Finst

How Uniswap dodged a major system flaw

A smart contract function on Uniswap turned out to be a major vulnerability for users.

How Uniswap dodged a major system flaw

A smart contract function on Uniswap turned out to be a major vulnerability for users. For potential attackers, it was an easy target.

The security firm Dedaub discovered and disclosed a critical vulnerability to the largest decentralized crypto exchange, Uniswap. The vulnerability apparently was unintentionally introduced with the UniversalRouter and Permit2 functions. With these features, Uniswap users can send ERC-20 tokens and NFTs in a single transaction. When used correctly, the UniversalRouter commands send the specified amount to the designated recipient. The vulnerability would have allowed a malicious actor to "re-enter" a transaction using this command. Once triggered, potential attackers could steal "the whole amount" from the sender's wallet.

The issue has been fixed

Dedaub advised the Uniswap team to add a so-called re-entrancy lock to their new router. The DeFi protocol "has addressed the issue and redeployed the UniversalRouter smart contracts on all chains," according to Dedaub. Currently, Uniswap is working on a pilot to let holders share in DEX revenue.

View post on X


Disclaimer: This content is for informational purposes only and does not constitute financial, investment, legal, or tax advice. The information provided may be incomplete, inaccurate, or outdated and should not be relied upon as such. Nothing on this website should be considered a recommendation to buy, sell, or hold any cryptocurrency. Investing in crypto-assets involves risk of loss.