81trust / 100

Arc Hook Risk

by APEX Arc Uniswap v4 hook risk in Onchain & crypto

x402 APIPassing, checked 3 h ago

Arc pre-trade risk in microseconds, no chain call: pass ?hook=0x… and get the verdict read straight out of the Uniswap v4 permission bits encoded in the hook address. It tells you what the hook is ALLOWED to do (run on every swap, rewrite the amounts, touch liquidity), not what it does: permission is not behaviour. No trap rate is quoted - the 83.7% we used to state came from a pre-buy sell quote and was withdrawn on 2026-09-22 after a real round trip sold 10 of 10 pools with that signature.

GET https://apexfaucet.xyz/api/x402/arc-hook-risk

Last 30 days

All checks passedSome failedAll failedNot checked
Uptime
100%
Response time
66 ms typical, 66 ms slowest 5%
Last check
3 h ago
Next check
any minute now

How to call it

# See the payment challenge (nothing is charged)
curl -i -X GET "https://apexfaucet.xyz/api/x402/arc-hook-risk?hook=0xB780642659b782b672f20516fC267d5069252044"
import { wrapFetchWithPayment } from "@x402/fetch";
import { x402Client } from "@x402/core/client";
import { ExactEvmScheme } from "@x402/evm/exact/client";
import { privateKeyToAccount } from "viem/accounts";

const client = new x402Client().register(
  "eip155:8453",
  new ExactEvmScheme(privateKeyToAccount(process.env.AGENT_KEY)),
);
const pay = wrapFetchWithPayment(fetch, client);

// Not sure it's safe to pay? Preflight it first for $0.005:
// GET https://toolvet.app/api/v1/check?url=https%3A%2F%2Fapexfaucet.xyz%2Fapi%2Fx402%2Farc-hook-risk
const res = await pay("https://apexfaucet.xyz/api/x402/arc-hook-risk?hook=0xB780642659b782b672f20516fC267d5069252044");
console.log(await res.json());

Example input

{
  "hook": "0xB780642659b782b672f20516fC267d5069252044"
}

Example output

{
  "data": {
    "historicalTrapRate": null,
    "hook": "0xb780642659b782b672f20516fc267d5069252044",
    "method": "Uniswap v4 permission bits read from the hook address. No base rate is given: the 2026-09-17 rates were measured with a …",
    "note": "Instant (no chain call). For a definitive answer on one pool use the exit check, which actually attempts the round trip.",
    "ok": true,
    "permissionBits": "10000001000100",
    "permissions": [
      "beforeInitialize",
      "afterSwap"
    ],
    "verdict": "can rewrite swaps",
    "why": "This hook runs on every swap AND may rewrite the amounts, which is the machinery that can block or tax a sell. Permissio…"
  },
  "ok": true,
  "paid": 0.003
}

Security scan

  • No findings. We scan names, descriptions and tool definitions for hidden instructions and other prompt-injection patterns.

Recent checks

WhenResultHTTPTimePrice
3 h agoPassed40268 ms$0.003
8 h agoPassed40266 ms$0.003