0x identifies that 54.2% of 84,163 Uniswap v4 hooks analyzed are malicious, exploiting quote mismatches across six chains.
Security & Exploits ·
0x has flagged a significant security issue within the Uniswap v4 ecosystem, identifying that 54.2% of 84,163 hooks analyzed across six blockchains exploit quote mismatches to behave maliciously. Hooks are customizable smart contracts that extend Uniswap v4's functionality, allowing developers to add specialized logic to trading pools.
Quote mismatches occur when the price data used to execute a transaction diverges from expected values, creating opportunities for malicious contracts to extract value from unsuspecting users or liquidity providers. By embedding exploit logic into hooks, attackers can manipulate swaps or drain funds without users realizing they have interacted with a compromised contract. The scale of the problem—affecting more than half of all hooks examined—suggests the issue extends across multiple chains rather than isolated instances.
The findings underscore emerging risks as Uniswap v4's flexible hook architecture gains adoption. It remains unclear how many of these malicious hooks have already caused financial losses, which chains face the highest concentration of exploits, or what remediation steps the Uniswap DAO or security researchers are undertaking to help developers identify and remove compromised code.