Uniswap v4 Hooks Malicious, Sparking Dispute Over DeFi Openness Costs
Financial news aggregator 0x released data on September 14 showing that over half of Uniswap's v4 Hooks are malicious. The analysis, which included 84,163 Hooks across six chains, found that only 19.4% were deemed safe, 54.2% were malicious, and 26.4% were suspected malicious.
Uniswap founder Hayden Adams responded to the allegations on X, stating that the existence of malicious Hooks is an inevitable byproduct of permissionless systems. However, he emphasized that users trading through Uniswap's official API and audited frontends will not access these malicious pools.
The dispute centers around the cost of DeFi's openness and whether the protocol layer or the application layer should bear the security costs for DeFi's permissionless openness. 0x defines the attack pattern as 'Quote Spoofing,' where malicious Hooks display highly competitive quotes during the aggregator's pricing inquiry stage, luring the routing engine to direct trades to their pools.
The issue at hand is not unique to v4 and has been a long-standing problem in DeFi. Uniswap's logic is that the value created by openness far outweighs the losses caused by malicious behavior, so security screening should be handled by the application layer rather than restricting innovation at the protocol layer.
Users trading via the Uniswap official frontend have a low risk of being affected by malicious Hooks. However, users interacting with third-party aggregators or directly with on-chain contracts are exposed to these risks. 0x has established detection and blocking mechanisms for malicious pools, but the costs of this arms race are continuously rising.