> For the complete documentation index, see [llms.txt](https://gamza-net.gitbook.io/gamza.net/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://gamza-net.gitbook.io/gamza.net/overview/quickstart.md).

# Introduction

## Motivation

This project aims to identify and address vulnerabilities arising from the lack of standardization- in Uniswap v4 hooks, enabling proactive threat mitigation within the web3 ecosystem.

## Summary of Herbicide

<figure><img src="https://959484927-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVYohyEukRkFCG7BpCwUW%2Fuploads%2FCgzliD7EAop8u4dcUXMb%2Fmaster_page_m%20%E2%80%93%203.png?alt=media&amp;token=90838e05-ee4e-41ed-9eb8-5f62c79f132b" alt="" width="563"><figcaption></figcaption></figure>

The Hook function, a key feature introduced in Uniswap V4, allows developers to apply custom business logic before and after actions like adding or removing liquidity, token swaps, and liquidity donations. In Uniswap V4, liquidity is managed by PoolKeys, which includes the addresses of two tokens to be exchanged, fees, tick spacing, and the address of the implemented Hook Contract.

Using Hook-applied liquidity, our project analyzes Uniswap V4 to define and address potential threats. The solution enables users to input a PoolKey corresponding to their Hook Contract deployed on the Uni Chain, then dynamically and statically analyze it to detect possible threats.

Dynamic testing is conducted across N categories with M tests, while static analysis follows with N categories and M tests, ultimately displaying results for the user. Uniswap continues to enhance the Uni Chain and blockchain ecosystem through initiatives like the Infinite Hackathon and Retro Program. We aim to assist Uniswap V4 users and Hook developers in creating safer Hook Contracts.

## Performance

Our Herbicide platform has identified security issues among various Uniswap v4 hooks detected through our platform. We conducted a direct triage process on each identified issue to verify their validity as vulnerabilities. The following outlines the results of this process.

<table><thead><tr><th width="93"></th><th></th><th></th><th></th><th></th><th></th><th></th><th></th><th></th></tr></thead><tbody><tr><td>IDX</td><td>Hook Name</td><td>Type</td><td>Minimum</td><td>Time-Lock</td><td><p>OnlyBy</p><p>PoolManager</p></td><td>Proxy</td><td><p>Re-</p><p>Initialize</p></td><td><p>Gas-</p><p>Griefing</p></td></tr><tr><td>P1</td><td>DeltaReturningHook</td><td>Uniswap Basic</td><td>P</td><td>P</td><td>P</td><td>P</td><td>P</td><td>P</td></tr><tr><td>P2</td><td>CustomCurveHook</td><td>Uniswap Basic</td><td>Detect</td><td>Detect</td><td>False Positive</td><td>P</td><td>P</td><td>P</td></tr><tr><td>P3</td><td>DynamicFeesTestHook</td><td>Uniswap Basic</td><td>P</td><td>P</td><td>Detect</td><td>P</td><td>P</td><td>P</td></tr><tr><td>P4</td><td>DynamicReturnFeeTestHook</td><td>Uniswap Basic</td><td>P</td><td>P</td><td>Detect</td><td>P</td><td>P</td><td>P</td></tr><tr><td>P5</td><td>FeeTakingHook</td><td>Uniswap Basic</td><td>P</td><td>P</td><td>P</td><td>P</td><td>P</td><td>P</td></tr><tr><td>P6</td><td>LPFeeTakingHook</td><td>Uniswap Basic</td><td>P</td><td>P</td><td>P</td><td>P</td><td>P</td><td>P</td></tr><tr><td>P7</td><td>FullRange</td><td>Uniswap Labs</td><td>Detect</td><td>Detect</td><td>False Positive</td><td>P</td><td>P</td><td>P</td></tr><tr><td>P8</td><td>GeomeanOracle</td><td>Uniswap Labs</td><td>Detect</td><td>Detect</td><td>False Positive</td><td>P</td><td>P</td><td>P</td></tr><tr><td>P9</td><td>LimitOrder</td><td>Uniswap Labs</td><td>P</td><td>P</td><td>P</td><td>P</td><td>P</td><td>P</td></tr><tr><td>P10</td><td>VolatilityOracle</td><td>Uniswap Labs</td><td>P</td><td>P</td><td>Detect</td><td>P</td><td>P</td><td>P</td></tr><tr><td>P11</td><td>StopLoss</td><td>Community</td><td>P</td><td>P</td><td>Detect</td><td>P</td><td>P</td><td>P</td></tr><tr><td>P12</td><td>TradingDays</td><td>Community</td><td>P</td><td>Detect</td><td>Detect</td><td>P</td><td>P</td><td>P</td></tr><tr><td>P13</td><td>ArrkisHook</td><td>ETHCC_Paris</td><td>P</td><td>P</td><td>Detect</td><td>P</td><td>Detect</td><td>P</td></tr></tbody></table>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://gamza-net.gitbook.io/gamza.net/overview/quickstart.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `automate deployments from our CI pipeline` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
