Skip to content

A Crypto News

Cryptocurrency News

  • Home
  • Crypto News
  • Bitcoin News
  • Altcoins News
  • Ethereum News
  • Blockchain News
  • Crypto Analysis
  • Disclaimer
  • Toggle search form
  • 100% bitcoin profit secrets to earn
    Earn what you want from bitcoin profit secrets 100%free full course – Educational Crypto Uncategorized
  • Token dump following Binance listing raises insider trading suspicions Blockchain News
  • Bitcoin sees most long liquidations of 2023 as BTC price tags $22.5K Bitcoin News
  • Dogecoin carbon emissions down by 25% following Elon Musk collaboration Altcoin News
  • Bitcoin price settles at $22.4K as daily RSI retraces 2023 bull run Bitcoin News
  • Elon Musk talks  on paypal
    PayPal has become an episode of Black Mirror: Elon Musk Crypto News
  • Rumor has it that Dogecoin could shift to proof-of-stake — What does that mean for miners? Altcoin News
  • What is USD Coin, crypto stable coin USDC
    What is USD Coin (USDC), fiat-backed stablecoin explained Crypto News
cryptocurrency market news on Uniswap

DeFi auditor nets $40,000 for identifying Uniswap vulnerability

Posted on January 4, 2023 By admin

Uniswap’s recently launched bug bounty program has led to the discovery of a now-fixed vulnerability of the protocol’s Universal Router smart contract.

The automated market maker released two new smart contracts to its platform in November 2022. Permit2 allows token approvals to be shared and managed across different applications, while Universal Router unifies ERC-20 and nonfungible tokens (NFTs) swapping into a single swap router.

Uniswap also advertised a lucrative bug bounty program to identify potential vulnerabilities in its smart contracts towards the end of 2022 as it looked to assure the safety and efficacy of its protocol.

Smart contract security and auditing firm Dedaub announced that it had received a bug bounty after flagging a vulnerability in the Universal Router smart contract that would have allowed reentrancy to drain user funds mid-transaction.

The Dedaub team has disclosed a Critical vulnerability to the Uniswap team!

Funds are safe – Uniswap addressed the issue and redeployed the Universal Router smart contracts on all its chains

The vulnerability allows re-entertrancy to drain the user\’s funds, mid-tx.

pic.twitter.com/wFSFsohPvy

— Dedaub (@dedaub) January 2, 2023

According to Dedaub’s breakdown, the Universal Router allows users to perform diverse actions including swapping multiple tokens and NFTs in one transaction.

The router embeds a scripting language for a wide variety of token actions, which could include transfers to third party recipients. If correctly implemented, transfers would go to the recipient within specified parameters.

Related: Immunefi says it has facilitated $66M in bug bounties since inception 

However, Dedaub identified a vulnerability in which a third-party code was invoked during the transfer, allowing the code to re-enter the Universal Router and claim any tokens that were temporarily in the contract.

Dedaub then suggested a straight-forward remedy, advising the Uniswap team to add a reentrancy lock to the core execution of the new router. Uniswap awarded the auditing firm a total of $40,000 for flagging the vulnerability. The amount included a 33% bonus for reporting the issue during Uniswap’s bonus period in November 2022.

Uniswap classified the issue as medium severity, while further assessment deemed the vulnerability to have high impact and low likelihood. According to Dedaub, the possibility of a user sending NFTs to an untrusted recipient directly was considered user error.

More complex and less likely scenarios were considered valid for reentrancy, which resulted in Uniswap deeming the vector to have a low likelihood. Cointelegraph has reached out to Uniswap to ascertain further details of its ongoing bounty program, amounts paid out and the number of bugs identified to date.

Bug bounties have become commonplace in the cryptocurrency and blockchain space as platforms and companies look to ensure the security of their software, systems and infrastructure.

Cryptocurrency exchange Coinbase recently clarified the terms of its bug bounty, while blockchain security firm Immunefi has facilitated over $65 million worth of bug bounties between ethical hackers and Web3 firms in 2022.

 

Source link

Crypto News Tags:uniswap

Post navigation

Previous Post: Indonesia to launch national crypto exchange in 2023: Report
Next Post: Israeli securities regulator moves to establish crypto legal framework

Related Posts

  • Sam Bankman-Fried\’s legal team warns of \’harassment and threats\’ to parents in latest court filing Crypto News
  • NFT Steez and Victor Solomon chat about building in Web3 and the Metaverse Crypto News
  • SBF prosecutors reportedly dig into donations
    SBF prosecutors reportedly dig into donations made to top US Democrats Crypto News
  • bitcoin trading market updates
    $8K dive or $22K rebound? Bitcoin traders anticipate Q1 BTC price action Crypto News
  • Corporate America has finally taken notice of Web3 — US trademark lawyer Crypto News
  • Quantum computers blockchain news
    Quantum computers may soon breach blockchain cryptography: Report Crypto News

  • JDBJDB$0.021575-0.61%
  • bitcoinBitcoin$23,159.00-1.36%
  • ethereumEthereum$1,647.29-2.17%
  • USDEXUSDEX$1.080.25%
  • tetherTether$1.00-0.09%
  • binancecoinBNB$328.11-1.05%
  • usd-coinUSD Coin$1.00-0.16%
  • rippleXRP$0.400538-3.16%
  • binance-usdBinance USD$1.00-0.17%
  • cardanoCardano$0.391789-3.06%

Crypto News Today

  • OKX to cease operations in Canada by June 22 2023
  • Rattled crypto industry could emerge stronger after USDC depeg
  • Arbitrum airdrop hype helps zkSync addresses jump over 5X in a week
  • Nonprofit to expand DLT adoption through grants of up to $5M
  • Will the Fed stop rate hikes? 5 things to know in Bitcoin this week

Bitcoin

Bitcoin

$28,017.07

BTC 2.25%

Ethereum

Ethereum

$1,768.76

ETH -1.27%

Binance Coin

Binance Coin

$337.68

BNB -0.82%

Shiba Inu

Shiba Inu

$0.0000

SHIB -2.28%

Bone ShibaSwap

Bone ShibaSwap

$1.19

BONE -4.66%

Crypto Categories

  • Altcoin News
  • Bitcoin News
  • Blockchain News
  • Crypto News
  • Ethereum News
  • Market Analysis
  • Uncategorized

  • Binance re-enters South Korea with GOPAX exchange Bitcoin News
  • BTC miner CleanSpark on the hunt for further crypto miner fire sales Bitcoin News
  • Dollar’s sharp recovery puts Bitcoin’s $25K breakout prospects at risk Bitcoin News
  • Celsius founder and CEO
    NY AG files lawsuit against Alex Mashinsky, alleging he hid Celsius’ \’dire financial condition\’ Crypto News
  • New York proposes to charge crypto companies for regulating them Crypto News
  • Bankman-Fried may enter plea in NY federal court next week before Judge Lewis Kaplan Crypto News
  • The ethics of the metaverse: Privacy, ownership and control Blockchain News
  • 3 BTC price hurdles Bitcoin bulls are failing to clear in 2023 Bitcoin News

Copyright © 2023 A Crypto News.

Powered by PressBook News WordPress theme