The number looked perfect. A 5% better price on a token swap. You click confirm. Gas burns. Transaction reverts. You lose the fee. The pool disappears. That’s the new attack vector: simulation spoofing.
I’ve seen this pattern before. In 2020, I audited Curve’s early contracts. Found an integer overflow in fee calculation. That was a bug. This is a weapon. Enso just exposed it.
Context: Why simulation matters
DeFi routing depends on simulation. Your wallet or aggregator calls the pool’s smart contract locally. It estimates output, gas, slippage. Then it chooses the best route. The assumption: the simulation is a proxy for execution. That assumption is broken.
Enter malicious pools. Deployed on Curve (Ethereum) and Uniswap v4 (Polygon). They return a fake, favorable quote during simulation. But when the real transaction hits, they revert. Or execute with a worse price. The user pays gas for nothing. The attacker collects the failed transaction fees.
This isn’t MEV. It’s not frontrunning or sandwiching. It’s an attack on the trust layer. The quote itself is the bait.
Core: The numbers don’t lie
Enso’s team traced the damage. On Ethereum, the malicious Curve pool processed 129,000 transactions. On Polygon, the Uniswap v4 hook saw constant activity. 99.1% of them failed. Over $30,000 in wasted gas. The attacker’s net profit? $34,600. Small for a single campaign. But scalable.
The mechanics are elegant. The pool checks if the caller is a known simulation environment (like Tenderly or Alchemy’s eth_call). If yes, it returns inflated output. If no, it executes honestly or reverts. The deception is context-dependent. A standard static analysis won’t catch it.
My take from the trenches
During the 2021 NFT minting chaos, I built bots that frontran human minters. I learned how gas price manipulation works. This is different. The attacker isn’t competing for block space. They’re exploiting the pre-trade optimization layer. Think of it as a phishing attack on your wallet’s intelligence.
I’ve run local nodes since 2017. In 2022, I identified Terra’s UST decoupling by monitoring burn rates 12 hours before exchanges halted withdrawals. That was about speed. This is about deception. Two different game plans.
Contrarian: This is not just another security hole
Everyone will say “use a better aggregator” or “check the pool’s audit.” Wrong. The problem is structural. The entire simulation paradigm assumes good faith from the pool. Uniswap v4’s hooks make it trivial to deploy such logic. Curve’s factory pools allow arbitrary parameters. The attacker only needs to deploy one malicious pool among thousands of legitimate ones. The aggregator will find it. The user will click it.
Enso’s co-founder calls it “simulation spoofing.” I call it a broken trust anchor. The real risk isn’t the $34k profit. It’s the erosion of confidence in DeFi’s most fundamental UX: “click to swap.”
The market hasn’t priced this in
Current market is sideways. Chop. Low volatility. That’s when users get complacent. They trust their wallet. They don’t question the quote. “Volatility is just fear wearing a disguise.” Right now, the disguise is a seemingly better price.
Takeaway: What comes next
Expect wallets to implement post-execution verification. Compare expected output against actual. Expect protocols to whitelist hooks or require audits. Expect Enso’s Shield product to gain traction. The cat is out of the bag.
But the attacker left other contracts on-chain. Enso confirmed they deployed more. The hunt is not over.
Signatures embedded
“Yields were too good to be true, so we didn’t trust them.” Now, quotes are too good to be true. Don’t trust them either. “The mint button was a lever, not a purchase.” The simulate button was a lever, not a guarantee. “Volatility is just fear wearing a disguise.” Complacency is fear wearing a calm mask.
Forward-looking thought
The next major DeFi hack won’t be a protocol exploit. It will be a UX exploit. Simulation spoofing is the first shot. The industry must rewire how wallets and routers vet liquidity. Or the trust will bleed out, one failed transaction at a time.