THE 99% TOLLBOOTH
Permissionless pools collected extreme fees through real execution paths. The chain proves the tollbooths existed and traded; it does not prove which frontend chose every route.
Abstract
8,000,000 blocks · 9.27 days · canonical PoolManagerWe censused Robinhood Chain blocks 27,845,418–35,845,417 and found 16,949 static Uniswap v4 pools configured for 85–99.9999% fees among 111,291 PoolManager initializations. Of that cohort, 4,755 pools executed 24,152 swap legs in 21,981 transactions; fee math reconciles for every observed leg, and 16,943 pools used no hook. ETH, WETH, and USDG inputs alone accrued a known LP-fee floor of $14,061.92 at the disclosed reference price, while 1,567 other input currencies remain unpriced. Immediate callers include Uniswap Universal Router and 0x-matching RobinHoodSettler. The evidence supports an automated duplicate-pair route-poisoning campaign and an integration-policy failure boundary—not a Uniswap v4 core exploit. It does not identify the offchain selector for every trade or establish brokerage-app involvement, victim loss, or realized operator profit.
- Method
- Canonical Initialize + Swap event census
- Result
- 4,755 traded extreme-fee pools
- Reconciliation
- 24,152 / 24,152 swap legs
- Conclusion
- Route policy, not v4 fee math
This is a permissionless EVM network. No evidence here establishes that the retail brokerage UI selected these trades.
Long-form investigation narrative Expand the mechanism, execution evidence, economics, and engineering implications
Permissionless pool identity created a hostile route-search surface
Uniswap v4 permits multiple pools for the same currency pair because fee, tick spacing, and hook address are part of pool identity. The observed campaign used that design surface at scale: 16,949 extreme-fee pools covered 7,674 pairs, and 99.965% of the pools were hookless. The mechanism therefore does not require malicious hook code or a broken PoolManager.
The pools were not inert spam
4,755 pools received at least one swap. The canonical event stream records 24,152 high-fee legs across 21,981 transactions. Universal Router directly called PoolManager for 5,275 legs and RobinHoodSettler for 3,951. Those contracts prove real execution paths touched the pools; they do not, by themselves, reveal the originating UI, API, smart account, or quote engine.
The priced slice is a floor, not a loss estimate
For ETH, WETH, and USDG input legs, $15,277.74 of gross input was observed and $14,061.92—92.0419%—accrued as configured LP fees. Another 1,567 input currencies were intentionally left unpriced. Accrual is not the same as fee collection, net profit, or victim loss; output value, liquidity ownership changes, inventory exposure, and gas are outside this reconstruction.
Integrators need adversarial pool-selection policy
The chain shows normal v4 fee accounting applied to abnormal pools. The defensible engineering response is upstream: reject or heavily penalize untrusted fee tiers, canonicalize duplicate-pair candidates, simulate exact output, enforce user-protective minimum output, and retain pool IDs in quote telemetry. The exact selector defect remains unproven, so the report attributes immediate execution contracts—not every frontend decision.
The snapshot is reproducible but not an all-time census
The locked discovery artifact records requested bounds, source hosts, block-hash anchors, reproducer parameters, and a 25/25 Blockscout confirmation. It predates the collector's per-range coverage ledger, so range-by-range completion cannot be retroactively proven. That limitation is preserved rather than papered over.
From pool spam to live tollbooths
Every stage is counted from the official v4 PoolManager event stream.
Almost entirely vanilla v4
This rejects the easy “malicious hook exploit” explanation. PoolManager applied ordinary configured fees.
Campaign persisted across the full scan
Duplicate pools make route poisoning tangible
Even the 99% cohort executed
Configured LP fee, activation, and fee accrual stay separate.
Pool population and observed execution
Where the known input went
Not victim loss or realized profit. The swap output may retain value; 1,567 other input currencies are deliberately unpriced.
Not primarily same-block sniping
Blocks are exact. Time equivalents use the scan window’s average seconds per block and are approximate.
Routers did touch the tollbooths
Immediate PoolManager callers are observable. Frontend and quote-engine selection usually are not.
Who immediately called PoolManager
Pool-origin clusters meeting execution paths
Left nodes are initial PositionManager NFT owners associated with the pool—not proven attackers or final fee recipients.
Concentrated at the top, long-tailed underneath
Initial NFT ownership gives a clustering handle, not a beneficiary ledger.
Largest active-pool clusters
| Initial owner | Active pools | Share | Associated known fees | Attribution state |
|---|
Three route shapes, one fee pattern
Direct router, wrapped router, and account-abstraction settlement examples.
Inspect the 16,949-pool cohort
The full compact index loads only when requested.
| Pool / pair | Fee | Block | Swaps | Known fee floor | Initial owner |
|---|
What the chain proves—and what it doesn’t
The confidence labels are part of the product, not fine print.
Full audit. Raw chain evidence. Reproducer source.
The public bundle carries every artifact used by the investigation—not just the dashboard’s compact projection.