Billions of dollars are traded on decentralized exchanges every day
Billions of dollars are traded on decentralized exchanges (DEX) every day. According to the latest data, DEX transaction volume in the past 24 hours has reached approximately US$5 billion. The aggregator evaluates rates and paths from different liquidity providers to find the best trading solution. For example, 0x collects data from about 150 service providers, while Uniswap's Quotation API shows users both prices and trading paths.
Many services also provide so-called "trading simulations", assuming that the simulation results are consistent with actual trading results. But a new research report released on July 16, 2026 by DeFi infrastructure company Enso pointed out that this trust could be manipulated-the company has identified a pool of liquidity that specifically exploits this vulnerability.
The risks go far beyond these two contracts. Wallets, DEX aggregators, and other user-facing applications often rely on off-chain simulations to find the best transactions for users. Enso found that certain liquidity pools can take advantage of this process: displaying attractive prices to win the trading path during simulations, but giving a worse price when the real transaction is executed on the blockchain.
Enso calls this setting a "toxic pool." They take advantage of the difference between simulated trading and real execution on the chain. By checking values such as tx.gasprice, tx.origin, and block.coinbase, smart contracts can determine whether a transaction is only in the simulation stage and behaves normally during preview, and change its behavior once the real transaction is executed.
Two real cases, two types of damage
With the assistance of the Curve Finance and Oku team, Enso conducted a two-month analysis of RPC data, transaction traces and contract data and successfully identified the "toxic pools" running on Ethereum and Polygon.
On Ethereum, a Curve USDC/USDT pool uses manipulated rate predictors to make simulated transactions look better than real transactions. During the simulation, the oracle applied a discount rate; but when the real transaction was executed, the discount disappeared and the user ended up earning less than expected revenue. This manipulation is difficult to detect because the oracle relies on a legitimate Chainlink price feed and changes its output only when a simulation is detected.
Enso calculations show that the pool's offer was inflated by nearly $225,000, but this does not mean that $225,000 was stolen. The operator recorded net income of $34,592.87, of which approximately $23,440 was Curve's normal fees. Enso also found 129,070 redemption transactions in which users received quotes less than the amount they deserved, and 37,425 failed transactions that still consumed users 'Gas fees.
The Polygon case caused more disruption than profit. A USDC/WETH pool that uses the Uniswap v4 hook charges approximately 98.9% when Gas prices exceed 100 gwei, and uses other signals to detect simulated transactions. Although the pool made little profits, it was repeatedly shown as the optimal path during simulations, while actual transactions always failed. This wastes Gas and other resources in routers and transaction systems.
Enso recorded 37,467 failed conversions, with a failure rate of 99.1%. About 93% of failed transactions involved MEVs and arbitrage robots. About 2,525 combustion wallets were recycled in one cross-DEX operation alone, and a total of 3,509 failed transactions were generated.
Rethinking DeFi security
Curve pools do not always exhibit malicious behavior, making it more difficult to detect. Enso found that the pool's discount settings changed 26 times over 48 observation windows, showing malicious behavior in approximately 59% of the monitored period. In other words, a pool that seems safe at one point may later become hostile, making static code reviews and reputation filters less reliable.
Enso also found that this technique may have been replicated. The report states that the same operator used an EIP-7702 smart account tied to a shared implementation and deployed 18 oracle contracts behind at least six similar pools.
The impact is not limited to robots and professional traders. Enso said MetaMask had routed 6,625 conversions to the toxic Curve pool, indicating that flaws in routing infrastructure can also affect ordinary users.
Enso does not accuse Curve, Uniswap or the wallets that interact with these pools. It believes that these systems are built on the reasonable assumption that liquidity pools behave the same at the time of simulation as when real transactions are executed.
"The entire industry has spent years optimizing price discovery," said Milos Costantini, co-founder and chief product officer of Enso."Our findings show that the next challenge is verifying execution integrity."
After Enso's disclosure, the two identified venues have ceased to be active. According to reports, Polygon's hooks have expired since May 15, and the discount on Curve Pool is now set to zero. Enso said it has added a "toxic pool" detection feature to Enso Shield, which is based on real-time on-chain context and historical quote behavior rather than relying on just a single simulation.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
ETH