Toxic Uniswap v4 hooks and Curve pools engineered to deceive traders, with one attack netting $34K across 129K failed swaps.
Security & Exploits ·
Malicious liquidity pools in decentralized finance are exploiting a fundamental gap between how trades are simulated and how they execute. A Uniswap v4 hook on Polygon caused 99.1% of swaps to fail, while a Curve pool on Ethereum extracted $34,592.87 across 129,070 successful transactions by consistently overquoting prices. Both pools displayed attractive pricing during simulation but altered their behavior when transactions settled on-chain, allowing them to win routing selection over honest liquidity.
Toxic pools work by inspecting blockchain context variables—such as gas price, transaction origin, or block information—that differ between simulated quotes and live execution. The Curve pool, for instance, was malicious only about 59% of the time, allowing it to appear legitimate during routine checks. It overstated quotes by approximately $225,000 across all interactions, though ordinary protocol fees accounted for roughly $23,440 of that discrepancy. The Polygon hook applied a roughly 98.9% fee at high gas prices while exempting the attacker's own address, creating a honeypot that appeared functional during testing but failed for ordinary traders.
What remains unclear is whether such exploits are widespread beyond these two identified cases or how quickly aggregators and wallet providers can detect and filter these pools. The fundamental vulnerability—that quote simulation does not perfectly mirror execution—affects routing engines across 1inch, deBridge, MetaMask, Binance Wallet and others, yet the extent of similar attacks in production remains undocumented.