Live
USD · 24h
DeFi

Uniswap v4 hooks: six myths vs facts after $8 billion volume migration

Uniswap v4 architecture reduces pool creation costs by 99% through a singleton contract and flash accounting. While hooks enable custom strategies, security risks persist, as seen when an attacker exploited a custom LP module to steal $7.8 million in rsETH.

Uniswap v4 hooks: six myths vs facts after $8 billion volume migration

The death of the independent pool

The $8$ billion monthly migration from v3 pools to v4 changes the underlying structure of Ethereum liquidity. While v3 used factory contracts to create separate pool instances, v4 utilizes a singleton contract to store all pool states, reducing creation costs by 99%. This architecture also uses flash accounting to allow callers to perform multiple swaps and only settle token transfers at the end of the sequence. A hooked pool adds delegated authority around the core pool. If a hook changes fees based on volatility, the hook holds fee authority, whereas a hook that returns deltas holds accounting authority.

Feature Uniswap v3 Uniswap v4
Architecture Factory contract Singleton contract
Pool Creation Cost High (gas-intensive) 99% cheaper
Accounting Manual token transfers Flash accounting
Native ETH Requires wrapping Supported natively

In v3, users providing liquidity to the same range and pool shared the same state, which required manual fee management. v4 uses a salt to distinguish positions of the same range on the same pool to simplify fee accounting. Increasing liquidity in v4 converts accrued fee revenue into liquidity inside the position, while decreasing liquidity requires the withdrawal of unclaimed fee revenue. Unlike v3, where users must transfer ERC-721 tokens to a contract for staking, v4 owners set a subscriber to receive notifications whenever liquidity or ownership changes.

Security is not an audit guarantee

Security remains a variable rather than a constant. On September 15, 2026, an attacker exploited a custom Uniswap v4 LP Safe module to steal $7.8$ million in rsETH. A malicious actor used a public keeper multicall function to redirect a Gnosis Safe wallet toward a malicious Hook pool. Because the module was authorized by the Safe, the attacker used the entrypoint to execute code inside the wallet’s own context, which gave the attacker control over the $7.73$ million worth of rsETH held in the 0x40E93…7AbA8 wallet. An MEV bot known as "yoink" detected the transaction in the mempool and front-ran the attacker to capture the funds. The stolen funds were effectively captured by the MEV bot before Kelp DAO could intervene.

Bunni, a protocol built on the Uniswap v4 hook system, also suffered a loss. Despite reviews by Trail of Bits, Pashov Audit Group, and Cyfrin in 2025, an attacker used a flash loan to manipulate a pool’s price on September 2, 2025. The attacker executed 44 consecutive small withdrawals that drained $8.4$ million from a USDC/USDT pool and a weETH/ETH pool. On May 13, 2026, the Boost protocol lost $46.75$K because its BoostHook used the pool’s slot0sqrtPriceX96 directly as the entry price. A malicious actor inflated the price within a single transaction to force the protocol to buy PERP tokens at the manipulated price.

The reality of the developer platform

The v4 hook interface provides surgical precision, but building on it presents distinct hurdles. Developers use the IHooks interface to implement callbacks, but they must find a CREATE2 salt that produces an address with the correct leading bytes. You should expect to spend time on address mining because the hook’s permissions are encoded in the contract address. A hooked pool can mimic some functions of a central limit order book, such as conditional execution or time-sliced flow, but it is not a price-time priority queue. This distinction matters for traders who rely on transparent execution. While hooks allow for new features, they do not create a hidden matching engine.

Current data shows V4 hooks have created 2500 custom pools and 150 strategies. The v4-periphery repository and the hook template from Uniswap Labs provide a starting point, and the Foundry test suite is more mature than Hardhat support. Uniswap reclaimed 36% of the DEX market share in late 2025, and its 30-day volume reached $73.4$ billion in May 2026. Does the constant expansion of programmable authority create more vectors for malicious actors to exploit?

Join the discussion

Leave a Reply

Your email address will not be published. Required fields are marked *