SECURITY
Cork and Bunni Exploits Expose Seven Uniswap v4 Hook Failure Patterns
Uniswap v4 hooks shift security to app code. Cork (~$12M) and Bunni ($8.4M) exploits stemmed from application logic, not core protocol. Seven failure patterns identified, including missing caller checks and accounting bugs passing PoolManager settlement. PoolManager singleton enforces protocol mechanics only; hooks must validate callers, pools, deltas, and external integrations.
