How Uniswap dodged a major system flaw
A smart contract function on Uniswap turned out to be a major vulnerability for users.

A smart contract function on Uniswap turned out to be a major vulnerability for users. For potential attackers, it was an easy target.
The security firm Dedaub discovered and disclosed a critical vulnerability to the largest decentralized crypto exchange, Uniswap. The vulnerability apparently was unintentionally introduced with the UniversalRouter and Permit2 functions. With these features, Uniswap users can send ERC-20 tokens and NFTs in a single transaction. When used correctly, the UniversalRouter commands send the specified amount to the designated recipient. The vulnerability would have allowed a malicious actor to "re-enter" a transaction using this command. Once triggered, potential attackers could steal "the whole amount" from the sender's wallet.
The issue has been fixed
Dedaub advised the Uniswap team to add a so-called re-entrancy lock to their new router. The DeFi protocol "has addressed the issue and redeployed the UniversalRouter smart contracts on all chains," according to Dedaub. Currently, Uniswap is working on a pilot to let holders share in DEX revenue.