84,000 Hooks, only 19.4% are safe: Uniswap's innovative mechanism is becoming a new on-chain trap.

CN
1 hour ago
Uniswap v4's open Hooks are becoming a new on-chain attack surface, with some malicious liquidity pools extracting funds from user transactions through "low price inducement and high price settlement."

Author: 0x

Compiled by: ShenChao TechFlow

ShenChao Overview: The Hooks in Uniswap v4 were originally an innovative mechanism for adding "custom plugins" to AMM, but an analysis by 0x across 6 chains and over 84,000 Hooks indicates that only 19.4% are deemed safe, with more than half identified as malicious. Some liquidity pools offer appealing "optimal prices" at the quote, only for users to receive up to 50% less at the actual settlement.

When permissionless liquidity begins to be exploited maliciously, this article discusses not just the vulnerabilities of Uniswap, but a more fundamental question: Can we still trust on-chain "optimal quotes" directly?

It's time to confront the issues with the hooks mechanism.

This year, 0x has routed 81.92 million transactions, with a total transaction value of $42.67 billion, of which approximately 70% have interacted with Uniswap's liquidity.

We receive dozens of review and integration requests for v4 hooks each month, both good and bad. However, recently, we have begun to see some ugly things.

In the past few weeks, 0x has observed a striking increase in the number of malicious Uniswap v4 hooks—these hooks offer one price during the quote request and a different price at settlement. The tactics of these malicious hooks vary, but the result is the same: they steal funds from users by deceiving aggregators, wallets, and trading applications.

Below is what we have observed on-chain, as well as the measures 0x has already taken in response.

The Problem with Hooks: Open to Both Builders and Malicious Actors

Let's start with the positives: v4 hooks provide a layer of innovation for the AMM space—developers can deploy AMMs with custom logic that can execute at key points in the pool's lifecycle (such as before and after swaps or during LP position changes). Hooks can be designed to do anything and be deployed by anyone, and once they exist, they automatically inherit the coverage of this highly integrated liquidity venue in DeFi.

Beyond saving developers from friction, hooks also open unlimited space for malicious behavior. A malicious hook does not need to establish a well-known brand, persuade users to visit a new interface, nor build its own distribution channel. It only needs to make its liquidity pool appealing to those systems that aggregate liquidity.

As long as an aggregator sees an "optimal quote," it has a reason to route the transaction there. And if a wallet or trading application relies on that aggregator, the same infrastructure that users have already trusted can direct transactions to that malicious liquidity pool.

Malicious Hooks

In the past 18 months, we have seen explosive growth in v4 hooks. We analyzed 84,163 hooks across 6 chains (combining static analysis, dynamic analysis, and observations of settled transactions), with the conclusion that only 19.4% are safe, 54.2% are malicious, and another 26.4% are likely malicious.

These tactics vary—some randomly harvest like rolling dice, while others check the EVM environment to identify "this is a quote." However, the underlying behavior is consistent: the price advertised by the routing is not equal to the price users actually receive. We have observed that transactions routed through malicious v4 hooks have executed at amounts that are up to 50% less than what was quoted to users.

Here are several examples:

Hook Address: 0x800cef53c3fd41109dffec62e5251bdd7acba5c7

  • Chain: Base
  • Trading Pair: ETH / NVDAc
  • Total Transactions: 6,516
  • Charged Transactions: 3,946 (60.6%)
  • Fee Rate Range: 0–18%
  • Median Fee Rate for All Transactions: 17.96%
  • Median Fee Rate When Charged: 18%
  • Total Fees Charged (USD): $143,000

Hook Address: 0x141984423d1a28242b3dd8888c5b0daa7b13c880

  • Chain: BNB
  • Trading Pair: USDT / WBNB
  • Total Transactions: 4,879
  • Charged Transactions: 1,619 (33.2%)
  • Fee Rate Range: 0–12.8%
  • Median Fee Rate for All Transactions: 0%
  • Median Fee Rate When Charged: 12.8%
  • Total Fees Charged (USD): $18,600

Conclusion

The initial design of Hooks was to make Uniswap more scalable, but it also opened up endless possibilities for malicious actors. This summer has demonstrated that permissionless liquidity does not equate to trustworthy liquidity. Just like the rise of previous propAMMs, the flexibility that allowed developers to customize swap mechanisms has also given malicious actors new means to manipulate the market. Based on this, we believe:

  • Routers need to ensure the amounts quoted by liquidity pools match their actual performance upon execution.
  • Applications need the control capability to quickly delist suspicious routes.
  • Users should understand that only when the underlying routing is secure, do those "optimal displayed quotes" truly matter.

As we have done for the past decade, we are taking concrete measures to protect our integrators and their users from the ever-shifting malicious actors on-chain. At 0x, we have implemented several measures to prevent these liquidity pools from appearing in routing results, including advanced detection technologies and extremely rigorous due diligence on liquidity pools.

Thank you for building with 0x.

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink