Uniswap; Reviewed & Scored | The Block Note
DEX Review · Updated August 2026

Uniswap:
the most decentralized DEX we've reviewed so far, on an AMM model with its own structural trade-offs.

We tore apart Uniswap, the largest automated market maker DEX by cumulative volume, across the same seven-category scorecard we built for this series. From genuinely massive scale ($3.671 trillion in cumulative volume across V2/V3/V4, $3.4 billion in current TVL), an extensively audited V4 (nine independent audits, a $15.5 million bug bounty, no critical bugs found at launch), and genuinely strong decentralization credentials (fully open-source, permissionless, and a February 2025 SEC investigation closed with no action against Uniswap Labs), to a real, documented April 2020 reentrancy incident on its ETH-imBTC pool, an honest, structural attack-surface expansion introduced by V4's newer Hooks framework, and a genuinely different risk than anything in Hyperliquid's order-book model: MEV sandwich attacks, a well-documented, ongoing cost baked into the AMM design itself, including one trader's real $215,000 loss in a single attack in March 2025; and landed on a score the marketing page won't show you.

Type Decentralized Exchange (AMM, spot swaps + liquidity pools) Platforms Web · Mobile browser · 18-20+ EVM chains Fees 0.01%-1.00% (V3 tiers); dynamic on V4 Discount Offer None
uniswap
DEX
AMM · Open-source · Permissionless
$3.67T cumulative volume

Our take, up front: Uniswap runs on a genuinely different architecture from Hyperliquid, the automated market maker model, where liquidity providers pool tokens and prices move algorithmically along a formula rather than through a matched order book. Real, genuinely massive scale: $3.671 trillion in cumulative decentralized exchange volume across V2, V3, and V4 as of May 2026, $3.4 billion in current total value locked, and $54.8 billion in trailing 30-day volume. Real, genuinely extensive V4 security investment: nine independent audits from named firms including OpenZeppelin, Trail of Bits, Certora, Spearbit, and ABDK Consulting, a $2.35 million security competition with more than 500 participants, and a $15.5 million bug bounty described as the largest in the industry's history, with no critical bugs found during the launch window. Real, genuinely strong decentralization credentials: fully open-source, permissionless, and non-custodial, with no equivalent to a foundation-controlled validator set making discretionary market interventions. Real, genuinely significant, positive regulatory resolution: Uniswap Labs disclosed in February 2025 that the SEC closed its multi-year investigation into the company with no enforcement action. What we can't set aside: a real, documented April 2020 incident where Uniswap's ETH-imBTC pool was drained via a reentrancy attack exploiting the interaction between a known vulnerability pattern and the ERC777 token standard, with reported losses between roughly $300,000 and $1.1 million; the underlying vulnerability had actually been identified by researchers over a year earlier, in January 2019. Real, honest, structural risk specific to V4's newer Hooks framework: hooks dramatically expand the potential attack surface, and a single misconfigured or malicious hook can lead to real financial losses, a genuinely different risk category from the core protocol's own extensively audited code. And real, a structural risk category that Hyperliquid's order-book model doesn't share in the same way: MEV sandwich attacks are well-documented and ongoing on AMM-style DEXs, with one trader losing a real $215,000 in a single attack in March 2025, and researchers estimating more than $650 million extracted from DEX users industry-wide since 2020. We weighted all of it below.

Real, genuinely extensive V4 security investment: nine independent audits from named firms including OpenZeppelin, Trail of Bits, Certora, Spearbit, and ABDK Consulting, a $2.35 million security competition with more than 500 participants, and a $15.5 million bug bounty described as the largest in the industry's history, with no critical bugs found during the launch window. Real, genuinely strong track record since 2020: V2 and V3 have processed trillions of dollars in cumulative volume without a protocol-level hack. What we can't set aside: a real, documented April 2020 incident where Uniswap's ETH-imBTC pool was drained via a reentrancy attack exploiting the interaction between a known vulnerability pattern and the ERC777 token standard, with reported losses between roughly $300,000 and $1.1 million; the underlying vulnerability had actually been identified by researchers over a year earlier, in January 2019. Real, honest, structural risk specific to V4's Hooks framework: hooks dramatically expand the potential attack surface, and a single misconfigured or malicious hook can lead to real financial losses, a genuinely different risk category from the core protocol's own audited code.

Why this scores above the midpoint: genuinely extensive, well-documented audit investment and a strong multi-year track record since the 2020 incident are substantive positives, tempered by that real, documented historical breach and an honest, structural risk introduced by the newer Hooks framework specifically.

Pros

  • Nine named, independent V4 audits plus a $15.5M bug bounty, no critical bugs found at launch
  • Trillions in cumulative V2/V3 volume processed without a protocol-level hack since 2020

Cons

  • Real, documented April 2020 reentrancy incident on the ETH-imBTC pool
  • V4's Hooks framework introduces a genuinely new, real attack-surface expansion

Real, genuinely massive scale: $3.671 trillion in cumulative decentralized exchange volume across V2, V3, and V4 as of May 2026, $3.415 billion in current total value locked, and $54.8 billion in trailing 30-day volume. Real, consistently described as among the deepest liquidity venues for major token pairs, anchoring price discovery across DeFi more broadly.

Why this scores well: genuinely massive, well-corroborated historical and current liquidity, among the deepest available for major asset pairs.

Pros

  • $3.671 trillion in cumulative volume, independently tracked via DefiLlama
  • Consistently anchors price discovery for major pairs across DeFi

Cons

  • Liquidity depth varies significantly by pool; thinner pairs carry real slippage risk

Real, genuinely non-custodial, permissionless, and fully open-source; anyone can trade or list a new pair by creating a liquidity pool, with no equivalent to a foundation-controlled validator set making discretionary market interventions. Real, genuinely significant, positive regulatory resolution: Uniswap Labs disclosed in February 2025 that the SEC closed its multi-year investigation into the company with no enforcement action. Real, active, functioning governance: a November 2025 proposal activated protocol fees on select pools, routed to a UNI token burn. Real, UNI governance token backed by early Ethereum Foundation support.

Why this scores among the highest Decentralization ratings we've given: genuinely strong decentralization credentials, fully open-source, permissionless, non-custodial, with a real, positive regulatory resolution and active, functioning on-chain governance.

Pros

  • Fully open-source, permissionless, non-custodial; no discretionary validator control
  • SEC investigation into Uniswap Labs closed with no action (Feb 2025)
  • Active, functioning on-chain governance (UNIfication fee/burn proposal)

Cons

  • Uniswap Labs, the company, still shapes which tokens/features surface in its own official interface

Real, genuinely broad reach: available on 18 to 20-plus EVM-compatible networks depending on the source and count method, supporting spot trading, liquidity provision, and cross-chain swaps across a vast number of listed token pairs given its permissionless listing model.

Why this scores well: genuinely broad, permissionless asset and network coverage, among the widest of any DEX in this category.

Pros

  • Deployed across 18-20+ EVM-compatible networks
  • Permissionless listing means virtually any ERC-20 pair can exist

Cons

  • Permissionless listing also means scam and low-quality tokens are freely listable

Real, works well in mobile browsers, with strong routing and a portfolio feature independently described as handy and accurate. Real, honest, notable limitation: no account-level support or reversals; help is mostly limited to documentation and community channels, a real gap if something goes wrong. Real, gas costs on Ethereum mainnet meaningfully affect small trades specifically, though this matters much less on Layer 2 networks.

Why this scores above the midpoint: a genuinely capable interface with strong routing is a real strength, tempered by an honest support limitation and gas-cost sensitivity for smaller trades on mainnet specifically.

Pros

  • Strong routing; accurate, handy portfolio feature
  • Works well in mobile browsers

Cons

  • No account-level support or reversals; help is docs/community only
  • Gas costs meaningfully affect small trades on Ethereum mainnet specifically

Real, fee structure varies meaningfully by version: V2 uses a fixed 0.3% swap fee, V3 offers tiered fees (0.01%, 0.05%, 0.30%, 1.00%) depending on the pool, and V4 allows fully flexible, dynamic fees set per pool via hooks. Real, honest, structural risk specific to the AMM model: MEV sandwich attacks are a well-documented, ongoing risk category, with one specific, real example costing a trader $215,000 in a single attack in March 2025, and researchers estimating more than $650 million extracted from DEX users since 2020 industry-wide.

Why this scores below the midpoint: genuinely competitive, transparent fee tiers for deep pools are a real positive, tempered by a real, structural MEV risk category that can silently cost traders more than the posted fee itself.

Pros

  • Transparent, tiered fees; genuinely low rates available on deep, major pools
  • V4's flexible fee model allows pool-specific optimization

Cons

  • Real, structural MEV sandwich-attack risk baked into the public-mempool AMM model
  • One trader lost $215,000 to a single sandwich attack in March 2025

Real, genuinely distinctive V4 singleton architecture, housing all pools in a single contract and cutting pool-creation gas costs by up to 99.99%. Real, genuinely flexible Hooks framework enabling dynamic fees, on-chain limit orders, and automated liquidity management, with more than 150 hooks already developed by V4's launch. Real, UniswapX for improved cross-chain and MEV-resistant execution routing.

Pros

  • Distinctive V4 singleton architecture; up to 99.99% cheaper pool creation
  • Flexible Hooks framework; 150+ hooks developed by launch
  • UniswapX for MEV-resistant execution routing

Cons

  • None significant found in our research
Where to get it

Access only through Uniswap's official app at app.uniswap.org.

Always set an explicit slippage tolerance rather than leaving it at a permissive default, and consider a private RPC or MEV-protected route for larger swaps specifically, given the real, documented sandwich-attack risk on public-mempool trades.

0/ 100

The strongest decentralization story in this series so far, with a different kind of trade-off than Hyperliquid's.

Uniswap earns real credit for a genuinely different profile than the first DEX we reviewed: it's fully open-source, permissionless, and has never had anything resembling Hyperliquid's JELLY situation, no foundation-controlled validator group unilaterally reversing a market outcome. Its V4 security investment is genuinely exceptional by any standard we've seen in this project. What keeps this from scoring even higher is that the AMM model Uniswap pioneered carries its own real, structural cost: MEV sandwich attacks are a documented, ongoing tax on public-mempool trades that a matched order book like Hyperliquid's doesn't create in the same way, and the 2020 reentrancy incident, while old, is a real part of the record. Neither platform is strictly safer than the other; they carry genuinely different kinds of risk, and we think that's worth saying plainly rather than collapsing both into a single "DEXs are risky" caveat.

Best forTraders and liquidity providers who prioritize genuine decentralization, permissionless access, and deep spot liquidity across a huge range of tokens and chains
Not forActive perpetuals traders wanting CEX-like order-book execution, or anyone trading large size without MEV protection
Score Ledger
uniswap · 7 line items
01Security22.5
02Liquidity17.0
03Decentralization12.75
04Assets8.0
05UX7.0
06Fees6.0
07Extras4.0
TOTAL77.25
≈ 77 / 100; Genuinely decentralized, different risk profile

The scorecard above is deliberately general. Whether Uniswap is right for you depends heavily on which of these you already are.

Best fit

The trader or liquidity provider who wants genuine decentralization and deep spot liquidity across a huge range of tokens

Fully open-source, permissionless architecture and massive, independently-verified liquidity serve this profile directly.

Good fit

The developer or advanced user who wants to build with V4's Hooks framework or route through UniswapX

These are genuinely distinctive, real tools built specifically for this kind of technical use case.

Workable fit

The trader willing to set explicit slippage limits and consider MEV-protected routes for larger swaps

Given the real, structural sandwich-attack risk we found, this precaution genuinely matters for trade size.

Poor fit

Active perpetuals traders wanting CEX-like order-book execution and deep leverage

Uniswap is a spot AMM; traders wanting that specific experience should look at an order-book perp DEX instead.

The scorecard covers the headline judgment calls. These four tables cover the specifics we didn't want to bury in prose; the April 2020 reentrancy incident timelined precisely, how MEV sandwich attacks actually work, fees broken down across every version, and Uniswap against the only other DEX we've reviewed so far.

The April 2020 reentrancy incident, timelined

StepWhat happened
The root causeA reentrancy pattern combining the ERC777 token standard's callback function with Uniswap's contract logic was identified by researchers in January 2019
The exploitOn April 18, 2020, an attacker used the imBTC token, which implements ERC777, to trigger a callback mid-transaction and drain Uniswap's ETH-imBTC liquidity pool
The scaleReported losses range from roughly $300,000 to $1.1 million depending on the source
The pattern repeatedA nearly identical exploit hit Lendf.me roughly 24 hours later, using the same ERC777/reentrancy interaction
Since thenV2 and V3 have processed trillions in cumulative volume with no repeat of a protocol-level hack

The vulnerability was a known interaction pattern between a specific token standard and AMM contract logic, not a flaw unique to Uniswap alone; a nearly identical exploit hit a different, unrelated protocol the very next day.

How a sandwich attack actually works

StepWhat happens
1. DetectionAn MEV bot spots your pending swap in the public mempool before it's confirmed
2. Front-runThe bot buys the same asset first, pushing the price up ahead of your trade
3. Your executionYour swap executes at the now-worse, inflated price
4. Back-runThe bot immediately sells, capturing the price difference your own trade created
Real-world scaleResearchers estimate $650M+ extracted from DEX users since 2020; one trader lost $215,000 in a single attack in March 2025

This is a structural feature of trading through a public mempool on an AMM, not a bug specific to Uniswap; setting a tight slippage tolerance and using a private or MEV-protected transaction route meaningfully reduces exposure.

Fees, precisely, across every version

VersionFee structure
V1 / V2Fixed 0.3% swap fee
V3Tiered: 0.01%, 0.05%, 0.30%, or 1.00%, depending on the pool
V4Fully flexible, dynamic fees set per pool via hooks
Protocol fee (Nov 2025 onward)Activated on select V2 and V3 pools, routed to a UNI token burn

The cheapest routes are typically deep stablecoin or blue-chip pools; thinner or more volatile pairs can cost materially more once slippage and MEV exposure are factored in alongside the posted fee.

Uniswap vs. Hyperliquid, the only other DEX we've reviewed so far

UniswapHyperliquid
ArchitectureAMM (liquidity pools)On-chain CLOB (order book)
Source codeFully open-sourceClosed-source core
Primary structural riskMEV / sandwich attacksValidator discretion (JELLY incident)
Historical incident2020 reentrancy exploit (~$300K-$1.1M)2025 JELLY market intervention
Primary use caseSpot swaps, broad token accessPerpetual futures, active execution

Neither platform is strictly safer than the other; they carry genuinely different kinds of risk rooted in genuinely different architectural choices.

We don't just want to hand you our number; we want to show you how it sits next to what other review desks and comparison sites have published. Uniswap's scale and history mean genuinely deep, specific independent coverage exists, giving us a strong comparison set here.

The Block Note (us)N/A / 100
Industry averageN/A / 100

Our score lands close to the aggregated industry average, the smallest gap we've found in this series so far; the genuinely strong decentralization credentials and extensive audit history we weighted heavily are the same qualities most independent sources single out favorably.

SourceScoreType

Scores compiled by our editorial team from publicly available reviews as of August 2026. "Editorial estimate" means the outlet didn't publish a single numeric score, so we converted their published verdict and sentiment into a comparable 100-point figure. Verify current figures directly with each source before citing them elsewhere.

Yes, once, in April 2020: a reentrancy attack drained its ETH-imBTC pool for a reported $300,000 to $1.1 million by exploiting the interaction between a known vulnerability pattern and the ERC777 token standard. Since then, V2 and V3 have processed trillions in cumulative volume without a repeat protocol-level hack.

An MEV bot spots your pending trade, buys ahead of it to push the price up, lets your trade execute at the worse price, then sells for the difference. This is a structural risk on any public-mempool AMM, Uniswap included, not a bug specific to the protocol. Setting a tight slippage tolerance and using MEV-protected routes for larger trades reduces exposure.

Uniswap Labs, the company behind the interface, disclosed in February 2025 that the SEC closed its multi-year investigation with no enforcement action, a genuinely significant, positive resolution.

It depends on the version and pool: V2 charges a fixed 0.3%, V3 offers tiers from 0.01% to 1.00% depending on the pool, and V4 allows fully dynamic, pool-specific fees. Gas costs on Ethereum mainnet add to this for smaller trades specifically; Layer 2 networks keep gas consistently low.

A framework letting developers add custom logic to liquidity pools, enabling dynamic fees, on-chain limit orders, and automated liquidity management. More than 150 hooks were developed by V4's launch, though hooks also genuinely expand the platform's attack surface beyond the core audited contracts.

Different architectures with different risks: Uniswap is a fully open-source AMM built for spot swaps, with MEV sandwich attacks as its primary structural risk. Hyperliquid is a closed-source, order-book perpetuals exchange, with validator-discretion incidents like JELLY as its primary decentralization concern. Neither is strictly safer.

Yes, fully. This is a genuine point of contrast with some other DEXs that keep parts of their core codebase closed, and it allows independent verification of exactly what the contracts do.

18 to 20-plus EVM-compatible networks depending on the source and count method, with permissionless listing meaning virtually any ERC-20 token pair can exist on it.

Affiliate & editorial disclosure: This page may contain affiliate links. If you buy through one, we may earn a commission at no extra cost to you. That relationship does not influence the category weightings or scores above; those are set by our editorial methodology before any offer is placed. Decentralized exchanges reduce custodial risk but do not eliminate risk: smart-contract, bridge, oracle, validator, and market-structure risk remain real regardless of how "decentralized" a platform's marketing describes it as. Leverage trading can result in losses exceeding your initial deposit. Nothing here is financial advice.
Features, pricing, and security details verified against public sources as of Aug 2026; always confirm current terms directly with Uniswap.

More Reviews

Vertex – DEX Review

Score: 62/100. Sophisticated cross-margin trading, reviewed mid-migration to a new chain with conflicting founder accounts.

Read More
raydium logo cover image

Raydium – DEX Review

Score: 68/100. Solana's liquidity leader, carrying two confirmed incidents and a real, wide gap in third-party security ratings.

Read More