Most “best cross-chain swap” round-ups put THORChain, LI.FI, 1inch, and instant-swap services in one ranked list, as if they compete for the same job. They don’t. These are four structurally different tools with different custody models, different attack surfaces, and different failure modes — and in May 2026, THORChain’s node network suffered an estimated $10.7 million exploit that put those differences on full display. This guide maps the categories, not a single winner, so you can pick the right tool for what you’re actually trying to do.
”Cross-chain swap” is four different things
The phrase gets used for anything that moves value between blockchains, but the mechanics — and who holds the risk if something breaks — vary by category.
Instant-swap / non-custodial exchange aggregators. No shared pool, no smart contract holding your funds. Each swap is a bilateral transaction: you send to a deposit address, the provider sends the output to your destination address. A hack here compromises one provider’s operational wallet during the swaps it’s mid-executing, not a shared reserve.
Cross-chain liquidity protocols. THORChain-style systems run shared vaults that pool deposited liquidity, secured by a validator network using threshold signatures (TSS). A hack here compromises the vault itself — the pooled funds behind every open position on that chain, not just one user’s trade.
Cross-chain bridge-swap aggregators. LI.FI, Rango, and similar tools don’t hold funds; they route your transaction through whichever underlying bridge and DEX combination gets the best result. The risk sits one layer down, in the bridge contract actually moving your asset.
DEX aggregators. 1inch, Jupiter, and peers find the best price across decentralized exchanges, executed as a signed on-chain transaction you approve yourself. Risk here is smart-contract risk on the DEXs and routers involved, scoped to your one transaction.
A hack in an instant-swap aggregator compromises one provider’s wallet mid-swap. A hack in a liquidity protocol compromises the shared vault behind every open position on that chain. That’s the single most important distinction when picking a tool — not speed, not fees.
| Category | Where funds sit during a swap | What a hack compromises |
|---|---|---|
| Instant-swap aggregator | Provider’s operational wallet, per-swap | That provider’s in-flight swaps |
| Liquidity protocol | Shared validator-secured vault | The pooled vault balance for that chain |
| Bridge-swap aggregator | Underlying bridge’s smart contract | Whichever bridge the route selected |
| DEX aggregator | Your own wallet, signed transaction | The specific DEX/router you interacted with |
Instant-swap and non-custodial exchange aggregators
This category skips wallets, smart contracts, and shared vaults entirely. You pick a pair, get a deposit address, send funds, and receive the output at an address you control. No connected wallet, no on-chain approval transaction, no pooled liquidity to drain.
SwapZilla routes each trade across multiple independent providers rather than relying on a single custodial point — if one provider’s rate or uptime is off, the aggregator shows you the next best option instead of forcing you through one operator. There’s no account or sign-up: pick a pair, get a deposit address, done. For BTC ↔ XMR specifically, SwapZilla also exposes a private routing option through Monero for users who want an extra layer of on-chain unlinkability rather than a direct swap.
Trocador is the closest structural peer — a non-custodial aggregator that compares rates across several partner instant-swap services and routes to whichever wins, without collecting an account or email. It leans hard into privacy tooling: a published AML/KYC-policy rating per partner, Tor/I2P access, and a swap-failure guarantee program with its own terms and claim deadlines.
ChangeNOW is the most recognizable brand in this category — a non-custodial instant exchange supporting a very wide asset list, including native BTC and XMR, with no mandatory registration. Identity checks apply only when a provider’s own AML monitoring flags a transaction, not as a default step.
None of the three is strictly “better” — they’re the same category solving the same problem with different trade-offs on privacy tooling, brand recognition, and asset coverage. If you already have a preferred non-custodial aggregator that fits your needs, switching categories entirely (to a liquidity protocol or bridge aggregator) usually isn’t the fix — it’s solving a different problem.
Cross-chain liquidity protocols
This is THORChain’s actual category — and where “alternative” means something specific: another protocol running shared, validator-secured vaults, not a swap exchange with a different brand name.
THORChain holds native assets — unwrapped BTC, ETH, and others — directly in vaults secured by threshold signature scheme (TSS), where node operators bond RUNE as collateral and a supermajority of validators must cooperate to move funds. No single node can steal from a vault alone. In May 2026, that assumption was tested: a newly churned node operator reportedly exploited the TSS signing process during a key ceremony, and the network’s automatic solvency checks halted trading network-wide within minutes while node operators voted to keep it paused for about five weeks. THORChain resumed trading afterward, reportedly absorbing the loss through protocol-owned reserves rather than inflating RUNE supply.
Maya Protocol is a fork of THORChain’s architecture with its own liquidity token and chain set, using a message-passing layer (Bifrost) to observe deposits and sign withdrawals across chains including Bitcoin, Ethereum, Arbitrum, and THORChain itself. Its distinguishing feature is native support for Dash and Zcash — including shielded Zcash swaps in some integrations — assets most liquidity protocols and bridge aggregators don’t touch directly.
Chainflip uses a similar TSS model but with a fixed, staked validator set — around 150 validators holding FLIP as collateral, requiring roughly a two-thirds threshold to sign a vault transaction. Its “State Chain,” a Substrate-based accounting layer, tracks balances and coordinates signing separately from the vaults themselves, which is a structural difference from THORChain’s shard-based vault design.
All three protocols share the same fundamental trade-off: funds sit in a shared, validator-secured vault rather than moving in a single bilateral transaction. That’s what makes native cross-chain routing possible without wrapped assets — and it’s also what makes a vault compromise a shared-pool event rather than a single-user event.
Cross-chain bridge-swap aggregators
This category doesn’t hold funds or run vaults at all — it’s a routing layer sitting on top of dozens of independent bridges and DEXs, picking whichever combination gets you the best result for a given corridor and size.
LI.FI operates as a meta-aggregator: rather than holding liquidity itself, it evaluates dozens of underlying bridges and DEXs in parallel and surfaces the best route through one SDK, powering cross-chain swaps inside wallets like MetaMask and Coinbase Wallet. Chain, bridge, and DEX counts shift as integrations are added — treat any specific figure as a snapshot, not a fixed spec.
Rango Exchange covers a broad set of chains, including several non-EVM and UTXO-style networks, and aggregates liquidity from a large pool of DEXs and bridges through its own routing engine. Like LI.FI, its exact coverage numbers move over time as new integrations ship.
Both require a connected wallet — you’re signing an on-chain approval and swap transaction, not sending to a deposit address. And because neither one custodies funds directly, your actual exposure is to whichever underlying bridge contract executes the route on a given trade. A LI.FI or Rango swap through a well-audited bridge and one through a newer, less-tested bridge carry different risk even inside the same aggregator UI — check the route detail before confirming.
DEX aggregators
DEX aggregators solve a narrower problem than the other three categories: best price across decentralized exchanges, usually within a single chain or ecosystem, executed as one transaction you sign yourself.
1inch built its reputation on Pathfinder, its price-routing engine, and has since layered on Fusion — an intent-based system where you sign an order and a resolver network competes to fill it — plus Fusion+ for the cross-chain version of the same model. 1inch never takes custody at any point; if a route can’t complete, the transaction is designed to revert rather than strand funds mid-swap.
Jupiter is the dominant DEX aggregator on Solana, commanding the large majority of aggregator volume on the chain. Its cross-chain product doesn’t run its own bridge — it compares quotes from Wormhole, Mayan, deBridge, and others, then routes through whichever is cheapest or fastest for that specific corridor, effectively functioning as a bridge aggregator for anything entering or leaving Solana.
Both require a connected wallet and a signed transaction per swap — there’s no deposit-address flow here. That’s a meaningful trade-off against instant-swap aggregators: more transparency into exactly which contract you’re interacting with, but no path to swap without exposing a wallet address on-chain.
How to pick a tool for the job
A quick, one-off retail swap — trading BTC for USDT to cash out, or XMR for ETH — is the clearest fit for an instant-swap aggregator. No wallet connection, no on-chain approval transaction, and for BTC-adjacent pairs, no smart-contract or vault risk to think about at all.
Rebalancing an existing DeFi position you’re already managing on-chain — moving liquidity between protocols on the same chain — is a DEX aggregator’s job. You’re already signing transactions and holding assets in a connected wallet; a DEX aggregator just gets you a better price on the swap you were going to do anyway.
Moving native BTC into an altcoin or a different chain’s ecosystem rules out DEX aggregators entirely — they can’t touch unwrapped Bitcoin. That leaves liquidity protocols (if you want on-chain, non-custodial routing and are comfortable with vault risk) or instant-swap aggregators (if you want the simplest path and no wallet connection).
A recurring merchant or payment flow — accepting crypto repeatedly, not a one-time trade — benefits from predictability over protocol sophistication: consistent settlement behavior, no wallet-connect friction for the counterparty, and no account required on either side. That’s the same no-account, no-wallet-connect angle instant-swap aggregators bring to individual trades, just applied to repeat flows.
Common mistakes
Routing BTC → XMR through a DEX aggregator. 1inch and Jupiter operate on assets that already live on a smart-contract chain. Native Bitcoin isn’t one of them — you’d need to bridge or wrap BTC first, adding a layer of risk and complexity that an instant-swap aggregator or a liquidity protocol skips entirely for that exact pair.
Expecting privacy from a bridge-swap aggregator. LI.FI and Rango route through public, on-chain infrastructure with a connected wallet — your address, the route, and the amounts are all visible on-chain by design. If privacy is the goal, that’s a job for an instant-swap route that doesn’t require a wallet connection, not a bridge aggregator.
Assuming “decentralized” means “risk-free.” THORChain’s 2026 exploit ran through a threshold signature scheme specifically built to prevent any single party from moving funds alone — and it still happened, through a validator that had only recently joined the network. Decentralization changes who can steal, and raises the bar for doing it, but it doesn’t remove the risk. Every category in this guide carries some form of trust — in a provider, a validator set, a bridge contract, or a router — just distributed differently. See how DEX, CEX, and swap aggregators actually differ for a deeper breakdown of that trust spectrum, or check the FAQ for specifics on how SwapZilla handles routing and refunds.
Picking the right category up front avoids most of the friction in this list. If your trade doesn’t need a smart contract or a wallet connection, swap it directly — no account, no bridge, no vault to trust.