Skip to main content

Security

Hooks are not audited​

SuperHooks writes real Solidity that runs with real funds on a live network. The code is generated by an AI model. It is compiled and its deployment is simulated, but it is not audited and is not guaranteed to do what you intended.

Before you put meaningful funds behind a hook:

  1. Read the source. View code is on every hook card.
  2. Ask SuperHooks to explain each callback and what could go wrong.
  3. Have someone qualified review it.
  4. Start small.

Hooks that take or give tokens (the ReturnDelta permissions) deserve the most care, because a mistake there can cost traders or liquidity providers money.

SuperHooks never holds your keys​

ActionWho signs
Signing inYour wallet signs a message. No gas, no transaction.
Deploying a hookYour wallet sends the transaction.
Creating a poolYour wallet sends the transaction.

SuperHooks' servers cannot deploy contracts, create pools or move funds. If the service went away, your hooks and pools would keep working, because they live on Uniswap V4 and belong to your wallet.

What you sign​

  • Sign-in message: a standard Sign-In with Ethereum message that names app.superhooks.dev. Do not sign a SuperHooks message on any other site.
  • Deploy: a transaction to the CREATE2 deployer at 0x4e59b44847b379578588920cA78FbF26c0B4956C.
  • Create pool: a call to initialize on the PoolManager at 0x8366a39cc670b4001a1121b8f6a443a643e40951.

SuperHooks never asks you to approve tokens or send funds. If something claiming to be SuperHooks does, it is not SuperHooks.

The code you deploy is the code you read​

Hooks compile in your browser from the source shown on the card. The bytecode in the deployment transaction is produced there, not on a server.

What is stored​

Your wallet address, your chats, the hooks written for you, and the pools you created or imported. Sign-in sessions last 14 days.