Rubic; Reviewed & Scored | The Block Note
DEX Aggregator Review · Updated August 2026

Rubic:
a genuinely broad cross-chain aggregator, carrying a severe 2022 incident history and a much smaller scale.

We tore apart Rubic, a cross-chain and on-chain DEX aggregator live since 2020, across the same aggregator-adapted scorecard we've used for 1inch and Jupiter. From a genuinely distinctive embeddable Relay widget and SDK letting other dApps build in cross-chain swap functionality directly, disclosed post-incident security reforms including a granular, transparently-published MixBytes audit, and a thoughtful ETH-denominated staking design, to what we can't set aside: two separate, confirmed hacks within two months in 2022, including a November incident where an attacker compromised the admin wallet's private keys directly, a more serious category of failure than a typical smart-contract bug, and a real, wide, unresolved discrepancy across our sources on Rubic's basic scope, chain counts ranging from 13 to 70+ and DEX counts ranging from 60 to 220+ depending on the source and its date; and landed on a score the marketing page won't show you.

Type Cross-Chain DEX Aggregator + embeddable SDK Platforms Web · Widget/SDK · 13-70+ chains (disputed) Fees Aggregated route fees; RBC used for staking/fees Discount Offer None
rubic
Aggregator
Two confirmed 2022 hacks in two months
Scope claims vary widely across sources

Our take, up front: Rubic is a decentralized cross-chain and on-chain DEX aggregator with roots back to 2020, positioning itself as a "one-click" way to swap assets both within and between blockchains, with no KYC required. Real, genuinely distinctive Rubic Relay widget and full SDK, letting other dApps embed cross-chain swap functionality directly into their own products, a genuine B2B extension beyond the core consumer aggregator most platforms in this category don't offer. Real, disclosed, granular audit transparency: a MixBytes audit specifically disclosed its exact findings (2 critical, 2 medium, and 1 low severity issues), with 2 critical and 1 medium subsequently fixed and reported publicly, a genuinely rare level of specific, verifiable audit detail. Real, disclosed Private RPC and MEV-bot safeguards, an open-source codebase, and a thoughtfully-designed staking program paying rewards in ETH specifically so their value doesn't depend on RBC's own token price. Real, disclosed accelerator and incubator participation, including Sony's Incubation Program, Consensys Scale, and Solana Superteam. What we can't set aside: a real, genuinely severe 2022 incident history. In November 2022, an attacker compromised the admin wallet's private keys directly and stole roughly 34 million RBC tokens, a more serious category of failure than a typical smart-contract bug, followed by a separate $1.2 million hack the very next month. Real, genuinely important, honest data-quality concern: our sources disagree substantially on Rubic's basic current scope, with cited chain counts ranging from 13 to more than 70 and DEX/bridge counts ranging from 60 to more than 220, depending on the specific source and how recently it was published. Real, honestly minimal disclosed scale and funding relative to the other aggregators we've reviewed: roughly $644 million in cumulative volume and 270,000 unique wallets at their most generously cited, against roughly $500,000 raised in a 2020 funding round, dramatically smaller than 1inch's or Jupiter's disclosed backing. We weighted all of it below.

Real, genuinely severe, confirmed 2022 incident history: two separate hacks within two months, an admin-wallet private-key compromise resulting in roughly 34 million RBC tokens stolen in November, and a separate $1.2 million hack in December. Real, genuinely positive, disclosed post-incident reforms: a MixBytes audit with granular, transparently-disclosed findings (2 critical, 2 medium, and 1 low severity, with 2 critical and 1 medium subsequently fixed), an open-source codebase, and disclosed Private RPC and MEV-bot safeguards. Real, honest, structurally distinctive aggregator risk shared with every platform in this category: security depends partly on the many third-party DEXs and bridges Rubic routes through.

Why this scores below the midpoint: genuinely transparent, granular post-incident audit disclosure and real security reforms are positives, tempered by a genuinely severe 2022 incident history that specifically included an admin-level private-key compromise, a more serious category of failure than a typical smart-contract bug.

Pros

  • Granular, transparently-disclosed MixBytes audit findings and remediation status
  • Open-source codebase; disclosed Private RPC and MEV-bot safeguards post-incident

Cons

  • Nov 2022: admin wallet private keys compromised, ~34M RBC stolen
  • Dec 2022: a separate $1.2M hack, one month later

Real, genuinely broad aggregation claims, though with a wide, unresolved discrepancy across our sources on exact scope: chain counts range from 13 to 70+ and DEX/bridge counts range from 60 to 220+ depending on the source and its date. Real, disclosed cumulative scale figures that are, even at their most generous, dramatically smaller than the aggregators we've reviewed so far: roughly $644 million in cumulative volume and 270,000 unique wallets, against 1inch's $300 billion-plus and Jupiter's $2.6-3 billion in TVL alone.

Why this scores below the midpoint: real, disclosed aggregation functionality, tempered by a genuinely wide, unresolved discrepancy in basic scope claims and a scale dramatically smaller than the category's leaders.

Pros

  • Genuinely broad aggregation, even at the more conservative end of our sources' claims

Cons

  • Wide, unresolved discrepancy on chain count (13 vs. 70+) and DEX count (60 vs. 220+)
  • Cumulative scale dramatically smaller than 1inch or Jupiter

Real, genuinely non-custodial; no KYC required to trade. Real, genuinely minimal disclosed funding: approximately $500,000 raised in 2020, dramatically smaller than the institutional backing we've found at other platforms in this series. Real, disclosed accelerator and incubator participation (Sony, Consensys, Solana Superteam), a modest but real credibility signal.

Why this scores at the midpoint: genuinely non-custodial architecture and disclosed accelerator participation are real positives, tempered by minimal disclosed funding relative to the category's better-capitalized platforms.

Pros

  • Genuinely non-custodial; no KYC required
  • Disclosed accelerator participation (Sony, Consensys, Solana Superteam)

Cons

  • Minimal disclosed funding (~$500K, 2020) relative to category-leading platforms

Real, genuinely broad aggregation across many blockchains and DEXs, even accounting for the discrepancy in the exact count across our sources. Real, a distinctive Rubic Relay widget and SDK letting other dApps embed cross-chain swap functionality directly, a genuine B2B extension of the core aggregator.

Why this scores above the midpoint: genuinely broad coverage claims and a distinctive embeddable SDK, tempered by the real, unresolved uncertainty in exactly how broad that coverage currently is.

Pros

  • Genuinely broad aggregation across many chains and DEXs
  • Distinctive Rubic Relay widget/SDK for embedding cross-chain swaps into other dApps

Cons

  • Exact current scope is genuinely unclear given the discrepancy across our sources

Real, genuinely accessible low minimum swap size, cited at just $0.50. Real, disclosed fiat on-ramp support via its Crypto Tap feature. Real, honest, disclosed broad geofencing list excluding a long list of jurisdictions, including some unusual inclusions worth confirming directly given how dated that specific source felt.

Why this scores above the midpoint: genuinely accessible minimums and disclosed fiat on-ramp support are real positives, tempered by an honest, broad geofencing footprint.

Pros

  • Genuinely low minimum swap size (from $0.50)
  • Disclosed fiat on-ramp support via Crypto Tap

Cons

  • A broad, disclosed geofencing list across many jurisdictions

Real, disclosed "1:1 stable-to-stable swaps with no hidden fees, no slippage" claim. Real, a Swap to Earn rewards program crediting RBC points for trading activity. Real, distinctive staking design paying rewards in ETH rather than RBC specifically to preserve reward value independent of the token's own price.

Why this scores above the midpoint: a genuinely thoughtful ETH-denominated staking design and disclosed stable-swap terms are real positives.

Pros

  • ETH-denominated staking rewards, insulated from RBC's own token price
  • Disclosed 1:1 stable-to-stable swap terms with no hidden fees

Cons

  • Some fee claims come from Rubic's own promotional material rather than independent testing

Real, genuinely distinctive Rubic Relay widget and full SDK for other dApps. Real, disclosed Private RPC and MEV-bot safeguards. Real, Swap to Earn points program.

Pros

  • Distinctive embeddable Relay widget/SDK; disclosed Private RPC and MEV-bot safeguards

Cons

  • Fewer distinctive consumer-facing extras than the larger aggregators in this series
Where to get it

Access only through Rubic's official app, and verify the current, correct domain directly before connecting a wallet.

Given the 2022 admin-key compromise specifically, treat this as a platform where operational security history matters as much as code audits; consider limiting the size of any single swap and revoking unused approvals regularly.

0/ 100

A real, distinctive aggregator, honestly overshadowed by its own 2022 history and its scale relative to category leaders.

We want to give Rubic real, specific credit for something genuinely rare: it published exact, granular details of its own MixBytes audit findings, including which critical issues were found and confirmed fixed, a level of transparency most platforms in this entire project simply don't offer. Its embeddable Relay widget is also a genuinely distinctive product most consumer-facing aggregators don't build. But we can't let that transparency and technical breadth outweigh what actually happened in 2022: two separate hacks within two months, one of them a direct compromise of the admin wallet's own private keys, a category of failure that says something different, and arguably more concerning, than a smart-contract bug alone. Layered on top of that is a real, honest uncertainty about the platform's current scale, since our sources gave us genuinely inconsistent numbers on how many chains and DEXs it actually covers today, and a scale that's dramatically smaller than the two aggregators we've reviewed so far. The fair picture is a real, technically interesting project that hasn't caught up to the caliber of the category's leaders.

Best forDevelopers interested specifically in embedding Rubic's cross-chain SDK into their own dApp, or users making smaller, less consequential swaps
Not forTraders moving significant value who want the scale, consistency, and security track record of the category's more established aggregators
Score Ledger
rubic · 7 line items
01Security12.0
02Routing9.0
03Decentralization5.5
04Coverage9.0
05UX6.0
06Fees6.5
07Extras3.25
TOTAL51.25
≈ 51 / 100; Distinctive, but overshadowed

The scorecard above is deliberately general. Whether Rubic is right for you depends heavily on which of these you already are.

Best fit

The developer who wants to embed cross-chain swap functionality directly into their own dApp via the Relay SDK

This is genuinely where Rubic's most distinctive, real value concentrates most heavily.

Good fit

The user making smaller, less consequential cross-chain swaps who values the low $0.50 minimum

Given the platform's history and scale, this profile genuinely carries less real risk than a large single swap.

Workable fit

The user who verifies the current official domain directly and revokes approvals regularly

Given the platform's operational-security history, these habits genuinely matter more here than elsewhere.

Poor fit

Traders moving significant value who want the scale and security track record of the category's established leaders

1inch or Jupiter, both reviewed earlier in this series, are the better fit for this specific profile.

The scorecard covers the headline judgment calls. These four tables cover the specifics we didn't want to bury in prose; the 2022 incidents timelined precisely, the scope discrepancy presented transparently, the MixBytes audit findings broken down, and our first three-way aggregator comparison.

Two hacks in two months, precisely

WhenWhat happened
November 2022Attacker compromised the admin wallet's private keys directly and stole ~34 million RBC tokens
December 2022A separate hack resulted in ~$1.2 million in losses
Since thenDisclosed security reforms: MixBytes audit, open-source codebase, Private RPC, MEV-bot safeguards

We're treating the November incident as a distinct, more serious category of failure than a typical smart-contract bug specifically because it involved direct compromise of administrative private keys, an operational security failure rather than a code-level vulnerability.

Scope claims, presented transparently

SourceChains citedDEXs/bridges cited
CoinGecko1360+
Medium (2023)60+90+
Messari (2024)70+220+
nadcab.com case studyNot specified200+

This is a genuinely wide, unresolved range; we'd recommend confirming current chain and DEX support directly on Rubic's own app before relying on any single cited figure, including ours.

The MixBytes audit findings, precisely

SeverityFoundStatus after revision
Critical22 fixed
Medium21 fixed, 1 demoted to low
Low1 (plus the demoted medium)Acknowledged

This level of granular, specific public disclosure is genuinely rare among the platforms we've reviewed in this project; most disclose only that an audit occurred, not its exact findings and remediation status.

Three aggregators, side by side

1inchJupiterRubic
ScopeMulti-chain, 13+ chainsSolana-nativeMulti-chain, exact count disputed
Confirmed incidentsOne (2025, resolver infra)One (2024, user phishing)Two (2022, incl. admin-key compromise)
Disclosed backing/fundingNot specifically disclosedNot specifically disclosed beyond token model~$500K (2020)
Distinctive extraFusion intent-based MEV protectionFull "DeFi superapp" suiteEmbeddable Relay widget/SDK

All three fill genuinely different niches; Rubic's real distinctiveness is its embeddable infrastructure product, though its security history and scale currently trail the other two significantly.

We don't just want to hand you our number; we want to show you how it sits next to what other review desks and comparison sites have published. Our usable, genuinely independent source pool for Rubic was notably thinner than for most platforms in this project; several sources we found were official documentation, promotional case studies, or dated, low-detail listings, and we've excluded all of those from this specific comparison.

The Block Note (us)N/A / 100
Industry averageN/A / 100

Our score lands meaningfully below the two genuinely independent sources we found; those sources describe Rubic's aggregation functionality and post-incident reforms without dwelling as heavily on the original severity of the 2022 admin-key compromise specifically, or on how small the platform's current scale is relative to category leaders.

SourceScoreType

Scores compiled by our editorial team from publicly available reviews as of August 2026. "Editorial estimate" means the outlet didn't publish a single numeric score, so we converted their published verdict and sentiment into a comparable 100-point figure. Verify current figures directly with each source before citing them elsewhere.

Yes, twice within two months in 2022: a November incident where an attacker compromised the admin wallet's private keys directly and stole roughly 34 million RBC tokens, and a separate $1.2 million hack in December.

It involved a direct compromise of admin wallet private keys, an operational security failure rather than a smart-contract bug. We treat this as a distinct, arguably more serious category of failure than a typical code-level exploit.

Our sources disagree substantially: chain counts range from 13 to more than 70, and DEX/bridge counts range from 60 to more than 220, depending on the source and its publication date. We'd recommend confirming current coverage directly on Rubic's own app.

An embeddable widget and SDK that lets other dApps build cross-chain swap functionality directly into their own products, a genuinely distinctive B2B extension of Rubic's core consumer aggregator.

No. Even at its most generously cited figures ($644 million cumulative volume), Rubic is dramatically smaller than 1inch's $300 billion-plus cumulative volume or Jupiter's $2.6-3 billion TVL.

No. It's non-custodial and doesn't require KYC to start swapping.

Users lock RBC tokens and earn staking rewards paid in ETH rather than RBC, a design specifically intended to keep reward value independent of RBC's own token price movements.

2 critical, 2 medium, and 1 low severity finding. After revision, 2 critical and 1 medium were fixed, and the remaining medium finding was demoted to low severity.

Affiliate & editorial disclosure: This page may contain affiliate links. If you buy through one, we may earn a commission at no extra cost to you. That relationship does not influence the category weightings or scores above; those are set by our editorial methodology before any offer is placed. Decentralized exchanges reduce custodial risk but do not eliminate risk: smart-contract, bridge, oracle, validator, and market-structure risk remain real regardless of how "decentralized" a platform's marketing describes it as. Leverage trading can result in losses exceeding your initial deposit. Nothing here is financial advice.
Features, pricing, and security details verified against public sources as of Aug 2026; always confirm current terms directly with Rubic.

More Reviews