas rises when many users and bots want inclusion at the same time. NFT mints, liquidations, token launches and volatile market moves can create sudden spikes.
Inline math matters more than theory.
At ETH = $[X], a transaction using 150,000 gas at 30 gwei costs around $[Y].
That estimate changes when ETH price, gas price or gas used changes.
A high gas quote does not always mean Ethereum is broken. A high quote usually means the market is bidding aggressively for blockspace right now.
When are ETH gas fees cheapest?The best time to transact is usually when fewer traders compete for blockspace. Cheaper gas periods often appear during quieter parts of the week, but patterns can change quickly. Typical lower-cost windows are:
late-night UTC hoursweekend periodsperiods outside major US and European trading sessionsSaturday and Sunday often show lower average gas than weekday market hours. The pattern can break during major launches, market crashes or popular mint events. Watch for high-gas triggers:
US market openMajor token launchesNFT mint windowsLiquidation cascadesVolatile ETH price movesA timing playbook:
send urgent trades when execution matters more than gas.wait for a quieter period for non-urgent swaps.set wallet alerts for a target gwei level.use 1inch intent-based swaps when you want gasless execution and do not want to manage timing manually. 1inch intent-based swaps are designed for traders who want execution without managing the gas bid directly. You sign an order. Resolvers compete to execute it. The resolver pays the gas.5 ways to actually pay less gas1. Time your transactionThe easiest gas saving is patience. Check the current gwei level. Compare it with recent network conditions. If the transaction is not urgent, waiting can make a real difference.Timing matters most for non-urgent actions:
Token approvalsWallet cleanupPortfolio rebalancingNFT transfersRoutine swapsA price alert can help. Set a target such as “send when gas falls below [X] gwei.”
2. Use a Layer 2 networkLayer 2 networks can be much cheaper than Ethereum mainnet.
Popular options include:
ArbitrumBaseOptimismLayer 2s are often useful for frequent traders, smaller swaps and active DeFi use.
The trade-off is simple. You may need to bridge funds first. Some withdrawals can take longer or require additional steps.
Layer 2 gas is not the same as mainnet gas. The transaction cost depends on the L2 fee model and the cost of posting data back to Ethereum.
3. Bundle approvals and swaps where possibleTwo transactions usually cost more than one. A token approval plus a swap creates extra gas overhead. A workflow that reduces repeated approvals can lower total cost over time.
Permit-style approvals can help when supported. Permit2 can also reduce friction across supported apps and tokens.
The practical rule is simple. Avoid unnecessary approvals. Avoid approving the same token repeatedly when a safer reusable approval flow is available.
4. Use a DEX aggregator with gas-efficient routingThe cheapest route is not always the route with the lowest token price. A good route must account for gas.
1inch evaluates routes based on net output. A route that gives a slightly better token price but costs much more gas may not be the best outcome.
This matters most when:
Liquidity is fragmentedThe trade size is meaningfulSeveral pools offer similar pricesMulti-hop routing may improve executionGas is elevatedA DEX aggregator helps compare execution across liquidity sources. A gas-aware aggregator helps avoid routes where extra complexity destroys the benefit.
Check the 1inch dApp to explore gas-efficient swaps and routing.
5. Use intent-based executionIntent-based execution changes the gas equation.
A regular swap requires you to submit a transaction and pay network gas.
With 1inch intent-based swaps, you sign an intent. Professional resolvers compete to fill the order. The resolver pays gas.
Intent-based swaps are useful when you want to avoid manual gas timing, reduce front-running exposure and simplify execution.
Intent-based execution does not remove all market risk. Price movement, liquidity and execution conditions still matter.
Intent-based execution does remove the need for you to pay gas directly for the swap.
How to think before sending a transactionUse gas as part of your decision flow. First, check current network conditions. If standard gas is close to the recent low range, sending now may be reasonable.
If fast gas is much higher than standard gas, the network may be congested. Waiting can help unless the trade is urgent.
Next, consider your transaction type. A simple ETH transfer uses less gas than a swap. A contract interaction can be much heavier than both.
Then compare the gas cost against the value of the transaction. A $12 fee may be acceptable for a $20,000 swap. The same $12 fee may be too high for a $100 transfer.
Finally, compare regular execution with intent-based swaps. If a regular DEX swap carries a meaningful gas cost, 1inch intent-based swaps can be a cleaner execution path.
ETH gas fees FAQHow much is an ETH gas fee right now?The current fee depends on the selected speed tier, ETH price and transaction type. Wallets and network explorers usually show current gas estimates before you confirm a transaction.
How do I avoid ETH gas fees?You cannot avoid network fees when sending a normal Ethereum mainnet transaction.
You can reduce the impact by timing transactions, using Layer 2 networks, avoiding unnecessary approvals or using 1inch intent-based swaps for gasless swaps.
What time of day is ETH gas cheapest?Cheaper gas often appears during quieter UTC hours and weekends. The exact window changes depending on network demand, market volatility and major on-chain events.
Does the gas fee depend on how much ETH I send?A simple ETH transfer usually costs the same amount of gas whether you send 0.1 ETH or 10 ETH. The dollar value of the gas changes with gas price and ETH price, not the transfer amount. Swaps are different. Larger swaps can trigger more complex routing or higher price impact.
Are L2 gas fees the same as mainnet?No. Layer 2 networks have their own fee models. L2 transactions are usually cheaper, but costs still depend on network demand and Ethereum data availability costs.
Will ETH gas fees go down?Ethereum upgrades can reduce some fee pressure, especially for Layer 2 activity. Proto-danksharding helped lower data costs for rollups. Mainnet gas can still spike when demand for blockspace is high.
Stop paying for gasGas timing should not decide whether your trade works. For non-urgent transactions, waiting for quieter network conditions can help. For swaps, 1inch intent-based swaps give you another option: sign the trade and let resolvers pay gas.
Stop paying for gas. Use 1inch intent-based swaps.
1inch runs several bug bounty programs that reward researchers for finding vulnerabilities and helping make 1inch products more secure.
Are you a whitehat hacker or crypto enthusiast keen on dissecting smart contracts? We at 1inch value support in discovering vulnerabilities and other issues across our products. Audit our smart contracts, find bugs and earn rewards for eligible reports.
These are the bug bounty programs we’re currently running - the same programs are mirrored on HackenProof and Immunefi, though platform requirements differ. Choose the platform you prefer. The process is simple. You discover a bug, submit it on one of the two platforms and, if it’s approved, you get rewarded there.
1inch Business
This bug bounty program is focused on 1inch Business, a platform for enterprise-grade DeFi APIs. The program offers rewards of up to $100,000.
Details: Hackenproof Immunefi
1inch Aqua
1inch Aqua is a self-custodial shared liquidity layer. It enables your liquidity to stay active across many positions, while your tokens stay in your wallet. This bug bounty program offers rewards of up to $100,000.
Details: Hackenproof Immunefi
1inch Smart Contract
The 1inch ecosystem relies on interconnected smart contracts that aggregate liquidity from multiple decentralized exchanges to execute optimal token swaps. This bounty program focuses on potential vulnerabilities in 1inch smart contracts and offers rewards of up to $500,000.
Details: Hackenproof Immunefi
1inch Wallet
This bug bounty program focuses on potential vulnerabilities in 1inch Wallet, a multi-chain non-custodial DeFi crypto wallet with a simple interface for storage and transactions. The program offers rewards of up to $100,000.
Details: Hackenproof Immunefi
1inch Web
The 1inch dApp is a major DeFi aggregator, providing access to the deepest liquidity and the best token swap rates across various DEXes. Its distinctive features include partial fill and the ability to identify the best swap paths across multiple liquidity sources. This bounty program focuses on uncovering potential vulnerabilities in the 1inch dApp and offers rewards of up to $50,000.
Details: Hackenproof Immunefi
1inch Infrastructure
This program focuses on finding vulnerabilities that affect the overall infrastructure of the 1inch platform, complementing the product-specific programs listed above. The program offers rewards of up to $20,000.
Details: Hackenproof Immunefi
Be aware of platform requirements. On HackenProof, the current 1inch programs require at least 100 reputation points to submit a report, and a proof of concept (PoC) is required. Some programs may also have additional requirements, such as KYC.
On Immunefi, the current 1inch programs require a PoC for all severity levels and KYC for payout processing, but the Pay to Submit doesn’t apply to 1inch’s programs.
Requirements can change, so always review the rules, eligibility criteria, scope and submission terms on the relevant HackenProof or Immunefi program page before starting your research or submitting a report. Reward eligibility and payouts are subject to the applicable platform’s terms, including identity verification and applicable sanctions requirements.
Join 1inch bug bounty programs, discover vulnerabilities and earn rewards for eligible findings.
Disclaimer: Bug bounty programs are governed by the terms, scope and eligibility criteria published on the relevant HackenProof or Immunefi program pages and may be modified or discontinued at any time. This article is for informational purposes only and does not constitute an offer or a guarantee of payment.
Providing liquidity has traditionally meant depositing tokens into a pool or vault and giving a smart contract custody of them until you withdraw. 1inch Aqua takes a self-custodial approach: your tokens stay in your wallet and move only when a swap fills.
What if you could provide liquidity without first handing your tokens over to a pool? That is the idea behind self-custodial liquidity provision.
With 1inch Aqua, liquidity providers do not deposit or lock tokens in an Aqua contract. Instead, positions quote against assets that remain in the LP’s own wallet. The tokens move only when the conditions of a swap are met, giving LPs a different way to participate in liquidity provision while retaining control of their assets.
What does self-custodial liquidity provision mean?Self-custody means you retain control of your assets rather than transferring them to another party or depositing them into a structure that holds them on your behalf.
Traditional AMMs usually work differently. LPs transfer tokens into a smart-contract pool. Those deposited tokens form the liquidity that traders swap against, and the LP later needs to withdraw assets from the pool to regain direct control of them.
Aqua removes that deposit-and-withdraw cycle. Tokens stay in the LP’s wallet until a swap fills. There is no separate withdrawal step because the assets were never deposited in the first place.
How Aqua keeps liquidity in your walletAn Aqua position works through a revocable token allowance.
The LP gives Aqua permission to access up to a specified amount of a token. The allowance sets a ceiling, but the actual wallet balance remains the binding limit. If a swap matches the position, tokens move directly as part of that atomic transaction. If the wallet does not contain enough of the token when execution occurs, the swap simply cannot fill.
This distinction is important. An allowance gives a smart contract permission to move tokens under defined conditions; it does not transfer ownership or custody of those tokens in advance.
LPs can also revoke the allowance at any time, preventing new swaps from using that token. Closing an Aqua position clears the position without moving the assets themselves.
Self-custody also enables shared liquidityKeeping assets in the wallet is not only a custody feature. It also changes how the same capital can be used.
In a traditional pool model, $10,000 deposited into one pool generally belongs to that specific liquidity position until it is withdrawn and redeployed elsewhere.
Aqua allows the same approved wallet balance to back multiple positions simultaneously. One balance can therefore support different token pairs or strategies without being split into separate deposits. 1inch describes this model as shared liquidity.
Only the assets actually available in the wallet can be used. Aqua does not borrow additional funds or create leverage simply because several positions reference the same balance.
What happens when a swap fills?Aqua uses atomic execution.
When a swap matches an LP’s position, the relevant assets are exchanged within a single blockchain transaction. The LP’s output token leaves the wallet and the incoming token is received as part of the same execution flow.
Atomic execution means the transaction completes as a whole or does not complete at all. The design avoids a situation where Aqua first takes custody of tokens and later has to return them.
What self-custody does not removeSelf-custodial liquidity provision does not make liquidity provision risk-free.
LPs can still face market risk, impermanent loss and smart-contract risk. Swap fees are not guaranteed, and a strategy may receive little or no trading activity. A token approval also remains a permission granted to smart-contract code, which is why approvals and contract security still matter. For a fuller view of these risks, see our guide on risk management for LPs.
Aqua changes a narrower part of the risk model: you do not have to deposit and lock your liquidity in a separate pool contract before it can be used.
That distinction matters because custody and market exposure are different risks. Keeping assets in your wallet does not protect their market value, but it does let you retain direct control of the balance until execution.
Liquidity without giving up controlLiquidity provision has traditionally involved a simple trade-off: to make tokens available to traders, LPs first had to move them out of their wallets and into a pool.
Aqua separates those two things.
Your tokens can remain in your wallet while Aqua positions make them available for execution. You can revoke access, close positions without withdrawing assets and let the same balance support multiple strategies.
Self-custodial liquidity provision therefore changes a basic assumption of the traditional AMM model: providing liquidity no longer has to mean depositing your tokens somewhere else first.
Explore 1inch Aqua and learn more about self-custodial shared liquidity.
Disclaimer: This content is provided for informational purposes only. Nothing in this material constitutes financial, investment, legal or tax advice, or a recommendation to enter into any transaction. Providing liquidity involves risk, including the possible loss of funds. Swap fees are not guaranteed, and 1inch Aqua remains subject to market, smart contract and strategy-related risks.
In the first article of our series on CREATE3 we’ll discuss what a CREATE3 address actually depends on and when two "CREATE3 deployments" land on the same address.
CREATE3 is a deployment technique that lets developers keep the same smart contract address even if they change the contract before deploying it. We’re digging deep into it CREATE3 to explore options it opens up for developers.
1. Why 1inch needs deterministic deployment1inch deploys related smart contracts across multiple Ethereum Virtual Machine (EVM) chains. For these deployments, a contract address is part of the integration interface: other contracts, deployment scripts, configuration files and off-chain services may need it. This creates two practical requirements:
Use the same address on every chain. A shared address reduces chain-specific configuration and lets integrations refer to one contract address across supported networks.Use a pre-mined vanity address on every chain. Some contracts need an address with a recognizable hexadecimal prefix or another chosen pattern. The address must be mined before deployment and reproduced on each target chain.The EVM does not provide one deployment mechanism that satisfies every version of these requirements. Plain CREATE derives an address from the deployer and its nonce. CREATE2 replaces the nonce with a salt and the target's init-code hash, which supports vanity mining but binds the mined address to the exact creation code. CREATE3 is not an opcode: it combines CREATE2 and CREATE so the final address can depend on the factory address and salt rather than the target's creation code. This distinction matters when constructor arguments differ between chains or the bytecode changes after a vanity salt has been mined.
This article first examines the native CREATE and CREATE2 address derivations, then shows how the CREATE3 pattern composes them and which conditions must hold to reproduce a target address across chains.
2. How CREATE determines a contract addressThe Ethereum Virtual Machine (EVM) has exactly two contract-creating instructions: CREATE (opcode 0xf0) and CREATE2 (0xf5). Everything else, including CREATE3, is built from these two.
For CREATE, the new address depends on the deployer and the deployer's account nonce:
address = keccak256(rlp([deployer, nonce]))[12:]
Simplified:
address = f(deployer, nonce)
rlp is Recursive Length Prefix encoding, Ethereum's canonical serialization; [12:] means the last 20 bytes of the 32-byte hash. The executable Ethereum specification implements exactly this (compute_contract_address), using the deployer's nonce as it was before the creation increments it.
Two properties follow:
The created contract's code is not an input: what lands there is whatever init code you run.The address is predictable only if the nonce is. For an externally owned account that means predicting its transaction count at deployment time; for a contract, tracking every creation it performs with CREATE or CREATE2 (even some failed creations consume a nonce).That second property is why CREATE alone does not solve cross-chain deployment: it means keeping an account's nonce synchronized across half a dozen networks, forever. One emergency transaction on one chain, and that chain's future addresses diverge until you pad the nonce everywhere else.
3. How CREATE2 improves deterministic deploymentEIP-1014 added the second creation opcode, whose formula replaces the nonce with two values the deployer chooses:
address = keccak256(0xff ++ deployer ++ salt ++ keccak256(initCode))[12:]
Simplified:
address = f(deployer, salt, initCode)
where ++ is byte concatenation. Each input has a distinct job:
deployer is the contract executing CREATE2 (20 bytes); addresses are namespaced per deployer, so two factories can use the same salt without colliding.salt is an arbitrary 32-byte value: the "which one of my deployments is this" selector.keccak256(initCode) commits the address to the exact init code: the bytecode that executes at creation, running the constructor and returning the runtime code.0xff is a one-byte domain separator. EIP-1014's rationale: an RLP encoding of [deployer, nonce] can never start with 0xff (that prefix would imply an absurdly long payload). So a CREATE2 address can never collide with a CREATE address, and the hash preimage has a fixed size of 85 bytes.This buys a lot. The address no longer depends on account history: a deployment can happen at any time, from any transaction, and still land where predicted. Salts can be brute-forced for vanity addresses. And with no chain-specific input in the formula, the same (deployer, salt, init code) triple produces the same address on every chain that implements Ethereum's creation semantics.
4. The limitation of CREATE2: the address commits to the init codedifferent initCode → different address
To see how sensitive this is, look at what "init code" contains for a Solidity contract. Сonstructor arguments are ABI-encoded and appended after the compiled creation bytecode, and by default the compiler embeds in the bytecode a metadata hash covering the compiler version, the settings and the source files.
So the CREATE2 address changes when any of the following changes:
Constructor arguments. A different wrapped native currency address per chain means a different init code per chain, and "same address everywhere" is gone.The compiler version. With solc's default metadata mode, upgrading the compiler changes the creation bytecode even if the source is untouched. (Teams doing deterministic deployments sometimes strip the metadata hash for this reason.)Optimizer settings. Measured concretely (solc 0.8.30, the small contract from section 10): optimizer at 200 runs, at 1,000,000 runs, and off produce three different creation-bytecode hashes.The source itself. Adding one require-check changes the bytecode, and with default metadata settings the Solidity documentation warns that even renaming a source file can.Timing against a mined salt. A vanity salt brute-forced for one init-code hash is valid only for that exact bytecode. Find the salt first, touch the code later, and the vanity address no longer belongs to your contract.None of this is a flaw in CREATE2. Committing the address to the code is a security feature: whoever verifies the address knows exactly which init code must have created any contract that appears there. But for the multichain scenario from section 1, the formula couples two things the team wants to decouple: the address's identity and the exact bytes of the release candidate.
5. How CREATE3 works5.1. CREATE3 is a pattern, not an opcodeThe name suggests a third EVM instruction. There is none. The current instruction set contains CREATE (0xf0) and CREATE2 (0xf5) only.
"CREATE3" is a community name for a pattern that composes the two real opcodes:
Factory
│
│ CREATE2(salt, fixed proxy init code)
▼
Single-use proxy
│
│ CREATE(target init code)
▼
Target contract
The factory deploys a minimal proxy with CREATE2; the proxy's only ability is to deploy whatever it is sent, using plain CREATE. Chain the two formulas and the target's init code drops out of the derivation.
Because this is a pattern rather than a standard, every implementation makes its own choices. Solady ships it as a Solidity library (Vectorized/solady, src/utils/CREATE3.sol), CreateX as a shared public factory contract (pcaversaccio/createx), 1inch as an owner-gated factory plus a vanity-salt miner (1inch/create3-contract).
5.2. Step one: deploying the proxy with CREATE2The factory deploys the proxy using the ordinary CREATE2 formula:
proxy = keccak256(0xff ++ factory ++ salt ++ keccak256(proxyInitCode))[12:]
The decisive property: proxyInitCode is a constant, the same bytes for every deployment the implementation ever performs. Solady, CreateX and the current 1inch Create3 code all use the same minimal proxy bytecode:
Since the third hash input is a constant, the proxy address depends on the factory address and the salt, and on nothing else; the factory does not yet need to know what will be deployed.
Three different "codes" are in play here:
Proxy init code: the one-time setup code that creates the proxy and installs its minimal behavior.Proxy runtime code: the small program that remains at the proxy address and deploys the target contract.Target init code: the deployment code for the actual contract. It is used only in step two, so it does not affect the proxy address.The proxy is a general-purpose deployer and explained in detail in Part 2.
5.3. Step two: deploying the target with CREATEThe factory now calls the proxy, passing the target's init code as raw calldata. The proxy copies it and executes CREATE, so the plain CREATE formula from section 2 applies, with the proxy as deployer:
target = keccak256(rlp([proxy, proxyNonce]))[12:]
Which nonce? EIP-161 requires that a newly created contract's nonce start at 1, not 0. The proxy, fresh from step one, has never deployed anything, so its first CREATE uses nonce exactly 1.
Now compose the two steps. The proxy address came from (factory, salt, proxy init code); the target address comes from (proxy, constant 1). Writing effective salt for the value that actually reaches CREATE2 (some factories transform user input first — Part 2), the composition gives:
When the factory and its proxy init code are fixed — the usual case inside one deployment system — that simplifies further to:
address = f(factory, salt)
and the target address does not depend on: target init code, constructor arguments, target runtime bytecode.
5.4. What CREATE3 actually guaranteesThe precise guarantee:
A CREATE3-style factory lets you compute the target's address in advance, independent of the target's init code, provided the factory address, the effective salt and the proxy init code are all fixed.
Beware the popular shorthand "the address depends only on the salt". Inside a single factory that reading is harmless (the other inputs are that factory's constants); across systems it is wrong. The full identity of a CREATE3 deployment is:
CREATE3 identity = factory address
+ effective salt
+ proxy init code
Fix all three and the address is yours regardless of what the target code becomes; change any one and the address moves. The word effective is doing real work there: the next section turns the identity into a compatibility condition.
6. When two CREATE3 deployments share an addressTwo systems can truthfully say "we use CREATE3" and still derive different addresses from the same user-provided salt. They produce the same target address if and only if:
same target address
= same factory address
∧ same effective salt (after each factory's transformation)
∧ same proxy init code (byte-identical)
∧ proxy nonce = 1 (target is the proxy's first CREATE)
Break any one of those and the addresses diverge:
Different factory address. The factory is hashed into the proxy address, so two factories at different addresses produce disjoint address spaces even with identical code and salts.Different proxy init code. One byte change in the proxy constant moves every target address. The hash is over the bytes: "equivalent" is not enough.Different salt transformation. The user salt and the effective salt that reaches CREATE2 need not be the same. Compare effective salts, not user salts; how each implementation derives that value is Part 2.Proxy nonce not 1. Any extra creation by the proxy before the target changes the nonce and the address.7. CREATE, CREATE2 and CREATE3 comparedEach method fits a different deployment workflow:
Use CREATE for simple, one-off deployments. It is the most direct option when the contract address does not need to be chosen in advance or reproduced across chains.Use CREATE2 when the address must be known before deployment and the code is already fixed. The address is tied to that exact deployment code, which gives integrators an additional integrity check.Use CREATE3 when the address must remain stable while the code or constructor arguments may change. This is useful for multichain deployments and vanity addresses mined before the final contract is ready.No method is a universal upgrade. The choice is between simplicity, an address tied to fixed code and an address that stays stable as the deployment changes. CREATE3 provides the last property, but the deployment process must verify the code separately, as the next section explains.
8. Security implications8.1. Same address does not mean same codeUnder CREATE2, the address itself certifies the init code. Under CREATE3, by construction, it certifies nothing about the code: any init code deployed through the same factory with the same salt would have received the same address.
CREATE3 stabilizes the address, and in exchange it moves code-integrity control from the address formula into the deployment process.
8.2. Salt squatting and front-runningA public, permissionless factory will deploy for anyone. If your planned salt is observable (in a pending transaction, a public repository, or a deployment on another chain) and the factory does not bind salts to senders, someone else can submit it first and occupy your address, on the chain you were about to use or on one you have not reached yet.
The three implementations answer the threat differently in cost and in what they protect; the comparison belongs to Part 2. What matters here: a salt not bound to a sender on a shared factory is claimable by anyone, on every chain the factory exists on.
8.3. InitializationCREATE3 changes where an address comes from - not the state of the contract that appears there. The classic hazard is unchanged: a proxy-based or otherwise initializable contract deployed and left uninitialized is an open invitation. A stable, beautiful, pre-announced address that briefly hosts an uninitialized contract is a stable, beautiful, pre-announced attack target.
9. ConclusionCREATE2 makes the address depend on init code; CREATE3 removes that dependency by chaining the two real opcodes: a factory deploys a fixed proxy with CREATE2, and the proxy deploys the target with CREATE. The target address is then fixed before the target's code exists:
address = f(factory, salt)
when the factory and its proxy init code are fixed. Across systems the full identity is factory address, effective salt and proxy init code - break any one and the addresses diverge. The trade-off is that the address no longer certifies the code; that check moves into the deployment process, along with salt-squatting and initialization risks.
Part 2 of this series opens the shared proxy bytecode and compares Solady, CreateX and the 1inch deployer. Part 3 will walk through 1inch’s CREATE3 deployment end-to-end.
In the second part of the CREATE3 series we’ll compare three production implementations (Solady, CreateX and the 1inch deployer) in depth.
1. How the CREATE3 proxy bytecode worksCREATE3 removes the target's init code from the address formula by separating address selection from target deployment. A factory first deploys a fixed proxy with CREATE2. It then sends the target's init code to that proxy, which deploys the target with CREATE.
At the pinned revisions, Solady, CreateX and the current 1inch implementation use the same 16-byte proxy init code:
0x67363d3d37363d34f03d5260086018f3
Those 16 bytes contain two small programs: init code that runs once while the proxy is created and runtime code that remains at the proxy address.
1.1. Annotated bytecodeThe listing below shows the byte offset, opcode byte, full instruction, mnemonic and stack after each instruction. The top of the stack is shown first; cds means call-data size and val means the native token value sent to the proxy.
1.2. How the init code installs the runtimeThink of proxy creation as a one-shot installer. The 16-byte program runs only while the proxy is being created; whatever it RETURNs becomes the code that stays at the proxy address.
The installer does three things:
Load the future runtime as data. PUSH8 reads the next eight bytes (0x363d3d37363d34f0) onto the stack as one 256-bit value. During creation those bytes are payload, not yet a program.Park that payload in memory. RETURNDATASIZE is a cheap way to push 0: no earlier external call has return data, so the size is zero. MSTORE then writes a full 32-byte word at memory offset 0. Because the stack value is only eight meaningful bytes, those bytes land in the right side of the word — memory offsets 24 through 31 — with zeros in 0-23:memory[0 .. 32):
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 36 3d 3d 37 36 3d 34 f0
^----------------------^
8-byte runtime at offset 24
Return only those eight bytes. PUSH1 0x08 and PUSH1 0x18 tell RETURN to hand back eight bytes starting at offset 24. The EVM stores that return blob as the deployed proxy's code. After this, the 16-byte installer never runs again; only the eight-byte runtime remains.1.3. How the runtime deploys the targetLater, the factory calls the proxy and puts the target's full init code in the call data. The eight-byte runtime's only job is: copy that call data into memory and CREATE from it.
Walk the stack arguments from the annotated listing:
Copy call data into memory. CALLDATACOPY needs (destOffset, dataOffset, length). The runtime builds that as (0, 0, cds):CALLDATASIZE → cds (how many bytes the factory sent)two RETURNDATASIZE → two zeros (again, a cheap 0)CALLDATACOPY → writes the whole call data to memory[0 .. cds)Create a contract from that memory. CREATE needs (value, memoryOffset, length). The runtime builds that as (val, 0, cds):CALLDATASIZE → cds again (length of the copied init code)RETURNDATASIZE → 0 (start of memory)CALLVALUE → val (native token forwarded with the call, if any)CREATE → runs memory[0 .. cds) as init code and leaves the new target address on the stackThat is the whole proxy: it is not a store of logic about salts or factories. It is a tiny "deploy whatever bytes you just sent me" program.
One consequence of the call shape: the target constructor sees the proxy as msg.sender, not the factory owner, so pass an owner or recipient in the constructor arguments when the target needs one. The proxy forwards any native token value it receives, but only if the factory API actually sends that value in the call.
2. How Solady, CreateX and 1inch differThe three implementations share the proxy bytecode above at their current pinned revisions. They diverge in how they package that mechanism, who may trigger a deployment and how the user salt becomes the salt that actually enters CREATE2. Those three choices decide address compatibility more than any shared CREATE3 label.
2.1. Form factorSolady, CreateX and 1inch are not three factories of the same kind.
Solady ships CREATE3 as an internal Solidity library. Nothing of Solady itself is deployed. The integrator writes a wrapper; that wrapper address is the factory address in the CREATE3 formula. Adoption cost is code and review; network coverage is whatever the integrator deploys.
CreateX is a shared public factory already deployed at a canonical address (0xba5Ed099633D3B313e4D5F7bdc1305d3c28ba5Ed) on many networks. Callers use the existing singleton; they do not maintain their own CREATE3 factory. The deployment surface is permissionless and broad: CREATE, CREATE2 and CREATE3 families live on one contract.
1inch is a per-project Ownable factory wrapping a vendored CREATE3 library, plus a Rust vanity-salt miner in the same repository. Each project deploys its own factory. The surface is small — essentially deploy and addressOf — and the operating model is owner-controlled deployment with bundled mining.
The practical fork is: build around a library (Solady), reuse a public singleton (CreateX), or own a private factory and miner (1inch).
2.2. Front-run protectionCREATE3 addresses are claimable: once the factory address, effective salt and proxy init code are fixed, whoever first succeeds at that salt wins the address. The three implementations put the guard in different places.
CreateX leaves the factory open to anyone and puts protection in the salt. Its _guard path can bind msg.sender and/or block.chainid into the effective salt. A salt whose first twenty bytes equal the caller's address is the recommended pattern against cross-chain proxy frontruns; a stranger cannot reproduce the same effective salt from another account. Section 2.3 details the salt transformations.
1inch leaves the salt raw and puts protection in ownership. Only the factory owner may call deploy. An outsider cannot claim a salt through that factory at all. The ownership model also fits how projects actually operate: the account that deploys may change over time — a new EOA, a multisignature wallet, a hand-off between teams — and transferOwnership keeps factory access with the current owner without rebinding salts to a fixed deployer. Because the salt stays raw, mined vanity salts survive that ownership change; CreateX-style sender-guarded salts would not.
Solady has no access control in the library. Protection is whatever the integrator's wrapper adds — ownership, allowlists or nothing. A wrapper that exposes raw-salt deploy publicly lets any caller claim salts under that wrapper's address space.
2.3. Salt handlingSalt is the sharpest address difference. Solady and 1inch use the user salt as the CREATE2 salt. CreateX almost never does.
Three consequences follow.
Same user salt, different target. Even if 1inch and CreateX somehow shared a factory address and the same proxy init code, CreateX deployment addresses would be different.Prediction helpers do not take the same input. Solady and 1inch take the raw user salt. CreateX's takes the salt after _guard. The two inputs do not match.Off-chain mining and scripts must match the factory rule. A vanity salt mined for a raw-salt factory is not the CreateX input unless the miner reproduces _guard. Conversely, treating a CreateX user salt as if it were Solady's CREATE2 salt predicts the wrong address.Solady and the current 1inch implementation can produce matching predictions when the factory address and raw salt match. CreateX is a different salt machine. The shared proxy does not make the salts interchangeable.
2.4. Comparison summaryThe matrix below collects the differences above with the remaining API and tooling choices.
Use Solady when you want a library primitive and will build and audit its wrapper. Use CreateX when you want an existing permissionless factory and can reproduce its _guard transformation off-chain; the repository lists 195 deployment records at the pinned revision, but this article did not verify them on-chain. Use the 1inch repository when deployment should remain owner-controlled and the workflow needs bundled vanity mining; you must still deploy the factory at the required address on every chain.
Address compatibility requires the same factory address, effective salt and proxy init code. Solady and the current 1inch implementation produce matching predictions when given the same factory address and raw salt. CreateX transforms user salts, while older 1inch factories use different proxy init code. The shared CREATE3 label does not imply matching target addresses.
In the third and final part of this series, we’ll explore how these constraints can be turned into an executable 1inch workflow: deploy the factory, mine and verify a vanity salt, build the target init code and deploy the target at the predicted address.
The third and final part of the CREATE3 series offers an example of how 1inch uses CREATE3.
The first part of this series focused on deriving CREATE3 addresses. In the second part, we explained the proxy bytecode and compared Solady, CreateX and 1inch. Now, let’s turn that analysis into an executable deployment workflow with the 1inch factory.
The example below applies to EVM-compatible chains with standard CREATE, CREATE2, contract-nonce and JSON-RPC behavior. It stores the RPC endpoint and generated addresses in environment variables. It signs with a Foundry encrypted-keystore account. Test it on a disposable network before using a production chain.
1. Check out and test the pinned codegit clone https://github.com/1inch/create3-contract.git
The repository pins Solidity 0.8.23. It does not pin a Rust toolchain, so record the Foundry and Rust versions used by your deployment pipeline. Run the remaining commands from the repository root in the same shell because later steps reuse the exported variables.
2. Configure the RPC endpoint and signerImport the funded deployment key into Foundry's encrypted keystore:
cast wallet import create3-deployer --interactive
export RPC_URL='<chain RPC URL>'
export ACCOUNT='create3-deployer'
The command prompts for the private key and a keystore password without placing either in shell history. Avoid passing a production private key through --private-key or an environment variable.
The account that deploys the factory becomes its owner. Keep that account as owner for this walkthrough. Section 6 explains what changes if ownership moves to a multisignature wallet.
3. Deploy and verify the factoryRun the repository's Foundry script:
forge script script/DeployCreate3Deployer.s.sol \
--rpc-url "$RPC_URL" \
--account "$ACCOUNT" \
--broadcast
The script prints the factory address. Export it, confirm that code exists and verify that owner() returns the address imported under $ACCOUNT:
The script deploys the factory with plain CREATE, so its address depends on the signer and that account's nonce. Reusing this script on another chain does not automatically reproduce the factory address. Cross-chain target parity requires the factory itself at the same address on every chain.
4. Mine a vanity saltChoose one miner based on the CPU architecture. Use the portable binary on any supported CPU:
cargo run --release --bin create3-miner -- \
"$FACTORY" --leading dead
On an aarch64 machine, including Apple Silicon, use the NEON binary instead:
cargo run --release --bin create3-miner-neon -- \
"$FACTORY" --leading dead
The miner prints a salt and its predicted target address:
Salt: 0x...
Address: 0x...
Export both values, then compare the factory's prediction with $PREDICTED before mining a longer pattern:
The returned address must equal $PREDICTED. The miner defaults to the current proxy init-code hash 0x21c35dbe…497c1f; use a bytecode override only after verifying that a deployed factory uses another proxy version.
5. Build the target init codeFor a minimal example, add contracts/Example.sol:
// SPDX-License-Identifier: MIT
pragma solidity 0.8.23;
contract Example {
address public owner;
constructor(address owner_) {
owner = owner_;
}
}
The constructor receives the owner explicitly because its msg.sender will be the temporary CREATE3 proxy.
Build the contract, encode the constructor argument and append it to the creation bytecode:
cast abi-encode returns the encoded argument tuple without a function selector; the synthetic function name f only supplies the argument types.
The 1inch deployment path cannot send native tokens to a target constructor: deploy is non-payable, and the factory calls the proxy with zero native token value. Use a target whose constructor does not require a nonzero msg.value.
6. Simulate and broadcast the target deploymentRead the factory owner into $OWNER, then simulate deploy from that address:
The simulated return value must equal $PREDICTED. If $ACCOUNT still owns the factory, broadcast the same call:
cast send "$FACTORY" 'deploy(bytes32,bytes)' \
"$SALT" "$INIT_CODE" \
--rpc-url "$RPC_URL" \
--account "$ACCOUNT"
If a multisignature wallet owns the factory, submit the same call data through that wallet instead. Any other signer reverts. A salt can be consumed only once through a given factory on a given chain.
If target creation fails, the library discards the proxy's return data and reverts with ErrorCreatingContract(). The target constructor's original revert reason is not propagated.
7. Verify the deployed contractConfirm that code exists at the mined address and that the constructor stored the intended owner:
The first command must return nonempty bytecode. The second must return $TARGET_OWNER. Complete the deployment record with the source commit, compiler settings, constructor arguments, creation and runtime bytecode hashes and explorer verification. CREATE3 stabilizes the address. It does not prove which code was deployed there.
In the first half of this year, over a thousand reports were submitted across six bug bounty programs, helping us to uncover vulnerabilities.
What does it take to build trust in institutional-grade DeFi? Transparency is a big part of the answer.
As traditional finance moves further on-chain, security and trust remain critical barriers to adoption. We have been working to address that challenge through initiatives including the second edition of its Risk Management Whitepaper, ISO 27001 certification and SOC 2 (Type 1) attestation.
Now, we are taking another step with the launch of a biannual bug bounty report, created in collaboration with HackenProof. The first report, released today, focuses on the 1inch Aqua bug bounty program and activity in H1 2026.
“Institutional-grade DeFi requires proactively adopting standards that go past what is prescribed,” comments Sergej Kunz, co-founder of 1inch. “The industry needs to go beyond the minimum to ensure products are secure and reliable. With Aqua, as with all our products, we put multiple layers of checks and testing in place from the start, and bug bounties are a key part of that approach.”
“Aqua’s approach to security highlights the value of making security an ongoing part of product development. Its bug bounty program provides continuous visibility into potential security risks as the product evolves, helping the team strengthen the protocol and reduce the likelihood of costly security incidents,” said Alex Horlan, CTO of HackenProof.
Across 1inch’s six core HackenProof bug bounty programs, 1,055 reports were submitted by security researchers in the January to June period. Of those reports, 32 resulted in payouts across different severity levels.
Focus on 1inch Aqua A separate in-depth report is focused on 1inch Aqua, our recently launched first-of-its-kind shared liquidity layer. Aqua has grown rapidly since being made public, surpassing $100 million in volume within a matter of weeks. However, its success and security weren’t built overnight. Its HackenProof bug bounty program saw a huge amount of interest and contributed greatly to the product's security from day one.
The Aqua bug bounty program saw high engagement from the security community, with 472 submissions received from 217 researchers, covering a range of vulnerabilities at different levels of severity.
A total of 9 vulnerabilities have been rewarded, including one high-severity vulnerability, as well as a number of medium and low-severity vulnerabilities. These included logic inconsistencies, unit mismatches, execution edge cases and tooling-related issues. As with all the vulnerabilities, these have now been resolved, adding to the stability and security of the protocol.
For more 1inch news and updates subscribe to our newsletter
Disclaimer: This content is for general information purposes only and does not constitute financial, investment, tax, or legal advice and is not a recommendation to buy or sell any particular digital asset or to employ any specific investment strategy.
Just-in-time liquidity can let opportunistic bots capture fees from swaps without taking the same ongoing exposure as long-term LPs. 1inch Aqua changes the structure that makes this possible.
You provided liquidity, took the market risk and waited for trades. Then a bot appeared for a single swap, captured part of the fee and disappeared.
That is the problem with just-in-time, or JIT, liquidity, which 1inch Aqua addresses at the level of liquidity architecture. In conventional pooled AMMs, fees are distributed to whoever has liquidity active when a trade executes. A sophisticated actor can therefore add liquidity immediately before a large swap and remove it immediately afterwards, taking a share of fees that would otherwise have gone to existing LPs.
Research suggests the impact can be significant. A 2025 academic study of concentrated liquidity market makers found that strategically deployed JIT liquidity could reduce passive LP profits by up to 44% per trade on average in its model. The same research also found that JIT liquidity can improve execution for traders by adding depth at the moment it is needed, making JIT a more nuanced phenomenon than a simple attack on the market as a whole. For passive LPs, however, the fee dilution is very real.
Conversely, with 1inch Aqua, an external LP cannot add liquidity to your Aqua strategy immediately before a swap and snipe your fee. The strategy executes only against your balance, and only you collect fees for your strategy. With that setup, a traditional JIT fee-sniping mechanism can’t work.
JIT liquidity exploits a simple feature of pooled AMMs: fee ownership depends on who is providing liquidity when the swap happens.
A typical sequence looks like this:
A large pending swap becomes visible in the mempool.A JIT actor adds a large amount of concentrated liquidity around the price range the trade is expected to cross.The swap executes and generates fees.The temporary liquidity receives a share of those fees.The JIT actor removes the liquidity immediately afterwards.The actor can provide and withdraw liquidity even in a single block - providing liquidity immediately before actual swap transaction and withdrawing it immediately after, gathering most of the swap fees. A long-term LP, meanwhile, may have kept capital in the pool for days or weeks while taking continuous market exposure.
The problem is not that the AMM distributes fees incorrectly. The system is working exactly as designed. Fees are distributed according to active liquidity at execution time.
That design creates an opening for fee-sniping.
As the 1inch analysis of liquidity provision and MEV explains, JIT differs from a conventional sandwich attack. A sandwich attack targets a trader’s execution. JIT targets the LP side of the trade by temporarily changing who receives the fees.
Why pooled liquidity creates the opportunityA conventional AMM pool combines capital from many LPs.
When a swap executes, fees are shared among eligible liquidity providers according to the protocol’s rules. In concentrated liquidity AMMs, that generally means LPs whose liquidity is active in the price range through which the trade passes.
This creates a shared fee event.
Anyone able to add enough liquidity at the right moment can increase their share of that event. The JIT actor does not need to have provided liquidity before the transaction appeared or remain exposed after it finishes.
For a passive LP, the effect is dilution. The swap still generates the same fee, but the long-term LP receives a smaller share because temporary liquidity arrived just in time to compete for it.
JIT strategies are especially relevant when a trade is large relative to existing liquidity and the expected fee is large enough to justify the cost and risk of inserting temporary capital.
Aqua removes the shared fee position1inch Aqua uses a fundamentally different liquidity model.
Aqua is a shared liquidity layer rather than a conventional pooled AMM. Tokens stay in the LP’s wallet until a swap fills, and the same wallet balance can support multiple positions at once.
More importantly for JIT, each Aqua strategy belongs to one LP.
An external LP cannot add liquidity to somebody else’s Aqua strategy immediately before a swap. The strategy executes against the balance of its owner, and fees generated by that strategy belong to that owner.
This removes the core mechanism behind traditional JIT fee-sniping.
There is no shared pool position that an outside actor can enter for one transaction, collect part of another LP’s fee and immediately leave.
One owner changes the fee equationConsider the difference between the two models.
In a pooled AMM, Alice and Bob may both provide liquidity to the same pool. If a large swap appears, a JIT bot can potentially add far more liquidity than either of them for the duration of that swap. Alice and Bob remain LPs, but their relative share of active liquidity falls, so their share of the fee falls with it.
With Aqua, Alice’s strategy is Alice’s strategy.
A bot cannot inject its own tokens into Alice’s position to claim part of the fee. If a swap is executed against Alice’s strategy, the resulting fee accrues according to that strategy’s rules without an external LP diluting her position at the last moment.
The protection comes from ownership structure rather than from trying to detect or outrun JIT bots.
No deposit-and-withdraw raceAqua also changes another part of the JIT mechanics. Traditional JIT depends on rapid liquidity entry and exit: deposit before the trade, withdraw after it.
Aqua LPs do not deposit their tokens into a shared pool. Tokens remain in the wallet, while strategies receive permission to use them when their execution conditions are met. Aqua’s architecture allows the same wallet balance to support several strategies without locking that balance into separate pools.
Because liquidity is not repeatedly added to and removed from a shared LP pool, there is no equivalent race to temporarily become part of another LP’s position.
This does not mean nobody can create a competing Aqua strategy. Different LPs can still quote competing prices and liquidity, which is a normal part of a market.
The key distinction is that competition happens between independently owned strategies, not by inserting temporary liquidity into somebody else’s strategy and taking part of its fee.
What Aqua does - and does not - protect againstAqua’s single-owner strategy model removes a structural JIT vector, but it does not remove the normal risks of liquidity provision.
LPs can still face:
price movements and impermanent loss;unfavorable market conditions;strategies that receive little or no order flow;smart contract risk;execution and strategy-design risk.Swap fees are also not guaranteed. The 1inch Aqua FAQ makes clear that a position earns fees only when swaps fill against it.
Aqua’s JIT protection is more specific: an outside actor cannot temporarily add liquidity to your strategy simply to dilute your fee share on an incoming trade.
Protecting the fee you actually earnedLiquidity provision means taking risk in exchange for the possibility of earning fees. A system in which somebody can arrive for a single profitable transaction and take a disproportionate share of those fees changes that equation for long-term LPs.
Pooled AMMs make JIT possible because liquidity and fees are shared at the moment of execution.
Aqua removes that shared ownership layer. Each strategy has one LP, so another liquidity provider cannot insert capital into your position just before a swap and leave with part of the fee afterwards.
The result is a simpler principle: if a swap executes against your Aqua strategy, another LP cannot use traditional JIT fee-sniping to dilute that strategy’s fee share.
Explore 1inch Aqua and learn how shared liquidity changes liquidity provision in DeFi.
Disclaimer: This content is provided for informational purposes only. Nothing in this material constitutes financial, investment, legal or tax advice, or a recommendation to enter into any transaction. Providing liquidity involves risk, including the possible loss of funds. Swap fees are not guaranteed, and 1inch Aqua remains subject to market, smart contract and strategy-related risks.
With a 1inch limit order, eligible users can set the rate they want for a supported tokenized asset and let the order wait for the market to come to them.
Real-world assets (RWAs) are bringing stocks, funds, commodities and other traditional assets onchain. And while you can swap supported RWAs directly on 1inch, sometimes you may want to buy or sell only when the asset reaches a specific price. That’s where 1inch Limit Orders come in.
Why use a limit order for RWAs?A limit order lets you specify the price at which you are willing to trade instead of accepting the current market rate. If the order can be filled at your chosen rate before it expires, it can be filled. If not, it simply expires.
Your assets remain in your wallet while the order is open. A 1inch limit order does not reserve the tokens you are offering, so if you move or spend them before the order is filled, there may no longer be sufficient balance to fill it.
That can be particularly useful for tokenized equities and other RWAs, where you may want to set a target based on the price of the underlying asset rather than constantly monitor the market.
What is different about RWA limit orders?Mechanically, creating a limit order for a supported RWA works much like creating one for another token. But the asset itself may come with additional conditions.
First, check eligibility. Tokenized assets can be subject to issuer terms and geographic restrictions. Some RWAs available through 1inch, for instance, are unavailable in the US, UK or other restricted jurisdictions.
Second, check liquidity. RWA liquidity can be thinner or more fragmented than liquidity for major crypto assets. That means reaching your target price does not necessarily guarantee that your entire order will immediately be filled. Liquidity remains one of the main challenges for onchain RWA markets.Token prices can also deviate from the price of the underlying asset, particularly outside traditional market trading hours.
Finally, understand what the token represents. A tokenized stock is not the same as directly owning the underlying share. The structure, rights and transfer conditions depend on the issuer. Before trading an RWA, check the issuer, token contract and applicable terms.
If the RWA and network you want to use are supported in Limit mode, placing an order takes just a few steps:
Open the 1inch dApp and connect your wallet.Go to Trade and select Limit.Select the network on which your RWA is available.Choose the RWA you want to buy or sell and the other token in the pair.Enter the amount you want to trade.Set your target price. You can use the available presets or enter your own rate.Choose how long the order should remain active.Review the asset, rate, amount and expiry period carefully.Click Place order and sign the order in your wallet.Track it under Active Orders. If your target can be met before expiry, the order can be filled; otherwise it expires.With RWAs expanding the range of assets available onchain, limit orders give eligible traders another way to control when and at what price they trade.
Explore limit orders for RWAs on 1inch.
Disclaimer: Tokenized real-world assets are issued by third parties and may be subject to issuer terms, transfer restrictions and geographic limitations. Availability and liquidity may vary. This content is for general information purposes only and does not constitute financial, investment, legal or tax advice. 1inch does not issue, sponsor or manage these assets and makes no representation or warranty as to their composition, backing, redemption or performance. Limit orders may be filled partially or not at all, and token prices may deviate from the price of any underlying asset. Digital assets involve risk, including possible loss of value. Access is subject to applicable law and the restrictions set out in the 1inch Terms of Use.
Coinbase has brought a new range of tokenized equities to Base, using the B20 token standard. From day one, eligible users can trade supported assets through 1inch.
Traditional markets are moving onchain, and 1inch has always been at the forefront of these changes, supporting RWAs from Ondo, xStocks and Maple.
Now, 1inch also supports Coinbase tokenized stocks on Base. The initial selection includes assets linked to Apple, Alphabet, Meta and Nvidia.
The launch strengthens 1inch’s position as a gateway to tokenized real-world assets, giving eligible users direct access to Coinbase’s new B20-based equities on Base. Because B20 is compatible with existing ERC-20 infrastructure, these assets can plug into 1inch’s swap routing from day one, expanding choice while keeping access within the same DeFi trading flow.
Tokenized equities on BaseTokenized equities are blockchain-based assets designed to track or provide exposure to companies and other equity-related instruments.
By bringing them on-chain, issuers can connect traditional financial assets with programmable DeFi infrastructure. These assets can be held in compatible wallets and integrated into trading applications and other on-chain products, subject to the issuer’s terms and regional restrictions.
Base has identified tokenized markets as a major part of its 2026 strategy. The network aims to support equities, commodities and other asset classes across spot, tokenized, prediction and derivatives markets.
Coinbase’s new assets take this strategy a step further by launching on Base through B20, a token standard designed with tokenized finance in mind.
What is the B20 token standard?B20 is a Base-native standard for issuing fungible assets such as stablecoins, tokenized equities and other RWAs.
Unlike a conventional ERC-20 token deployed through an individual smart contract on the Ethereum network, B20 is implemented at the protocol level. It gives issuers a standardized framework without requiring them to build and audit a new token contract from scratch.
B20 supports built-in controls for functions such as minting, burning, pausing, supply limits and transfer policies. At the same time, it remains compatible with ERC-20 infrastructure, helping existing wallets, exchanges and DeFi applications interact with B20 assets.
The standard has two configurations:
Asset tokens, designed for RWAs, tokenized equities and other fungible assetsStablecoin tokens, which use a fixed six-decimal format and specify a fiat currency denominationThis combination of standardized issuance, issuer controls and ERC-20 compatibility is designed to make it easier to bring regulated and real-world assets on-chain.
Which Coinbase tokenized assets are supported?The initial selection available through 1inch includes:
AAPLc - AppleGOOGLc - AlphabetMETAc - Meta PlatformsNVDAc - NvidiaAvailability, liquidity and trading conditions may differ between assets. The tokens are not available in the US, UK and other restricted jurisdictions.
Trading Coinbase RWAs through 1inchEligible users can now access supported Coinbase tokenized assets on Base through the 1inch dApp, 1inch Wallet and 1inch APIs.
When you initiate a swap, 1inch scans available on-chain liquidity and routes your transaction along an efficient path. This removes the need to check individual liquidity venues manually.
To explore the assets:
Open the 1inch dApp.Connect a compatible wallet.Select Base as the network.Choose one of the supported tokenized assets.Review the route, rate and transaction details before confirming the swap.As with any new on-chain asset, liquidity may vary. Always verify the token, issuer information and transaction details before proceeding.
Towards an onchain futureTokenized equities connect familiar financial assets with open, programmable infrastructure. B20 provides Base with tokenization tools built directly into the network. Coinbase is using those rails to bring a new selection of equity-linked assets on-chain. And 1inch makes supported tokens accessible through its swap infrastructure from day one.
Explore Coinbase tokenized assets on 1inch.
Disclaimer: This campaign is operated by Merkl (Angle Labs), which calculates and distributes all rewards, and is subject to Merkl's applicable terms and policies. The campaign forms part of the tokenized-equities launch programme on Base; 1inch Network has contributed funding. It is not sponsored or endorsed by Base or Coinbase. Rewards are paid in USDC on qualifying purchases made through the 1inch dApp or 1inch Wallet and held through the applicable epoch; purchases made through other interfaces, integrations or APIs do not qualify. Rewards are not an investment opportunity, and no reward, rate or return is guaranteed. Reward calculations are final once processed. Campaign parameters may change, and the campaign may be modified, suspended or discontinued at any time. Participation is subject to eligibility, geographic, integrity and compliance screening, and any wallet or participant may be excluded from the campaign or from rewards on that basis at any time; attempts to circumvent geographic or eligibility restrictions, including through VPNs or other means, result in exclusion and forfeiture of rewards. Rewards must be claimed on the Merkl app and may cease to be claimable after the end of the campaign. Tokenized stocks are issued by third parties and are subject to the issuer's terms and to transfer and regional restrictions; their availability, liquidity, transferability and market value may fluctuate, are not guaranteed and are outside the campaign's control. 1inch is not the issuer of, and is not responsible for, any tokenized asset. You are solely responsible for any taxes arising in connection with rewards or trading. Any figures shown on campaign interfaces are informational only and not a promise of returns. By participating in the campaign or claiming rewards, you agree to the campaign rules described in this post and to the 1inch.com Terms of Use, which also apply to campaign participation to the extent relevant. Not available to persons located in, residents of, or accessing from the United States, Canada, the United Kingdom, Australia, Singapore, Switzerland, or any sanctioned or otherwise restricted jurisdiction. Nothing in this post constitutes financial, investment, legal or tax advice, or a recommendation, solicitation or inducement to buy or sell any security or other asset.
Artificial intelligence is rapidly changing cybersecurity - and DeFi is no exception. Recently, Alexandra Gulamova and Igor Gulamov from Savant.Chat, a security firm focused on AI-powered audits, discussed with 1inch how AI is changing the rules for both attackers and defenders.
AI is making it easier to discover vulnerabilities, combine expertise from multiple domains and uncover attack paths that would have been difficult for even experienced hackers to find just a few years ago. Does that mean decentralized finance is becoming impossible to defend?
Not necessarily. According to Igor and Alexandra, the projects that embrace AI-first security practices will be far better positioned than those relying solely on traditional audits and bug bounties. The question is no longer whether AI will reshape DeFi security - it's whether protocols can adapt quickly enough.
AI is making attackers smarterOne of the biggest misconceptions in the industry is that AI simply makes hacking easier. Igor argues the real change is deeper: AI bridges knowledge gaps that previously limited attackers.
Modern exploits increasingly require expertise across multiple disciplines, from cryptography and mathematics to low-level programming and business logic. Until recently, assembling all that knowledge in a single person - or even a single team - was difficult.
"AI removes these gaps," Igor explains. Instead of needing specialists in every field, attackers can rely on AI to combine expertise across domains, enabling far more sophisticated exploits.
He points to recent zero-knowledge (ZK) exploits as an example. Successfully attacking these systems often requires simultaneously understanding advanced mathematics, cryptography and low-level programming - something AI excels at.
It's not lowering the barrier - it expands what's possibleAlexandra believes that, rather than lowering the barrier to entry, AI dramatically expands what attackers can accomplish.
Previously, hackers needed to assemble people with different specializations. Today, "it could be done by one machine," she says.
The problem is amplified by the fact that many DeFi projects still rely primarily on traditional security approaches - human audits, bug bounty programs and manual reviews. While those practices remain valuable, they are no longer sufficient on their own against AI-assisted adversaries.
Which protocols are most at risk?According to Igor, the greatest risk lies in systems that combine multiple complex domains.
Protocols involving advanced cryptography, sophisticated business logic, arithmetic-heavy calculations or cross-domain interactions become significantly more attractive targets because AI can reason across all these areas simultaneously.
Bridge protocols remain especially exposed as well. Recent attacks have demonstrated how attackers can combine seemingly unrelated weaknesses - such as arithmetic bugs with flaws in business logic - to create devastating exploits. AI makes identifying these combinations considerably easier.
He also notes that closed-source software is no longer much of a defense.
"Closed source isn't a shield," he says, because AI-powered reverse engineering and decompilation continue to improve.
Can AI defend DeFi too?Fortunately, the same technology empowering attackers can also strengthen defenders.
Igor believes AI's greatest value isn't monitoring live smart contracts in real time, where defenders inherently face an asymmetric challenge. Attackers can spend weeks using enormous computing resources to discover an exploit before launching it in seconds.
Instead, AI delivers its biggest advantage much earlier - in development.
Running comprehensive AI audits throughout continuous integration and continuous deployment (CI/CD), scanning every pull request and identifying broken invariants before code reaches production dramatically reduces the available attack surface.
As Igor explains, defenders don't necessarily need to discover the exact exploit an attacker would eventually use. If AI identifies a broken invariant, developers can simply fix it before anyone has a chance to weaponize it.
Human auditors aren't going awayNeither expert believes AI will replace human security experts anytime soon.
Alexandra describes AI audits as a new foundational layer rather than a replacement for traditional reviews.
Her recommended workflow is straightforward:
Run comprehensive AI audits across the codebase.Integrate AI into every CI/CD pipeline and pull request.Periodically re-scan the entire codebase as it evolves.Finish with human security audits before major releases.Each layer catches different classes of issues, making the overall security posture significantly stronger.
The race between sword and shieldLooking ahead, Igor expects an ongoing arms race.
Attackers will inevitably gain access to increasingly powerful models - including open-source models with fewer restrictions. As frontier AI becomes widely available, sophisticated vulnerability discovery will become accessible to many more threat actors.
That means defenders cannot afford to rely on outdated tooling or AI models that lag months behind the state of the art.
Instead, security teams will increasingly combine frontier LLMs with formal verification, invariant checking and continuous AI-driven auditing to eliminate vulnerabilities before attackers find them.
So... can AI kill DeFi?Both experts answer with a simple and confident "No."
AI undoubtedly gives attackers new capabilities. It can combine knowledge across disciplines, uncover complex exploit chains and dramatically accelerate vulnerability discovery.
But AI also gives defenders unprecedented tools to secure protocols before they're deployed.
The winners won't be the projects trying to fight AI - they'll be the ones embracing it first. As AI reshapes both sides of cybersecurity, DeFi's future won't depend on whether artificial intelligence exists. It will depend on how effectively protocols use it to stay one step ahead of attackers.
For more security insights subscribe to our newsletter
Disclaimer: This content is for general information purposes only and does not constitute financial, investment, tax or legal advice and is not a recommendation to buy or sell any particular digital asset or to employ any specific investment strategy.
More and more traditional assets are moving onchain. But how far are we into the RWA cycle? We discussed that with several major RWA providers on 1inch.
Eventually, most real-world assets are going to be traded onchain. But we are still closer to the beginning of that road, and a few hurdles will have to be cleared before onchain trading of tokenized assets becomes universally accepted.
“First car on the road”Industry insiders say that tokenized assets have moved beyond the early adoption stage, as volumes of RWA onchain trade have proven.
“The diversity of assets held, the consistency of net inflows, and the caliber of institutional integration proves that tokenized securities have moved beyond early adoption into a fundamental capital markets product,” says Ian De Bode, President of Ondo Finance.
However, there are entire asset classes that haven’t yet been touched by tokenization, which suggests that the process is likely to be still in an early stage.
“Tokenized real-world assets hit $38 bln onchain this year, nearly triple the total from twelve months ago,” adds Val Gui, GM of xStocks. “That's live capital running through production infrastructure. Offchain, equities, credit, and real estate markets add up to tens of trillions of dollars, and almost none of that has touched a blockchain yet. This is early. The growth curve suggests that won't last.”
“It's still very early days,” agrees Martin de Rijke, Head of Commercial at Maple. “We've seen T-bills come onchain, several private credit structures, a handful of corporate bonds, and tokenized stocks that are just starting to move. But the total across all of it still sits around ten to twenty billion. Think of it like the first car on the road. Someone's uncle's uncle's uncle owns one, and everyone else is still watching.”
Tokenized Treasuries take the leadAccording to RWA issuers, tokenized versions of Treasury bills have so far been the most popular asset class onchain.
“Tokenized Treasuries lead by a wide margin, sitting around $15 bln onchain. Institutions treat this category as production-grade, backed by more than a hundred distinct products,” says xStocks’ Val Gui. “Private credit sits close behind in dollar terms, though a large share of that volume traces back to a small number of issuers. Tokenized equities are smaller by total value but the fastest growing by product count. xStocks went from 60 tokenized stocks and ETFs at launch to more than 500 in the first year.”
“Tokenized yield products, tokenized stocks, T-bills, and private credit structures are where the activity is concentrated right now,” adds Martin de Rijke. “Tokenized stocks in particular are starting to gain traction on Robinhood Chain and Solana.”
The biggest bottlenecksStill, bottlenecks preventing asset tokenization from rolling out more rapidly need to be resolved first, such as insufficient liquidity and a lack of clear regulation.
“Two things need to move before the market can really scale,” says Maple’s Martin de Rijke. “First, regulatory clarity: the US Clarity Act is the catalyst that unlocks broader institutional participation, the same way earlier clarity did for stablecoins. Second, liquidity: Real liquidity flow onchain hasn't properly started yet. Once both regulation and liquidity are in place, adoption follows.”
xStocks’ Val Gui, GM, agrees that liquidity is the biggest bottleneck. “Most tokenized Treasuries and private credit get minted and redeemed rather than traded on a secondary market, so a lot of that capital just sits there,” he explains. “What liquidity exists gets split across issuers, chains, and trading venues instead of pooling somewhere deep enough to trade well.”
“Regulatory frameworks still vary sharply by jurisdiction, which adds cost and delay for anything built to operate globally,” he adds.
Direction: onchainAt this point, few doubt that the process of assets moving onchain is irreversible. The question is how fast it is going to be and what share of real-world assets will be available in a tokenized form.
“You should prepare for a world in which tokenized securities coexist with normal securities,” says Ondo Finance’s Ian De Bode.
“Right now we're at the beginning of an S-curve for trading moving onchain, and that curve hasn't really started in earnest yet,” says Maple’s Martin de Rijke, adding that the pace of growth is likely to accelerate once the regulatory and liquidity bottlenecks have been cleared.
“Here's the mechanism,” Martin de Rijke goes on to say. “Liquidity enables arbitrage, arbitrage draws in more liquidity, and more liquidity produces better prices. Onchain markets run 24 hours a day, every day, with a global pool of participants able to trade at any time. That combination makes onchain markets a more accurate representation of an asset's true price than their offchain equivalents. Once price discovery happens onchain, trading follows it there, because that's where the real opportunity sits.”
xStocks’ Val Gui agrees. “Onchain markets run continuously, settle in seconds, and reach anyone with an internet connection regardless of where they live,” he explains. “Those advantages get stronger as more liquidity and more assets show up in the same place. I won't attach a percentage or a year to it. The direction is set, and the infrastructure to support it is close to ready.”
For more insights from 1inch subscribe to our newsletter
1inch Aqua was built around self-custody, so its security depends heavily on the smart contracts that make shared liquidity possible. These contracts have been heavily audited by top crypto security firms.
How do you secure a liquidity layer that never takes custody of users' funds?
In 1inch Aqua, LP’s tokens remain in the wallet and move only when a swap executes. That makes the integrity of the underlying contracts critical.
So Aqua and its underlying SwapVM engine went through multiple independent audits before launch. Eight leading external security teams reviewed different parts of the system, giving the code several rounds of scrutiny and making the findings available for anyone to inspect.
All the reports are publicly available - you’ll find them linked below
What was the security process for 1inch Aqua?Internal review by the 1inch security teamAI-assisted pre-audit with SavantChat (link to existing blog post or Link the SavantChat pre-audit blog post)Eight independent audit firms on the contracts - the same core scope, each going deep on a different layerA separate application-level audit of the frontend and backendAn ongoing bug bounty programAcross the eight reports, auditors raised roughly 190 findings. Every critical finding was fixed before launch; the rest were fixed or explicitly acknowledged with documented reasoning, and re-tested on updated code.
Who audited 1inch Aqua?Each team reviewed the same core codebase - the Aqua contracts, the SwapVM engine and the supporting libraries - and each went deep on a different layer of it. These are links to their reports:
MixBytesOpenZeppelinNethermindHexensTheoriDecurityHashlockBailsecWhat do audits mean - and what don't they?An audit is not a guarantee. It is an independent, expert attempt to break the system before anyone else can. Findings raised during these reviews were resolved or explicitly accepted with documented reasoning, and every report is public, so anyone can check that work.
On top of the contract reviews, Aqua swaps are filled by resolvers, independent counterparties that complete an onboarding and verification process, with access conditions enforced on-chain at swap time.
Security doesn't stop at launchAudits are part of an ongoing process: new versions go through the same review cycle, the bug bounty program stays open, and a dedicated incident response process is in place. 1inch has also adopted the SEAL Whitehat Safe Harbor Agreement through DAO governance (1IP-104), enabling qualified whitehats to intervene during active exploits.
Read all eight audit reports and explore 1inch Aqua.
Disclaimer: This content is provided for informational purposes only. Nothing in this material constitutes financial, investment, legal, or tax advice, or a recommendation to enter into any transaction. Interacting with Aqua involves risk, including the possible loss of all funds involved.
1inch Aqua gives you several options to provide liquidity, depending on the assets you're trading and how actively you want to manage your position. In this article, we’ll explain what options you have.
1inch Aqua offers several position types designed for different trading scenarios. Here's some advice on creating Aqua positions for:
passive vs active strategiesstable vs volatile pairsshort- vs long-term goalsexperienced LPs vs newcomers.But before choosing, make sure you understand the risks of liquidity provision - see our guide on risk management for LPs.
Full rangeFull range is the simplest way to provide liquidity.
Your liquidity is available across the entire possible price range, so the position never goes out of range. You don't need to predict where the market will move or adjust your range as prices change.
This makes full-range positions well suited for users who prefer a low-maintenance approach.
The trade-off is capital efficiency. Because your liquidity is spread across every possible price, less of it is concentrated around the current market price compared with narrower positions.
Best for:
Users newer to liquidity provisionLong-term liquidity providersVolatile trading pairs when you don't want to manage rangesConcentrated liquidityConcentrated liquidity lets you choose the price range where your liquidity is active.
Instead of covering the entire market, your capital is focused within a specific range. If trading happens there, more of your liquidity is available, potentially increasing fee generation.
The trade-off is that if the market moves outside your chosen range, your position stops earning swap fees until the price returns or you create a new position.
Aqua offers preset ranges for convenience, while advanced users can define a custom range that better matches their market view.
Also, with 1inch Aqua, it is easy to create single-sided positions: simply set either the minimum or maximum price equal to the current market price. The position will then start with one token only, gradually converting into the other token as trades are executed.
Best for:
Experienced LPsVolatile assets such as ETH or BTCUsers seeking higher capital efficiencyPegged positionsPegged positions are designed for assets that typically trade close to the same value.
Examples include:
USDC and USDTETH liquid staking tokens and ETHOther closely correlated assetsInstead of setting separate minimum and maximum prices, you choose a symmetric range around the current market price. Aqua then configures the position for assets expected to maintain a close relationship.
Because these assets usually experience relatively small price differences, pegged positions can provide highly efficient liquidity.
They are not intended for assets with large price swings. And pegged assets can still lose their peg: if that happens, a pegged position can end up holding mostly the weaker asset.
Best for:
Stablecoin pairsLiquid staking tokensOther correlated assetsChoosing your rangeWhen creating a position, Aqua automatically suggests range presets based on the type of assets you're providing.
For volatile pairs, the available presets are wider to accommodate larger price movements.
For correlated assets, the presets are much narrower because those assets are expected to remain close in value.
If you have a specific market view, you can also define your own custom range.
Fees are reinvested automaticallyOne feature applies to every Aqua position.
Any swap fees your position earns are automatically reinvested into your liquidity. There is nothing to claim or manually compound. Where a protocol fee applies, reinvested amounts are net of that fee.
Keep in mindOnce a position is created, its parameters cannot be edited.
If you later decide to change the range, fee settings or other configuration, you'll need to close the existing position and create a new one.
This keeps every deployed position immutable while making its behavior predictable on-chain.
Which position should you choose?There isn't a single "best" position type.
Choose Full range if you want the simplest, lowest-maintenance experience.Choose Concentrated liquidity if you're comfortable selecting a price range in exchange for greater capital efficiency.Choose Pegged when providing liquidity for assets that are designed to stay close in value.Whichever position you create, Aqua lets you back it with the same wallet balance through shared liquidity while keeping your assets in your wallet until a qualifying swap is executed. As with any form of liquidity provision, all position types remain exposed to market risk, and fees are not guaranteed.
Explore Aqua and start creating liquidity positions at 1inch.com/aqua.
Disclaimer: This content is provided for informational purposes only. Nothing in this material constitutes financial, investment, legal, or tax advice, or a recommendation to enter into any transaction. Interacting with Aqua involves risk, including the possible loss of all funds involved.
1inch has joined the SEAL Whitehat Safe Harbor Agreement, enabling whitehat hackers to step in effectively when needed.
In DeFi, attacks don’t happen slowly. They unfold in real time. Funds move in minutes. And in that narrow window, the difference between loss and recovery often comes down to whether someone is willing - and able - to act immediately. That “someone” is often a white hat hacker.
What are white hats and what’s their role in DeFi?White hat hackers are security researchers who identify vulnerabilities in protocols - not to exploit them, but to prevent damage.
In traditional software, their role is relatively straightforward:
find a bugreport itreceive a bountyIn DeFi, the stakes are higher.
Protocols are live, permissionless and often hold hundreds of millions in user funds. When an exploit begins, there may be no time to report and wait. The only way to stop the attack may be to act immediately - interacting directly with smart contracts, moving funds, or front-running the attacker.
In other words, white hats may need to behave like attackers in order to stop one.
What is SEAL?Security Alliance (SEAL) is a crypto security nonprofit founded by samczsun, one of the most respected figures in the DeFi security space.
The organization focuses on improving how the industry responds to threats in real time. Its initiatives include:
SEAL 911 - an emergency response hotline for active exploitsSEAL Intel - a threat intelligence sharing networkSEAL Frameworks - open-source security playbooksSEAL Certifications - certifications for operational securityThe goal is to move beyond static security and toward coordinated, rapid response.
What is the Safe Harbor Agreement?The Safe Harbor Agreement is designed to solve a very specific problem: enabling white hats to act during active exploits without fear of legal consequences.
At its core, it is a simple commitment from a protocol:
If you step in to protect funds during a live exploit and follow the rules, we will not pursue legal action against you.
This creates a defined framework for emergency intervention, where speed is critical and traditional processes are too slow.
How the agreement works in practiceThe Safe Harbor Agreement establishes clear boundaries for white hat action.
White hats are allowed to intervene - but only under strict conditions.
They can act only during an active exploit, not for general testing or vulnerability research. The agreement is explicitly limited to situations where funds are at immediate risk.
They must contact the protocol’s security team as soon as intervention begins, ensuring coordination and transparency. For 1inch, the designated contact is 1inch Security ([email protected]).
Any funds recovered must be returned in full within 72 hours to a designated recovery address designated in the adoption. This ensures that rescued assets are secured quickly and do not become a secondary risk.
White hats are also incentivized. Successful interventions are rewarded with a bounty - typically a percentage of the recovered funds, capped at a predefined amount.
At the same time, the agreement provides legal protection, reducing the risk of liability for good-faith actions taken under these conditions.
Importantly, researchers can remain pseudonymous, identifying themselves to the protocol without public disclosure. Bounty payment is subject to sanctions and AML screening under 1inch’s adopted terms.
What the agreement does - and does not doThe Safe Harbor Agreement is not a guarantee of recovery.
It does not:
ensure that funds can be savedbind regulators or third partiesreplace traditional security practicesWhat it does is remove a key barrier to action.
It gives white hats the confidence to step in when it matters most—during the narrow window where intervention can still make a difference.
From passive security to active defenseDeFi security has traditionally focused on prevention: audits, bug bounties, and responsible disclosure.
But as exploits become more sophisticated, prevention alone is not enough.
The industry is moving toward active defense:
real-time monitoringcoordinated responserapid interventionWhite hats are central to this shift. They are often the first to detect anomalies and the only actors capable of reacting fast enough to mitigate damage.
The Safe Harbor model formalizes their role—not as external observers, but as participants in emergency response.
A growing industry standardThe Safe Harbor Agreement has already been adopted by leading protocols, including Uniswap, zkSync, Pendle, PancakeSwap and Balancer.
Its adoption reflects a broader recognition: DeFi needs mechanisms that enable action, not just analysis.
As protocols become more complex and interconnected, the ability to respond quickly to exploits becomes a critical layer of security.
Building safer DeFiBy adopting the SEAL Whitehat Safe Harbor Agreement, 1inch is aligning with this emerging standard. The adoption was approved through 1inch DAO governance.
The agreement provides clear guidelines for action, increases the protection of user funds and demonstrates a commitment to proactive security - empowering white hats to act when it matters most. The covered protocols (including the 1inch Aqua Protocol), the designated recovery addresses and the bounty terms are set out in 1inch’s adoption record (1IP-104).
For 1inch news and updates subscribe to our newsletter
Disclaimer: This article is a summary for informational purposes only and does not constitute legal advice. The terms of the SEAL Whitehat Safe Harbor Agreement and 1inch’s published adoption record govern in all cases; nothing in this article expands or modifies them.
Liquidity providers earn fees by taking on risk - but not every risk is worth taking. Here's how to evaluate the real economics of liquidity provision and why 1inch Aqua changes an important part of the risk equation.
Every LP’s position is a trade-off. By providing liquidity, you're effectively selling volatility in exchange for fees. The key question is always the same: Do the fees compensate you for the risks you're taking?
Sometimes they do. Often they don't. The problem is that many LPs never measure it. Understanding where fees come from - and how 1inch Aqua’s design helps avoids the risk of depositing and locking assets in an external contract - is essential before committing capital.
Impermanent loss is not a bugThe biggest risk for most LPs is impermanent loss. In a traditional AMM, the pool constantly rebalances your position. It automatically sells assets that are rising in price and buys assets that are falling. As a result, your portfolio gradually drifts away from what you would have earned by simply holding the same assets.
For example, in a 50:50 liquidity pool:
if one asset doubles in price, your position underperforms simple holding by about 5.7%;if it increases fivefold, the gap grows to roughly 25%.This isn't a flaw in the protocol. It's how AMMs work.
A more accurate way to think about this today is through loss-versus-rebalancing (LVR). Every time the market moves, arbitrageurs trade against the pool until its prices catch up with the broader market. In other words, LPs continuously quote prices that are slightly behind the market, while arbitrageurs capture the difference. Trading fees are meant to compensate LPs for this loss - but whether they actually do depends on market conditions.
More volume doesn't always mean better resultsMany LPs assume higher trading volume automatically leads to better results for LPs. Not necessarily.
Retail order flow is generally beneficial because it generates fees without consistently exploiting stale prices. Arbitrage flow is different. While it also generates fees, it primarily exists to extract pricing inefficiencies from the pool.
As a result, a pool can process billions in trading volume while still delivering disappointing results to LPs.
Looking at APY or volume alone rarely tells the whole story.
Stable pairs aren't always stablePairs that appear low-risk can hide significant tail risk.
Stablecoin pools or liquid staking token pairs may generate modest, consistent fees for months. Then a depeg occurs.
When that happens, the pool naturally shifts your position toward the weaker asset. By the time prices stabilize, you may end up holding mostly the token that the market no longer wants.
Small, steady fees often come with rare but potentially severe downside.
Smart contract audits significantly improve security but cannot guarantee the absence of vulnerabilities. Oracle mechanisms can be manipulated under certain conditions. Governance also deserves attention: a protocol secured by a multisig with a timelock presents a different risk profile than one controlled by a single externally owned account.
It's also important to understand where yield comes from.
If most of an attractive APY is funded by token emissions rather than actual trading activity, you're effectively being compensated with dilution. Sustainable yield should have a clear economic source.
A useful rule: if it's unclear where the yield comes from, the yield may be coming from you. For a structured overview of how 1inch approaches protocol security, audits and operational risk controls, see the 1inch risk management whitepaper.
Don't overlook approvalsOne of the most common - and most overlooked - risks has little to do with liquidity provision itself.
Unlimited token approvals can expose your wallet long after you've stopped using a protocol. If a contract is compromised, an unlimited allowance may allow an attacker to transfer approved tokens without requiring another transaction from you.
Old approvals are often forgotten, making them one of the most frequent operational security issues in DeFi.
Regularly reviewing and revoking unnecessary approvals is a simple habit that can significantly reduce risk.
Managing LP riskNo strategy eliminates risk, but disciplined risk management can improve long-term outcomes.
These are some factors LPs may consider when assessing a position:
Position size can be viewed in relation to downside scenarios, rather than expected APY alone.Different pools carry different dominant risks. Volatile pairs are more exposed to price movements, while correlated assets may carry tail risks such as depegs.Performance can also be compared with simply holding the same assets, which may provide a more informative reference point than the APY shown in an interface.Token approvals are another area worth reviewing periodically, with permissions that are no longer needed potentially revoked.Risk management starts with understanding what you're actually being paid for.
How Aqua changes the custody modelMost of the risks discussed above apply to liquidity provision regardless of the protocol.
However, one important aspect depends entirely on protocol design: what happens to your assets while they provide liquidity.
In traditional AMMs, tokens are deposited into liquidity pools and remain locked until withdrawn.
1inch Aqua takes a different approach. Instead of depositing assets into a pool, liquidity positions are quoted directly against the balances in your wallet. If a swap matches your position, the LP receives the trader's input tokens directly into their wallet, while the trader receives the LP's output tokens directly from that wallet. If no swap occurs, the assets never leave your wallet.
This design changes several aspects of operational risk.
Since assets remain in your wallet, there's nothing to withdraw, exposure is limited to the assets actually held there, and token approvals can be revoked at any time on a per-token, per-network basis. Market and protocol risk stay the same no matter what custody model is used. What's different here is narrower: this design avoids the specific risk of depositing and locking assets in an external contract.
That doesn't mean market risk disappears.
LPs are still exposed to price movements, fees are never guaranteed, and Aqua, while audited, is still a relatively new protocol. Its audit history and the broader security posture are described in the 1inch risk management whitepaper. By keeping assets in users' wallets until execution, Aqua narrows custody-related risk specifically, without changing the market and protocol risks described above.
Know what risk you’re acceptingLiquidity provision isn't passive income. It's an active market position.
Every LP earns fees by taking on risk. The objective isn't to avoid risk entirely - it's to understand which risks you're accepting, how you're being compensated, and whether the trade-off makes sense.
The better you understand those trade-offs, the better equipped you'll be to build a sustainable liquidity strategy.
For 1inch news and updates subscribe to our newsletter
Disclaimer: This article is for general educational purposes only and does not constitute financial, investment, legal, or tax advice, nor a recommendation or solicitation to engage in any transaction. Providing liquidity involves significant risk, including the potential loss of some or all of the assets deposited or held. Past performance and historical examples referenced here are not indicative of future results. 1inch Aqua is a relatively new protocol; smart contract audits reduce but do not eliminate the risk of vulnerabilities, and no statement in this article should be read as a guarantee of asset safety or return. Availability of 1inch products may be restricted in certain jurisdictions; it is your responsibility to confirm that your use complies with the laws applicable to you. Please conduct your own research and consult an independent professional advisor before making any decisions involving digital assets.
The US Senate has pushed consideration of the CLARITY Act to September, narrowing the window for crypto market-structure legislation this year. For DeFi, 1inch Senior Legal Counsel Maylea Ma says an imperfect but protective framework is still preferable to continued regulatory uncertainty.
The CLARITY Act will have to wait. The US Senate did not take up the crypto market-structure bill before its August recess, pushing the next possible action to September. The delay is significant because lawmakers are running out of time before the November midterms, when passing major legislation becomes considerably harder.
For DeFi, the stakes go beyond the timing of one vote. Maylea Ma, Senior Legal Counsel at 1inch, argues that the current bill contains important protections for non-custodial protocols, software developers and self-custody. The question now is whether lawmakers can preserve those provisions and pass the legislation this year.
Why passage this year mattersMaylea says passing the CLARITY Act this year is very important, even if some parts of the legislation remain imperfect.
One point of contention has been ethics provisions. But Maylea notes that those rules are essentially self-contained and do not change how a non-custodial aggregator such as 1inch would be regulated.
The provisions that matter most for DeFi are already in the merged text: protections under the Blockchain Regulatory Certainty Act, safeguards for software developers and self-custody, and exclusions that recognize the difference between non-custodial software and traditional financial intermediaries. Some of these protections were narrowed during earlier amendment rounds, which makes preserving the remaining language in the current text all the more important.
For Maylea, imperfect ethics language should therefore not be enough to derail the broader framework.
“The alternative to imperfect-but-enacted is not perfect-but-enacted,” she says. “It is no law at all.”
The August recess had been widely viewed as an important deadline because the legislative window becomes much tighter as the midterms approach. With the vote now pushed back, September becomes the next critical opportunity.
Is an imperfect framework better than uncertainty?For 1inch, Maylea says yes - as long as the DeFi-specific protections remain intact.
A federal law would turn today’s favorable but reversible regulatory guidance into a more durable framework. Agency interpretations can change under a new administration or new regulators. Legislation is harder to reverse.
A law could also reduce reliance on case-by-case enforcement and provide greater consistency across US states.
The qualification is important. “Imperfect” does not mean the industry should support any bill simply to get legislation passed.
Maylea points to Coinbase’s temporary withdrawal of support earlier this year as evidence that the industry can and should push back if legislation becomes affirmatively worse for DeFi than the status quo.
On the current text, however, she believes the DeFi provisions remain protective enough to justify supporting passage.
What happens if the CLARITY Act fails?If negotiations break down, DeFi would remain dependent on the existing regulatory environment.
That would mean continued reliance on agency interpretations that can be reversed, continued uncertainty around enforcement and continued differences between state-level regulatory regimes.
For 1inch, the practical approach would not suddenly change. The non-custodial model would continue operating under the same conservative legal posture centered on self-custody.
What would remain missing is statutory certainty.
Without legislation, future administrations and regulators could reinterpret how existing financial laws apply to DeFi. Developers would continue operating without the type of explicit legal protections that the current CLARITY Act text aims to provide.
Failure this year could also stall legislative momentum until after the November 2026 midterms. The next Congress may have a different composition and a different appetite for crypto legislation.
September becomes the next testThe CLARITY Act has not failed, but the clock is running.
The Senate delay gives negotiators more time to resolve outstanding disagreements. It also leaves less time to move the bill through the remaining legislative process before election politics take over.
For Maylea, the priority is not a perfect bill at any cost. It is a durable framework that preserves meaningful protections for DeFi developers, non-custodial infrastructure and self-custody. September will show whether Congress can deliver one.
For more insights from 1inch subscribe to our newsletter
Disclaimer: This article discusses pending legislation and reflects policy perspectives shared by 1inch Senior Legal Counsel Maylea Ma. It does not constitute legal advice. Statements reflect the status of the legislation as of early August 2026. The CLARITY Act remains subject to change as it moves through the legislative process.
This article explains why total value locked (TVL) may not always be a meaningful metric and why, in the context of liquidity provision, it may be more accurate to speak of total value unlocked.
You added liquidity to a pool and helped increase its total value locked (TVL). But how much does TVL really tell you about whether your liquidity is working?
Locked capital is not the same as active capital. That is where 1inch Aqua introduces a different approach: shared liquidity. Instead of tying capital to one pool or strategy, Aqua lets multiple strategies draw on the same balance, subject to execution constraints.
That means more chances to see activity, in more markets, across more token pairs. Instead of thinking about ‘total value locked’, we can think instead about ‘total value unlocked’: the amount of potential liquidity we’re creating across our positions, rather than how much we’re removing from circulation elsewhere.
To see why this matters, compare 1inch Aqua with DeFi’s most common liquidity model: classic AMM pools.
How classic AMM pools workIn a classic AMM, liquidity providers deposit tokens into a pool that acts as a shared pot of capital. Traders swap directly against this pool, and fees are generally distributed pro-rata, depending on protocol design.
This design creates key properties:
Liquidity is typically tied to a single venueOnce deposited, capital cannot be used elsewhere.
Capital only earns when trades occurLiquidity generates fees only when swaps happen in that pool, without active management by the provider.
Fees are sharedAnyone providing liquidity at the right time receives a portion of fees, regardless of how long they’ve been in the pool.
MEV and fee extraction
In classic AMMs, fees are paid into the pool and distributed to everyone who has liquidity active at the moment a trade occurs. Fee ownership depends on timing rather than duration of exposure. As a result, AMMs are vulnerable to fee extraction strategies such as just-in-time liquidity, where bots add liquidity immediately before a large trade and remove it right after, capturing fees without taking meaningful market risk. Long-term LPs see their share of fees diluted even though they provided liquidity over time.
How Aqua differs from classic AMM pools
Aqua is not another liquidity pool. It is a shared liquidity layer that lets you use one wallet balance across multiple positions at once. Your tokens are not deposited into Aqua contracts. They stay in your wallet and move only when a taker swap is executed against one of your positions. This design creates a very different set of properties.
Liquidity is not pooledTokens are never deposited into a shared AMM. They stay in the LP’s wallet and are accessed by strategies only when needed through atomic execution.
Each strategy belongs to one LPStrategies are individually owned, and each LP controls their own positions. Multiple strategies can use the same LP balance, improving capital efficiency.
Reduced JIT or fee snipingBecause there is no on-chain deposit or withdrawal into a shared pool, the common JIT vectors seen in pooled AMMs largely fall away - the timing games that enable classic JIT liquidity have no direct equivalent in this design.
Total Value Locked vs Total Value Unlocked
Classic AMMs are built around TVL. Capital is measured by how much is locked inside pools, even if much of it is not being used.
Aqua is built around TVU. Capital is measured by how much of it is actively available for execution across markets. That difference is subtle, but it changes everything.
Aqua does not try to replace AMMs. It changes how liquidity connects to them.
Instead of asking LPs to choose one pool, one range or one strategy, Aqua lets a single balance serve all of them. That is what it means for liquidity to be truly unlocked. As with any form of liquidity provision, Aqua positions remain exposed to market risk, and fees are not guaranteed.
Activate your DeFi liquidity with 1inch Aqua.
Disclaimer: This content is provided for informational purposes only. Nothing in this material constitutes financial, investment, legal, or tax advice, or a recommendation to enter into any transaction. Interacting with Aqua involves risk, including the possible loss of all funds involved.
Ondo’s tokenized Treasury product USDY, bringing yield-bearing dollar exposure to one of DeFi’s largest ecosystems, is now available via 1inch.
Tokenized US Treasuries are moving deeper into DeFi. Ondo’s US Dollar Yield Token, USDY, is now natively available on BNB Chain and supported by 1inch. Users can swap USDY through 1inch, while builders can access it through 1inch APIs.
With more than $2.15 bln in total asset value, USDY is one of the largest tokenized US Treasury products onchain. Its expansion to BNB Chain gives the asset access to another major DeFi ecosystem and creates new opportunities for trading, collateral and treasury management.
What is USDY?USDY is a tokenized note offered by Ondo to eligible non-US individuals and institutions.
It is secured by a portfolio of short-term US Treasuries and bank demand deposits. The underlying assets are held by a collateral agent, while the product is designed to give eligible global investors access to US dollar-denominated yield and institutional-grade protections.
Unlike a conventional dollar-pegged stablecoin, USDY is yield-bearing. Unlike a conventional dollar-pegged stablecoin, USDY's value is not fixed to the dollar. Its price reflects the value of the underlying short-term US Treasuries and cash instruments over time, and can move up or down.
USDY is designed for use across DeFi, including cash and treasury management, lending, borrowing, payments, trading and collateral. On BNB Chain, eligible users can mint and redeem USDY instantly, reducing wait times and making it easier to manage positions. A cross-chain bridge also enables transfers between BNB Chain and other supported networks.
For developers, USDY can serve as a composable yield-bearing asset across BNB Chain applications. It can be integrated into lending markets, trading products, liquidity strategies and treasury-management tools, or used as collateral where supported.
USDY expands to BNB ChainThe BNB Chain launch introduces three key components:
native USDY on BNB Chaininstant minting and redemptiona cross-chain bridge connecting BNB Chain with other supported networksNative issuance means eligible users can access USDY directly on BNB Chain rather than first acquiring it elsewhere and bridging it across.
Instant minting and redemption reduce waiting periods and make it easier to manage positions. Meanwhile, the bridge allows USDY to move between BNB Chain and other networks in Ondo’s growing multichain ecosystem.
USDY is also available on Ethereum and is tradable there via 1inch, as well.
USDY swaps through 1inchOn 1inch.com, users can swap into or out of USDY through available liquidity on BNB Chain and Ethereum. 1inch routing searches across liquidity sources to find an efficient route rather than requiring users to check individual venues manually.
For wallets, applications and institutional platforms, USDY swaps can also be integrated through the APIs available on 1inch Business.
1inch does not issue USDY or manage its reserves, yield, minting, redemption or cross-chain bridge. Those functions remain with Ondo. The role of 1inch is to provide swap and routing infrastructure that helps users and applications access the token through available onchain liquidity.
Why routing matters for tokenized assetsIssuing an asset onchain is only part of the journey. To become useful across DeFi, tokenized assets also need connectivity and liquidity.
Users need practical ways to enter and exit positions. Developers need infrastructure that allows those assets to interact with wallets, trading interfaces and other applications. Liquidity may be distributed across different venues, making the most obvious route not always the most efficient one.
1inch helps connect USDY with the wider DeFi market by supporting swaps through its aggregation and intent-based infrastructure.
As tokenized Treasury assets expand across chains, this infrastructure can help make them more accessible, portable and useful across the onchain economy.
Explore USDY on 1inch.
Disclaimer: This content is for general information purposes only and does not constitute financial, investment, tax or legal advice. USDY is subject to eligibility requirements and may not be available in the US or other restricted jurisdictions. Holding or interacting with tokenized assets involves risk, including the possible loss of funds.
Shared liquidity is an innovative DeFi liquidity model that lets the same wallet balance support multiple strategies at once.
1inch Aqua brings you shared liquidity: a new type of liquidity provision, in which the same token balance can back multiple liquidity positions while remaining in the user's wallet, without the need to be deposited into a liquidity pool.
What does shared liquidity mean in practice? How does it work? And how does it change the results you can expect?
Why traditional liquidity falls shortFor years, automated market makers (AMMs) have been the foundation of DeFi trading.
The model is simple. LPs deposit tokens into a liquidity pool, traders swap against that pool and LPs earn fees in return.
This helped DeFi grow because anyone could become a liquidity provider without relying on centralized market makers.
But the model also has limitations.
Each deposit is tied to a specific pool, trading pair or price range. If an LP wants to provide liquidity across several markets, the balance must be divided into multiple positions. Once the tokens are deposited, they remain committed to those positions until they are withdrawn.
As a result, capital often becomes fragmented. Some positions may see heavy trading while others receive little or no activity. A protocol can report high TVL, yet only a fraction of that liquidity may actually support trades when demand appears.
What is shared liquidity?Shared liquidity, pioneered by 1inch Aqua, is a liquidity provision model that allows the same token balance to support multiple liquidity positions or strategies simultaneously without requiring the assets to be deposited into a liquidity pool.
Instead of transferring tokens into pool contracts, LPs approve their wallet balance for liquidity provision. Multiple positions can reference that same approved balance.
The assets remain in the wallet until one of those positions is used to execute a swap.
This changes an important assumption in DeFi. Rather than asking LPs to decide in advance exactly where their capital should sit, shared liquidity allows one balance to remain available across several opportunities at the same time.
Shared liquidity replaces deposits with approvals.
Rather than moving tokens into a pool, an LP authorizes a wallet balance to back one or more liquidity positions.
Those positions define trading parameters such as the token pair, price range or fee settings. However, they do not hold the tokens themselves.
If a swap matches one of the positions, the LP receives the trader’s input tokens directly into their wallet, while the trader receives the LP’s output tokens directly from that wallet. In other words, the assets move into and out of the LP’s wallet as part of the swap. If no swap occurs, the tokens never leave the wallet.
Because every position references the same available balance, LPs do not have to divide their assets before knowing where trading activity will occur.
Why shared liquidity mattersThe biggest advantage of shared liquidity is better capital utilization.
In traditional AMMs, one balance often becomes fragmented across multiple positions. Each position is backed by only part of the LP's capital, regardless of where trading demand eventually appears.
Shared liquidity removes that constraint. The same wallet balance can support multiple positions simultaneously, allowing liquidity to remain available across more markets without being pre-split.
This also reduces liquidity fragmentation. Instead of creating separate deposits for every pool, strategy or trading opportunity, LPs can manage multiple positions from a single balance.
For developers, shared liquidity opens the door to more flexible liquidity infrastructure that does not depend on isolated pools for every new application.
Self-custody remains intactShared liquidity also changes where assets are held.
In traditional liquidity pools, tokens leave the wallet and are deposited into a smart contract. LPs no longer hold those assets directly while they provide liquidity.
With shared liquidity tokens never leave your wallet: the settlement between the LP and the taker happens atomically: on a wallet-to-wallet basis. This preserves self-custody throughout the process. LPs keep control of their assets, and the approved balance can be updated or revoked according to the protocol's rules.
For many users, this makes liquidity provision feel closer to the wallet-native experience that originally attracted them to DeFi.
It can also reduce certain risksTraditional pooled liquidity introduces more than capital inefficiency.
It can also expose LPs to strategies such as Just-in-Time (JIT) attacks. In these attacks, sophisticated bots add liquidity immediately before a large swap and remove it immediately afterward, capturing trading fees that would otherwise have gone to long-term liquidity providers.
Research has estimated that JIT attacks can reduce LP fee income by as much as 44%. Shared liquidity models can be designed differently. Because liquidity positions are no longer shared pool deposits, they can reduce or eliminate opportunities for this type of fee-sniping strategy, depending on the protocol's architecture. For instance, in 1inch Aqua, JIT is substantially reduced by design.
A new direction for DeFi liquidityShared liquidity is still an emerging concept, but it reflects a broader shift in how DeFi thinks about liquidity.
The industry is moving beyond simply measuring how much capital is locked on-chain. Increasingly, the focus is on how efficiently that capital can support trading when demand appears.
Rather than locking assets into isolated pools, shared liquidity aims to make one balance available across multiple positions while preserving self-custody.
Shared liquidity on 1inchThe shared liquidity model was first introduced by 1inch Aqua, a self-custodial liquidity layer built around this approach.
Instead of depositing tokens into pools, LPs approve their wallet balance to support multiple liquidity positions simultaneously. Their assets remain in their wallet and are transferred only when a qualifying swap is executed.
This allows one balance to back multiple positions while helping reduce liquidity fragmentation and improving capital utilization. As with any form of liquidity provision, positions remain exposed to market risk, and fees are not guaranteed.
Explore 1inch Aqua and discover how shared liquidity is reshaping DeFi liquidity provision.
Disclaimer: This content is provided for informational purposes only. Nothing in this material constitutes financial, investment, legal, or tax advice, or a recommendation to enter into any transaction. Interacting with Aqua involves risk, including the possible loss of all funds involved.
Recently, 1inch’s Chief Legal Officer Orest Gavryliak joined Cointelegraph’s Chain Reactions to discuss the situation around Clarity Act.
For years, the crypto industry has faced the same problem: innovation moved fast while regulation struggled to keep up. The result? A patchwork of rules, legal uncertainty and, in the US, regulation by enforcement.
That may finally be changing. In a recent episode of Cointelegraph's Chain Reaction, 1inch Chief Legal Officer Orest Gavryliak explained why the US Clarity Act could become a watershed moment not only for DeFi, but for the entire digital asset industry. If passed, the legislation would establish the first comprehensive regulatory framework for crypto, including decentralized, non-custodial protocols that have long operated without clear legal guidance.
Moving beyond regulation by enforcementAccording to Orest, the industry's biggest challenge has never been regulation itself. It has been the absence of clear rules.
"Just give us rules," he said, describing the uncertainty that DeFi builders have faced for years. Without established playbooks, projects have been forced to navigate legal gray areas while trying to innovate responsibly.
The Clarity Act aims to change that by replacing enforcement-driven oversight with a defined legislative framework covering crypto, DeFi and decentralized protocols. Unlike existing regulations that largely focus on custodial businesses such as exchanges and stablecoin issuers, the proposed law recognizes that non-custodial protocols operate fundamentally differently.
Why DeFi needs its own frameworkOne of the biggest shortcomings of previous regulatory efforts is that decentralized protocols simply do not fit into traditional financial categories.
For years, regulators have attempted to apply rules designed for custodians and financial intermediaries to protocols that never take custody of user assets. Orest argues that this mismatch has been the root cause of much of the industry's legal uncertainty.
Instead of forcing DeFi into legacy frameworks, the Clarity Act creates dedicated regulatory "boxes" for decentralized technologies and non-custodial services. That distinction could give developers and businesses the certainty they need to continue building.
Building ahead of the rulesOrest noted that 1inch has actively participated in discussions with policymakers and industry working groups while sharing the company's approach to compliance and risk management.
According to him, 1inch has been building its risk management and compliance infrastructure in the same direction the Clarity Act is heading, including through publicly documented risk management frameworks. While the text is still evolving through the legislative process, he believes this proactive approach positions the company well as the final framework takes shape.
Compliance without compromising decentralizationOne topic that continues to generate debate is KYC requirements for DeFi.
Orest argued that blockchain-native risk management can often provide stronger protection than traditional identity verification alone. Modern DeFi platforms can combine onchain analytics, machine learning, wallet risk assessment, behavioral analysis and law enforcement cooperation to identify malicious actors.
At the same time, he emphasized that 1inch is prepared to comply with whatever framework lawmakers ultimately adopt.
"If you're putting that inside the rulebook, we're OK to implement and obey," he said.
Protecting open-source developmentThe interview also touched the wider debate about legal exposure for open-source software developers.
Orest stressed that developers should not face liability simply for publishing open-source code. Regulatory obligations, he argued, should reflect the degree of control a person actually exercises over user assets and transactions, rather than the act of writing and releasing code.
That distinction is particularly important for projects like 1inch, which develop open-source infrastructure while also operating user-facing products. Clear legal standards would help define where protocol development ends and business responsibilities begin.
A global impactThe significance of the Clarity Act extends far beyond the United States. Orest believes the legislation could go beyond Europe's MiCA framework by covering a much broader range of crypto businesses, including DeFi and emerging technologies such as AI-powered financial services. Rather than regulating only centralized players, the Act seeks to provide legal certainty across the entire crypto ecosystem. If successful, the framework could become a model for regulators worldwide.
One financial systemFor Orest, the long-term vision goes well beyond regulation. He believes clear rules could accelerate the convergence of traditional finance, centralized finance and DeFi into a single financial ecosystem built on modern infrastructure.
"We need new rails," he said. "I really believe that Clarity will make CeFi, TradFi and DeFi be one thing, which is the new finance."
Disclaimer: This article summarizes views shared during a public discussion of pending legislation. It reflects personal policy perspectives, does not constitute legal advice, and the Clarity Act remains subject to change as it moves through the legislative process.
For more insights from 1inch subscribe to our newsletter
The three-month campaign runs through Merkl across 80+ 1INCH markets, with BNB Chain named as the first co-incentive partner.
1inch launched its Aqua liquidity protocol to the public on July 28, backing the release with a rewards program funded with 10 million 1INCH from the 1inch Foundation and 500,000 USDC from the 1inch DAO, the company said.
The program, called 1inch Network Incentives, is delivered through incentive platform Merkl and led by Degensoft Ltd, a British Virgin Islands entity. It is designed to drive liquidity and swap activity across supported pairs on Aqua, which went live on 13 EVM chains including Ethereum, Arbitrum, Base, BNB Chain and Robinhood Chain, following a developer-only launch in November 2025.
Shared Liquidity LayerAqua is a self-custodial shared liquidity layer: instead of depositing tokens into pools, a liquidity provider approves a wallet balance that multiple positions can quote against. When a swap order matches a position, the protocol pulls the tokens from the wallet and pushes back the received tokens and fees in one atomic transaction. Until that moment, the tokens stay in the provider's wallet.
The design lets the same balance back several quotes at once — $100,000 in a wallet can support three positions collectively quoting $300,000, with execution capped by what the wallet actually holds. Positions can be full range, concentrated or pegged, with no lock-ups.
"The liquidity provisioning space is broken, but you only see how broken once there's an alternative," said 1inch co-founder Sergej Kunz in the announcement. "With Aqua, liquidity providers no longer have to accept the inefficient pool structure they've put up with for years."
Case Against Pools1inch is aiming the launch at what it says is widespread waste in DEX liquidity. Per onchain research by Dune commissioned by 1inch, 85% of concentrated liquidity across major DEXs sat underutilized in the first half of 2026 — roughly $1.6 billion of the $1.84 billion tracked — including about $542 million fully out of range in an average week, for an estimated $150 million in foregone fees per year.
Aqua has been through eight independent audits, by OpenZeppelin, Bailsec, Hashlock, Hexens, MixBytes, Nethermind, Theori and Decurity. Providers still bear market and smart-contract risk, and swap fees are not guaranteed; the design bounds exposure to tokens actually held, and single-owner positions remove the shared fee event that just-in-time liquidity bots exploit in pooled AMMs.
Incentives ProgramsIncentive programs funded in native tokens are DeFi's standard playbook for bootstrapping liquidity, and they tend to buy volume only as long as emissions last. The more consequential test is whether Aqua's registry model — quoting from wallets rather than locking capital in pools — retains providers once the 10 million 1INCH runs out. If capital efficiency claims hold, professional market makers get pool-level reach without custody handoff, which is the audience 1inch needs to win over from established AMMs.
1inch Aqua activates DeFi liquidity. Back multiple positions with one token balance and keep your assets in your wallet until swap.
DeFi liquidity isn’t working. Most tokens in most pools do nothing most of the time. You still bear the risk, without the reward DeFi was built on. 1inch Aqua is here to solve that.
Now you can back multiple liquidity positions with the same token balance, without depositing your assets in a pool, while your tokens safely remain in your wallet and any swap fees are protected from JIT attacks.
That means assets can stay active across more markets and positions from a single balance instead of being split across fragmented positions.
We call this approach Shared Liquidity.
We released the protocol for developers last November. Now, 1inch Aqua is available for all users to access at 1inch.com/aqua.
The liquidity problemMost DeFi liquidity sits idle most of the time. A protocol can show high TVL, but only part of that liquidity may be useful when swaps actually happen. Liquidity can sit outside the active price range, earn no fees and still carry exposure to market movement.
And even if it does see activity, LPs’ liquidity is fragmented. They have to split limited balances across protocols, pairs and price ranges. No single position has the full balance behind it, reducing capital utilization.
To make things worse: tokens deposited into a pool leave the LP’s wallet, meaning their utility is lost, and bringing all the security and control issues that come when you give up custody of your tokens.
In addition, LPs’ tokens are exposed to attacks from JIT (just-in-time) bots that skim fees the LPs should have earned.
1inch Aqua addresses all of these problems.
What 1inch Aqua is1inch Aqua is a self-custodial shared liquidity layer. It enables your liquidity to stay active across many positions, while your tokens stay in your wallet.
It works as a registry: a user connects their wallet to approve a token balance and create liquidity positions that can access that balance. The Aqua protocol tracks that balance, and when it receives a swap order that meets the criteria of the position, it pulls the requested tokens from the wallet and pushes back received tokens and fees in a single atomic transaction.
Otherwise, the user’s funds remain in their wallet and completely under their control. Tokens are not deposited into Aqua - or any other - contracts. They remain in your wallet and move only when a taker swap fills against a position.
How Aqua works1inch Aqua lets you create positions by choosing the pair, range and swap fee. A position can be full range, concentrated or pegged, depending on the selected pair and position type. You can open and close positions yourself, with no lock-up.
Your exposure is capped by the tokens you actually hold, not by the theoretical combined size of every position you create. If your wallet cannot cover a swap, Aqua simply does not call on your funds.
From today, you can create positions across 13 EVM chains, including Ethereum, Arbitrum, Base, Robinhood Chain and BNB Chain.
Why shared liquidity matters1inch Aqua changes the way you think about liquidity provision. In a traditional model, providing liquidity often means splitting tokens between multiple pools and positions. That can reduce capital utilization.
With Aqua, the same wallet balance can stand behind many positions. This gives you better capital utilization and more flexibility.
This is especially important in a multi-chain DeFi market, where liquidity is spread across venues, networks and trading flows.
Self-custody by design1inch Aqua is built around self-custody. You do not deposit tokens into a pool. You do not hand custody to Aqua. Your tokens remain in your wallet until a swap fills.
Approvals are handled per token and per chain, and they can be revoked. Your actual exposure is still limited by your wallet balance.
This matters because liquidity provision has often required LPs to move tokens into a specific pool or contract. 1inch Aqua keeps you closer to the wallet-native DeFi model: keep your keys, keep your tokens, choose your positions.
Risk-controlled liquidityWe’re rapidly moving toward risk-controlled and regulated DeFi. And Aqua is the first risk-controlled liquidity venue where every swap is settled by verified counterparties, while you keep full self-custody of your tokens.
Why is Aqua liquidity risk-controlled? Every swap is executed by a verified counterparty - a market maker or arbitrage bot that has been verified, enforced on-chain at swap time. Therefore, LPs are not exposed to unverified counterparties.
And the product itself has been audited by 8 independent teams, including Hexens, OpenZeppelin, Bailsec and Nethermind.
JIT protectionAqua liquidity is protected from JIT fee sniping by design. In normal pooled AMMs, JIT bots can insert liquidity right before a large swap and pull it out right after, skimming the fees that waiting LPs should have earned. Due to JIT attacks, LPs could lose up to 44% of their fee income. An Aqua position has a single owner, making it impossible for a JIT bot to carry out such an attack.
The future of liquidityDeFi does not just need more liquidity. It needs more risk-controlled and useful liquidity - liquidity that can be active where demand appears. 1inch Aqua is designed to make that possible.
Disclaimer: Aqua involves risk, including loss of funds. It's built for experienced users - do your own research. Not financial advice.
DeFi has plenty of capital, but too much of it sits idle, fragmented or locked into single-purpose positions. The next step is not simply more TVL - it is liquidity that can actually work when and where demand appears.
DeFi does not lack liquidity. That may sound strange when users still face price impact, fragmented routes and pools that cannot handle larger trades efficiently. But the problem is not always the amount of capital sitting in DeFi. It is how that capital is used.
Huge amounts of liquidity are deposited in pools without doing meaningful work. Assets have been deposited on-chain, but are not consistently helping execution or earning fees.
At the same time, liquidity providers often have to divide one wallet balance across different protocols, pairs, price ranges and strategies. Once those tokens are deposited, they leave the wallet and become committed to individual pools or positions until the LP withdraws and reallocates them, or until the agreed lock period ends.
So the real question is no longer: how much liquidity is locked? It is: how much liquidity is actually usable?
Passive pools made DeFi openThe first major liquidity model in DeFi was simple: users deposit tokens into a pool, traders swap against that pool and liquidity providers earn fees.
This changed crypto markets. Anyone could provide liquidity. Anyone could trade. There was no need for a centralized order book or a traditional market maker.
The strength was openness. But the weakness was efficiency. In many pools, most capital is not close enough to the active trading range to be used often. It exists in the pool, but does not process many swaps. For liquidity providers, this creates a difficult reality: capital can be allocated, locked in a pool and still barely work.
Concentrated liquidity improved efficiency, but added complexityConcentrated liquidity tried to solve that problem. Instead of spreading liquidity across a broad price curve, LPs place capital in selected price ranges. When trades happen inside that range, capital works harder and can earn more fees.
This was an important improvement. But it shifted more responsibility to LPs. Now they need to think about ranges, price movement, volatility and rebalancing. If the market moves outside the selected range, the position may stop earning fees. The liquidity is still deposited, but it is no longer useful for current trading.
To cover more possible price movement, LPs may split their balance across several ranges. That gives them more positions, but each position is backed by only part of the original balance.
Concentrated liquidity therefore makes capital more targeted, but it can also make liquidity more fragmented and management more demanding.
Stable pools work well until the relationship breaksStable pools are built for assets expected to trade close to the same value: stablecoins, wrapped assets or similar tokens.
When the relationship holds, these pools can offer deep liquidity and low slippage. But the strength of the model is also its weakness. If one asset depegs or loses market confidence, the pool can become one-sided. LPs may end up holding more of the weaker asset. What looked like a low-volatility strategy can quickly become concentrated exposure to the token everyone else is trying to sell.
Stable pools solve a specific problem well. However, they do not solve the wider issue of idle and fragmented liquidity across DeFi. Capital is still deposited into an individual pool and committed to that pool’s specific purpose.
Managed strategies reduce manual workManaged LP strategies and vaults try to make liquidity provision easier. Instead of choosing ranges or managing positions manually, LPs deposit into a strategy that handles part of the work for them.
This can be useful. It reduces complexity and gives users access to more advanced liquidity management. But capital is still committed to one strategy. If that strategy is not capturing much flow, the capital may still sit underused. If better opportunities appear elsewhere, the LP often has to withdraw, move funds and reallocate them through additional transactions.
The interface becomes easier. The structural problem remains: liquidity is still locked into separate boxes.
Market makers help, but cannot cover everythingProfessional market makers use inventory, pricing systems and risk management to quote trades. In intent-based systems, professional participants can compete to fill orders and source liquidity from different venues.
This can improve execution, especially where public pools are too shallow. But market-maker liquidity depends on inventory and risk appetite. It may not cover every asset, every chain or every market condition. During volatility, spreads can widen and available liquidity can shrink.
Market makers are important. But they are not a full answer to DeFi’s liquidity problem.
Fragmentation is the root issueDEX trackers now count tens of millions of liquidity pools across hundreds of networks — the vast majority of them shallow or inactive.
For LPs, that creates a structural constraint: one deposited balance normally cannot back several opportunities at the same time. To participate across pools, ranges or strategies, assets must be divided into separate deposits. Once capital is split, efficiency can fall.
A simple example:
An LP provides liquidity for the same pair across three venues. One pool gets 80% of the trading volume that month. The other two share the remaining 20%.
If the LP split capital evenly, only one third of the balance sat where most fees were generated. The rest was technically allocated, but mostly watching from the sidelines.
The total deposit did not change. The fee capture did. This is why DeFi needs liquidity models that do not force LPs to divide one wallet balance before knowing where demand will appear.
TVL is not enoughFor years, DeFi measured success through TVL: total value locked. TVL is easy to understand. It tells you how much capital is deposited in a protocol. But it does not tell you how much of that capital is useful.
A pool can have high TVL and still contribute little to real execution. A strategy can hold large deposits while most liquidity sits away from actual demand. A network can look liquid on paper while routing still struggles in practice.
TVL also reflects a model in which tokens are transferred into pools and contracts. That capital may be locked, but locking it does not guarantee that it is active.
That is why DeFi needs a shift from TVL to useful liquidity. The better question is: How much capital can actually be applied when trades happen?
This is the logic behind TVU - Total Value Unlocked, - a metric 1inch introduced to capture exactly this shift. The focus moves from capital that is merely deposited to capital that remains available and can support execution across more than one position.
Why LPs feel the cost firstLiquidity inefficiency affects the whole market, but LPs often feel it first. They provide the capital. They take the risk. Yet a large share of that capital may not earn meaningful fees.
The problem becomes worse once impermanent loss is included. Impermanent loss occurs when the relative price of pooled assets changes after deposit: the LP can end up with less value than if they had simply held the tokens, even after fees. Concentrated positions can amplify this effect, since capital is exposed to price movement within a narrow band. Some LPs also face more advanced risks, such as Just-in-Time liquidity (see below).
LPs can also face unnecessary friction when they want to move capital. Tokens deposited into one pool cannot support another position unless the LP withdraws them, pays gas and reallocates them elsewhere.
This shows a larger point. LPs do not just need access to pools. They need structures that help liquidity stay active across more opportunities, remain under their control and move only when it is actually needed.
JIT liquidity weakens long-term LP economicsNot every liquidity problem comes from idle capital. Some arise because liquidity can be strategically timed.
One example is Just-in-Time (JIT) liquidity. Instead of providing liquidity continuously, sophisticated bots can detect a large pending swap, add liquidity immediately before it executes and remove it immediately afterward. The goal is to capture a share of the trading fees without keeping capital in the pool for longer than necessary.
For long-term LPs, this creates another source of inefficiency. They supply liquidity over extended periods, but some of the fees generated by large swaps can be captured by short-lived liquidity that appears only for those transactions.
This highlights another limitation of shared liquidity pools. They do not just fragment capital - they can also create opportunities for sophisticated participants to extract value from liquidity providers. As DeFi evolves, improving capital efficiency will also mean designing liquidity infrastructure that is more resistant to these kinds of strategies.
Current liquidity models have failed to fully solve a core issue: liquidity remains fragmented, underused and often locked into single-purpose structures.
The next model should change that assumption. It should let one balance support multiple positions instead of forcing LPs to pre-split capital. It should reduce idle liquidity. It should allow tokens to remain under the user’s control until they are actually needed for execution. It should help developers access useful liquidity without rebuilding the same infrastructure again and again. Most importantly, it should make existing capital work harder.
Explore 1inch to follow the next stage of DeFi liquidity infrastructure.
With limit orders in 1inch Wallet, you set your swap target price and keep full self-custody from your phone.
A swap is simple when you want to trade right now. But what if you want to buy only when the price drops? Or sell only when the market surges?
Until now, you could place limit orders only through the 1inch dApp. That meant opening a browser, connecting a wallet and managing trades outside the main wallet experience.
Now, limit orders are coming directly to 1inch Wallet. This gives you a cleaner way to place, manage and execute non-custodial limit orders without switching tools.
Why limit orders matterA market swap executes at the current available price. That is useful when speed matters. But it also means you accept the market as it is.
A limit order works differently. You choose the price at which you want to trade. The order can be filled only if market conditions reach your target.
For example, instead of swapping ETH for USDC immediately, you can set a target rate and wait. If the market reaches that rate and the order can be executed, it gets filled. If not, the order remains open until it expires or you cancel it. This is useful when you do not want to monitor prices manually.
It can help you:
buy only at a price you are comfortable with;sell only when your target is reached;plan trades in advance;manage DeFi trades from mobile more easily.Limit orders without leaving 1inch WalletNow, limit order functionality has been brought natively into 1inch Wallet. That matters because mobile traders should not have to move between interfaces just to use a basic trading tool. Wallets are where users hold assets, check balances and make decisions. Limit orders now fit into that same flow.
In 1inch Wallet, you can switch between a regular swap and a limit order from the trading screen.
You choose the asset you want to sell, the asset you want to receive, the price you want and the expiration period. Then you create the order directly from the wallet.
The experience is designed to feel simple on mobile while preserving the core benefits of DeFi: self-custody, transparency and programmable execution.
First, you select the token you want to sell and the token you want to receive. Limit orders work within a single chain, so the receiving token is selected on the same network as the source token.
Then you enter the amount. You can type the amount manually or use shortcuts such as 25%, 50%, 75% or max. If the amount is higher than your balance, the wallet will show an insufficient balance state and the order cannot be created.
Next, you set your target price. You can enter the price manually or use shortcuts based on the current market rate, such as market price or a percentage above or below it. You can also review the pair price in both directions, making it easier to understand the rate before creating the order.
Finally, you choose how long the order should stay active. If the market reaches your price before the expiry time and the order can be filled, execution can happen. If the order is not filled before expiry, it expires.
A better mobile trading flowLimit orders are especially useful when you have a clear target but do not want to stay online waiting for the market.
Imagine you want to buy a token, but only if it becomes 5% cheaper. With a regular swap, you would need to keep checking the price and act manually. With a limit order, you can set the target and let the order wait.
Or imagine you already hold a token and want to sell only if it reaches a certain level. A limit order lets you define that level in advance.
This brings 1inch Wallet closer to the trading experience users expect from advanced platforms, but without giving up self-custody.
Your assets remain in your wallet. You do not deposit funds into a centralized account. You create a non-custodial order that can be executed according to the conditions you set.
Supported networksLimit orders in 1inch Wallet support major blockchain networks:
Ethereum;BNB Chain;Solana;Polygon;Optimism;Arbitrum;Gnosis;Avalanche;zkSync EraBase;Linea;Sonic;Unichain.This gives traders access to limit order functionality across a broad DeFi environment, directly from mobile.
Trade on your termsLimit orders allow you to define execution conditions in advance, rather than acting on current market prices.
With limit orders in 1inch Wallet, you can define the rate you want, set the order from your phone and keep control of your assets throughout the process.
New data reveals: in DeFi, over $500 mln, or nearly one third of tracked liquidity, sits fully idle.
Does DeFi have enough liquidity? Yes. Is that liquidity working efficiently? No.
Recent research by on-chain analytics platform Dune (commissioned by 1inch) suggests that 85% of concentrated liquidity on decentralized exchanges is underutilized at any given time. That’s about $1.6 bln of the $1.84 bln tracked.
And around $542 mln of that sits fully idle and out of range in an average week.
This is a structural problem for DeFi. Liquidity pools have helped decentralized markets grow, but as tokenized assets and institutional capital move on-chain, the industry needs a more efficient mechanism.
How the research was conductedDune analyzed four major concentrated-liquidity venues:
Uniswap v3Uniswap v4PancakeSwap v3Aerodrome SlipstreamThe research covered seven networks: Ethereum, Base, Arbitrum, BNB Chain, Unichain, Polygon and Optimism.
Dune took weekly snapshots between January 6 and June 30, 2026. For each venue, researchers selected approximately 200 of the largest pools by trailing 30-day trading volume and kept that group fixed across the 26-week period.
This produced a panel of between 559 and 776 pools, with approximately $1.84 bln in average tracked capital.
Researchers also analyzed three constant-product venues - Uniswap v2, PancakeSwap v2 and Aerodrome’s basic pools - using the same methodology. These pools served as a baseline for assessing concentrated liquidity.
The scale of underutilized liquidityConcentrated liquidity lets liquidity providers choose specific price ranges in which their capital is available for trades.
The model can improve capital efficiency when the market price stays inside the selected range. But once the price moves outside that range, the position stops supporting trades and earning fees.
Across the 26 weeks covered by the research, an average of 29.5% of concentrated-liquidity capital was fully out of range.
The idle share generally remained between 25% and 35%, briefly rising to almost 41% in early February.
The cost to liquidity providers is significant. Dune estimates that out-of-range LPs forgo between $185 mln and $195 mln in fees annually.
The estimate was calculated by applying the blended in-range fee APR of approximately 40% over the period to the out-of-range TVL. The calculation used the fee tiers of Uniswap and PancakeSwap pools and bounded estimates for Aerodrome’s dynamic fees.
“Due to structural inefficiencies in DeFi, liquidity providers are leaving billions of dollars in underutilized capital and millions of dollars in fees on the table. If the industry is serious about bringing TradFi’s trillions on-chain, solving this needs to be priority number one,” said Sergej Kunz, 1inch co-founder. “Shared liquidity models and the advent of AI have the potential to create a far more efficient future for liquidity providers. That's why 1inch is set to launch Aqua, so LPs can maximize their capital and earn more from every dollar.”
"Decentralized exchanges have grown into one of the deepest, most liquid markets in crypto, and it is now competing with centralized exchanges and traditional trading venues,” added Filippo Armani, Research Lead at Dune. “What our research shows is that it has reached this scale even though much of its liquidity is not yet fully at work. It is easy to imagine what these venues will do as efficiency improves and institutional capital keeps arriving. Getting there depends on measuring liquidity precisely across every venue and chain, possibly real time, which is exactly the kind of on-chain visibility Dune has been building.”
Larger positions hold most idle capital
The research found that smaller positions were more likely to be out of range. Around 54% of positions worth less than $1,000 were idle, compared with approximately 26% of positions worth more than $1 mln.
But the largest positions still accounted for most of the idle capital.
Positions above $1 mln held approximately 47% of all idle liquidity, equivalent to roughly $260 mln. Positions worth more than $100,000 accounted for around 76%.
This suggests that underutilization is not limited to inexperienced or small-scale liquidity providers. Large, well-funded positions also drift outside their chosen ranges and stop earning fees.
Price direction matters more than volatilityThe research also examined why concentrated-liquidity positions move out of range.
The strongest factor was not volatility itself, but how far the market price moved in one direction over the week.
A highly volatile market can rise and fall before returning close to its starting point, leaving many positions in range. By contrast, a relatively calm but consistent price move can push large amounts of liquidity outside their selected ranges.
In other words, distance strands liquidity more reliably than short-term market turbulence.
No concentrated-liquidity design avoids the problemThe findings did not identify one protocol that consistently performed better across all markets.
When researchers compared the same trading pairs across different venues, the ranking changed from pair to pair. No single DEX was reliably more or less idle than the others.
Uniswap v4, despite being a newer architecture, recorded an idle share of around 30%, broadly in line with Uniswap v3.
Stablecoin pools also averaged around 30% idle liquidity.
Although stablecoins are designed to remain close in price, LPs often choose extremely narrow ranges only a few basis points wide. Even a small movement away from the peg can therefore push liquidity out of range.
Individually managed liquidity is more likely to sit idleMost out-of-range capital was held in individual wallets. On Uniswap v3, individually owned positions accounted for approximately 82% to 94% of idle capital across the networks where ownership could be attributed.
Capital managed by contracts, including active liquidity managers and market-making systems, stayed in range more consistently.
Incentives also helped. Aerodrome’s staked liquidity recorded the lowest idle rate in the study, at approximately 16%, because rewards are directed toward in-range capital.
However, incentives reduced the problem rather than eliminating it.
DeFi needs more efficient liquidityDeFi needs liquidity that remains available across changing market conditions. It needs models that reduce fragmentation, improve capital utilization and give LPs more opportunities to earn fees from the assets they already hold.
The next stage of DeFi will not be measured only by how much liquidity is deposited. It will be measured by how much of that liquidity is actually working.
Access liquidity across DeFi in the 1inch dApp.
Disclaimer: This report was commissioned by 1inch and prepared independently by Dune. The methodology, data collection, and analysis are Dune's own, and the findings represent Dune's independent conclusions. References to third-party protocols, including Uniswap, PancakeSwap, and Aerodrome, are made solely for research and informational purposes and do not imply any affiliation or endorsement. This report does not constitute financial advice.
Maple’s syrupUSDC and syrupUSDT bring tokenized lending positions closer to everyday DeFi trading.
Stablecoins are useful. But they can also sit still. Hold USDC or USDT in a wallet, and you hold a dollar-pegged asset. That is simple. But in institutional credit markets, stablecoins can also become productive capital. That is the idea behind Maple.
Maple is an on-chain lending platform for institutions. Trading firms can borrow stablecoins through Maple and post crypto assets, such as BTC or ETH, as overcollateralized security. Lenders provide stablecoins and receive tokens that represent their position.
Now, Maple’s syrupUSDC and syrupUSDT are available through 1inch.
That gives users and builders another way to access assets across DeFi, with 1inch providing routing and swap infrastructure.
What Maple doesMaple connects lenders and institutional borrowers on-chain.
In simple terms, borrowers receive stablecoin loans. They post crypto collateral. They pay interest on those loans. Lenders provide USDC or USDT and receive a token that represents their deposit.
For USDC, the flow looks like this:
USDC → deposit into Maple → receive syrupUSDC
For USDT, it works the same way:
USDT → deposit into Maple → receive syrupUSDT
But these tokens are not the same as plain stablecoins. USDC is a dollar-pegged stablecoin, not creating any earning opportunity. By contrast, syrupUSDC represents USDC that has been deployed through Maple’s lending system. Its value can increase as, while remaining subject to the risks of the underlying lending strategy.
That is where the RWA angle comes in. These are on-chain tokens connected to institutional credit activity, not just crypto-native trading pairs.
Tokenized credit as part of DeFi infrastructureRWAs are not only tokenized stocks or funds. Tokenized credit is also becoming part of the on-chain economy.
In traditional finance, credit positions are typically difficult to transfer and integrate with other financial infrastructure. Tokenization changes that. It allows credit positions to be represented, tracked and moved as on-chain assets.
For DeFi, that matters because it expands the range of assets that can move through decentralized infrastructure.
Stablecoins become more than settlement assets. Credit positions can become tokens. And those tokens can move through the same routing, swapping and wallet infrastructure that people already use across DeFi.
This does not remove risk. Lending markets still depend on borrower quality, collateral management, liquidity, protocol design and market conditions.
But it does make tokenized credit more portable and interoperable, allowing it to participate in the broader DeFi ecosystem alongside other on-chain assets.
What 1inch supports1inch now supports Maple tokens:
syrupUSDC - on Ethereum, Arbitrum and BasesyrupUSDT - on Ethereum and BNB ChainThese tokens are available across the 1inch ecosystem.
On 1inch.com, users can access them through Swap, Trade or Terminal. In Portfolio, users can track prices, balances and bundles.
For builders and institutional teams, Maple token swaps are supported through APIs available on 1inch Business.
1inch’s role1inch does not run Maple’s lending strategy. Minting, redeeming and lending remain on Maple’s side. Maple manages the credit product and the underlying lending mechanics.
1inch’s role is different: it helps users move into and out of these tokens through swap infrastructure. That distinction matters.
If you want to lend directly through Maple, you use Maple. If you want to trade syrupUSDC or syrupUSDT through available liquidity, 1inch can help route the swap.
This makes access simpler without turning 1inch into the issuer or manager of the asset.
Why routing matters for RWA tokensRWA tokens need more than issuance. They need liquidity. A token can be well designed, but if users cannot enter or exit efficiently, the market remains hard to use. Liquidity may be spread across venues, chains and pools. Prices may differ. A direct route may not always be the best route.
That is where 1inch intent-based swaps are useful.Instead of manually checking routes, users can express the trade they want.
For Maple tokens, this helps make trading more flexible. A user can move between stablecoins and syrup tokens through 1inch, while the routing layer searches for efficient execution across available liquidity.
Why this matters for stablecoin usersMany users understand USDC and USDT. They are simple, liquid and widely used across DeFi.
Maple tokens introduce a different question: what if a stablecoin position could also represent access to institutional lending activity?
That is the difference between holding a plain dollar stablecoin and holding a tokenized credit position linked to that stablecoin.
USDC is idle unless you do something with it. syrupUSDC is designed to represent USDC deployed through Maple’s lending system. USDT works the same way with syrupUSDT.
This makes Maple tokens part of a broader shift in DeFi: stablecoins are increasingly becoming the base layer for more advanced on-chain financial products.
Explore Maple tokens on 1inch.
Disclaimer: This content is for general information purposes only and does not constitute financial, investment, tax or legal advice. Not available in the US and other restricted jurisdictions.
1inch co-founder Anton Bukov says he has fully stepped away from the decentralized finance project’s operations after more than seven years and is now launching a new venture called Second Tier.
Summary
Anton Bukov says 1inch fired him in November 2025 after he pushed for management changes. Bukov says he remains a co-founder and 50% shareholder but no longer oversees company operations. 1inch says Bukov stopped active involvement in December 2025 and insists its systems remain unaffected. Bukov said the company fired him in late November 2025 after he pushed for changes to management and operations.
However, 1inch gave a different account of his recent role. The company said Bukov had not been actively involved in organizations linked to the project since December 2025. Bukov said he remains a co-founder and 50% shareholder but no longer has operational authority.
Bukov says management push ended with his firing In a statement published on X, Bukov said feedback from users and colleagues led him to become more involved in leadership and company operations. He said he spent months working on his leadership and communication approach while trying to change how the organization operated. “In late November 2025 I was fired,” he said.
Bukov also drew a clear line between his ownership position and his current responsibilities. “I no longer take part in the company’s operations,” he said.
He added that he has no role in product architecture or security and no oversight of either area. His statement leaves him as a shareholder and co-founder without a stated day-to-day management role.
1inch says operations and infrastructure remain unaffected 1inch responded on X by saying Bukov had not been actively involved in any associated organizations since December 2025. The statement presents a different timeline for his operational departure but does not change Bukov’s claim that the company dismissed him the previous month. The company has not publicly detailed the internal discussions that preceded the split.
We can confirm that Anton Bukov is no longer contributing to the 1inch project and has not been actively involved in any associated organizations since December 2025.
This does not affect the operation of 1inch Network or any associated organizations. The protocols,…
— 1inch (@1inch) July 16, 2026 Meanwhile, co-founder Sergej Kunz sought to reassure users about the project’s operations. He said Bukov’s departure “is not disrupting, will not disrupt, 1inch Network’s infrastructure or systems.” Kunz remains in charge as the protocol continues developing its trading and liquidity products.
Second Tier becomes Bukov’s next project Alongside his departure statement, Bukov announced Second Tier as his next venture. He said he is building the project with people who share the same values from the start. However, public information about its products, funding and launch schedule remains limited.
The move closes Bukov’s active operating role at a project he co-founded with Kunz in May 2019. During his time at 1inch, Bukov worked on protocol architecture and security, according to his account. The project later expanded from decentralized exchange aggregation into cross-chain trading tools and other DeFi infrastructure.
1inch continues expanding its DeFi products As previously reported by crypto.news, 1inch partnered with Rewardy Wallet in January to provide gasless cross-chain swaps across five blockchain networks through its Swap API. The integration formed part of 1inch’s broader effort to simplify decentralized trading while keeping users in control of their assets.
More recently, the leadership split comes after renewed attention on security across 1inch-linked infrastructure. In May, TrustedVolumes lost about $5.87 million after an attacker targeted its custom RFQ swap proxy. The incident did not affect a standard 1inch user swap route.
Kunz later called for safer lending structures following separate stresses in DeFi markets. Bukov’s latest statement now makes clear that he no longer oversees 1inch product architecture or security, while the company maintains that its systems and ongoing operations remain unaffected by his departure.
DeFi liquidity is not one thing. It comes from pools, ranges, vaults, market makers and intent-based systems - each with clear strengths and trade-offs.
What happens when DeFi capital isn’t where traders need it? That’s the liquidity problem.
When liquidity is deep, swaps feel effortless. You choose a token, confirm the trade and receive the asset you wanted at a fair rate.
When liquidity is weak, everything gets harder. Prices move against you. Routes fragment. Large swaps create high price impact. Liquidity providers may deposit capital but still earn less than expected.
DeFi no longer relies on one liquidity provision model. Different systems now compete to answer the same question: how can capital be made available where it is needed most? Here are the main liquidity models - and where each one works or breaks down.
Traditional AMM poolsAutomated market makers, or AMMs, are the classic DeFi liquidity model. LPs deposit two or more assets into a pool. Traders swap against that pool. The pool uses a formula to set prices, and LPs earn fees from trading activity.
The strength is simplicity. Anyone can provide liquidity. Anyone can trade. There is no need for a centralized order book or a traditional market maker.
This model helped DeFi scale because it made markets open by default. But the weakness is capital efficiency. In many AMM pools, much of the deposited liquidity does not actively support trades most of the time. Capital sits in the pool, but only part of it may be close enough to the active price range to earn meaningful fees. For LPs, that creates a problem: funds can be “deployed” but still underused.
Concentrated liquidityConcentrated liquidity tries to make LP capital work harder. Instead of spreading liquidity across all possible prices, LPs choose a price range. If trades happen inside that range, the capital can be more efficient and earn more fees.
The strength is better capital utilization. This model can support deeper liquidity around the current market price, which can reduce price impact for traders and improve fee capture for active LPs.
But the weakness is complexity. LPs have to choose ranges, monitor price movement and rebalance positions. If the market moves outside the chosen range, the liquidity may stop earning fees. This makes concentrated liquidity powerful for active or professional LPs, but harder for passive users.
Stable poolsStable pools are designed for assets that should trade near the same value. That usually means stablecoins or closely related assets, such as different versions of wrapped tokens.
The strength is low-slippage trading. When the assets stay close in value, stable pools can provide very efficient swaps. This makes them useful for stablecoin trading, payments, treasury movement and other low-volatility flows.
But the weakness appears when the relationship breaks. If one asset depegs or becomes less trusted, the pool can become imbalanced. LPs may end up holding more of the weaker asset. So stable pools work well for a specific type of liquidity, but they do not solve the broader issue of fragmented capital across DeFi.
Order book liquidityOrder book systems look more like traditional exchanges. Buyers place bids. Sellers place asks. Trades happen when prices match.
The strength is precision. Order books can work well for active markets, advanced trading and derivatives. They allow limit orders, visible depth and more familiar trading mechanics for professional users.
But the weakness is that order books need constant liquidity. They depend on active market makers and fast updates. Fully on-chain order books can also be expensive or slow on some networks, which is why many systems use hybrid designs.
Order books can be effective, but they are not always the best fit for long-tail assets or fragmented liquidity.
Managed liquidity vaultsManaged vaults make liquidity provision easier. Instead of choosing pools or ranges manually, LPs deposit assets into a vault. The strategy then manages allocation, rebalancing and execution.
The strength is convenience. Users do not need to manage every position themselves. This can make advanced LP strategies more accessible.
But the weakness is that capital is still usually committed to one strategy. If the strategy does not capture enough flow, the capital may still be underused. LPs also take on strategy risk and depend on the manager or automation behind the vault.
Managed vaults reduce manual work. They do not remove the deeper issue of capital being locked into separate structures.
Professional market makersProfessional market makers provide liquidity using inventory, pricing systems and risk management.
They can quote prices, support larger trades and source assets from different venues. The strength is execution quality. Market makers can be especially useful where public liquidity is thin. They can help support new assets, larger trades and intent-based execution.
But the weakness is availability. Market-maker liquidity depends on inventory, risk appetite and market conditions. During volatile periods, spreads can widen or liquidity can disappear. This makes market makers an important part of DeFi, but not a universal answer.
The shared problem: fragmentationEvery liquidity model has pushed DeFi forward in its own way. AMMs made decentralized trading accessible. Concentrated liquidity improved capital efficiency. Stable pools reduced slippage for similar assets, while order books brought more advanced trading capabilities. Vaults simplified liquidity management, market makers improved execution and intent-based systems made routing more flexible. Aggregators then connected fragmented liquidity across multiple venues.
Yet the same challenge remains. Liquidity is still spread across different pools, chains, strategies and trading venues. LPs must decide in advance where to deploy their capital, and if demand emerges elsewhere, that liquidity may never be used. As a result, there is often a gap between deposited liquidity and useful liquidity. A protocol may report high TVL, but only a fraction of that capital may actually be available when traders need it most.
From locked liquidity to useful liquidityThe next phase of DeFi liquidity should not be measured only by how much capital is locked. The better question is: how much of that capital can actually be used?
Useful liquidity is liquidity that can support execution when demand appears. It is not just sitting in a pool. It is available, active and connected to real trading flow. That shift matters for everyone.
For traders, it can mean better prices and lower price impact. For LPs, it can mean better capital utilization. For builders, it can mean less need to compete for isolated deposits. For DeFi, it can mean more efficient markets.
Liquidity provision is evolvingThere is no single perfect liquidity model. Each approach solves part of the problem and introduces its own trade-offs.
The important trend is clear: DeFi is moving away from simple locked capital and toward more flexible liquidity infrastructure.
That does not mean existing models disappear. AMMs, stable pools, vaults, market makers and aggregators will continue to matter.
But the market is starting to demand more. Liquidity needs to be easier to access, less fragmented and more productive. One promising direction is shared liquidity: capital that is not locked into one isolated pool or strategy, but can support multiple opportunities at the same time.
For LPs, this could mean better utilization. For traders, it could mean deeper and more available liquidity. For builders, it could reduce the need to compete for separate deposits across every venue.
Capital should not just sit on-chain. It should work where demand appears. That is the next challenge for DeFi liquidity - and one of the most important areas for the industry to solve.
Explore 1inch to access efficient routing across DeFi liquidity.
Bulletproof DeFi securityProtect your crypto against front-running, sandwich attacks and asset loss with MEV protection, wallet screening & more.
Wallet scanning, risk scoring and blocklists keep you safe from bad actors.
Learn more
Questions? Answers.
What is DeFi? DeFi (decentralized finance) is an infrastructure of financial services based on blockchain technology that lets people trade, lend, borrow and earn interest directly, without banks or intermediaries.
What is a DeFi exchange? A DeFi exchange is a decentralized platform that enables users to trade cryptocurrencies directly with each other using smart contracts, without intermediaries like banks or centralized exchanges. It gives traders full control over their funds and enables peer-to-peer transactions on the blockchain.
Is 1inch a DeFi exchange? 1inch Swap began as a DEX aggregator, combining liquidity across multiple exchanges to find users the best swap rates. Now, it’s a lot more - with intent-based swaps and cross-chain functionality built on atomic execution to keep assets safe. But it’s still built on the principle of uniting liquidity from across the ecosystem to make crypto swaps more efficient and return better token prices.
What is a DEX aggregator? A DEX aggregator helps users swap tokens by combining liquidity from several decentralized exchanges to secure better prices. The advanced DEX aggregator accessed through 1inch’s Pro interface can split a single trade across different platforms and market depth to reduce slippage and access better pricing. Explore better swap rates in the 1inch dApp or Wallet.
How are DEX aggregators better than DEXes? A DEX aggregator searches multiple DEXes to find the best token prices, lowest fees, and most efficient routes for your swap. This saves you time and money compared to using a single DEX.
How can I swap tokens on 1inch? To order a token swap on 1inch, go to the 1inch dApp or 1inch Wallet, choose the token you want to swap and the token you want to receive, select the network(s) and mode, then hit the Swap button. For more details, visit the Help Center.
Need to swap tokens now, at the current market price? A market order on 1inch lets you execute a swap immediately while 1inch searches across liquidity sources for an efficient route.
Let's imagine you want to swap tokens at the current available market price, without waiting for a specific price target to be reached.
In the moment, you don’t want to set a future price or wait for a limit order to fill. You want the swap executed at the best available rate right now.
That is what a market order does. On 1inch, this usually means making a standard swap: you choose the tokens, enter the amount and confirm the transaction.
A market order is an order to buy or sell an asset immediately at the current available market price.
In DeFi, this means your swap is executed using available liquidity across decentralized exchanges and other liquidity sources, like private market makers. The final rate can change slightly before execution, especially during volatile market conditions.
That is why 1inch shows important details before you confirm the swap, including the estimated rate, route and minimum amount you are expected to receive.
How to set a market order on 1inchTo place a market order on 1inch, open the 1inch dApp and select Market under the Trade tab.
Then:
Select the token you want to sell and the network you have it on.Select the token you want to buy and the network you want to have it on.Enter the amount.Check the slippage setting. Auto is set at 0.5%, but you can choose another percentage.Check the network fee setting. You can use the presets Aggressive and Market or set a custom amount.Confirm the swap in your wallet.Once confirmed, the swap is sent on-chain and executed according to the available market conditions.
Why use 1inch for market orders?Market orders depend on execution quality. A small difference in price, route or slippage can affect the final amount you receive.
1inch helps by searching across multiple liquidity sources to find an efficient swap route. Instead of checking different DEXs manually, you can use one interface to access aggregated liquidity.
This is especially relevant when swapping larger amounts or trading tokens with fragmented liquidity, where price impact and execution quality become more significant factors.
What to check before confirmingBefore you confirm a market order, always review the transaction details.
Pay attention to:
the token pairthe amount you are sellingthe estimated amount you will receiveslippage tolerancenetwork feesthe selected networkThese checks help you avoid simple mistakes, such as accepting worse execution than expected.
Market order vs limit orderA market order is for immediate execution. You accept the current available price and complete the swap now.
A limit order is different. With a limit order, you choose a target price, and the order executes only if market conditions match it.
Use a market order when speed matters. Use a limit order when price matters more than timing.
Swap tokens on 1inchMarket orders are the simplest way to swap tokens when you want execution now.
With 1inch, you can access aggregated DeFi liquidity, review key swap details and complete the transaction from one interface.
In the run-up to a major release, Aqua, we have strengthened our leadership team by appointing a chief product and technology officer and a new head of product design.
As Chief Product and Technology Officer (CPTO), Holly Atkinson will focus on shaping product strategy to ensure that 1inch continues to innovate with its core routing infrastructure and successfully launches a new shared liquidity product, Aqua.
Holly brings experience across full-stack engineering, blockchain architecture, product development and executive leadership. Before joining 1inch, she worked as a Blockchain Architect at The Sandbox, led metaverse technology initiatives at Boson Protocol and began her Web3 career as a Full Stack Engineer at Tracr.
1inch also welcomes George Evans as Head of Product Design. George joins us with more than 15 years of experience building and leading design teams at companies including Careem, Noon and Majid Al Futtaim. At 1inch, he will lead the product design function, focusing on creating intuitive user experiences, strengthening design across the product portfolio and ensuring design plays a central role in product development.
These appointments come as we prepare for major product launches. Following recent major integrations, including the partnership with Robinhood Chain to expand access to tokenized real-world assets, we are preparing the public launch of Aqua, a shared liquidity protocol.
As one of the company's most significant upcoming initiatives, Aqua is designed to address liquidity fragmentation across DeFi and contribute to the next generation of on-chain finance infrastructure.
Robinhood Chain brings tokenized real-world assets on-chain. 1inch makes them easier to trade.
What chain should you use to trade RWAs smoothly and efficiently? One answer is Robinhood Chain, an Arbitrum-based network specifically built for real-world asset trading. 1inch has integrated Robinhood Chain with a simple goal: make tokenized real-world assets easier to access, route and trade through 1inch.
“Robinhood Chain brings tokenized real-world assets on-chain,” says Sergej Kunz, 1inch co-founder. “Our role is to provide the infrastructure that makes them liquid and tradable. As one of the largest US retail crypto platforms enters the RWA market, efficient routing, deep liquidity and reliable execution become increasingly important. That’s what 1inch has spent years building.”
Bringing RWA swaps to 1inchRobinhood Chain is expected to become a high-visibility network for tokenized assets. For eligible users, this means a new network focused on real-world assets. Now, 1inch brings its routing and swap infrastructure to one of the most closely watched RWA ecosystems from the start.
As a launch partner on Robinhood Chain, 1inch supports RWA swaps on the 1inch dApp and in 1inch Wallet, helping eligible users access tokenized assets through a familiar DeFi flow. Beyond 1inch’s consumer apps, Robinhood Chain RWA swaps will also be accessible via the 1inch Swap API, available on 1inch Business alongside other APIs - enabling third-party apps and partners to integrate Robinhood Chain swaps directly.
No waiting for the bell. No fragmented manual routing. Just on-chain access through 1inch.
Why Robinhood Chain mattersRWAs are changing what can move on-chain.
Tokenized RWAs and other real-world assets can enable eligible users to gain exposure to more traditional financial products. But tokenization alone is not enough. These assets also need liquidity, pricing and reliable execution.
That is where swap infrastructure matters.
If users need to move between venues, chains and interfaces just to trade an RWA, the experience remains too fragmented. Robinhood Chain can bring assets on-chain. 1inch can help make them tradable.
Built for 24/7 tokenized marketsThe product promise is clear: traditional markets close at 4 pm, but tokenized markets can move around the clock.
With Robinhood Chain integration, 1inch aims to let eligible users swap tokenized real-world assets anytime during the work week, from anywhere, using the execution quality 1inch is known for.
This matters because RWA liquidity can be fragmented across issuers, venues and market participants. 1inch routing helps eligible users access available liquidity more efficiently, also supporting intent-based execution where available.
For RWA traders, that means less manual route hunting and a simpler path to execution.
Supporting the Robinhood Chain ecosystemThe integration is not only about users.
Token issuers, liquidity providers and ecosystem partners also need infrastructure that can support early network growth. By integrating and supporting Robinhood Chain at its launch, 1inch can help create a smoother trading environment for the assets and partners building on the network.
This is how DeFi infrastructure scales: not through isolated products, but through connected systems.
Robinhood Chain brings RWAs on-chain. 1inch helps make them swappable.
The next phase of RWA tradingRWA markets are moving from issuance to usability.
The next question is not only which assets can be tokenized. It is whether eligible users can actually trade them easily, efficiently and securely across DeFi.
By supporting Robinhood Chain, 1inch is one of the first major routing and swap platforms available on the network. This strengthens 1inch’s role in RWA execution and gives eligible users a new way to access tokenized asset markets through the 1inch dApp and 1inch Wallet.
Swap on 1inch across networks, including Robinhood Chain.
Disclaimer 1:
This content is for general information purposes only and does not constitute financial, investment, tax, or legal advice and is not a recommendation to buy or sell any particular digital asset or to employ any specific investment strategy.
Disclaimer 2:
Not available in the US, UK, Canada, Singapore, UAE and Switzerland, and OFAC-sanctioned countries including Iran, North Korea, Syria, Cuba, Crimea/Donetsk/Luhansk regions.
For many crypto companies operating in Europe, the July 1 deadline is about licensing, market access and whether they can keep serving EU users.
How often has a crypto project operating in Europe had to ask the same question: are we actually compliant?
MiCA - the EU’s Markets in Crypto-Assets Regulation - is meant to make that answer clearer. It creates a common framework for stablecoins, exchanges, custodians and other crypto service providers across Europe.
July 1 is a key transition point. In jurisdictions that used the maximum grace period, existing crypto-asset service providers may need MiCA authorization to continue operating in the EU market after that date, depending on their specific activities and business model.
For centralized crypto companies, this creates a clearer path. For DeFi, the picture is less complete: MiCA is built around identifiable intermediaries, not decentralized protocols. That makes July 1 less of an endpoint and more of a starting point for Europe’s next crypto phase.
What MiCA is trying to doMiCA is the EU’s attempt to create a single crypto rulebook across member states.
Before MiCA, crypto regulation in Europe was fragmented. One country could have a licensing regime for custody. Another could rely mainly on anti-money laundering registration. A third could take a different approach again. That made life complicated for crypto businesses and users.
MiCA changes that by setting common rules for crypto-asset issuers and centralized service providers across the EU. The goal is to create legal clarity, improve consumer protection and make it easier for authorized companies to operate across the single market.
In practice, MiCA affects several groups:
crypto exchanges;custodians;brokers and trading platforms;crypto asset issuers;stablecoin issuers;companies providing crypto transfer, execution or advisory services.For crypto projects, the message is clear: if you want regulated access to the EU market as an identifiable service provider, understanding where you fit under MiCA is an important starting point.".
For DeFi projects, the message is more complicated. MiCA can affect teams, interfaces and service providers around DeFi, but it does not yet give decentralized infrastructure a dedicated rulebook that reflects how DeFi actually works.
Why July 1 mattersMiCA did not hit the whole industry at once. Rules for asset-referenced tokens and e-money tokens, including stablecoins, began applying earlier. The broader rules for crypto-asset service providers - CASPs - became applicable later, with transition periods for companies that were already operating under national regimes.
Some EU member states allowed existing providers to keep operating during a transition period while they applied for MiCA authorization. In several jurisdictions, the maximum transition period runs until July 1, 2026. That is why the date matters.
It is the point where the old patchwork model gives way to the new MiCA framework for many centralized providers. If a company has relied on national registration or a temporary permission, it may no longer be enough.
For users, that could mean changes in available platforms, assets or services. For crypto companies, it means market access becomes more closely tied to licensing status. For DeFi, however, July 1 does not resolve the central question: how should regulation apply to systems that are not built around a single intermediary?
The biggest change is that compliance becomes part of product strategy. Under MiCA, crypto projects can no longer treat EU access as an afterthought. If they serve European users, list assets for European customers or provide crypto services in the EU, they need to understand whether they are acting as a regulated provider. That can affect several areas.
LicensingCrypto-asset service providers need authorization to operate under MiCA.
This applies to activities such as custody, exchange, execution, placement, transfer services and operating a trading platform. The exact implications depend on the business model, but the direction is clear: many centralized service providers now need a license, not just a registration.
Once authorized, a CASP can use MiCA's passporting mechanism to offer services across the EU, subject to applicable notification procedures. That is one of the main benefits of the framework. The cost is higher compliance. The reward is broader regulated market access.
For centralized players, this is the part MiCA gets right. It offers a clearer route into the regulated European market.
For decentralized systems, the route is less clear. DeFi protocols do not always fit neatly into categories built for intermediaries that custody assets, operate platforms or provide services through a legal entity.
Stablecoin supportStablecoins have been one of the most sensitive areas under MiCA.
For exchanges, wallets and apps, this raises a practical question: which stablecoins can be offered to EU users?
MiCA creates stricter rules for issuers of e-money tokens and asset-referenced tokens. That means platforms may need to review stablecoin listings, issuer status, redemption arrangements and user access.
This does not make stablecoins less important. If anything, it makes compliant stablecoin infrastructure more important. Stablecoins remain one of the clearest bridges between traditional finance and crypto, but their role in Europe is becoming more regulated.
Token listingsMiCA also affects how crypto assets are offered and marketed.
Projects may need clearer white papers, risk disclosures and information for users. Trading platforms may need listing procedures and more structured controls around the assets they make available.
This matters especially for new tokens, RWAs and emerging asset categories.
The market is moving toward more documentation, more due diligence and more accountability.
For centralized platforms, that can be a workable path.
For DeFi, the question is how to protect users without forcing decentralized protocols into rules designed for centralized gatekeepers.
Operations and governanceMiCA is not only about getting a license. It also pushes crypto companies toward stronger operational standards. That can include governance, complaints handling, conflict management, custody safeguards, outsourcing controls and business continuity.
For younger crypto projects, this can feel heavy. But for institutional adoption, it can also be useful. Banks, asset managers and fintechs are more likely to work with crypto infrastructure when rules are clearer.
The challenge is to make sure the next stage of regulation also fits DeFi, where users interact with protocols, wallets, smart contracts and liquidity networks in a very different way.
A stronger market, but a tougher oneMiCA creates costs. Licensing takes time. Legal reviews become more important. Some projects may stop serving EU users if the compliance burden is too high. Smaller players may struggle more than larger platforms.
But MiCA also creates opportunity. A single EU framework can make the market easier to scale for companies that meet the requirements. Instead of navigating 27 different national approaches, authorized providers can build with a clearer route to cross-border operations.
For institutions, that matters. Banks and asset managers are unlikely to adopt crypto infrastructure at scale if the rules are unclear. MiCA does not solve every problem, but it gives European crypto markets a more defined regulatory foundation.
That can help bring more serious builders into the space. Still, the market will only be stronger if the next phase includes DeFi. Centralized crypto services now have a clearer path. DeFi still needs one.
The next phase: rules for DeFi“MiCA goes fully live on July 1st - and it gets one half of crypto right,” commented Orest Gavryliak, 1inch Chief Legal Officer. “Centralized players finally have a clearer way to operate inside a regulated framework, which the market has been waiting for. But MiCA is built around identifiable intermediaries. In its current form it wasn't designed for DeFi, and it doesn't work for it.”
“We see July as the start of Europe's crypto journey - not the end - and we're hopeful Europe follows the direction the US is taking with the CLARITY Act, giving DeFi a framework it can actually operate within,” he added. “We want to help build that next stage: working with regulators on the rules that actually apply to DeFi, for the users, the projects and the regulators themselves.”
Building a compliant solution? Consider APIs available on 1inch Business.
Disclaimer: This content is for general information purposes only and does not constitute legal, financial, tax or investment advice.
RWAs can look simple in a wallet, but every tokenized real-world asset has a structure behind it. To understand the risk, you need to know what the token represents, who stands behind it, how it moves and what rights it gives you.
If you’re holding or trading RWAs, it’s a good idea to know what you actually own.
You can access tokens representing thousands of equities, treasuries, funds, credit products and other assets.
But behind the token, there may be an issuer, a wrapper, offering documents, transfer rules, redemption conditions, investor restrictions and jurisdiction-specific limits. If you want to understand an RWA, you need to read the whole structure — not just the ticker.
That is where “observable RWAs” come in. The key question is simple: what can you verify about the asset, and what remains unclear?
Start with what the token actually representsThe first thing to ask about any RWA is not “What is the token called?” It is: what does the token actually represent?
A label does not define the asset. A token can be called a “digital asset,” “note,” “wrapper” or “on-chain product,” but the underlying exposure still matters.
Two broad categories are worth separating.
The first is DeFi-native synthetic exposure. This could include yield-bearing vault tokens, lending receipts or structured DeFi products that do not wrap an off-chain security. Here, the key question is what the law of each relevant jurisdiction says about that instrument.
The second is a wrapped real-world security. If a token represents shares, debt or fund units, the underlying instrument does not stop being what it is. A stock is still a stock. A bond is still a bond. A fund unit is still a fund unit.
Putting it on-chain does not remove the regulatory, legal or distribution rules attached to the underlying asset.
Look at the legal envelopeEvery RWA sits inside a legal envelope.
That envelope may include offering documents, terms and conditions, private placement memoranda, issuer disclosures or other legal materials. These documents often explain the most important parts of the asset:
who the issuer is;which jurisdiction governs the issuer;which jurisdiction governs the instrument;who is allowed to hold the asset;which persons or countries are restricted;what rights the token holder has;how redemption works;what happens if transfers are paused or restricted.This is where a lot of RWA risk becomes visible.
If the documents clearly explain the issuer, the instrument, the restrictions and the holder’s rights, the asset is more observable. If those details are missing or vague, the token may be harder to understand.
Understand the wrapperMany RWAs are not direct claims on the underlying asset. They are wrapped structures.
A wrapper is a legal or technical layer between the token holder and the underlying asset. It may be a fund, note, special purpose vehicle or another structure that holds or references the asset.
This matters because the wrapper defines the holder’s real position.
If the token gives the holder a direct claim against the issuer of the underlying asset, the recourse path may be clearer. The counterparty is identifiable, and the legal relationship may be easier to understand.
If the holder has a claim only against a wrapper entity, the analysis changes. The user’s rights depend on the wrapper’s own terms. The wrapper may have limited assets, limited operating history or unclear pass-through rights to the underlying asset.
This is especially important for wrappers built over institutional vehicles. A token may appear freely transferable on-chain, while the underlying asset was originally designed for a restricted investor base.
Check transfer mechanicsAn RWA is not only defined by documents. It is also defined by how the token moves on-chain.
Some RWAs are permissioned. That means transfers are controlled by an issuer-managed allowlist at the smart contract level. Only approved wallets can hold or receive the token.
In that model, eligibility is enforced by the issuer’s own infrastructure. Whitelisted participants are typically the ones positioned to interact directly with the issuer.
Other RWAs are permissionless. They may move like ordinary tokens, without contract-level checks on who can receive them.
That creates a different risk profile. If a token has no built-in transfer restrictions, the restrictions may need to be handled elsewhere — by interfaces, platforms, APIs or user-facing controls.
So, when looking at an RWA, check the transfer logic. Can anyone receive it? Is there an allowlist? Can transfers be paused? Can the issuer freeze addresses? These mechanics say a lot about how the asset actually works.
Read the distribution constraintsFor many RWAs, access is not global.
A tokenized equity, fund unit or credit product may be unavailable to users in certain jurisdictions. It may be restricted to qualified investors, professional investors or non-US persons. It may require KYC or KYB.
These restrictions usually come from several places at once.
First, the nature of the asset matters. A tokenized equity carries equity-related rules into the wrapper. A fund unit carries fund-related rules. A synthetic DeFi-native instrument may require a different analysis.
Second, the issuer’s own documents matter. Restricted-person and restricted-jurisdiction clauses often appear in terms, offering documents or private placement materials.
Third, platforms may apply their own conservative restrictions where information is incomplete or ambiguous.
The important point is that “not restricted in one document” does not always mean “freely available everywhere.” RWA distribution is usually layered.
Do not skip redemption rightsRedeemability is one of the most important parts of an RWA.
If something goes wrong, the key question is often: who can the holder make a claim against?
Maybe the token de-pegs from the underlying asset. Maybe redemptions pause. Maybe the issuer freezes transfers. Maybe liquidity disappears. In each case, the holder’s practical position depends on the chain of recourse.
A strong RWA structure should make this clear.
Can the token holder redeem directly with the issuer? Is redemption limited to certain participants? Does the holder only have a claim against a wrapper? Are there gates, delays, fees or minimums? What happens in stress conditions?
If the answer is hard to find, that is itself a risk signal.
What on-chain mechanics can showThe blockchain can reveal important information about an RWA.
You may be able to see:
the token contract;transfer activity;holder concentration;minting and burning;allowlist mechanics;freeze or pause functions;supply changes;liquidity pools;trading routes.This data can help you understand how the asset behaves in practice.
But on-chain data has limits. It can show token movement, but it usually cannot explain the full legal structure. It can show that tokens were minted or burned, but not always why. It can show who holds tokens, but not always whether those holders are eligible or what rights they have.
That is why on-chain mechanics should be read together with off-chain documents.
What structured data can show — and what it may missStructured RWA data sources can be useful. They can help track market size, issuers, asset categories, chains, token supply and other metrics.
But they do not always capture everything.
Issuer-specific restrictions, redemption terms, legal clauses and wrapper structures may not be normalized in public data feeds. In many cases, they still have to be read directly from documents.
This is one of the biggest challenges in the RWA market. Some data is visible on-chain. Some is available in structured form. Some is buried in legal documents. Some may not be clear at all.
A well-understood RWA is one where these pieces can be connected.
How to read an RWA before interacting with itBefore interacting with an RWA, ask a few simple questions.
What does the token represent? Who issued it? Is there a wrapper? Which jurisdiction governs the issuer and the instrument? Who is allowed to hold it? Are there restricted countries or restricted persons? Is the token permissioned or permissionless? Can transfers be frozen or paused? Can the holder redeem directly? Where does liquidity come from?
These questions do not remove risk. But they help you understand what kind of risk you are taking.
An RWA is easier to evaluate when the answers are observable. It is harder to evaluate when the structure depends on vague labels, incomplete documents or assumptions about what the token “should” mean.
Why observable RWAs matterRWAs can become a major part of on-chain finance. They can bring equities, credit, treasuries, funds and other assets into crypto-native environments.
But tokenization does not make complexity disappear. It often moves complexity into a new form.
The token is only the visible part. The real structure sits behind it: legal envelope, wrapper, transfer rules, redemption path, distribution limits and market data.
To understand an RWA, do not stop at the name of the token. Look for what is verifiable.
The more observable the structure is, the easier it becomes to understand the asset, the risks and the rights attached to it.
Disclaimer 1:
This content is for general information purposes only and does not constitute financial, investment, tax, or legal advice and is not a recommendation to buy or sell any particular digital asset or to employ any specific investment strategy.
Disclaimer 2:
Not available in the US, EU, UK and other restricted jurisdictions.
Explore 1inch for more insights on DeFi infrastructure, on-chain trading and the future of tokenized assets.
Another multi-million-dollar attack has hit the DeFi sector after liquidity provider and market maker TrustedVolumes fell victim to a smart contract exploit on Thursday night.
TrustedVolumes Hit By $6.7M Hack On Thursday, DeFi platform TrustedVolumes, one of 1inch liquidity providers and market makers, suffered a new exploit that drained millions of dollars in multiple assets from the project.
According to reports from blockchain security firms PeckShield and Blockaid, the attacker stole approximately $6 million in Wrapped Ethereum (WETH), Wrapped Bitcoin (WBTC), USDT, and USDT after exploiting a vulnerability in the protocol’s core signature validation logic, which allowed them to bypass authorization checks and forge trading orders.
Notably, the hacker quickly exchanged all assets for 2.513 ETH on a Decentralized Exchange (DEX) and distributed them across three addresses. In an X post, TrustedVolumes confirmed the incident, sharing the addresses currently holding the stolen funds and updating the estimated loss to roughly $6.7 million.
TrustedVolumes confirms exploit. Source: X The vulnerability was a TrustedVolumes-controlled custom RFQ (request for quote) swap proxy. Crypto researcher Humphrey explained that “the Custom RFQ Swap Proxy contract contains a function designed to manage the ‘authorized order signer’ whitelist. Such whitelist mechanisms are common in DeFi—only addresses on the whitelist can issue valid transaction instructions on behalf of the protocol.”
However, he noted that “this registration function is public and lacks any permission modifiers.” As a result, the attacker exploited this public function within the contract, registering themselves as an authorized order signer.
“Since any external address can call this function, it is equivalent to giving everyone the ability to make a copy of the safe’s key,” the researcher continued.
Same Hacker, Different Attack The online reports revealed that the attacker was the same hacker responsible for the $5 million 1inch Fusion V1 Settlement contract exploit in March 2025, which TrustedVolumes was the primary victim.
Humprey highlighted that while the same individual carried out both attacks, they were significantly different on a technical level. According to the post, the 2025 vulnerability involved low-level EVM memory manipulation in the 1inch Fusion V1 Settlement contract.
At the time, the hacker “proactively initiated on-chain negotiations,” offering to return the stolen assets for a white hat bounty. The DeFi platform accepted the proposal, and most of the funds were safely returned.
Now, TrustedVolumes affirmed that it is “open to constructive communication regarding a bug bounty and a mutually acceptable resolution.”
Decentralized exchange aggregator 1inch clarified that there was no impact on its systems, infrastructure, or user funds, explaining that “TrustedVolumes operate independently as a liquidity provider, used by multiple protocols across the industry, and are not exclusive to 1inch.”
DeFi Exploits See Historic Surge This attack follows a wave of exploits that has shaken the DeFi sector over the past month. Last week, PeckShield revealed that the crypto space saw 40 major hacks in April, which drained approximately $647 million.
This figure represents a 1,140% Month-over-Month (MoM) increase from March’s $52.2 million. It also represents a 292% surge from the $165 million the DeFi sector lost during the first quarter of 2026.
Notably, the top two incidents of the month, Drift Protocol’s $285 million and KelpDAO’s $290 million exploits, accounted for 91% of the funds lost last month. In addition, they now rank among the Top 10 hacks since 2021.
ETH’s performance in the one-week chart. Source: ETHUSDT on TradingView Featured Image from Unsplash.com, Chart from TradingView.com
Growing concerns around quantum breakthroughs are starting to reshape conversations across DeFi.
Quantum computing is no longer a distant theoretical threat. That perception is rapidly changing. Recent research from Google, Quantum AI, Ethereum Foundation and Stanford suggests that breaking widely used cryptography could require far fewer quantum resources than previously believed.
The immediate risk is not that Bitcoin or Ethereum suddenly collapse tomorrow. The real challenge is timing: blockchains depend heavily on cryptography, and as blockchains become critical financial infrastructure, upgrading global financial infrastructure takes years.
That is why quantum computing is becoming a serious topic of discussion in the crypto industry, and DeFi appears to be better positioned to adapt to this potential threat.
Why quantum computing matters for cryptoModern blockchains rely on public-key cryptography to secure:
walletssignaturestransactionssmart contractsToday’s systems are secure against classical computers because deriving private keys from public keys is computationally infeasible.
Quantum computers could eventually change that.
In particular, researchers focus on Shor’s algorithm, a quantum algorithm theoretically capable of breaking elliptic curve cryptography (ECC), which underpins many blockchain systems. Google researchers recently estimated there is now a 10% chance that “Q-Day” — the point at which quantum computers can break modern public-key cryptography — could arrive by 2032.
That timeline remains highly debated. But the direction is clear:
quantum risk is increasingly treated as an infrastructure problem, not science fiction.
The growing urgency around post-quantum securityIn April 2026, Nature reported that recent quantum advances are “imminent risk” to cybersecurity infrastructure.
At the same time, Google and Caltech research suggested that the cost of breaking traditional encryption may be dropping faster than expected.
This has triggered broader conversations around:
post-quantum cryptography (PQC)quantum-resistant walletsmigration timelinesblockchain governance upgradesThe challenge is not just technical.
Crypto systems are decentralized. Upgrading cryptographic standards across:
Why DeFi could be especially exposedDeFi is highly composable and deeply interconnected.
That creates unique vulnerabilities in a post-quantum scenario.
If quantum systems eventually compromise private keys or signature systems, the consequences could cascade across:
liquidity poolslending marketscross-chain bridgesvault systemsDAOsSome analysts argue that dormant wallets with publicly exposed keys may become especially vulnerable over time.
This is one reason why a blockchain-specific variant of “harvest now, decrypt later” concerns is growing. Unlike traditional HNDL scenarios involving intercepted encrypted communications, blockchain data is already public. Public keys exposed in past on-chain transactions are permanently visible, meaning attackers would not need to harvest anything — the data needed to derive private keys with a future quantum computer is already sitting on-chain for attackers to collect.
DeFi’s advantage: adaptabilityIronically, crypto may also have an advantage.
Unlike traditional banking systems, blockchain protocols are designed to evolve through:
upgradeshard forksgovernance proposalsmodular infrastructureForbes recently argued that quantum computing represents less of an existential threat and more of a forced redesign of blockchain security architecture.
That adaptability may become one of DeFi’s biggest strengths.
Why this matters for the future of DeFiQuantum computing highlights a broader reality:
DeFi is becoming critical infrastructure.
As institutional adoption grows, the industry increasingly needs:
long-term security planningcryptographic agilityresilient execution infrastructureupgrade-ready protocolsThe conversation is no longer: “Will quantum computing affect crypto?”
It is increasingly: “How should crypto prepare?”
Challenge: preparationQuantum computing does not mean the end of crypto or DeFi.
But it does mean the industry will likely need to evolve its security foundations over time.
The good news:
post-quantum cryptography already existsmigration discussions are already happeningblockchain systems can upgradecrypto infrastructure is inherently adaptableThe challenge now is preparation.
As DeFi matures into global financial infrastructure, quantum resilience may eventually become as important as scalability, liquidity, and interoperability.
For more insights from 1inch subscribe to our newsletter
In 2026, cross-chain bridges remain vulnerable. Learn why they are still one of crypto’s most dangerous weak points and why 1inch’s bridgeless cross-chain swaps are more secure.
Moving assets across chains should feel simple. You send tokens from one network and receive them on another.
But behind that simple flow sits a complex system of messages, proofs, validators, contracts and liquidity pools. If one link breaks, funds can disappear fast.
The latest reminder came from Verus Protocol’s Ethereum bridge, which was reportedly exploited for about $11.6 mln after a fake cross-chain transfer message tricked the bridge into sending funds from its reserves to an attacker-controlled wallet.
The case is still developing. But it fits a familiar pattern: bridges are not just moving tokens. They are asking one blockchain to trust information from another. That is where things get risky.
Verus: a fake message, real lossesAccording to the Cointelegraph report, security firms Blockaid and PeckShield flagged the Verus-Ethereum bridge exploit on May 18. The attacker reportedly drained assets including ETH, USDC and tBTC, then converted the funds into roughly 5,402 ETH.
Blockaid said the issue was not an ECDSA bypass, not a notary key compromise and not a parser bug. Instead, it pointed to missing source-amount validation in the bridge’s Solidity logic.
That detail matters. The attack was not only about stealing keys. It was about making the bridge believe that a cross-chain instruction was valid.
For DeFi, that is the scary part. A bridge can have real liquidity, real users and real contracts - but still fail if the message-to-execution logic is not strict enough.
Kelp: the biggest bridge-related hit so farThe largest bridge-related exploit reported so far in 2026 was the Kelp DAO attack. TechRadar reported that hackers allegedly stole about $290 mln after exploiting Kelp's LayerZero setup. Some security researchers have linked the attack to Lazarus Group.
LayerZero reportedly said the issue was tied to Kelp’s configuration, including its use of a single DVN. Kelp disputed that explanation. But the lesson is clear: cross-chain security is not only about the messaging protocol. It is also about how each project configures and operates it.
In the wake of the attack, 1inch participated alongside other protocols in efforts to assist with the recovery of assets affected by the incident on Aave.
Hyperbridge: small loss, big warningHyperbridge suffered a smaller exploit in April, but the mechanics were alarming. The attacker reportedly used a forged cross-chain message to gain control of a bridged DOT token contract, mint 1 bln bridged DOT tokens and sell them into available liquidity. Initial losses were reported at about $237,000, while a later assessment put realized losses closer to $2.5 mln.
The dollar figure was modest only because liquidity was limited.
That is an important distinction. Sometimes the exploit size does not show the real severity of the bug. A flaw that drains $2.5 mln today could drain far more tomorrow if the pool grows.
Why bridges keep breakingBridge hacks are rarely identical. Some involve stolen keys. Some involve fake messages. Some involve flawed validation. Some involve bad governance or operational controls.
But the core problem is usually the same.
A bridge has to answer one dangerous question:
Did something really happen on another chain?
If the answer is wrong, money can move when it should not.
That is why bridges are such attractive targets. They often hold large reserves. They connect multiple ecosystems. And they turn verification mistakes into direct withdrawals.
The old bridge problem is not solvedThis is not new. The Verus Cointelegraph report compared the incident to the 2022 Nomad and Wormhole exploits, two of the most infamous bridge failures in crypto history.
What is new is that DeFi is now more interconnected. More chains. More wrappers. More message layers. More abstracted UX.
That makes the user experience better. But it also increases the number of places where a small validation gap can become a major loss.
The bigger lesson for DeFiThe recent bridge hacks show that cross-chain bridge infrastructure is still one of DeFi’s hardest problems.
The industry is moving toward a multi-chain future. That future needs safer cross-chain operations, better validation, stronger monitoring and cleaner failure modes.
One solution is already available: 1inch cross-chain swaps. Instead of bridging and swapping assets manually, you define the tokens and chains you want to move between, and the protocol executes your instructions according to your specified parameters - without taking custody of your assets at any point. Learn more about 1inch cross-chain swaps here.
It’s Bitcoin Pizza Day. Behind the memes, plenty of users have a serious question. Can Bitcoin’s period of explosive growth ever repeat?
Sixteen years ago, an independent programmer named Laszlo Hanyecz ordered two pizzas from a Papa John’s on Atlantic Boulevard in Jacksonville, Florida. Ordinarily, it would have been an unremarkable takeaway order. What made it historic was the means of payment: Hanyecz paid 10,000 Bitcoin for the pizzas - worth roughly $41 at the time.
Hanyecz was one of Bitcoin’s earliest developers and contributed code to the project itself, including some of the first experiments with GPU mining. What he could not foresee was how dramatically Bitcoin’s value would rise in the years that followed.The question is, can that pattern possibly repeat itself? In 16 years’ time, will we be sharing memes about people who sold at $70,000? Or are the days of 1000x firmly behind us?
A decade of impressive growthBitcoin’s growth over the past decade has been one of the most dramatic examples of exponential adoption in modern financial history. When Bitcoin launched in 2009, it had effectively no market value. By 2013, it briefly crossed $1,000 for the first time.
In 2017, it surged close to $20,000 during the first major retail-driven crypto bull market. By 2021, Bitcoin reached nearly $69,000, and in 2025 it climbed above $120,000 amid accelerating institutional adoption and inflows into spot Bitcoin ETFs.
Adoption as a driverThis growth has not been driven by price alone. On-chain activity and adoption metrics have expanded significantly over time. According to Dune Analytics, the Bitcoin network now processes millions of weekly transactions and maintains millions of active addresses.
Institutional adoption has also accelerated Bitcoin’s expansion. The launch of spot Bitcoin ETFs in the United States in 2024 marked a major turning point. By mid-2025, US spot Bitcoin ETFs had attracted more than $50 bln in cumulative inflows, with major financial firms such as BlackRock participating directly in the market.
Will that repeat again?The big question many in the crypto community are asking is whether Bitcoin will ever repeat its past pace of growth. And this is where opinions differ.
Last month, Michael Saylor, head of Bitcoin custodian Strategy, reiterated an ultra-bullish long-term outlook for Bitcoin, projecting that Bitcoin could eventually reach $10 mln per coin.
Tom Lee, head of Ethereum treasury firm BitMine, repeatedly reaffirmed one of the most bullish near-term institutional BTC targets during early 2026 and maintained his famous $250,000 Bitcoin target.
Cathie Wood, CEO of ARK Invest, also remained one of the strongest institutional Bitcoin bulls throughout early 2026.
Meanwhile, skeptics are predicting Bitcoin’s collapse from the current levels.
Peter Schiff, a longtime Bitcoin critic, repeatedly warned of a major BTC collapse during early 2026. “Bitcoin could crash to $20,000 or lower.”
“There is no organic use case reason for Bitcoin to slow or stop its descent,” Michael Burry, an investor known for predicting the 2008 financial crisis, claimed, adding that if the Bitcoin price plunges to $50,000, BTC mining companies that secure the network and process transactions in exchange for fees and newly minted bitcoins could face bankruptcy.
1inch doesn't comment on price movements, and we never give financial advice. And you probably have your own take on this anyway. What we're interested in is utility. What excites us about DeFi isn't asset price fluctuation. It's the capacity this technology has to transform access to finance, for everyone around the world, and free us all to take true control of our assets.
For more insights from 1inch, subscribe to our newsletter
In April, the average RWA swap size on 1inch rose by roughly 91%, pointing to larger on-chain capital allocation.
RWA trading is entering a more serious phase. March brought a spike in activity. But April showed something that's just as important: larger trades.
According to recent 1inch data, average trade size almost doubled - from about $2,000 in March to around $3,800 in April.
What does that mean? It seems that users aren’t just testing tokenized real-world assets, but putting more capital behind them.
Let's understand the market with a deeper dive into the data.
RWA trading activity becomes more selective Q1 2026 was off to a strong start, with RWA tokens generating around $1.15 bln in total volume across roughly 578k transactions, in March alone. Data from April shows activity normalising, with approximately $575 mln in volume and around 152k transactions recorded during the month. However, the average trade size increased sharply, from around $2.0k in March to approximately $3.8k in April. This means that while there were fewer trades, those trades became significantly larger.
Source: 1inch Dune dashboard
RWA trading became less crowded, but the users who remained active traded in larger sizes. The number of active tokens stayed nearly unchanged, showing that the slowdown was not driven by a collapse in asset coverage or user interest across the category.
Leading RWA assets show strong equity and ETF demandOver the last 30 days, the largest RWA tokens by volume included CRCLon, NVDAon, QQQon, SNDKon and MUon. These assets show that user interest remains concentrated around tokenized exposure to major public-market themes, including large-cap equities, ETFs and semiconductor-linked assets.
Source: 1inch Dune dashboard
CRCLon remained the largest asset by volume, while NVDAon and QQQon continued to show strong demand. At the same time, SNDKon and MUon entered the top group, pointing to growing activity around semiconductor-related exposure.
Trading activity rotates into broader market themesOne of the healthier signs is the decline in top-token concentration. In the previous 30 days, the top five RWA tokens accounted for around 62% of total volume. In the last 30 days, that share fell to approximately 50%.
This suggests that RWA trading became less dependent on a small number of dominant assets. Activity started spreading across a wider basket of tokenized instruments, which is a positive signal for market depth and category expansion.
Source: 1inch Dune dashboard
The growth of SNDKon, AMDon, MRVLon, SPYon and INTCon points to a broader shift in user behavior. RWA trading is no longer only about a few headline assets. It is beginning to look more like on-chain access to traditional market sectors, including semiconductors, broad-market ETFs and large-cap equity exposure.
Q1 2026 was the burst phase, Q2 2026 is about the post-hype phaseWhile the first quarter of 2026 was marked by several intense bursts of RWA trading activity, with the strongest daily spike coming on March 10, when RWA volume reached roughly $128M and transactions climbed to around 200k. QQQon was the main driver of that day, contributing approximately $95M in volume.
Other major spikes occurred on March 25, March 11 and March 9, confirming that March activity was highly concentrated in several intense trading sessions.
Source: 1inch Dune dashboard
From April onwards, the pattern changed. The market looked calmer and more selective. There were fewer sharp transaction spikes, lower total volume and fewer trades overall. But average trade size rose, concentration fell and activity remained spread across almost the same number of assets.
The story is clear: early 2026 was the discovery phase. April onwards looks like the consolidation phase.
That suggests RWA trading is becoming more mature. March was about spikes, testing and high transaction counts. April was about larger tickets, wider distribution and more selective activity.
For the RWA narrative, that matters. The category appears to be moving beyond short-term trading bursts and toward more structured on-chain exposure to traditional financial assets.
Disclaimer: Data pulled on May 13, 2026. This content is for general information purposes only and does not constitute financial, investment, tax, or legal advice and is not a recommendation to buy or sell any particular digital asset or to employ any specific investment strategy.