The next DeFi exploit may already be hiding in Toxic Pools

Every day, billions are traded through decentralized exchanges, with the latest figures from DefiLlama showing the DEX volume has reached about $5 billion in the past 24 hours. Aggregators assess rates and paths available from various liquidity providers to find the best deals. To illustrate, while 0x collects data from approximately 150 services, Uniswap’s quote API shows the user both the price and the route. A number of services also provide a so-called transaction simulation, which assumes that the results will correspond to what would happen in reality. New research from the DeFi infrastructure company Enso published July 16, 2026, reports that trust can be manipulated — and the company has identified pools that do just that. The risk goes beyond these two contracts. Wallets, DEX aggregators, and other consumer-facing apps often rely on off-chain simulations to find users the best trade. Enso found that a pool can exploit this process by showing an attractive price during simulation to win the route, then delivering a worse price when the actual transaction hits the blockchain. Enso calls these setups “toxic pools.” They take advantage of the gap between a simulated trade and what actually happens on-chain. By checking values such as tx.gasprice, tx.origin, and block.coinbase, a smart contract can tell when a transaction is only being simulated and behave normally during the preview, then change its behavior when the real trade goes through. Two live cases, two kinds of damage After conducting two months of analysis of RPC data, transaction traces and contract data with the support of Curve Finance and Oku contacts, Enso managed to identify pools that function on Ethereum and Polygon. On Ethereum, a Curve USDC/USDT pool used a manipulated rate oracle to make simulated trades look better than the real ones. During a simulation, the oracle applied a discounted rate. But when the actual trade went through, that discount vanished, leaving users with less than expected. The manipulation was also difficult to spot because the oracle relied on legitimate Chainlink price feeds, only changing their output when it detected a simulation. Enso calculated that the pool quotes were inflated by nearly $225,000, although this does not mean that $225,000 has been stolen. The operator’s recorded net gain was $34,592.87, with nearly $23,440 being normal fees of the Curve. Enso also spotted 129,070 swaps whereby the users received quotes below what they were supposed to receive and saw 37,425 failed transactions that still cost gas to their users. The Polygon case caused more disruption than profit. A USDC/WETH pool using a Uniswap v4 hook charged a roughly 98.9% fee when gas prices rose above 100 gwei and used other signals to detect simulations.
عنوان اصلی (انگلیسی): The next DeFi exploit may already be hiding in Toxic Pools
مشاهدهی خبر کامل در منبع ↗ بازگشت به Ensoاین خلاصه بهصورت خودکار از کوینمارکتکپ ترجمه شده و ممکن است خطای ماشینی داشته باشد؛ صرفاً جهت اطلاعرسانی است و توصیهی معاملاتی نیست.