0x Flags 54% of Uniswap v4 Hooks

Editorial portrait of security analyst at a desk, with code on a laptop and a faint Uniswap v4 schematic and warning shield.

Research from 0x has raised concerns about the security of third-party Uniswap v4 hooks after the exchange infrastructure provider analyzed more than 84,000 deployments. 0x classified 54.2% of the 84,163 hooks it examined as malicious, another 26.4% as likely malicious and only 19.4% as safe, based on static analysis, dynamic testing and observed settled trades across six blockchains.

In its official analysis shared on X, 0x argued that malicious hooks can advertise attractive swap quotes and then change execution behavior after a route has been selected. Some trades interacting with malicious v4 pools delivered as much as 50% less than the amount originally quoted, according to the company, creating a risk for aggregators, wallets and applications that route through permissionless liquidity.

Uniswap Hooks Expand the Routing Attack Surface

Hooks are external smart contracts attached to Uniswap v4 pools that can execute custom logic at specific stages of a swap or liquidity operation. They enable capabilities including dynamic fees, custom curves, automated liquidity management and external integrations without modifying Uniswap’s core PoolManager, but their arbitrary logic creates security assumptions beyond the underlying protocol itself.

The disagreement centers partly on who should manage that risk. As highlighted in the discussion involving Uniswap founder Hayden Adams, Adams argued that routers should avoid unsafe hooks rather than treating permissionless hooks themselves as a protocol flaw, characterizing the problem as a “skill issue.” He pointed to filtering at the routing layer as the appropriate defense.

That distinction is important because permissionless deployment does not mean every hook is automatically approved for routing. Uniswap maintains a public registry of known v4 hook deployments, while routing eligibility is handled separately, and inclusion in the registry itself does not constitute a security certification or automatic routing approval.

Recent incidents also require careful attribution. The approximately $7.8 million rsETH Safe incident initially associated with Uniswap v4 infrastructure was not ultimately traced to malicious hook logic. Transaction-level analysis found an ordinary v4 pool with no custom hook; the exploitable authorization path instead involved a third-party Safe module and helper contract.

Uniswap Adds a Hook Security Framework

The Uniswap Foundation has published an official Security Framework for v4 hooks covering nine risk dimensions, including custom mathematics, external dependencies, liquidity exposure, upgradeability and price-impacting behavior. The framework assigns hooks to risk tiers and recommends controls such as audits, invariant testing, monitoring, bug bounties and formal verification depending on their architecture.

The framework is explicitly self-directed rather than a certification system. Uniswap does not audit, approve or guarantee the safety of hooks based on their score, leaving developers, routers and users responsible for evaluating third-party implementations and their associated dependencies.

The 0x findings therefore highlight a trade-off inherent in Uniswap v4’s design rather than evidence that the core protocol itself has been compromised. The next security challenge is whether routers can reliably identify quote-manipulating hooks before trades reach them, particularly as permissionless hook development continues expanding across multiple networks.

Related post

Best crypto platforms