DEX aggregator 0x published research on Sept. 14 under the headline "Uniswap v4 hooks were a mistake," arguing that most v4 hooks it has analyzed are built to quote one price and settle another. Uniswap founder Hayden Adams replied early on Sept. 15 that it was a "skill issue."

The question the discussion raises is: who is responsible when a permissionless pool advertises a price it does not honor. 0x says the hook design itself pushes that cost onto routers and the wallets and apps built on top of them. Uniswap and Paradigm say aggregators should vet which hooks they route to, and that Uniswap's own router already does.

0x analyzed 84,163 hooks across six chains using static analysis, dynamic analysis and observation of settled trades. As of Sept. 11, it classified 19.4% as safe, 54.2% as malicious and 26.4% as likely malicious. Trades routed through malicious v4 pools delivered "as much as 50% less at execution than the amount quoted to the user," according to the post. 0x said it has routed 81.92 million trades and $42.67 billion in volume this year, with roughly 70% of transactions touching Uniswap liquidity.

Quote One Price, Settle Another

The post named two live hooks. One on Base, paired ETH against NVDAc, took fees on 3,946 of 6,516 fills, a 60.6% rate, with a median fee of 18% when charged and $143,037 collected. A second on BNB Chain, paired USDT against WBNB, charged 1,619 of 4,879 fills at up to 12.8%, collecting $18,592.

0x described the patterns as varied — "some operate like a dice roll, some inspect the EVM environment to detect quoting" — with the same outcome. A hook needs no interface and no users of its own. It only has to look like the best quote to the systems that aggregate liquidity.

Duncan Townsend, a smart contract engineer at 0x, wrote that the company "put in a phenomenal amount of work to get hooks to work correctly in 0x API, but fundamentally they set bad expectations between hook authors and aggregators."

Responding to the suggestion that routers simulate trades before quoting, Townsend said simulation does not work: "hooks often detect simulation and conceal their behavior."

Skill Issue

Adams did not dispute the figures. He said routers should not send orders to bad hooks and pointed developers to Uniswap's API, which he said avoids malicious hooks, routes to all Uniswap liquidity without added fees, and now aggregates external liquidity.

"v4 hooks have unlocked huge amounts of innovation," he wrote, describing the 0x post as a waste of time. In a separate reply he compared it to saying "ethereum is bad because you can make malicious smart contracts."

Adams also said the StablePair hook Uniswap Labs released on Sept. 10 is now the highest-volume pool on Ethereum and is earning higher returns for liquidity providers. Only Uniswap Labs can create pools against that hook on Ethereum.

Hours later he broadened the argument: "Any sufficiently useful new technology deals with scams. Phone calls, text messages, email, websites, social media etc - all rife with scam content, no filtering system is perfect. No one argues it's the fault of the core underlying protocols like smtp and https."

Uniswap’s Niko Kampouris called the headline clickbait and said traders should "just use the uniswap api, where all hooks are vetted."

The Allowlist Argument

Dan Robinson, general partner and head of research at Paradigm, a Uniswap investor, said the post "should be titled '0x routing made a mistake'" and linked to Uniswap's hook routing allowlist.

"If you're an aggregator, you can't just route to arbitrary hooks," he wrote. In a later reply he said there is no approval process for creating a hook, and that any aggregator picks which hooks to route to. He compared the complaint to "someone saying 'ERC-20 was a mistake because I bought an ERC-20 token and it turned out to be worthless.'"

Uniswap's allowlist documentation says submission is only required if a hook uses a delta flag, has a deployment address starting with 0x91, or targets major token pairs. Everything else is approved automatically. The docs also say upgradable hooks and hooks requiring custom data inputs are not approved.

Townsend said 0x already uses that list. "There's at least one malicious hook on that list and many good hooks that need to be routed faster than they can get added to the list," he wrote. He posted a Blockscout link to what he described as an upgradeable hook whitelisted by the Uniswap interface, and a transaction he said the Uniswap interface routed through a malicious hook.

Fully Onchain Routing

Keone Hon, co-founder of Monad, said the behavior 0x documented first appeared in proprietary AMMs and has moved to v4 hooks. Malicious makers alternate between very tight and very wide quotes, he wrote: the tight quote wins the route, the wide one executes.

Slippage limits stop some of those trades, he said, but "many users set their slippage settings far too permissively. Those users get taxed brutally."

Hon said the fix is fully onchain order routing, which requires an EVM fast enough to run routing logic at execution time. In a later reply he added that the spoofing window exists "because the aggregator chooses the route before the tx is signed."

Volume Keeps Climbing

Uniswap v4 holds $1.06 billion in total value locked, up 39.9% over 30 days, according to DefiLlama. The protocol processed $38.12 billion in DEX volume over the same period, led by Robinhood Chain at $15.94 billion and Ethereum at $12.56 billion.

UNI traded at $6.35 on Sept. 15, up 1.5% on the day and down 9% over the week, according to CoinGecko.

Adams has argued before that AMMs will take the largest markets from order books. The v4 hook architecture, which shipped in February 2025, is the vehicle for that claim.