Dedaub receives $40,000 vulnerability bounty for disclosing Uniswap reentry vulnerability

01/03 15:33

security firm Dedaub has announced that it has received a 40,000 USDC security vulnerability bounty from Uniswap Labs for disclosing a serious vulnerability in Uniswap that had the potential to reenter and deplete users' funds. However, the Uniswap team has resolved the vulnerability and redeployed the Universal Router smart contract on all chains and the funds are safe. Uniswap is releasing the Universal Router smart contract in November 2022, which unifies ERC20 and NFT exchanges into a single exchange router that allows users to perform heterogeneous operations, for example, exchanging multiple Tokens and NFTs in a single transaction. The router embeds a scripting language for various Token operations, and such commands may include transmissions to third-party (and possibly untrusted) recipients," says Dedaub. If third-party code is invoked at any point during a transmission, that code can re-enter the UniversalRouter and temporarily claim any Token in the contract. dedaub recommends that Uniswap add a re-entry lock to the new router's core execution and redeploy it."
bullishbullishbullish1bearishbearishbearishBearish1Share
DisclaimerThe content above does not represent HTX's positions.HTX does not provide any trading recommendations.

Related Articles

  • Image

    Slonks:一个会主动消失的 NFT 项目

  • Image

    $500 mln USDC added to Solana: What it means for liquidity

  • Image

    Uniswap rebounds: Can UNI push past $4.2 EMA resistance?

All Comments0LatestHot

avatar
LatestHot

Related Articles

  • Image

    Slonks:一个会主动消失的 NFT 项目

  • Image

    $500 mln USDC added to Solana: What it means for liquidity

  • Image

    Uniswap rebounds: Can UNI push past $4.2 EMA resistance?