|

DeFi auditor nets $40,000 for identifying Uniswap vulnerability

Uniswap’s recently launched bug bounty program has led to the discovery of a now-fixed vulnerability of the protocol’s Universal Router smart contract.

The automated market maker released two new smart contracts to its platform in November 2022. Permit2 allows token approvals to be shared and managed across different applications, while Universal Router unifies ERC-20 and nonfungible tokens (NFTs) swapping into a single swap router.

Uniswap also advertised a lucrative bug bounty program to identify potential vulnerabilities in its smart contracts towards the end of 2022 as it looked to assure the safety and efficacy of its protocol.

Smart contract security and auditing firm Dedaub announced that it had received a bug bounty after flagging a vulnerability in the Universal Router smart contract that would have allowed reentrancy to drain user funds mid-transaction.

According to Dedaub’s breakdown, the Universal Router allows users to perform diverse actions including swapping multiple tokens and NFTs in one transaction.

The router embeds a scripting language for a wide variety of token actions, which could include transfers to third party recipients. If correctly implemented, transfers would go to the recipient within specified parameters.

However, Dedaub identified a vulnerability in which a third-party code was invoked during the transfer, allowing the code to re-enter the Universal Router and claim any tokens that were temporarily in the contract.

Dedaub then suggested a straight-forward remedy, advising the Uniswap team to add a reentrancy lock to the core execution of the new router. Uniswap awarded the auditing firm a total of $40,000 for flagging the vulnerability. The amount included a 33% bonus for reporting the issue during Uniswap’s bonus period in November 2022.

Uniswap classified the issue as medium severity, while further assessment deemed the vulnerability to have high impact and low likelihood. According to Dedaub, the possibility of a user sending NFTs to an untrusted recipient directly was considered user error.

More complex and less likely scenarios were considered valid for reentrancy, which resulted in Uniswap deeming the vector to have a low likelihood. Cointelegraph has reached out to Uniswap to ascertain further details of its ongoing bounty program, amounts paid out and the number of bugs identified to date.

Bug bounties have become commonplace in the cryptocurrency and blockchain space as platforms and companies look to ensure the security of their software, systems and infrastructure. 

Cryptocurrency exchange Coinbase recently clarified the terms of its bug bounty, while blockchain security firm Immunefi has facilitated over $65 million worth of bug bounties between ethical hackers and Web3 firms in 2022.

Author

Cointelegraph Team

Cointelegraph Team

Cointelegraph

We are privileged enough to work with the best and brightest in Bitcoin.

More from Cointelegraph Team
Share:

Editor's Picks

Ripple Price Forecast: XRP potential bottom could be in sight

Ripple edges up above the intraday low of $1.35 at the time of writing on Friday amid mixed price actions across the crypto market. The remittance token failed to hold support at $1.40 the previous day, reflecting risk-off sentiment amid a decline in retail and institutional sentiment. 

Crypto Today: Bitcoin, Ethereum, XRP in choppy price action, weighed down by falling institutional interest 

Bitcoin holds above support at $65,118 at the time of writing on Friday. Ethereum remains choppy in a narrow range between support at $1,900 and resistance at $2,000, while Ripple attempts another upward move toward the pivotal $1.40 level.

PancakeSwap Price Analysis: Bearish momentum suggests further downside

PancakeSwap (CAKE) is trading below $1.26 at the time of writing on Friday, extending the losses by over 8% so far this week. The weakening derivatives market further supports the bearish outlook, with bears aiming for levels below $1.18.

Decred Price Forecast: DCR rebounds toward key resistance zone on volume spike

Decred (DCR) rebounds over 7% at press time on Friday after a three-day decline of almost 14%. Roughly 60% increase in trading volume over the last 24 hours supports the recovery, suggesting heightened spot-market demand. 

Bitcoin Price Annual Forecast: BTC holds long-term bullish structure heading into 2026

Bitcoin (BTC) is wrapping up 2025 as one of its most eventful years, defined by unprecedented institutional participation, major regulatory developments, and extreme price volatility.

Bitcoin: BTC bears aren’t done yet

Bitcoin (BTC) price slips below $67,000 at the time of writing on Friday, remaining under pressure and extending losses of nearly 5% so far this week.