Sample Audit Report
Security Review: 0xprogrammable Uniswap v4 Hooks
Demonstration audit report showing the depth and format of our smart contract security review service.
Target: 0xprogrammable/programmable
Commit: main (Aug 2026)
Reviewer: Danylo Morozov
Date: 2026-08-01
Executive Summary
A comprehensive security review was conducted on the 0xprogrammable protocol — a launch-model infrastructure built on Uniswap v4 hooks. The codebase consists of Uniswap v4 hook contracts (EthCreatorFeeHook V1/V2/V3), memecoin launch contracts (MemeLaunch V1/V2), fee distribution (FeeSplitVaultV1), and vesting (ClassicInitialBuyVestingWalletV1).
The codebase demonstrates above-average security quality. The development team shows strong understanding of Uniswap v4 hook semantics, proper beforeSwap/afterSwap delta handling, and robust custody validation. No critical or high-severity vulnerabilities were identified.
Scope
Contracts Reviewed
- MemeLaunchV1.sol (477 LOC) — Memecoin launch with initial buy and liquidity locking
- MemeLaunchV2.sol (643 LOC) — V2 with launch hash attestation and custody checks
- EthCreatorFeeHookV1.sol (414 LOC) — Uniswap v4 hook for creator fee on swaps
- EthCreatorFeeHookV2.sol (464 LOC) — V2 with HookFee/HookSwap event emissions
- EthCreatorFeeHookV3.sol (512 LOC) — V3 with directional fees and FeeSplitVault
- FeeSplitVaultV1.sol (182 LOC) — Fee split distribution with claim pattern
- ClassicRewardVaultV1.sol (318 LOC) — Reward vault with accrual
- ClassicInitialBuyVestingWalletV1.sol (181 LOC) — Vesting wallet for initial buys
Methodology
- Manual line-by-line review of all source contracts
- Slither static analysis (0 findings on src/)
- Forge build verification
- Access control and authorization audit
- Reentrancy and cross-contract interaction analysis
- Uniswap v4 hook delta accounting verification
- ERC20 token handling and safe-transfer review
- Fee calculation and distribution math verification
Findings
Low
L-01: Missing zero-address validation in FeeSplitVaultV1 constructor
File: FeeSplitVaultV1.sol
Description: The constructor accepts recipient and token addresses without validating they are non-zero. If deployed with address(0), fee distributions would be permanently lost.
Recommendation: Add require(recipient != address(0)) and require(token != address(0)) in the constructor.
Impact: Low — deployment error only, not exploitable by external parties.
Info
I-01: Inconsistent event emission across hook versions
File: EthCreatorFeeHookV1.sol vs V2/V3
Description: V1 does not emit HookFee/HookSwap events that V2 and V3 emit. While this doesn't affect security, it limits off-chain monitoring and indexing for V1 deployments.
Recommendation: Backport event emissions to V1 or document the upgrade path for existing V1 users.
Areas of Strength
- Hook delta accounting: beforeSwap correctly returns toBeforeSwapDelta(totalFee, 0) and afterSwap verifies actual amounts. Partial fill handling is correct — reverts when actualNativePoolAmount != expectedNativePoolAmount for specified-in swaps.
- Custody validation: MemeLaunchV2 validates poolMatchesTokenPair and custody mismatch checks prevent token/pool desync attacks.
- Forced ETH handling: _executeInitialBuy correctly handles forced ETH amount via msg.value without bypassing fee logic.
- Fee math: _chargeNative correctly computes gross from net (nativeAmount + totalFee) and uses NATIVE.take for PoolManager settlement.
- Reentrancy protection: Transient reentrancy guards (t-load/t-store) used consistently across state-modifying functions.
Conclusion
The 0xprogrammable codebase is well-engineered with strong security practices. The development team demonstrates deep understanding of Uniswap v4 hook mechanics, EVM execution semantics, and common attack vectors. No exploitable vulnerabilities were found. The two low/info findings are minor hardening suggestions.
Need a security review for your contracts?
Full manual + automated review, written report, 5-day turnaround.
Get a review — $1,499