HookGuard continuously measures the v4 hook ecosystem — the registry,
everything deployed off it, and what bytecode says when source is missing.
This is not an audit. Every number below is regenerated from public
chain data and reproducible from a clone.
both upgradeable-proxy class · one proven on-chain
Registry pulse
hooklist snapshot · refreshed weekly
Audit coverage
audit recorded30
no audit listed521
can move value393
value-moving · unaudited367
Hooks by chain · hatched share = unaudited
Unichain deep dive
full chain history · PoolManager 0x1F98…0004
What the registry sees of Unichain
%
19 of 1211 distinct deployed hooks are registered.
The empty ring is the point.
◈
Unichain runs the v4 preview deployment. Hook addresses there encode callback
permissions in the reverse bit order vs final v4 (validated against every
source-verifiable hook: 17/18). Tooling reading permissions with mainnet semantics
misreads this chain — including most dashboards you have seen.
107
multi-pool hooks off registry
17.8%
publish any source
28 / 88
DELEGATECALL in runtime code
—
distinct programs found
Cross-chain attribution
byte-identical runtime code under different addresses
Risk distribution
every scored record · weights published, nothing hidden
Score 0–100 from itemized facts only: source findings, bytecode signals,
registry/audit status, author confirmations. Full weight table:
src/score.py.
Adoption
external projects running chaosxcode/hookguard@v1 · measured, not claimed
of 5-goal unrelated projects
Measured via public code search over .github/workflows/; our own repositories are excluded.
Add HookGuard to yours:
- uses: chaosxcode/hookguard@v1
Advisory ledger
every author contact, logged in public
The feed
one record per known hook · click an address to copy