Uniswap:
the most decentralized DEX we've reviewed so far, on an AMM model with its own structural trade-offs.
We tore apart Uniswap, the largest automated market maker DEX by cumulative volume, across the same seven-category scorecard we built for this series. From genuinely massive scale ($3.671 trillion in cumulative volume across V2/V3/V4, $3.4 billion in current TVL), an extensively audited V4 (nine independent audits, a $15.5 million bug bounty, no critical bugs found at launch), and genuinely strong decentralization credentials (fully open-source, permissionless, and a February 2025 SEC investigation closed with no action against Uniswap Labs), to a real, documented April 2020 reentrancy incident on its ETH-imBTC pool, an honest, structural attack-surface expansion introduced by V4's newer Hooks framework, and a genuinely different risk than anything in Hyperliquid's order-book model: MEV sandwich attacks, a well-documented, ongoing cost baked into the AMM design itself, including one trader's real $215,000 loss in a single attack in March 2025; and landed on a score the marketing page won't show you.
Our take, up front: Uniswap runs on a genuinely different architecture from Hyperliquid, the automated market maker model, where liquidity providers pool tokens and prices move algorithmically along a formula rather than through a matched order book. Real, genuinely massive scale: $3.671 trillion in cumulative decentralized exchange volume across V2, V3, and V4 as of May 2026, $3.4 billion in current total value locked, and $54.8 billion in trailing 30-day volume. Real, genuinely extensive V4 security investment: nine independent audits from named firms including OpenZeppelin, Trail of Bits, Certora, Spearbit, and ABDK Consulting, a $2.35 million security competition with more than 500 participants, and a $15.5 million bug bounty described as the largest in the industry's history, with no critical bugs found during the launch window. Real, genuinely strong decentralization credentials: fully open-source, permissionless, and non-custodial, with no equivalent to a foundation-controlled validator set making discretionary market interventions. Real, genuinely significant, positive regulatory resolution: Uniswap Labs disclosed in February 2025 that the SEC closed its multi-year investigation into the company with no enforcement action. What we can't set aside: a real, documented April 2020 incident where Uniswap's ETH-imBTC pool was drained via a reentrancy attack exploiting the interaction between a known vulnerability pattern and the ERC777 token standard, with reported losses between roughly $300,000 and $1.1 million; the underlying vulnerability had actually been identified by researchers over a year earlier, in January 2019. Real, honest, structural risk specific to V4's newer Hooks framework: hooks dramatically expand the potential attack surface, and a single misconfigured or malicious hook can lead to real financial losses, a genuinely different risk category from the core protocol's own extensively audited code. And real, a structural risk category that Hyperliquid's order-book model doesn't share in the same way: MEV sandwich attacks are well-documented and ongoing on AMM-style DEXs, with one trader losing a real $215,000 in a single attack in March 2025, and researchers estimating more than $650 million extracted from DEX users industry-wide since 2020. We weighted all of it below.
Real, genuinely extensive V4 security investment: nine independent audits from named firms including OpenZeppelin, Trail of Bits, Certora, Spearbit, and ABDK Consulting, a $2.35 million security competition with more than 500 participants, and a $15.5 million bug bounty described as the largest in the industry's history, with no critical bugs found during the launch window. Real, genuinely strong track record since 2020: V2 and V3 have processed trillions of dollars in cumulative volume without a protocol-level hack. What we can't set aside: a real, documented April 2020 incident where Uniswap's ETH-imBTC pool was drained via a reentrancy attack exploiting the interaction between a known vulnerability pattern and the ERC777 token standard, with reported losses between roughly $300,000 and $1.1 million; the underlying vulnerability had actually been identified by researchers over a year earlier, in January 2019. Real, honest, structural risk specific to V4's Hooks framework: hooks dramatically expand the potential attack surface, and a single misconfigured or malicious hook can lead to real financial losses, a genuinely different risk category from the core protocol's own audited code.
Pros
- Nine named, independent V4 audits plus a $15.5M bug bounty, no critical bugs found at launch
- Trillions in cumulative V2/V3 volume processed without a protocol-level hack since 2020
Cons
- Real, documented April 2020 reentrancy incident on the ETH-imBTC pool
- V4's Hooks framework introduces a genuinely new, real attack-surface expansion
Real, genuinely massive scale: $3.671 trillion in cumulative decentralized exchange volume across V2, V3, and V4 as of May 2026, $3.415 billion in current total value locked, and $54.8 billion in trailing 30-day volume. Real, consistently described as among the deepest liquidity venues for major token pairs, anchoring price discovery across DeFi more broadly.
Pros
- $3.671 trillion in cumulative volume, independently tracked via DefiLlama
- Consistently anchors price discovery for major pairs across DeFi
Cons
- Liquidity depth varies significantly by pool; thinner pairs carry real slippage risk
Real, genuinely non-custodial, permissionless, and fully open-source; anyone can trade or list a new pair by creating a liquidity pool, with no equivalent to a foundation-controlled validator set making discretionary market interventions. Real, genuinely significant, positive regulatory resolution: Uniswap Labs disclosed in February 2025 that the SEC closed its multi-year investigation into the company with no enforcement action. Real, active, functioning governance: a November 2025 proposal activated protocol fees on select pools, routed to a UNI token burn. Real, UNI governance token backed by early Ethereum Foundation support.
Pros
- Fully open-source, permissionless, non-custodial; no discretionary validator control
- SEC investigation into Uniswap Labs closed with no action (Feb 2025)
- Active, functioning on-chain governance (UNIfication fee/burn proposal)
Cons
- Uniswap Labs, the company, still shapes which tokens/features surface in its own official interface
Real, genuinely broad reach: available on 18 to 20-plus EVM-compatible networks depending on the source and count method, supporting spot trading, liquidity provision, and cross-chain swaps across a vast number of listed token pairs given its permissionless listing model.
Pros
- Deployed across 18-20+ EVM-compatible networks
- Permissionless listing means virtually any ERC-20 pair can exist
Cons
- Permissionless listing also means scam and low-quality tokens are freely listable
Real, works well in mobile browsers, with strong routing and a portfolio feature independently described as handy and accurate. Real, honest, notable limitation: no account-level support or reversals; help is mostly limited to documentation and community channels, a real gap if something goes wrong. Real, gas costs on Ethereum mainnet meaningfully affect small trades specifically, though this matters much less on Layer 2 networks.
Pros
- Strong routing; accurate, handy portfolio feature
- Works well in mobile browsers
Cons
- No account-level support or reversals; help is docs/community only
- Gas costs meaningfully affect small trades on Ethereum mainnet specifically
Real, fee structure varies meaningfully by version: V2 uses a fixed 0.3% swap fee, V3 offers tiered fees (0.01%, 0.05%, 0.30%, 1.00%) depending on the pool, and V4 allows fully flexible, dynamic fees set per pool via hooks. Real, honest, structural risk specific to the AMM model: MEV sandwich attacks are a well-documented, ongoing risk category, with one specific, real example costing a trader $215,000 in a single attack in March 2025, and researchers estimating more than $650 million extracted from DEX users since 2020 industry-wide.
Pros
- Transparent, tiered fees; genuinely low rates available on deep, major pools
- V4's flexible fee model allows pool-specific optimization
Cons
- Real, structural MEV sandwich-attack risk baked into the public-mempool AMM model
- One trader lost $215,000 to a single sandwich attack in March 2025
Real, genuinely distinctive V4 singleton architecture, housing all pools in a single contract and cutting pool-creation gas costs by up to 99.99%. Real, genuinely flexible Hooks framework enabling dynamic fees, on-chain limit orders, and automated liquidity management, with more than 150 hooks already developed by V4's launch. Real, UniswapX for improved cross-chain and MEV-resistant execution routing.
Pros
- Distinctive V4 singleton architecture; up to 99.99% cheaper pool creation
- Flexible Hooks framework; 150+ hooks developed by launch
- UniswapX for MEV-resistant execution routing
Cons
- None significant found in our research
Access only through Uniswap's official app at app.uniswap.org.
Always set an explicit slippage tolerance rather than leaving it at a permissive default, and consider a private RPC or MEV-protected route for larger swaps specifically, given the real, documented sandwich-attack risk on public-mempool trades.
The strongest decentralization story in this series so far, with a different kind of trade-off than Hyperliquid's.
Uniswap earns real credit for a genuinely different profile than the first DEX we reviewed: it's fully open-source, permissionless, and has never had anything resembling Hyperliquid's JELLY situation, no foundation-controlled validator group unilaterally reversing a market outcome. Its V4 security investment is genuinely exceptional by any standard we've seen in this project. What keeps this from scoring even higher is that the AMM model Uniswap pioneered carries its own real, structural cost: MEV sandwich attacks are a documented, ongoing tax on public-mempool trades that a matched order book like Hyperliquid's doesn't create in the same way, and the 2020 reentrancy incident, while old, is a real part of the record. Neither platform is strictly safer than the other; they carry genuinely different kinds of risk, and we think that's worth saying plainly rather than collapsing both into a single "DEXs are risky" caveat.
The scorecard above is deliberately general. Whether Uniswap is right for you depends heavily on which of these you already are.
The trader or liquidity provider who wants genuine decentralization and deep spot liquidity across a huge range of tokens
Fully open-source, permissionless architecture and massive, independently-verified liquidity serve this profile directly.
The developer or advanced user who wants to build with V4's Hooks framework or route through UniswapX
These are genuinely distinctive, real tools built specifically for this kind of technical use case.
The trader willing to set explicit slippage limits and consider MEV-protected routes for larger swaps
Given the real, structural sandwich-attack risk we found, this precaution genuinely matters for trade size.
Active perpetuals traders wanting CEX-like order-book execution and deep leverage
Uniswap is a spot AMM; traders wanting that specific experience should look at an order-book perp DEX instead.
The scorecard covers the headline judgment calls. These four tables cover the specifics we didn't want to bury in prose; the April 2020 reentrancy incident timelined precisely, how MEV sandwich attacks actually work, fees broken down across every version, and Uniswap against the only other DEX we've reviewed so far.
The April 2020 reentrancy incident, timelined
| Step | What happened |
|---|---|
| The root cause | A reentrancy pattern combining the ERC777 token standard's callback function with Uniswap's contract logic was identified by researchers in January 2019 |
| The exploit | On April 18, 2020, an attacker used the imBTC token, which implements ERC777, to trigger a callback mid-transaction and drain Uniswap's ETH-imBTC liquidity pool |
| The scale | Reported losses range from roughly $300,000 to $1.1 million depending on the source |
| The pattern repeated | A nearly identical exploit hit Lendf.me roughly 24 hours later, using the same ERC777/reentrancy interaction |
| Since then | V2 and V3 have processed trillions in cumulative volume with no repeat of a protocol-level hack |
The vulnerability was a known interaction pattern between a specific token standard and AMM contract logic, not a flaw unique to Uniswap alone; a nearly identical exploit hit a different, unrelated protocol the very next day.
How a sandwich attack actually works
| Step | What happens |
|---|---|
| 1. Detection | An MEV bot spots your pending swap in the public mempool before it's confirmed |
| 2. Front-run | The bot buys the same asset first, pushing the price up ahead of your trade |
| 3. Your execution | Your swap executes at the now-worse, inflated price |
| 4. Back-run | The bot immediately sells, capturing the price difference your own trade created |
| Real-world scale | Researchers estimate $650M+ extracted from DEX users since 2020; one trader lost $215,000 in a single attack in March 2025 |
This is a structural feature of trading through a public mempool on an AMM, not a bug specific to Uniswap; setting a tight slippage tolerance and using a private or MEV-protected transaction route meaningfully reduces exposure.
Fees, precisely, across every version
| Version | Fee structure |
|---|---|
| V1 / V2 | Fixed 0.3% swap fee |
| V3 | Tiered: 0.01%, 0.05%, 0.30%, or 1.00%, depending on the pool |
| V4 | Fully flexible, dynamic fees set per pool via hooks |
| Protocol fee (Nov 2025 onward) | Activated on select V2 and V3 pools, routed to a UNI token burn |
The cheapest routes are typically deep stablecoin or blue-chip pools; thinner or more volatile pairs can cost materially more once slippage and MEV exposure are factored in alongside the posted fee.
Uniswap vs. Hyperliquid, the only other DEX we've reviewed so far
| Uniswap | Hyperliquid | |
|---|---|---|
| Architecture | AMM (liquidity pools) | On-chain CLOB (order book) |
| Source code | Fully open-source | Closed-source core |
| Primary structural risk | MEV / sandwich attacks | Validator discretion (JELLY incident) |
| Historical incident | 2020 reentrancy exploit (~$300K-$1.1M) | 2025 JELLY market intervention |
| Primary use case | Spot swaps, broad token access | Perpetual futures, active execution |
Neither platform is strictly safer than the other; they carry genuinely different kinds of risk rooted in genuinely different architectural choices.
We don't just want to hand you our number; we want to show you how it sits next to what other review desks and comparison sites have published. Uniswap's scale and history mean genuinely deep, specific independent coverage exists, giving us a strong comparison set here.
Our score lands close to the aggregated industry average, the smallest gap we've found in this series so far; the genuinely strong decentralization credentials and extensive audit history we weighted heavily are the same qualities most independent sources single out favorably.
| Source | Score | Type |
|---|
Scores compiled by our editorial team from publicly available reviews as of August 2026. "Editorial estimate" means the outlet didn't publish a single numeric score, so we converted their published verdict and sentiment into a comparable 100-point figure. Verify current figures directly with each source before citing them elsewhere.
Yes, once, in April 2020: a reentrancy attack drained its ETH-imBTC pool for a reported $300,000 to $1.1 million by exploiting the interaction between a known vulnerability pattern and the ERC777 token standard. Since then, V2 and V3 have processed trillions in cumulative volume without a repeat protocol-level hack.
An MEV bot spots your pending trade, buys ahead of it to push the price up, lets your trade execute at the worse price, then sells for the difference. This is a structural risk on any public-mempool AMM, Uniswap included, not a bug specific to the protocol. Setting a tight slippage tolerance and using MEV-protected routes for larger trades reduces exposure.
Uniswap Labs, the company behind the interface, disclosed in February 2025 that the SEC closed its multi-year investigation with no enforcement action, a genuinely significant, positive resolution.
It depends on the version and pool: V2 charges a fixed 0.3%, V3 offers tiers from 0.01% to 1.00% depending on the pool, and V4 allows fully dynamic, pool-specific fees. Gas costs on Ethereum mainnet add to this for smaller trades specifically; Layer 2 networks keep gas consistently low.
A framework letting developers add custom logic to liquidity pools, enabling dynamic fees, on-chain limit orders, and automated liquidity management. More than 150 hooks were developed by V4's launch, though hooks also genuinely expand the platform's attack surface beyond the core audited contracts.
Different architectures with different risks: Uniswap is a fully open-source AMM built for spot swaps, with MEV sandwich attacks as its primary structural risk. Hyperliquid is a closed-source, order-book perpetuals exchange, with validator-discretion incidents like JELLY as its primary decentralization concern. Neither is strictly safer.
Yes, fully. This is a genuine point of contrast with some other DEXs that keep parts of their core codebase closed, and it allows independent verification of exactly what the contracts do.
18 to 20-plus EVM-compatible networks depending on the source and count method, with permissionless listing meaning virtually any ERC-20 token pair can exist on it.
More Reviews
THORChain – DEX Review
Score: 46/100. Unmatched native cross-chain swaps, carrying 2021 hacks, a $200M 2025 crisis, and use as a laundering conduit.
Read MoreHyperliquid – DEX Review
Score: 73/100. Dominant perp DEX, but closed-source code and the JELLY delisting controversy are real, unresolved trust questions.
Read MoreVertex – DEX Review
Score: 62/100. Sophisticated cross-margin trading, reviewed mid-migration to a new chain with conflicting founder accounts.
Read MoreRaydium – DEX Review
Score: 68/100. Solana's liquidity leader, carrying two confirmed incidents and a real, wide gap in third-party security ratings.
Read More



