Toxic liquidity pools fake quotes on Ethereum, Polygon

Enso warns ‘toxic pools’ on Ethereum and Polygon return fake quotes in off-chain simulations, then change behavior on-chain, causing worse execution and many failed trades.

DeFi infrastructure firm Enso published a July 16 report identifying a new class of malicious liquidity pools it calls “toxic pools.” The company found these contracts return attractive price quotes during off-chain, read-only trade simulations and then change behavior when transactions are broadcast on Ethereum and Polygon, resulting in worse execution or failed trades.

Enso said its findings come from roughly two months of on-chain forensic analysis combining archive-node data, transaction trace analysis and smart contract inspections. One manipulated Curve pool on Ethereum processed more than 129,000 swaps while returning overstated quotes that Enso estimated at about $225,000 in misleading price information. A separate Curve pool caused more than 37,000 reverted trades, which led to nearly $30,000 in gas fees paid by users. On Polygon, a malicious “hook”—a plugin-style contract used by modular exchanges such as Uniswap v4-produced a 99.1% transaction failure rate after luring routing systems with fake rates during simulation.

The report describes how these pools detect simulation environments used by wallets and DEX aggregators and respond with artificially attractive prices. When the transaction goes on-chain, the contracts alter math or routing so the trade executes at a degraded rate or reverts. Enso engineers found operators alternate between honest and malicious states to evade static code scanners and reputation checks, and they discovered multiple oracle contracts deployed by the same operator to support additional pools.

Enso warned the tactic targets the simulation layer that wallets and aggregators use to select the best execution path. If routing systems cannot tell the difference between genuine quotes and simulated bait, front ends may continue to route trades toward toxic pools, producing worse outcomes for users and exposing interface providers to potential legal and financial risk for promising “best execution.” Enso provided its analysis to Curve Finance and Oku during the investigation.

Milos Costantini, Enso’s co-founder and chief product officer, wrote in the report: “Our investigation leads us to believe this is not simply another isolated smart contract exploit.” He added: “If transaction simulations can be manipulated while real execution tells a different story, we need better ways to verify what users actually receive.”

As a response, Enso updated its Enso Shield execution-protection product to include toxic-pool detection for Ethereum and Polygon. The tool monitors live on-chain context, tracks quote histories and uses transaction traces to detect discrepancies between quoted and executed prices.

Enso recommended further research into simulation manipulation and urged wallets, front ends and aggregators to add execution-integrity checks into routing logic. The report notes that newer exchange components like hooks and external oracles can introduce attack surfaces that target off-chain simulations rather than directly draining contract balances.

The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.

Articles by this author