0x says its review of Uniswap v4 Hooks found that more than half of the custom contracts it analyzed carried malicious behavior, placing renewed scrutiny on how decentralized trading applications screen pools before routing user orders. The firm said on Sept. 14 that it reviewed 84,163 Hooks deployed across six blockchains through Sept. 11, classifying 54.2% as malicious and another 26.4% as suspected malicious.
The finding centers on a trading exploit that 0x calls “quote spoofing.” In that pattern, a Hook displays an appealing exchange rate when an aggregator simulates a swap and requests a quote, then changes its behavior when the user submits the actual blockchain transaction. A user can therefore approve a trade based on one expected outcome and receive materially less once it executes.
Uniswap founder Hayden Adams disputed the implication that the figures describe a failure unique to Uniswap v4. He said malicious contracts are an expected byproduct of permissionless systems, where anyone can deploy code, and argued that users of Uniswap’s official API and vetted interfaces would not be routed into these pools.
Hooks can alter a swap after the quote
Uniswap v4 Hooks allow developers to attach custom code to a liquidity pool and run it before or after trades. The system can support features such as specialized fees, automated liquidity management, and custom market mechanics. It also gives pool creators a place to insert logic that an aggregator must assess before using the pool as part of a route.
According to 0x, malicious Hooks can exploit the gap between a simulated trade and a completed transaction. The contracts can change pricing parameters after an aggregator has identified the pool as offering the best rate, or add fees that were absent from the original quote.
0x said some of the contracts it reviewed used EVM execution-context checks to distinguish between a quote simulation and a live transaction. The Ethereum Virtual Machine, or EVM, is the environment that processes smart-contract instructions. By identifying how their code is being called, malicious Hooks can present benign behavior during testing before applying different rules to a signed swap.
The firm also described contracts that randomly alternate parameters, making the harmful behavior less predictable and more difficult to reproduce in a single test. That approach complicates filtering systems that rely on repeated simulations to catch abnormal output before sending an order to the blockchain.
0x said it observed hidden fees of up to 18% on active trading pairs. In an extreme case cited by the firm, the amount received by the trader was 50% below the quoted amount. The company said the tactic particularly targets swaps made with looser slippage settings, which permit execution at a price worse than the displayed quote to avoid failed transactions during volatile market conditions.
The company said losses from the technique had reached “hundreds of thousands of dollars,” though the supplied findings did not provide a full breakdown of affected users or transactions.
Dispute focuses on active pools and routing responsibility
Adams said the 84,163 figure represents all Hooks analyzed by 0x, rather than a count of contracts receiving meaningful user activity. He said that total includes inactive deployments, which he described as “zombie” Hooks. That distinction affects how the 54.2% malicious classification should be read: a large share of the analyzed code may never have attracted liquidity, trades, or routing volume.
0x’s figures nevertheless point to a demanding screening problem for applications that search broadly across v4 pools. The firm categorized only 19.4% of the Hooks it reviewed as safe, leaving more than four-fifths either malicious or suspected malicious under its methodology.
Adams drew a line between the protocol and the interfaces built on top of it. Uniswap v4 permits open deployment of pool logic, while official products can choose which pools to index, display, or route through. He said third-party aggregators connecting to extensive sets of unreviewed Hooks remain responsible for their own routing choices.
That model is common in permissionless finance, but custom pool logic gives the filtering task a more immediate effect on trade execution. An application may accurately compare quoted prices across pools yet still route through a contract designed to invalidate the quote once the transaction reaches the chain.
Aggregators face a costly detection contest
0x framed the issue as an ongoing arms race between malicious Hook developers and trading infrastructure providers. The company said it has built detection and blocking mechanisms intended to identify harmful pools before users trade through them, while arguing that protocol-level tooling could give downstream applications better ways to isolate suspicious code.
Its concern is tied to the scale of its own routing operation. 0x said that from the start of 2026, its platform had routed 81.92 million transactions totaling $42.67 billion in volume. About 70% of that activity involved Uniswap liquidity, according to the company. Large aggregators can direct significant order flow toward any pool that appears competitive in a quote, making reliable pool screening a practical execution issue rather than merely a code-review concern.
The exchange between 0x and Adams outlines two approaches to the problem. Adams favors an open protocol layer with safeguards applied by trusted front ends and APIs. 0x argues that the volume of potentially harmful contracts increases the cost and difficulty of application-level screening, particularly when contracts are built to deceive simulations.
For users, the immediate distinction is between interacting through interfaces that apply pool-selection policies and accepting routes from services that may include less-reviewed custom liquidity. Slippage settings can also determine how much deviation from a displayed quote a transaction permits, though reducing slippage does not replace screening and may cause more transactions to fail.
Uniswap v4’s Hook architecture was designed to make pool behavior more flexible. The 0x findings show that the same flexibility can shift part of the security burden onto routers, interfaces, and the systems that decide which pools deserve access to user order flow.
Concerned about malicious DeFi contracts? Strengthen your defenses with Toobit’s crypto safety standards guide before your next trade.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.
