Your quote is not your fill
0x analyzed 84,163 Uniswap v4 hooks and found 54.2% malicious. Trades routed through them settled up to 50% below the quoted amount. What that means for the number on your screen.

Every router shows you a number before it trades. The number is a quote. What you receive is a fill. For most of DeFi's history those were the same thing, or close enough that nobody asked.
They are not the same thing now.
The research
0x published a study on 14 September 2026 that examined Uniswap v4 hooks, and it is worth reading the method before the headline number. They analysed 84,163 hooks across 6 chains, using static analysis, dynamic analysis and observation of settled trades. Data as of 11 September 2026.
The result: 19.4% safe, 54.2% malicious, 26.4% likely malicious.
The mechanism is not a clever exploit. It is simpler and worse. A malicious hook advertises one price when your aggregator asks for a quote, and settles at another price when the swap executes. Some patterns behave like a dice roll. Some inspect the EVM environment to detect that they are being quoted. The underlying behaviour is consistent: the price a route advertises is not the price a user can reliably expect to receive.
0x states the cost directly: trades routed through malicious v4 deliver as much as 50% less at execution than the amount quoted to the user.
The part that makes it concrete
Aggregate percentages are easy to shrug off. One pool is harder.
From the same analysis: hook 0x800cef53c3fd41109dffec62e5251bdd7acba5c7, on Base, pair ETH/NVDAc. Total fills 6,516. Charged fills 3,946, which is 60.6%. Fee range 0 to 18%. Median fee on all fills 17.96%.
Read that again. In more than half the fills, the pool took a fee. The fee it advertises is 0 to 18 percent. That is not a hidden transfer in the sense of a scam exit; it is a pool that reports an attractive number and then charges for the trade, and an aggregator that routed you there because the quote looked best.
Note also what 0x's routing volume means here. They say they routed 81.92 million trades and $42.67 billion in volume this year, with roughly 70% of transactions touching Uniswap liquidity. They are describing an aggregator with real distribution, and they are describing themselves as the party at risk from this. Read the incentive accordingly, and read the numbers anyway.
Why a hook can do this at all
Uniswap's own documentation explains the design. Hooks are external smart contracts attached to individual pools. Each pool can have one; a hook can serve an unlimited number of pools. A pool's hook is specified at creation, in the PoolManager.initialize call.
Hooks fire at specific points: beforeSwap and afterSwap around swaps, with a matching pair around liquidity changes and donations. Permissions are encoded in the hook's contract address, and the PoolManager uses those encoded permissions to decide which functions to call for a given pool.
None of that is a flaw. It is the feature. Uniswap's documentation lists intended uses: customised AMMs with pricing curves other than xy = k, yield farming, derivative and synthetic platforms, lending hooks.
The same documentation also lists what is possible with a hook that is deployed by anyone and intercepts a swap: it is custom code running inside the execution path of a pool that the most-integrated venue in DeFi routes to.
That is the tradeoff 0x is arguing about, and they put it plainly. The same design that gives legitimate builders expressive control over execution also makes it harder for aggregators to determine which pools can be trusted. A malicious hook does not need a brand, users, or distribution. It only needs to make its pool look attractive to the systems that aggregate liquidity. If an aggregator sees the best quote, it has a reason to route there. If a wallet or app trusts that aggregator, the pool is reached through infrastructure the user already trusts.
What Uniswap says
Uniswap's response was that this is a skill issue, and pointed to its own API as the path that avoids it.
Worth knowing how that API is described. Its allowlist is narrow: manual review applies only to hooks deployed at 0x91 addresses or using delta flags or dynamic fees. Everything else is already automatically allowlisted. And the review itself, by Uniswap's own wording, is not a security audit and not an endorsement.
That is a candid statement of scope, which is more than most projects would say. It is also not the same thing as a guarantee that a hook cannot quote one price and settle another.
What a trader can actually do
There is no way to audit the hook on a pool you are routed to in the time you have. So the useful moves are structural, not investigative.
Treat an advertised fee as a claim, not a fact. A pool showing 0 to 18 percent, charging on 60.6 percent of fills, is describing itself accurately. Ask what the median fee is, not the minimum.
Watch for the tell. A quote materially better than every other route for the same pair is not automatically a good deal. In this dataset it is also the signature of the problem. An aggregator picking the best quote is doing what it was built to do.
Prefer venues with a quote you can hold. The failure mode here is a price that exists only at request time. A route that settles against an order book at a stated price, or that shows a firm quote with an address, gives you something to check the fill against afterwards.
Set slippage tolerance deliberately and understand what it covers. Tolerance is the gap between quote and fill. A malicious hook that settles outside your tolerance should revert. A hook that settles inside it has still taken a fee you did not agree to, so a generous tolerance is not a free choice.
Check the fill, not just the transaction. A successful transaction is not evidence of a good trade. Compare the amount received against the amount quoted, every time, until you have your own baseline.
The wider point
Aggregation solved a real problem: one interface across fragmented liquidity. It did not solve trust, and the two are easy to confuse. A router can show you the best available price and still route you somewhere that price is fiction.
The numbers here come from one company's research, and that company sells aggregation. The methodology is published and the named examples are specific enough to check. But the honest reading is not that 54 percent of Uniswap is malicious. It is that permissionless extensibility moved the trust boundary from a known curve to arbitrary code, and the tooling that aggregates price has not fully absorbed that shift.
The full analysis, with the primary source, is embedded above.
Risk note: cryptocurrency trading, leveraged perpetual futures, and automated algorithmic strategies carry significant risk of rapid and total financial loss. Never risk funds you cannot afford to lose completely. Routing through third-party liquidity carries its own execution risk, including fills materially worse than the quoted price. Nothing in this article is investment advice, a recommendation, or an offer to sell any product.
