Uniswap’s recently launched bug bounty program has led to the discovery of a now-fixed vulnerability of the protocol’s Universal Router smart contract.
The automated market maker released two new smart contracts to its platform in November 2022. Permit2 allows token approvals to be shared and managed across different applications, while Universal Router unifies ERC-20 and nonfungible tokens (NFTs) swapping into a single swap router.
Uniswap also advertised a lucrative bug bounty program to identify potential vulnerabilities in its smart contracts towards the end of 2022 as it looked to assure the safety and efficacy of its protocol.
Smart contract security and auditing firm Dedaub announced that it had received a bug bounty after flagging a vulnerability in the Universal Router smart contract that would have allowed reentrancy to drain user funds mid-transaction.
According to Dedaub’s breakdown, the Universal Router allows users to perform diverse actions including swapping multiple tokens and NFTs in one transaction.
The router embeds a scripting language for a wide variety of token actions, which could include transfers to third party recipients. If correctly implemented, transfers would go to the recipient within specified parameters.
However, Dedaub identified a vulnerability in which a third-party code was invoked during the transfer, allowing the code to re-enter the Universal Router and claim any tokens that were temporarily in the contract.
Dedaub then suggested a straight-forward remedy, advising the Uniswap team to add a reentrancy lock to the core execution of the new router. Uniswap awarded the auditing firm a total of $40,000 for flagging the vulnerability. The amount included a 33% bonus for reporting the issue during Uniswap’s bonus period in November 2022.
Uniswap classified the issue as medium severity, while further assessment deemed the vulnerability to have high impact and low likelihood. According to Dedaub, the possibility of a user sending NFTs to an untrusted recipient directly was considered user error.
More complex and less likely scenarios were considered valid for reentrancy, which resulted in Uniswap deeming the vector to have a low likelihood. Cointelegraph has reached out to Uniswap to ascertain further details of its ongoing bounty program, amounts paid out and the number of bugs identified to date.
Bug bounties have become commonplace in the cryptocurrency and blockchain space as platforms and companies look to ensure the security of their software, systems and infrastructure.
Cryptocurrency exchange Coinbase recently clarified the terms of its bug bounty, while blockchain security firm Immunefi has facilitated over $65 million worth of bug bounties between ethical hackers and Web3 firms in 2022.
Information on these pages contains forward-looking statements that involve risks and uncertainties. Markets and instruments profiled on this page are for informational purposes only and should not in any way come across as a recommendation to buy or sell in these assets. You should do your own thorough research before making any investment decisions. FXStreet does not in any way guarantee that this information is free from mistakes, errors, or material misstatements. It also does not guarantee that this information is of a timely nature. Investing in Open Markets involves a great deal of risk, including the loss of all or a portion of your investment, as well as emotional distress. All risks, losses and costs associated with investing, including total loss of principal, are your responsibility. The views and opinions expressed in this article are those of the authors and do not necessarily reflect the official policy or position of FXStreet nor its advertisers.
Recommended Content
Editors’ Picks
SEC Chair Gensler hints at resignation amid lawsuit from 18 states accusing the regulator of unlawful overreach
In a filing on Thursday, 18 states, along with the DeFi Education Fund, issued a lawsuit against the Securities and Exchange Commission, alleging that the regulator's crackdown on the crypto industry has been unlawful and unconstitutional.
Bitcoin Price Forecast: BTC eyes $100K, what are the key factors to watch out for?
Bitcoin trades below $90K in the Asian session on Friday as investors realized nearly $8 billion in profits in the past two days. Despite the profit-taking, Bitwise CIO Matt Hougan suggested that BTC could be ready for the $100K level, fueled by increased stablecoin supply and potential government investment.
Ethereum Price Forecast: ETH could rally to $4,522 despite mixed on-chain flows among investors
Ethereum is down over 1% on Thursday following record net inflows across ETH exchange-traded funds in the past six days. Despite the bullish market outlook, $300 million worth of unstaked ETH could hit the market and cause downward pressure on prices.
Crypto Today: Bhutan sells $33M BTC, McDonald’s launches NFTs, PEPE, SUI emerge top gainers
The aggregate cryptocurrency market capitalization shrank by 1.45% on November 14, reflecting a $42.6 billion dip. In the last 24 hours, 170,878 traders were liquidated to the tune of $485.13 million, per Coinglass data.
Bitcoin: Further upside likely after hitting new all-time high
Bitcoin hit a fresh high of $76,849 on Thursday as crypto-friendly candidate Donald Trump won the US presidential election. Institutional demand returned with the highest single-day inflow on Thursday since the ETFs’ launch in January.
Best Forex Brokers with Low Spreads
VERIFIED Low spreads are crucial for reducing trading costs. Explore top Forex brokers offering competitive spreads and high leverage. Compare options for EUR/USD, GBP/USD, USD/JPY, and Gold.