Highlights
- 84,163 Uniswap v4 Hooks scanned across six chains; 54.2% classified malicious, 26.4% suspected malicious, just 19.4% safe
- Malicious hooks quote an attractive price, then alter the execution price at settlement
- Some affected trades settled for up to 50% less than the quoted amount
- Roughly 70% of the aggregator's $42.67B in 2026 routed volume touched Uniswap liquidity
Uniswap v4's biggest architectural bet — letting anyone plug custom code called Hooks directly into a liquidity pool to modify how swaps execute — has also become its biggest attack surface. A leading DEX aggregator scanned 84,163 Hooks deployed across six chains as of September 11 and found that fewer than one in five could be classified as clean. Just 19.4% came back safe. The rest split between 54.2% flagged outright malicious and 26.4% flagged as suspected malicious, meaning roughly four out of every five Hooks live on Uniswap v4 today carry some degree of risk to the trader routed through them.
The mechanism is what makes this particularly hard for ordinary users to catch. A malicious Hook doesn't misbehave at the quoting stage — it shows a competitive, sometimes even best-in-market price when a wallet, aggregator or trading app first asks for a quote. The manipulation happens at settlement, after the user has already committed to the trade, when the Hook's custom logic silently alters the execution price. Because the front-end price looked fine, most users have no way of knowing they were routed through a bad pool until the trade has already settled for less.
Related: Chainflip Halts Tron Route After Attacker Double-Spends $736K in USDT
The scale of the shortfall is significant: on some trades routed through the worst offenders, users received as little as half of what they were quoted. That's not slippage in the normal sense, where price moves against a trader between quote and execution due to market conditions — it's engineered value extraction built directly into a pool's own code, sitting one layer beneath the interface most traders actually interact with.
What makes the finding sting is how central Uniswap liquidity has become to the aggregator's own business. The firm disclosed it has routed 81.92 million transactions worth $42.67 billion in cumulative volume so far this year, and roughly 70% of that flow touched Uniswap pools in some form. That dependency is precisely why the aggregator has had to build its own detection layer rather than trust Hook deployers to self-police: it says it now screens pools before routing trades through them and has already blocked a number of malicious pools from its own paths, treating Hook risk as a routing-layer problem rather than something Uniswap itself can fully solve at the protocol level.
The report lands at an awkward moment for Uniswap v4's Hooks ecosystem, which has otherwise been on a tear — Hook-routed trading volume has set a weekly record for five straight weeks, and the version's flexibility has been central to Uniswap pulling in more monthly volume than its three closest rivals combined. Rapid Hook adoption without equally rapid screening infrastructure is a familiar pattern in DeFi — a dormant Notional Finance escrow was drained for $1.7 million in an overflow bug earlier this year, another case where composable, permissionless code outpaced the tooling meant to catch it — and it suggests the burden of protecting traders from bad Hooks is, for now, falling almost entirely on aggregators and wallets rather than the protocol layer itself.
