Back to Blog

Lead in: Uniswap V4 Hook Risks

Code AuditingPhalcon Security
November 22, 2023
3 min read
Key Insights
  • Uniswap v4’s novel hook system expands integration flexibility but significantly widens the attack surface.

  • Two threat models frame risks in hook interactions, centering on access control and input validation gaps.

  • Flawed access control may let unau

This article series explores critical security vulnerabilities in Uniswap v4's novel hook mechanisms, focusing on flawed access control and improper input validation. It offers actionable mitigation strategies to help developers and security professionals strengthen DeFi security on Ethereum and other L1/L2 chains.

Breaking Down: A Comprehensive Overview

Uniswap v4 introduces innovative hook mechanisms that enable flexible integrations within decentralized finance (DeFi) protocols. However, these hooks also bring new security challenges that require careful analysis. This article series titled "Uniswap V4 Hook Risks" examines the core mechanisms of Uniswap v4 hooks, identifies key vulnerabilities, and discusses their implications for blockchain security.

We begin by summarizing the fundamental workings of Uniswap v4 hooks and defining two primary threat models. These models help frame the security risks associated with hook interactions, particularly focusing on access control weaknesses and input validation flaws.

Lethal Integration: Vulnerabilities in Hooks Due to Risky Interactions

The hook interaction logic in Uniswap v4 can expose vulnerabilities that attackers might exploit. Two critical scenarios are highlighted:

  • Flawed Access Control: Insufficient restrictions on who can invoke hooks may allow unauthorized actors to manipulate contract behavior.
  • Improper Input Validation: Failure to validate inputs correctly can lead to unexpected states or exploits such as reentrancy or oracle manipulation.

This article provides a detailed vulnerability analysis, including proof-of-concept (PoC) exploit demonstrations. It also outlines mitigation strategies to prevent these attacks, contributing to safer smart contract development and robust DeFi security.

Best Security Auditor for Web3

Validate design, code, and business logic before launch

About BlockSec

BlockSec is a leading blockchain security company founded in 2021 by globally recognized security experts. Our mission is to enhance Web3 security and usability to accelerate mass adoption of decentralized technologies. We offer comprehensive services including:

  • Smart Contract Audits and Infrastructure Audits for Ethereum, Solana, BSC, and other L1/L2 chains.
  • The Phalcon Security platform for real-time threat detection, alerting, and attack blocking.
  • Phalcon Compliance, a crypto compliance hub for wallet screening, AML/CFT, Know Your Asset (KYA), and Know Your Transaction (KYT).
  • MetaSleuth, a powerful tool for tracing illicit funds and conducting on-chain investigations.
  • MetaSuites, an extension designed to improve Web3 security monitoring and developer efficiency.

To date, BlockSec has served over 1,000 clients, including MetaMask, Uniswap Foundation, Compound, Forta, and PancakeSwap. We have secured tens of millions in funding from top investors such as Matrix Partners, Vitalbridge Capital, and Fenbushi Capital.

Official website: https://blocksec.com/
Official Twitter: https://twitter.com/BlockSecTeam

Get Started with Phalcon Security

Detect every threat, alert what matters, and block attacks.

Try now for free

Get Started with Phalcon Compliance

Crypto compliance hub for wallet screening and KYT

Try now for free
Sign up for the latest updates
~$418M Lost: Bitget, NEAR Intents Exploits | BlockSec Weekly
Security Insights

~$418M Lost: Bitget, NEAR Intents Exploits | BlockSec Weekly

This biweekly security report records eight incidents from September 21 to October 4, 2026, with approximately $418.4M in losses across Ethereum, BNB Chain, Solana, Bitcoin, TRON, XRP Ledger, Zcash, Avalanche, NEAR, and related networks. Detailed analysis covers Bitget's $387.5M third-party security product vulnerability and NEAR Intents' $3.87M refund validation flaw and missing state rollback.

Bitget's $387.5M Off-Chain Breach: Beyond Keys and Contracts
Security Insights

Bitget's $387.5M Off-Chain Breach: Beyond Keys and Contracts

On September 24, 2026, attackers exploited a vulnerability in a third-party security product, obtained internal credentials, and forged withdrawal commands. The resulting transfers moved approximately $387.5M from some of Bitget's operational wallets across Ethereum, other EVM networks, XRP Ledger, Zcash, and TRON; private keys and cold wallets remained intact. This deep dive summarizes the disclosed incident path and fund flow, examines rapid conversion into native assets and the ecosystem recovery response, proposes a systematic defense-in-depth framework for institutions, and explains how authorized blockchain penetration testing can validate cross-layer assumptions.

~$11.3M Lost: Multicall Router, Nostra | BlockSec Weekly
Security Insights

~$11.3M Lost: Multicall Router, Nostra | BlockSec Weekly

This report, covering 2026/09/14 - 2026/09/20, examines two security incidents with approximately $11.3M in combined losses, on Ethereum and Starknet. In the larger one, a multicall router accepted its own address as a dispatch target, so the nested call reached the Gateway module of a Safe wallet carrying the router's own already-authorized identity instead of the external caller's, and roughly 2,900 `aEthrsETH` was routed out of that wallet into an attacker-created Uniswap v4 pool. On Starknet, Nostra's oracle integration required a minimum of only one aggregated source, so when only two of the three configured price sources reached the aggregation, a manipulated thin-pool quote averaged with a normal quote to value `NSTR` at roughly $49.52, supporting approximately $3.5M of borrowing against overvalued collateral.

Best Security Auditor for Web3

Validate design, code, and business logic before launch. Aligned with the highest industry security standards.

BlockSec Audit

Get Real-Time Protection with Phalcon Security

Audits alone are not enough. Phalcon Security detects attacks in real time and blocks threats mid-flight.

phalcon security