1inch HackenProof Bug Bounty — Live PoC Index

Attacker infrastructure: attack.netfragile.store (VPS 145.239.36.49)

IDSeverityTargetTypePoC
MCP-01CRITICALapi.1inch.comOpen OAuth DCRLive Demo | Callback
SC-01CRITICAL1inch.networkExternal script no SRIDemo
XSS-01HIGH1inch.networkrrweb postMessageLive Demo
XSS-02HIGH1inch.networkpostMessage no originLive Demo
CONFIG-LEAK-02HIGHbusiness.1inch.com5 creds in JS bundleVerified via scripts
ANALYTICS-01MEDIUM1inch.networkAnalytics injectionVerified 5/5