Adopt The SEAL Safe Harbor Agreement
Authors: Orest (1inch), Ilya (1inch), Dickson (SEAL)
Introduction
This proposal outlines 1inch’s adoption of the SEAL (Security Alliance) Whitehat Safe Harbor Agreement (“Safe Harbor Agreement”). By adopting the Safe Harbor Agreement, 1inch improves the security of its on-chain assets by allowing whitehats to intervene during active exploits to save protocol funds.
What is the Safe Harbor Agreement?
The Safe Harbor Agreement addresses a critical need in crypto: enabling whitehats to intervene during active exploits when the urgency of an attack makes traditional processes too slow to save funds.
The Safe Harbor Agreement was created by SEAL, a nonprofit founded by samczsun, to secure the future of crypto. In addition to the Safe Harbor Agreement, SEAL runs multiple initiatives, including SEAL 911 (emergency response hotline for exploits), SEAL Intel (crypto-native threat intelligence sharing), SEAL Frameworks (open source security best practices and playbooks), SEAL Wargames (incident response training), and more in development.
Key aspects of the agreement include:
- Encouraging Whitehats to Protect the Protocol: By adopting the Safe Harbor Agreement, 1inch incentivizes whitehats to step in and protect the protocol during active exploits by limiting their legal exposure.
- Intervention Only During Active Exploits: Whitehats are authorized to act only when there is an immediate or ongoing exploit that threatens the protocol. This agreement is not intended for routine security testing or bug bounty reporting. It applies only to critical situations where the urgency of the exploit supersedes traditional procedures for responsible disclosure in order to save funds.
- Mandatory Return of Rescued Funds: Under the terms of the Safe Harbor, whitehats are required to return all rescued assets to a pre-designated recovery address controlled by the protocol within 72 hours of recovery to ensure these funds are quickly secured, preventing delay or potential loss.
- Clear Guidelines and Legal Protection: The agreement establishes strict rules for how whitehats must operate during an exploit, ensuring recovery efforts are conducted professionally and safely, minimizing the risk of mistakes or further damage to the protocol. By adhering to these guidelines, whitehats can limit their potential legal exposure, allowing them to act in good faith without fear of liability.
- Incentivized Rescue Efforts: To motivate whitehats to act during critical situations, the agreement offers a bounty system that rewards rescuers with a percentage of the recovered assets, up to a predefined cap, for successful interventions.
Safe Harbor has already been adopted by leading protocols such as Uniswap, Zksync, Pendle, Pancakeswap, and Balancer, establishing it as a trusted industry standard for empowering whitehats during active exploits.
Rationale
1inch is committed to enhancing its security and protecting user funds during critical moments. While security audits and other preventive measures are crucial, the unpredictable nature of active exploits requires a swift, decisive response mechanism to minimize potential damage.
Benefits of adopting the Safe Harbor Agreement include:
- Agile Defense Against Exploits: Whitehats are authorized to intervene as soon as an active exploit is detected, enabling them to respond faster than traditional methods. Immediate action minimizes the window for malicious actors, reduces damage, and accelerates asset recovery during critical moments.
- Clarified Rescue Process: The agreement ensures that every step, from intervention to fund recovery, is predetermined and streamlined. Whitehats know exactly where to send recovered funds, preventing chaotic negotiations or rushed decisions during an exploit. This clarity ensures efficient, decisive action when it matters most.
- Clear Financial Boundaries: The predefined bounty system, with a cap matching 1inch’s existing bug bounty, ensures that whitehats are incentivized fairly without creating conflicting priorities between exploit intervention and standard vulnerability disclosure. By setting expectations upfront, it eliminates post-exploit negotiations, ensuring funds are returned promptly without attempts to change the reward amount, keeping the process fair and transparent.
- Aligning with Industry Best Practices: By adopting the Safe Harbor Agreement, 1inch aligns itself with leading security practices across the industry, reinforcing its commitment to staying at the forefront of protocol security.
Adoption of the agreement complements audits by providing an additional layer of security, ensuring that the protocol is better prepared to respond to active threats.
Adoption Details
The 1inch DAO, by approving this proposal, adopts the Safe Harbor Agreement with the parameters set forth below. The 1inch Foundation will act as the designated representative for off-chain and on-chain administrative actions necessary to effectuate the adoption, including execution of the on-chain registration on behalf of the DAO, and will ensure that adjacent entities within the 1inch ecosystem implement the corresponding actions required to give full effect to the adoption.
Bounty Terms
-
Percentage: 10%
-
Cap (USD): 500,000
-
Aggregate Cap (USD): 500,000. Bounties will be distributed pro rata across all qualifying whitehats for a single incident. USD value to be assessed at the time of rescue using the 24-hour volume-weighted average price (VWAP) from a recognized exchange.
-
Retainable: No. Whitehats are required to return all recovered funds in full to the designated recovery address within 72 hours of rescue. 1inch will verify the recovered amounts and disburse the applicable bounty to the whitehat thereafter. No deductions from recovered funds are permitted under any circumstances.
-
Identity: Pseudonymous. Whitehats must identify themselves to the protocol but are not required to provide their real name or any identification, except in cases where we reasonably expect a Whitehat to be in breach of the Diligence Requirements (see the Diligence Requirements section below).
-
Diligence Requirements. Whitehats must:
- Notification. Contact 1inch Security (contact details listed below in the Contact Details section) immediately upon initiating any rescue action;
- Disclosure. Provide a full written disclosure of the vulnerability, rescue methodology, and all addresses used within 24 hours of initiating the rescue;
- Confidentiality. Execute and adhere to a non-disclosure agreement covering all vulnerability details until 1inch confirms the vulnerability has been fully patched and publicly disclosed;
- Sanctions. The Whitehat is not, and is not owned or controlled by or acting on behalf of any person that is the subject of sanctions administered or enforced by OFAC, the UK, the EU, or the UN, and will cooperate with comprehensive sanctions and AML screening by 1inch prior to disbursement.
- Forensic cooperation. For any rescue involving gross exploited value exceeding USD 250,000, provide reasonable cooperation with a forensic investigation conducted by an independent incident-response firm engaged by 1inch, in each case solely for the purpose of verifying Whitehat’s eligibility under Section 2.3(b) of the Agreement.
Not applicable to: - Blackhats and accomplices. Any person who directly or indirectly caused, initiated, assisted, funded, or coordinated the exploit, or is acting in concert with or under common control with such a person. Returning funds does not convert such a person into an Eligible Whitehat.
- Former insiders (12-month look-back). Any person who is, or within the twelve (12) months preceding the rescue was, an employee, contractor, officer, director, or service provider of an entity adjacent to the 1inch ecosystem or any of their affiliates (or an immediate family member of such a person).
Where 1inch has reasonable doubt as to a Whitehat’s compliance with any of the above, 1inch may require the Whitehat to provide additional information, including documentation sufficient to verify their identity, jurisdiction, and beneficial ownership, as a precondition to bounty disbursement. Failure to provide such information within a reasonable period renders the Whitehat ineligible.
Contact Details
| Name | Contact |
|---|---|
| Legal Department | legal@1inch. com |
| Information Technology Department | security@1inch. com |
| Data Privacy | privacy@1inch. com |
Chains & Asset Recovery Addresses
The Asset Recovery Addresses listed above are wallets operated by Degensoft Ltd., the software development company and operator of 1inch User-facing interfaces. Degensoft Ltd. is designated as the recipient of rescued funds because if any active exploit affects Users, the relationship in respect of which the consequences of an incident are felt most acutely, Degensoft Ltd. is the entity that holds the direct contractual relationship with such Users through its Terms of Service. Degensoft Ltd. is therefore best positioned, operationally and legally, to receive rescued funds, coordinate with affected Users, and manage related communications and disclosures.
Where rescued funds are attributable to Users or counterparties of other entities within the 1inch ecosystem (including Resolvers), Degensoft Ltd. will coordinate with the relevant entity to ensure that all parties cooperate in good faith on verification, return, and any required follow-up.
| Chain | Asset Recovery Address |
|---|---|
| Ethereum | 0x7910a10c8c9551c04f69904Be9FF1EE40393FC64 |
| Arbitrum, Avalanche, Base, BSC, Gnosis, Linea, Optimism, Polygon, Sonic, Unichain | 0x3b675cF8Fa7bD1Ad47Ffb03fE3EEcd9a9e234C56 |
| Aurora, Fantom, Klaytn (Kaia), zkSync Era | 0xF1089Db23cD8f6475447e779b91B1bb8719846a3 |
Accounts
| Chain | Name | Address | Child Contract Scope |
|---|---|---|---|
| Mainnet | 1inch Token | 0x111111111117dC0aa78b770fA6A738034120C302 | All |
| Polygon | 1inch Token | 0x9c2C5fd7b07E95EE044DDeba0E97a665F142394f | All |
| Arbitrum | 1inch Token | 0x6314C31A7a1652cE482cffe247E9CB7c3f4BB9aF | All |
| Optimism | 1inch Token | 0xAd42D013ac31486B73b6b059e748172994736426 | All |
| Base | 1inch Token | 0xc5fecC3a29Fb57B5024eEc8a2239d4621e111CBE | All |
| Mainnet | 1inch Staking (st1inch) | 0x9A0C8Ff858d273f57072D714bca7411D717501D7 | All |
| All chains (except zkSync) | Aggregation Router and Limit Order Protocol | 0x111111125421cA6dc452d289314280a0f8842A65 | All |
| zkSync | Aggregation Router and Limit Order Protocol | 0x6fd4383cb451173d5f9304f041c7bcbf27d561ff | All |
| All chains (except zkSync) | KYC Token - Limit orders | 0xAcce5500000f71A32B5E5514D1577E14b7aacC4a | All |
| zkSync | KYC Token - Limit orders | 0x4888651051B2Dc08Ac55Cd0f7D671e0FCba0DEED | All |
| All chains (except zkSync) | Fusion settlement | 0xabd4e5fb590aa132749bbf2a04ea57efbaac399e | All |
| zkSync | Fusion settlement | 0x8261425bf01caf25259dabe36fd05f430b38aee0 | All |
| Mainnet | Fusion settlement with surplus | 0x399740157391a9f1bf4e9921a8834f9bc8f2678e | All |
| All chains (except mainnet and zkSync) | Fusion settlement with surplus | 0x2ad5004c60e16e54d5007c80ce329adde5b51ef5 | All |
| All chains (except zkSync) | KYC Token - Fusion | 0xAccE550000863572B867E661647CD7D97b72C507 | All |
| zkSync | KYC Token - Fusion | 0x46B64318C4f764F6Fe81dFd1F26282A52E0f1680 | All |
| All chains (except zkSync and Gnosis) | Fusion Resolver (proxy) | 0xad3b67BCA8935Cb510C8D18bD45F0b94F54A968f | All |
| Gnosis | Fusion Resolver (proxy) | 0x12b26280e05f82510910cE31A0c03F0c37c6d3a9 | All |
| zkSync | Fusion Resolver (proxy) | 0x07857734576450efd0120C60e0c8501fe285D626 | All |
| All chains (except zkSync) | Crosschain escrow factory | 0x03a25b3215a0e5c15cf23ac4d2e5cf86c0ff7efa | All |
| zkSync | Crosschain escrow factory | 0xd9085ac07da21bd6eb003a530a524ab054ca8652 | All |
| All chains (except zkSync) | KYC Token - Crosschain | 0xACCe550000159e70908C0499a1119D04e7039C28 | All |
| zkSync | KYC Token - Crosschain | 0xC2c4fE863EC835D7DdbFE91Fe33cf1C7Df45Fa7C | All |
| All chains (except zkSync) | Crosschain resolver | 0x33b41fe18d3a39046ad672f8a0c8c415454f629c | All |
| zkSync | Crosschain resolver | 0xAa21Bd5ED538aBb39EA87a613D10e44077F307F3 | All |
| All chains | 1inch Aqua Protocol | 0x4a055aa172c98ec32de118b9b5b6ac8b4099a580 | All |
| All chains | SwapVM | 0xdfd05fe230bfe7b212878414270c72c8345506fa | All |
* All chains - mean the list of the following chains - Mainnet, Base, Klaytn, Aurora, Fantom, Avalanche, Optimism, Arbitrum, Polygon, BSC, Gnosis, Linea, Sonic, Unichain, zkSync
Scope & Limits
This Safe Harbor is a unilateral public commitment from the 1inch Protocol Community to qualifying Whitehats. It irrevocably releases 1inch’s own claims against any Whitehat who conducts an Eligible Funds Rescue in full compliance with this agreement. It does not, and cannot, bind Users or third parties who are not parties to this agreement, including regulators and law enforcement, and does not waive or limit any claims, enforcement actions, or proceedings that such third parties may bring against Whitehat. User consent to Eligible Funds Rescues is obtained separately through the Safe Harbor clause inserted into the 1inch Terms of Service, which Users accept as a condition of using the Products. Residual third-party risk is disclosed in Exhibit E of the Safe Harbor Agreement and is acknowledged by Whitehats as a condition of participation.
Scope Note
1inch protocols are non-custodial. 1inch does not hold User private keys and does not take custody of User or counterparty funds. Tokens, nevertheless, may become exposed to an exploit through a variety of architectural dependencies, and the intended scope of Eligible Funds Rescues under this Agreement includes, without limitation:
- Tokens with an on-chain balance attributable to any in-scope 1inch Account at the time of an active exploit;
- Tokens subject to an active ERC-20 (or equivalent) approval granted by a User or other counterparty to any in-scope 1inch Account at the time of the exploit;
- Tokens in transit or in temporary positions arising from the execution or settlement of any 1inch order, intent, or cross-chain flow, until final settlement is complete;
- Any other Tokens that, at the time of an active exploit, are indirectly under the control of an in-scope 1inch Account by virtue of approvals, signed intents, routing dependencies, or other architectural linkage to such Account.
For the avoidance of doubt, the fact that such tokens are protected under this Agreement does not imply any custody or control by 1inch. 1inch does not hold User or counterparty private keys, does not take custody of tokens, and does not control assets held by Users, resolvers, or third parties. Exposure to a 1inch-related exploit arises through voluntary approvals, signed intents, cross-chain escrow arrangements, or other architectural dependencies between those actors and the in-scope 1inch contracts.
Important Disclaimers
- The Safe Harbor Agreement is a legal framework published by the Security Alliance (SEAL). 1inch DAO is proposed to adopt the standard Safe Harbor Agreement without modifying its core legal language, and to configure only protocol-specific parameters (bounty terms, scope, diligence requirements, asset recovery addresses, contact details).
- Safe Harbor is a civil contract. It does not provide immunity from criminal liability, regulatory enforcement action, or claims brought by third parties that are not bound by the Agreement.
The Agreement’s enforceability may vary by jurisdiction. Whitehats remain solely responsible for compliance with all applicable laws, including securities, money transmission, tax, and cybercrime laws.
Implementation Plan
- Register Agreement On-Chain. The agreement will be registered on Ethereum in the Safe Harbor Registry at address
0x326733493E143b8904716E7A64A9f4fb6A185a2c, including all adoptionDetails. This ensures transparency and immutability. - Terms of Service integration. 1inch DAO adopts the Agreement at the Protocol level; relevant disclosures shall be placed within GitHub repositories. Adjacent entities within the 1inch ecosystem that operate User-facing interfaces (including wallet applications, dApp front-ends, and other UIs interacting with in-scope 1inch Accounts) shall procure the corresponding User-consent language in their own terms, aligning those terms with Exhibit D of the Agreement.
- Documentation. The adoption details, scope, recovery addresses, contact information, and associated disclosures shall be published on 1inch’s official documentation site and maintained as an ongoing reference point for Whitehats, Users, and ecosystem participants.
- Communicate Adoption. An official announcement will be made across all 1inch communication channels, explaining the adoption and its significance to the community.
- Future Updates to Scope:
- New protocols deployed within the 1inch ecosystem may be added to the scope of the Agreement either through a governance vote or, where such Protocols are deployed by other entities within the ecosystem, through action by those deploying entities in line with the purpose of this Proposal. The 1inch Foundation shall be requested to assist with the on-chain registration of such additions.
- Material changes to the Agreement, including the removal of existing in-scope contracts, changes to the bounty percentage or cap, changes to the Asset Recovery Addresses, or amendments to the Diligence Requirements, shall require a governance vote.
- A changelog of scope updates shall be published on the documentation site regularly.
Conclusion
Adopting the SEAL Whitehat Safe Harbor Agreement equips 1inch with a rapid response mechanism for active exploits, enabling whitehats to step in effectively when needed most. The agreement provides clear guidelines for action, increasing the protection of User and protocol funds and demonstrating 1inch’s commitment to proactive security.
Note: This proposal does not request any funds from the DAO treasury and does not involve any budget allocation. It solely seeks governance approval for 1inch to adopt the SEAL Whitehat Safe Harbor Agreement.