ChainBleedv0.1 · open intel
← back to feed·ETHACCESS-CONTROL2026-05-12 · 28d ago
Incident · TENARMOR

BoostHook

Uniswap V4 hook-contract logic exploit
Estimated loss
$47.5K
VERDICT —UNRATED
Verdict pending. Auto-ingested incidents are reviewed before a public verdict is rendered.
▰ METHOD
Uniswap V4 hook-contract logic exploit
ACCESS-CONTROLBYTECODE CATCHABLEAI SCANNABLE
Root cause

BoostHook is a Uniswap V4-style hook contract. Hook contracts execute alongside swaps and can introduce vulnerabilities in their beforeSwap / afterSwap / beforeAddLiquidity callbacks. Common subtypes: (a) missing authorization checks allowing arbitrary callers to invoke hook entry points, (b) improper validation of pool/sender state inside the hook, (c) accounting flaws where hook-collected fees or rewards are credited to the wrong account, (d) reentrancy into the PoolManager via the hook. The small loss size suggests a precise targeted call against a hook function with insufficient caller validation rather than a broad math exploit.

Forensic narrative

Method: Uniswap V4 hook-contract logic exploit. Root cause: BoostHook is a Uniswap V4-style hook contract. Hook contracts execute alongside swaps and can introduce vulnerabilities in their beforeSwap / afterSwap / beforeAddLiquidity callbacks. Common subtypes: (a) missing authorization checks allowing arbitrary callers to invoke hook entry points, (b) improper validation of pool/sender state inside the hook, (c) accounting flaws where hook-collected fees or rewards are credited to the wrong account, (d) reentrancy into the PoolManager via the hook. The small loss size suggests a precise targeted call against a hook function with insufficient caller validation rather than a broad math exploit. Attack tx: 0xb45cc4d9c13c2c24b4bbf71db9e6f52ed24d174ad23ed2622a290289cebd3811. First flagged by TenArmor TenMonitor.

Primary source
https://etherscan.io/tx/0xb45cc4d9c13c2c24b4bbf71db9e6f52ed24d174ad23ed2622a290289cebd3811
Sourced from
tenarmor
Technical record
chain
ethereum
protocol
BoostHook
bug_class
access-control
date_occurred
2026-05-12
loss_usd
$47,500
source_id
tenarmor:ethereum:0xb45cc4d9c13c2c24b4bbf71db9e6f52ed24d174ad23ed2622a290289cebd3811
Related — same bug class· access-control
2026-05-13
27d ago
ARB
ShapeShift FOX Colony (Colony Network)
executeMetaTransaction → resolver-repoint via setTarget → delegatecall drain
access-control
$132.7K
AUDIT-CATCHABLE
2026-05-12
28d ago
Aurellion Labs
Contract Vulnerability
access-control
$455.0K
UNRATED
2026-05-11
29d ago
POLY
Huma Finance V1 (deprecated)
refreshAccount() unconditional GoodStanding state flip → unauthorized drawdown
access-control
$101.4K
AUDIT-CATCHABLE
2026-05-10
1mo ago
ARB
Renegade
Unprotected Initializer Exploit
access-control
$209.0K
UNRATED
2026-05-10
1mo ago
ARB
Renegade
Contract Vulnerability
access-control
$209.0K
UNRATED
2026-05-07
1mo ago
ETH
TrustedVolumes
Forged RFQ Orders
access-control
$6.70M
AUDIT-CATCHABLE
ChainBleed — live web3 threat intelligence