Skip to main content
AVOID.NET
1inchreviewed 2026-09-17 · 31 claims checked

Fact-check findings

What an automated fact-checker found when it re-read 1inch against the sources the page cites. Only the most recent review is shown.

Read this first

These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.

“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.

Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.

disputed

1 claim

The reviewer could not reconcile the claim with the evidence it cited. This is a lead, not a ruling that the claim is false.

  1. #6[disputed][awaiting moderator]in section: Security Incident: Front-End Supply Chain Attack (October 2024)
    Attackers gained access to the GitHub account of a LottieFiles senior software engineer and pushed three malicious updates in rapid succession, injecting unauthorized scripts into JSON files served by affected sites.
    reviewerAttackers compromised a GitHub account of a LottieFiles senior engineer to push malicious updates in the October 2024 supply chain attack.Multiple independent security-industry writeups (Socket.dev, The Hacker News, TechTarget, Sonatype) attribute the attack to a compromised npm/npmjs publishing token obtained by phishing, and one source explicitly states there was no evidence the GitHub repository itself was altered. The page's claim that attackers accessed a 'GitHub account' is a mischaracterization of the actual attack vector.
    Proposed correction (not yet applied)
    Attackers compromised the npm (npmjs.com) publishing credentials of a LottieFiles software engineer via a phishing attack and pushed three malicious updates in rapid succession, injecting unauthorized scripts into the package served by affected sites.

unverifiable

3 claims

No source the reviewer could reach confirms or contradicts the claim.

  1. #4[unverifiable][awaiting moderator]in section: Overview and Background
    1inch Labs maintains onsite offices in Dubai.
    reviewer1inch Labs maintains onsite offices in Dubai.Plausible given the DIFC entity structure, but a physical onsite office (as opposed to a registered legal address) could not be independently confirmed.
  2. #25[unverifiable][awaiting moderator]in section: Token Price Performance and Market Position
    At the time of the March 2025 exploit, the token was trading near $0.23.
    reviewerAt the time of the March 2025 exploit, the 1INCH token was trading near $0.23.Plausible given the broader 2024-2025 price trend but not independently confirmed to the day.
  3. #28[unverifiable][awaiting moderator]in section: Regulatory Posture
    No direct regulatory enforcement actions by the SEC, CFTC, DOJ, or OFAC against 1inch or its principals have been identified as of this investigation.
    reviewerNo direct SEC/CFTC/DOJ/OFAC enforcement actions against 1inch or its principals have been identified.This is a negative claim (absence of enforcement action). No search turned up any contradicting enforcement record, which is consistent with the page, but a negative claim of this kind cannot be fully confirmed by web search alone.

partially supported

1 claim

The cited evidence supports part of the claim but not all of it.

  1. #26[partially supported][awaiting moderator]in section: Token Price Performance and Market Position
    On the competitive landscape, 1inch held a dominant position in DEX aggregation through mid-2025, capturing approximately 59.1% of aggregator volume in Q2 2025, before contracting to 28.3% in Q3 2025 as BNB Chain incentive activity normalized.
    reviewer1inch captured approximately 59.1% of DEX aggregator volume in Q2 2025, contracting to 28.3% in Q3 2025 as BNB Chain incentive activity normalized.The Q2 2025 59.1% figure and the underlying BNB Chain-driven narrative are confirmed. The specific Q3 2025 28.3% figure could not be independently verified due to access restrictions on the primary source during this review; it is plausible and directionally consistent with reported BNB Chain incentive normalization, but should be treated as not yet independently confirmed.

confirmed

24 claims

The cited evidence supports the claim as written.

  1. #1[confirmed][no action needed]in section: Overview and Background
    The protocol was first prototyped at a New York ETHGlobal hackathon in May 2019 by Sergej Kunz and Anton Bukov, who collaborated under the YouTube channel CryptoManiacs, which focused on live smart contract security audits.
    reviewer1inch was prototyped at a New York ETHGlobal hackathon in May 2019 by Sergej Kunz and Anton Bukov, who met through the CryptoManiacs YouTube channel.Multiple independent sources corroborate the founding story exactly as stated.
  2. #2[confirmed][no action needed]in section: Overview and Background
    The protocol launched publicly in August 2020.
    reviewer1inch protocol launched publicly in August 2020.Confirmed by independent secondary sources.
  3. #3[confirmed][no action needed]in section: Overview and Background
    The company's legal structure operates through Degensoft Ltd (DIFC, UAE) as the developer entity and Degensoft Ltd (BVI) as the operator.
    reviewer1inch's legal structure runs through Degensoft Ltd (DIFC, UAE) as developer and Degensoft Ltd (BVI) as operator.Verified directly against 1inch/Degensoft's own disclosure page.
  4. #5[confirmed][no action needed]in section: Overview and Background
    Fusion+ (cross-chain atomic swaps launched in September 2024)
    reviewerFusion+ cross-chain atomic swap system launched in September 2024.Timeline entry (2024-09-18) and section text agree with the cited press release date.
  5. #7[confirmed][no action needed]in section: Security Incident: Front-End Supply Chain Attack (October 2024)
    The malicious code caused 1inch's frontend to display wallet-connection popups linked to a known crypto drainer called 'Ace Drainer.'
    reviewerThe malicious code caused wallet-connection popups linked to the 'Ace Drainer' crypto drainer.Well corroborated across multiple outlets.
  6. #8[confirmed][no action needed]in section: Security Incident: Front-End Supply Chain Attack (October 2024)
    The 1inch Foundation subsequently submitted a governance proposal to compensate affected users with approximately $768,026 in USDC.
    reviewerThe 1inch Foundation proposed compensating affected users with approximately $768,026 in USDC.Exact dollar figure matches the cited source precisely.
  7. #9[confirmed][no action needed]in section: Security Incident: Private Key Compromise (December 2024)
    On December 9, 2024, 1inch disclosed an unauthorized access incident in which attackers fraudulently obtained the private key of the owner of the 1inch Labs Resolver smart contract.
    reviewerOn December 9, 2024, attackers fraudulently obtained the private key of the 1inch Labs Resolver contract owner and altered contract settings/transferred funds; user funds were not at risk.Confirmed by 1inch's own incident report and secondary reporting; the page omits that 1inch offered a $250,000 bounty for information on the attacker, which is a minor coverage gap rather than an error.
  8. #10[confirmed][no action needed]in section: Security Incident: Fusion v1 Resolver Exploit — $5 Million (March 2025)
    On March 5–6, 2025, attackers exploited a buffer overflow vulnerability in the deprecated Fusion v1 Settlement contract.
    reviewerOn March 5-6, 2025, attackers exploited a buffer-overflow-style calldata corruption in the deprecated Fusion v1 Settlement contract's `_settleOrder` function, corrupting `interactionLength` to impersonate a resolver and steal ~2.4M USDC and 1,276 WETH (~$5M).Date range, mechanism, and stolen amounts are corroborated across Halborn, Olympix, Cointelegraph and SlowMist reporting. Some technical writeups describe the root cause more precisely as an integer underflow/negative-length calldata corruption rather than a classic 'overflow,' but 'buffer overflow' is the term used by the page's own cited sources and is a reasonable lay description of the same corruption bug, so this is not treated as a dispute.
  9. #11[confirmed][no action needed]in section: Security Incident: Fusion v1 Resolver Exploit — $5 Million (March 2025)
    Following on-chain negotiations and a bug bounty agreement, the attacker returned the majority of the stolen funds by approximately 4:12 AM on March 6, retaining roughly $450,000 (approximately 10%) as a bounty.
    reviewerThe attacker returned the majority of stolen funds after a bug-bounty negotiation, keeping roughly $450,000 (~10%) as a bounty.The $450,000/~10% bounty figure is well corroborated. The precise '4:12 AM' return time could not be independently confirmed (the Halborn technical writeup that likely contains this level of detail returned a 403/429 on repeated fetch attempts), so treat that specific timestamp as a minor unverified detail rather than a dispute.
  10. #12[confirmed][no action needed]in section: Security Incident: Fusion v1 Resolver Exploit — $5 Million (March 2025)
    This incident temporarily shifted market share leadership to CoW Swap, with 1inch falling to a 22.8% share in March 2025.
    reviewerThe March 2025 hack temporarily shifted DEX aggregator market-share leadership to CoW Swap, with 1inch falling to 22.8% share in March 2025.Figures match independent reporting exactly.
  11. #13[confirmed][no action needed]in section: Security Incident: TrustedVolumes Resolver Exploit — $5.87 Million (May 2025)
    In early May 2025, 1inch liquidity provider and resolver TrustedVolumes was drained of approximately $5.87 million in crypto assets, including 1,291.16 WETH, 206,282 USDT, 16.939 WBTC, and 1,268,771 USDC.
    reviewerIn early May 2025, TrustedVolumes was drained of ~$5.87M (1,291.16 WETH, 206,282 USDT, 16.939 WBTC, 1,268,771 USDC) via a flaw in its custom RFQ proxy, attributed to the same March 2025 attacker; 1inch said its own systems/funds were unaffected; some reporting cited $6.7M.All figures, the RFQ-proxy mechanism, attacker attribution, and the higher $6.7M reporting variant are corroborated by independent outlets (The Block, The Defiant, Cryptopolitan).
  12. #14[confirmed][no action needed]in section: Security Incident: TrustedVolumes Resolver Exploit — $5.87 Million (May 2025)
    This was reported as the fifth major DeFi hack in the first two weeks of May 2025.
    reviewerThis was reported as the fifth major DeFi hack in the first two weeks of May 2025.Matches independent reporting on the DeFi exploit wave that week.
  13. #15[confirmed][no action needed]in section: Alleged Connections to Russian Federal Security Service
    According to the Molfar report, Bukov allegedly graduated in 2011 from the Institute of Cryptography, Communications and Informatics of the FSS Academy of the Russian Federation with a degree in high-performance computer systems engineering.
    reviewerMolfar's report states Bukov graduated in 2011 from the Institute of Cryptography, Communications and Informatics of the FSS Academy of the Russian Federation with a degree in high-performance computer systems engineering.The page correctly frames this as Molfar's allegation, which the source text supports. Independent corroboration of Bukov's biography outside the Molfar report was not found, consistent with the page's own caveat that this is a single-source allegation.
  14. #16[confirmed][no action needed]in section: Alleged Connections to Russian Federal Security Service
    The Molfar report also flagged an anomalous airdrop allocation in December 2020, where one wallet received tokens then valued at approximately $22.7 million.
    reviewerMolfar's report flagged an airdrop wallet receiving tokens valued at approximately $22.7 million in December 2020.Accurately represents the source's specific figure.
  15. #17[confirmed][no action needed]in section: Alleged Connections to Russian Federal Security Service
    As a secondary concern, the investigators noted that Binance Labs participated in 1inch's seed round, referencing a Reuters report alleging Binance had cooperated with the Russian FSS by sharing customer data.
    reviewerInvestigators noted Binance Labs participated in 1inch's seed round, referencing a Reuters report alleging Binance cooperated with the Russian FSS by sharing customer data.Accurately represents the source, and correctly frames this as a secondary/derivative concern rather than a direct allegation against 1inch.
  16. #18[confirmed][no action needed]in section: Alleged Connections to Russian Federal Security Service
    Molfar acknowledged limitations in its own analysis, stating that 'based on the available information, it is impossible to establish exactly' certain claims.
    reviewerMolfar acknowledged limitations in its own analysis (quoted hedge language).Faithful paraphrase of Molfar's own hedging language, applied appropriately to signal the report's limitations.
  17. #21[confirmed][no action needed]in section: Governance and Tokenomics Concerns
    The 1INCH token has a total maximum supply of 1.5 billion tokens. At launch in December 2020, the distribution was allocated as follows: approximately 33% to backers and investors, 30% to community incentives, 22.5% to core contributors, and 14.5% to a network growth fund. All tokens were scheduled to have fully unlocked by end of 2024.
    reviewerThe 1INCH token has a maximum supply of 1.5 billion, allocated ~33% backers/investors, 30% community incentives, 22.5% core contributors, 14.5% network growth fund, fully unlocked by end of 2024.Supply cap and allocation percentages are confirmed. Note that as of this review, tokenomist.ai shows roughly 93.7% of supply as unlocked/circulating rather than 100%, but this appears to reflect claim-rate/circulating-supply accounting rather than a later vesting schedule; the underlying December 2024 vesting-completion event is independently corroborated, so this is not treated as a dispute.
  18. #22[confirmed][no action needed]in section: Governance and Tokenomics Concerns
    In July 2025, the 1inch team was reported to have purchased 11.81 million 1INCH tokens valued at approximately $3.3 million, a move that can reduce circulating supply but also concentrates holdings among insiders.
    reviewerIn July 2025, the 1inch team purchased 11.81 million 1INCH tokens valued at approximately $3.3 million.Figures match multiple independent outlets covering the same on-chain purchase.
  19. #23[confirmed][no action needed]in section: Token Price Performance and Market Position
    By end of 2022, the token had fallen over 80% from its peak, trading near $0.38.
    reviewerBy end of 2022 the token had fallen over 80% from its peak, trading near $0.38; in 2024 it hit an all-time low of approximately $0.21 in early September.Confirmed within reasonable rounding.
  20. #24[confirmed][no action needed]in section: Token Price Performance and Market Position
    In 2024, performance worsened further, with the token hitting an all-time low of approximately $0.21 in early September 2024.
    reviewerIn 2024 the token hit an all-time low of approximately $0.21 in early September 2024.Confirmed within reasonable rounding.
  21. #27[confirmed][no action needed]in section: Token Price Performance and Market Position
    CoW Protocol has emerged as a direct competitor, briefly overtaking 1inch in monthly market share following the March 2025 hack, with CoW Swap reaching 33.85% share in March 2025 versus 1inch's 22.8%.
    reviewerCoW Swap reached 33.85% market share in March 2025 versus 1inch's 22.8%.Precisely matches independent reporting.
  22. #29[confirmed][no action needed]in section: Regulatory Posture
    1inch co-founder Sergej Kunz has publicly commented on SEC enforcement activity against centralized exchanges, stating in 2023 that the SEC was 'killing innovation in the United States.'
    reviewerSergej Kunz publicly stated in 2023 that the SEC was 'killing innovation in the United States.'Direct quote and attribution confirmed against the cited article.
  23. #30[confirmed][no action needed]in section: Regulatory Posture
    The company has also integrated with TRM Labs for AML screening, identifying hundreds of high-risk addresses across screened wallets.
    reviewer1inch integrated with TRM Labs for AML screening, identifying hundreds of high-risk addresses across screened wallets.Matches the cited case study almost verbatim.
  24. #31[confirmed][no action needed]in section: Phishing and Impersonation Risks
    Security research firms PCRisk and EnigmaSoft have catalogued multiple variants of these impersonation schemes.
    reviewerPCRisk and EnigmaSoft have catalogued multiple 1inch impersonation/phishing scam variants.Direct citations are removal guides that describe exactly the impersonation pattern the page summarizes.
How this fits together. The reviewer reads the published page and its cited sources and records one finding per claim. A human moderator decides whether each proposed correction is applied; those decisions, and the score changes they cause, appear in the audit log. Earlier review runs are not shown here; only the latest reflects the page as it stands.