How Uniswap Was Saved From Critical Vulnerability By This Security Firm

How Uniswap Was Saved From Critical Vulnerability By This Security Firm
фото показано с : newsbtc.com

2023-1-4 03:00

Security firm Dedaub discovered and disclosed a critical vulnerability on the popular Ethereum decentralized exchange Uniswap. The team behind the protocol fixed the bug, and the affected components were successfully redeployed—otherwise, an attacker could have tempered with transactions to steal a user’s funds. 

Uniswap Avoids Danger And Fixes New Features

According to the security firm, the vulnerability was unintentionally implemented with the Universal Router. This component allows Uniswap users to trade ERC-20 tokens and non-fungible tokens “into a single swap router.”

In other words, Uniswap users can optimize their operations and trade multiple tokens and NFTs in a single transaction, saving time and money. This new component also allows users to transfer funds to third parties. 

When the vulnerability was in-placed, a user could send a transaction to a third party, and the latter could have gained access to the sender’s funds. Dedaub explained the following:

(…) if third-party code is invoked at any point in the transfer (which manifests itself due to composition of protocols), the code can reenter the UniversalRouter and claim any tokens temporarily in the contract (…). The attacker also needs to implement code to reenter the router (calling execute) and sweep all token amounts. The router may contain funds mid-transaction due to other actions and transfers in a complex swap.

The Universal Router hold the sender’s funds while the transaction is completed. While this happened, the funds were vulnerable, and a bad actor could drain them by calling specific commands such as “dispatch” with a “.TRANSFER” or. “.SWEEP.”

The vulnerability could have allowed a bad actor to “re-entered” a transaction using this command. Once inside, the attacker could have been able to “drain the entire amount” from the sender’s wallet. 

The security firm added the following on the “endless scenarios” where the vulnerability could have been exploited:

If untrusted code is invoked at any point in the transfer, the code can re-enter the UniversalRouter and claim any tokens already in the UniversalRouter contract. Such tokens can, for instance, exist because the user intends to later buy an NFT, or transfer tokens to a second recipient, or because the user swaps a larger amount than needed and intends to “sweep” the remainder to themselves at the end of the UniversalRouter call. And there is no shortage of scenarios in which an untrusted recipient may be called (…).

Ethereum DEX Grants $3 Million In Bug Bounty

In December 2022, Uniswap launched the Universal Router as part of their new NFT compatibility. At that time, Uniswap Labs announced a $3 million bounty program. Dedaub was granted this amount for their bug report on the new component.

The firm celebrated the reward and the fact that a bad actor never exploited the vulnerability. In addition, the security firm was “the only bug report that Uniswap acted upon.” 

2022 was a troublesome year for crypto and risk-on assets, while macroeconomic forces played against the nascent sector. Users experienced hurdles beyond declining prices as hackers and bad actors took billions from the industry. 

Data from on-chain analytics firm Chainalysis claims that bad actors have received over $26 billion in cryptocurrency from 2017 to 2021 alone. It remains to be seen if 2023 will extend or mitigate this trend. 

As of this writing, UNI’s price trades at $5.70 with sideways movement on the daily chart. 

Similar to Notcoin - Blum - Airdrops In 2024

origin »

SherLOCK Security (LOCK) на Currencies.ru

$ 0.1387 (+1.71%)
Объем 24H $13
Изменеия 24h: 10.06 %, 7d: -33.06 %
Cегодня L: $0.1387 - H: $0.1387
Капитализация $0 Rank 3458
Доступно / Всего 0 LOCK / 4.969m LOCK

critical vulnerability firm uniswap security otherwise attacker

critical vulnerability → Результатов: 83


Ethereum-based AirSwap reports vulnerability issue on newly released smart contract

AirSwap reported that their development team had detected a ‘critical vulnerability’ in a recently launched AirSwap smart contract. According to a blog released on medium, AirSwap, a decentralized token-trading platform built on the Ethereum blockchain, revealed that on 12th September, the internal security review team recognized a major flaw in the mainnet of the smart […] The post Ethereum-based AirSwap reports vulnerability issue on newly released smart contract appeared first on AMBCrypto.

2019-9-15 19:30


Фото:

PSA: Update your Windows machine now to fix 29 Critical security vulnerabilities

Microsoft has patched four serious vulnerabilities that could allow a malicious actor to remotely take control of Windows computers. The four remote code execution flaws — addressed as part of the company’s monthly Patch Tuesday updates — affect all in-support versions of Windows and concern the Windows Remote Desktop Services (RDS) component, enabling attackers to take over a computer and then propagate malware to other computers without any user intervention.

2019-8-14 14:35


В сети Cosmos состоялся хардфорк для устранения критической уязвимости

Команда Tendermint, работающая над проектом Cosmos, сообщила об успешном проведении хардфорка в основной сети после того, как была обнаружена критическая уязвимость. 🚨 Attn: All Hands, Cosmos Hub 🚨 There was a critical security vulnerability found on #CosmosSDK two days ago.

2019-5-31 13:08


Redditor Claims Theft of $70,000 in Life Savings Due to Critical Coinomi Wallet Bug

According to cryptocurrency investor Warith Al Mawali, he has lost all of his life savings in the tune of $60,000 to $70,000 on Coinomi, a widely utilized crypto wallet on Android. In a detailed report, Mawali claimed that a critical vulnerability found on the wallet led to the loss of user funds as it compromised the private key of his wallet.

2019-2-27 16:31


$275 Million ZCash’s Fix of Deadly ‘Infinite Counterfeit’ Vulnerability Earns Praise from Edward Snowden

According to a disclosure made Tuesday by the development team behind ZCash, the most highly capitalized privacy-focused cryptocurrency (with a market cap in excess of $270M at the time of publication), has secretly fixed a critical security flaw in ZCash’s design, which was discovered by ZCash cryptographer, Ariel Gabizon, about a year ago.

2019-2-7 11:15


Фото:

The Daily: Critical Bug Found in Beam Wallet, Wirex Adds Another Cryptocurrency

In Friday’s edition of The Daily, we cover the news about a vulnerability found in the Beam Wallet days after the launch of the Mimblewimble-based coin. Also, crypto card provider Wirex has added waves to its list of supported cryptocurrencies, and digital asset exchange Exmo has registered an increase in the number of Belarusian users […] The post The Daily: Critical Bug Found in Beam Wallet, Wirex Adds Another Cryptocurrency appeared first on Bitcoin News.

2019-1-11 14:30


В Beam Wallet обнаружена критическая уязвимость

Разработчики приватной криптовалюты Beam на базе протокола MimbleWimble обнаружили критическую уязвимость в кошельке Beam Wallet, затрагивающую и десктопную версию, и CLI-имплементацию. CRITICAL VULNERABILITY IN BEAM WALLET 9.

2019-1-10 11:06


Фото:

Ethereum Vulnerability Could Have Allowed Attackers to Drain Hot Wallets

A recent vulnerability in the Ethereum network could have reportedly allowed hackers to gain massive profits from cryptocurrency exchanges which haven’t set up a Gas usage limit. A Critical Vulnerability A group of researchers discovered a vulnerability in Ethereum which allowed attackers to drain exchanges by burning their ETH on high transaction costs or to benefit directly by minting GasToken.

2018-11-27 02:00