Loading prices…
🩸BEARISH

Uniswap v4 Hooks Settle Swaps 50% Worse Than Quoted

A 0x analysis of 84,163 hooks across six chains classified over half as malicious, and the flagged pools are winning route comparisons only to pay traders far less at execution.

Liquidity aggregator 0x reported on Sept. 14 a sharp rise in malicious Uniswap v4 hooks that quote one price and settle at another. In the worst trades observed, users received up to 50% less at execution than the amount displayed. The firm examined 84,163 hooks across six chains and, in a dataset labeled as of Sept. 11, classified 19.4% as safe, 54.2% as malicious, and 26.4% as likely malicious.

The mechanism exploits how aggregators route orders: they scan many pools and favor the route promising the most tokens. A malicious pool can look unusually attractive at quote time, win the comparison, then settle materially worse. One Base hook trading the ETH/NVDAc pair showed 6,516 fills, with 3,946 charged fills carrying fees from 0% to 18% and a median of 18% when charged, collecting $143,037 in total fees as of Sept. 11.

Why it matters

Uniswap v4 hooks are optional external contracts that run around key pool actions, executing before or after swaps and adjusting balance deltas under selected permissions. That flexibility powers legitimate features like dynamic fees and custom accounting, but it also lets permissionless third-party code enter a price competition whose output looks objective to the trader approving the swap. Uniswap's own documentation warns that hooks are written by independent parties and may be malicious.

The problem is not new but is adapting. In July, routing provider Enso documented toxic pools including a Polygon Uniswap v4 hook keyed to execution-environment signals, and a March 0x study found a Base market maker beating a reference AMM in 100% of sampled quote-time observations while settling consistently worse, typically by 5 to 10 basis points.

Market impact

0x said it cuts off liquidity sources until execution issues are fixed, even when its displayed quotes then look less competitive, and it routed 81.92 million trades and $42.67 billion in volume during 2026 through Sept. 14, with roughly 70% of transactions touching Uniswap liquidity. ClearTrace's Sept.

Related tokens
$UNI

Frequently asked questions

  1. How much worse can a malicious Uniswap v4 hook settle than its quote?

    In the most extreme trades 0x observed, users received up to 50% less at execution than the amount displayed in the quote. This is a maximum shortfall rather than the typical outcome.

  2. What share of Uniswap v4 hooks did 0x classify as malicious?

    In its analysis of 84,163 hooks across six chains, 0x classified 19.4% as safe, 54.2% as malicious, and 26.4% as likely malicious as of Sept. 11.

  3. How do malicious hooks win swap orders on DEX aggregators?

    Aggregators scan many pools and favor the route promising the most tokens. A malicious pool can look unusually attractive at quote time, win the comparison, and then settle at a materially worse price.

  4. How are aggregators responding to toxic Uniswap v4 hooks?

    0x cuts off liquidity sources until execution issues are fixed, even when its displayed quotes then look less competitive. KyberSwap's Smart Settlement compares multiple candidate pools on-chain at execution and atomically selects the highest output.

  5. Is swap routing broadly dishonest, or is this a specific venue problem?

    ClearTrace's Sept. 8 scorecard found zero or small median quote gaps for several sampled aggregators in Ethereum fork simulations, suggesting the abuse is venue-specific rather than proof that swap routing is broadly dishonest.

Source attribution
Aggregated from CryptoSlate · Verified · Last refreshed 2h ago
Open original →