Resources
Security
What Uniswap v4 and Socket's design guarantee for pool tokens, hooks, the buyback and governance, and how to report a problem.
Every pool Socket uses is a Uniswap v4 pool on Robinhood Chain. This page lists what v4 guarantees for every pool, and what Socket's own contracts add.
What Uniswap v4 guarantees#
- PoolManager holds the tokens. Every pool's tokens sit in one contract, PoolManager, and leave it only when an operation settles.
- A pool's hook and permissions are fixed. The hook's address is part of the pool key, and the lowest 14 bits of that address are the calls PoolManager makes to it. Neither changes for the life of the pool. A different hook, or different permissions, is a different pool.
- A hook does only what its flags allow. PoolManager calls a hook only at the points its address sets. A hook changes a swap's amounts only with a swap returns-delta flag, and a position's amounts only with a liquidity returns-delta flag. It sets the LP fee only in a pool whose fee is the dynamic-fee flag.
- Every operation settles or reverts. Each swap and position change runs inside one
unlock. PoolManager and the hook record what each party owes or is owed, and all of it must be settled beforeunlockends. If anything is left unsettled, or any hook call reverts, the whole transaction reverts and nothing moves. - Your minimum output holds. The app swaps through the Universal Router with the minimum output you sign. The router checks it after the swap, so whatever a pool's hook does, a swap that would pay you less reverts.
- A swap's approval goes to the router. For a swap, you approve the token to Permit2 and sign a permit for the Universal Router. The pool's hook gets neither.
What Socket's design adds#
- The buyback share comes only from collected LP fees. A pool on Socket's hooks takes its share from
feesAccruedin afterAddLiquidity and afterRemoveLiquidity, when a position collects fees. Swaps and quotes are untouched. Pools on External hooks, and pools with no hook, keep no share. - The buyback can only buy SOCKET and burn it. The hook sends the share straight to the
Buybackcontract. Buyback can only swap toward SOCKET, through pools with no hook or a listed hook, and burn the SOCKET. No key holds the fees on the way. One run moves a pool's price by at most 0.25%, and each input token runs at most once every ten minutes. - Pool settings are fixed at initialization. A dynamic-fee pool's creator sets every setting in the transaction that initializes the pool, and none can change after. Each pool keeps the buyback share it was initialized with.
- The hooks read only their own pool. The dynamic fee reads no external price and needs no keeper; its clock is the block timestamp. The TWAP hook records the pool's own ticks. A range order leaves the pool in the same swap that fills it.
- Governance reaches the allowlist, the stakes and one number.
HookRegistry's authority is the governance timelock. A vote can list or remove a hook, burn a removed hook's stake, and set the buyback share for pools initialized afterwards, from 0% to 50%. Every passed proposal waits two days in the timelock before anyone can execute it. - No vote reaches pools or positions. No vote can change an existing pool, move tokens out of PoolManager or anyone's position, or pause trading.
Reading a pool's hook#
The app routes only through pools with no hook or a hook on the allowlist. Socket's built-in hooks show by name. Any other listed hook shows as External hook.
An External hook is on the list because SOCKET holders voted it on. Its author proposed it with its verified source on the explorer, its address and flags, and an independent review, and its 1,000,000 SOCKET stake stays locked while it is listed. A removal vote can burn that stake if the deployed code doesn't match the published source.
A hook's flags are in its address. Read them on Hooks and permissions, and see Limits for each bound in detail.