header-langage
简体中文
繁體中文
English
Tiếng Việt
한국어
日本語
ภาษาไทย
Türkçe
Scan to Download the APP

Security company Dedaub received a $40,000 bug bounty for disclosing the Uniswap re-entry bug

BlockBeats, January 3, the Dedaub team, a security company, announced that it has received a security bug bounty from Uniswap Labs for disclosing a serious vulnerability in Uniswap that has the potential to re-enter and drain users' funds. However, the Uniswap team has addressed the vulnerability and redeployed the Universal Router smart contract across all chains, and the funding is safe. Uniswap released the Universal Router smart contract in November 2022, which unified ERC20 and NFT conversions into a single switching router, allowing users to perform heterogeneous operations, for example, exchanging multiple tokens and NFT in a single transaction. Dedaub says, "The router has embedded scripting languages for various Token operations, and such commands may include transfers to third-party (possibly untrusted) recipients. If third-party code is called at any time during the transfer, that code can re-enter the UniversalRouter and temporarily claim any tokens in the contract. Dedaub recommends that Uniswap add a reentrant lock to the core execution of the new router and redeploy."
举报 Correction/Report
Correction/Report
Submit
Add Library
Visible to myself only
Public
Save
Choose Library
Add Library
Cancel
Finish