Pond Street Ledger

An Aggregator Says Half the Uniswap v4 Hooks It Checked Were Malicious

0x analysed 84,163 hooks on Uniswap v4 and found 54.2 percent of them malicious, calling the design a mistake. Uniswap's founder and a Paradigm partner said the failure is in how 0x routes orders.

✓ 1450.efrogs.eth2026-09-174 min
Sources: The Defiant

0x, a decentralised exchange aggregator that routes orders across trading venues, published an analysis of Uniswap v4 hooks and said 54.2 percent of the 84,163 it examined were malicious, according to The Defiant. Its conclusion was blunt: the hooks design was a mistake. Uniswap founder Hayden Adams and Dan Robinson of Paradigm pushed back, arguing the problem lies in 0x's own routing rather than in the architecture.

Hooks are the headline feature of Uniswap's fourth version. They let anyone attach custom code to a liquidity pool, firing at defined moments such as before or after a swap, so a pool can implement bespoke fees, limit orders, custom pricing curves or access rules without a new protocol. The tradeoff is inherent in the design: arbitrary code attached to a pool can also do things a trader would not consent to, such as taxing an exit or refusing one.

Why the number is large and what it does not say

A majority-malicious count sounds catastrophic until you consider what is being counted. Deploying a hook is permissionless and cheap, so the population of hooks is not a curated list of products, it is everything anyone has ever pushed on chain, including spam, tests and deliberate traps that were never going to attract liquidity. A share of contracts is not a share of volume or of capital at risk.

That is the substance of the rebuttal from Adams and Robinson, as reported by The Defiant. If an aggregator's router can be steered into a hostile pool, the exposure is created at the routing layer, which is where the decision about where to send an order actually gets made. Counting bad contracts measures the size of the hazard. It does not measure who walks into it.

Both sides can be right

The two positions are not mutually exclusive, and that is the uncomfortable part. A permissionless extension system will accumulate hostile deployments as a matter of arithmetic, and any router that treats all pools as equally valid will eventually touch one. The open question is who is responsible for filtering, the protocol that allows the code or the aggregator that chooses the route.

This matters beyond a technical argument between builders because v4 is not a niche deployment. On Robinhood Chain, Uniswap V4 handled $543.2m of the chain's $1.49bn of 24-hour decentralised exchange volume, according to DefiLlama, second only to Uniswap V3 at $649.9m. Whatever the hooks surface turns out to be worth in practice, it is already carrying institutional-scale flow on a chain built for tokenized equities.

What would settle it

The figure that would move this debate is not the count of malicious hooks but the volume and total value locked sitting behind them, alongside a tally of actual losses attributable to hook behaviour. 0x has supplied the numerator of the wrong fraction. Until somebody publishes the exposure-weighted version, both claims stand as stated.

Watch for whoever screens first. Aggregators, wallets and front ends all sit between a user and a pool, and a public allowlist or hook-risk score from any of them would be a tacit concession that the filtering job belongs to the routing layer.

We report facts in our own words and link to the reporting we drew them from. We do not reproduce a source's prose, headline or images. Nothing here is investment advice.