Lifecycle-aware security evaluation of programmable DeFi hooks: A framework for Uniswap V4

Citations

WEB OF SCIENCE

0
Citations

SCOPUS

0

초록

The programmable hook architecture introduced in Uniswap V4 enables external logic to be executed at predefined lifecycle events within automated market maker (AMM) protocols, enhancing the customizability. However, this design introduces a novel attack surface that conventional static analysis tools are ill-equipped to handle, particularly due to hooks' context-dependent behavior and lack of publicly available source code. This paper proposes HookScope, a lifecycle-aware dynamic analysis framework for evaluating the structural security of programmable hooks. HookScope defines five runtime threat types (T1-T5) specific to the Uniswap V4 hook model and employs simulation-based testing to detect their manifestation during live contract execution. Risk scores are computed using a CVSS-inspired model that incorporates threat severity, execution context, and system-level impact. Comparative evaluation demonstrates that HookScope identifies threats overlooked by widely-used baseline tools such as Mythril, highlighting the necessity of lifecycle-aware dynamic analysis for programmable DeFi infrastructure. The proposed framework contributes a reproducible, quantifiable approach to threat detection in decentralized protocols and provides a foundation for future research on secure extensibility in AMM-based systems.

키워드

Uniswap V4DeFi securitySmart contract analysisThreat modelingDynamic analysis
제목
Lifecycle-aware security evaluation of programmable DeFi hooks: A framework for Uniswap V4
저자
Oh, HoonLee, Seyoung
DOI
10.1016/j.comnet.2025.111900
발행일
2026-02
유형
Article
저널명
Computer Networks
275