DeFi

DeFi auditor nets $40,000 for identifying Uniswap vulnerability

Uniswap’s lately launched bug bounty program has led to the invention of a now-fixed vulnerability of the protocol’s Common Router sensible contract.

The automated market maker released two new sensible contracts to its platform in November 2022. Permit2 permits token approvals to be shared and managed throughout totally different functions, whereas Common Router unifies ERC-20 and nonfungible tokens (NFTs) swapping right into a single swap router.

Uniswap additionally marketed a profitable bug bounty program to determine potential vulnerabilities in its sensible contracts in direction of the tip of 2022 because it regarded to guarantee the security and efficacy of its protocol.

Good contract safety and auditing agency Dedaub introduced that it had acquired a bug bounty after flagging a vulnerability within the Common Router sensible contract that might have allowed reentrancy to empty consumer funds mid-transaction.

In line with Dedaub’s breakdown, the Common Router permits customers to carry out various actions together with swapping a number of tokens and NFTs in a single transaction.

The router embeds a scripting language for all kinds of token actions, which may embrace transfers to 3rd occasion recipients. If accurately carried out, transfers would go to the recipient inside specified parameters.

Associated: Immunefi says it has facilitated $66M in bug bounties since inception 

Nevertheless, Dedaub recognized a vulnerability through which a third-party code was invoked in the course of the switch, permitting the code to re-enter the Common Router and declare any tokens that had been quickly within the contract.

Dedaub then advised a straight-forward treatment, advising the Uniswap group so as to add a reentrancy lock to the core execution of the brand new router. Uniswap awarded the auditing agency a complete of $40,000 for flagging the vulnerability. The quantity included a 33% bonus for reporting the difficulty throughout Uniswap’s bonus interval in November 2022.

Uniswap labeled the difficulty as medium severity, whereas additional evaluation deemed the vulnerability to have excessive impression and low probability. In line with Dedaub, the potential of a consumer sending NFTs to an untrusted recipient straight was thought-about consumer error.

Extra complicated and fewer probably situations had been thought-about legitimate for reentrancy, which resulted in Uniswap deeming the vector to have a low probability. Cointelegraph has reached out to Uniswap to establish additional particulars of its ongoing bounty program, quantities paid out and the variety of bugs recognized so far.

Bug bounties have develop into commonplace within the cryptocurrency and blockchain area as platforms and firms look to make sure the safety of their software program, methods and infrastructure. 

Cryptocurrency trade Coinbase lately clarified the phrases of its bug bounty, whereas blockchain safety agency Immunefi has facilitated over $65 million price of bug bounties between moral hackers and Web3 companies in 2022.

Subscribe to our mailing list to receive new updates and special offers

We don’t spam! Read our [link]privacy policy[/link] for more info.

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button
You have not selected any currencies to display