Blog-new-logo-2023Blog-new-logo-2023Blog-new-logo-2023Blog-new-logo-2023
  • CRYPTO NEWS
  • TOPICS
    • Futures Trading
    • Crypto Basics
    • DeFi
    • Metaverse
    • NFT
    • Blockchain
  • CRYPTO VERSE
    • Personal Finance
    • Cryptocurrency
    • Price Predictions
    • Crypto Deep Dives
  • PRODUCT
    • Tutorials
    • Product Features
    • Security
  • COINDCX
    • Announcements
    • Community
    • Crypto Competition
    • Listings
    • Opinion
    • Stories
Visit CoinDCX
✕
            No results See all results

            Uniswap Bug Bounty Program paid $40,000 to a DeFi Auditor for pointing out Vulnerability

            Uniswap launched bug bounty program has been very quick to lead them to the discovery of a now-fixed vulnerability of the protocol’s new Universal Router smart contract.

            5 Jan 2023 | 3 min read
            The Uniswap Bug Bounty Program Paid $40,000 To a DeFi Auditor For Pointing Out Vulnerability

            The various crypto projects that are available often have developmental work going on to adapt to the ever evolving space of crypto. In order to do the same, many a times organization introduces or hosts bug bounty programs. One of the newer players in this has been Uniswap. Their recently launched bug bounty program has been very quick to lead them to the discovery of a now-fixed vulnerability of the protocol’s new Universal Router smart contract.

            Back in November, Uniswap protocol, the automated market maker introduced two new smart contracts, Permit2; which allows token approvals to be shared and managed across different applications and as a result helps in creating a more unified, cost-efficient, and safer UX. Another one is the Universal Router. This smart contract unifies ERC20 and NFT swapping into a single swap router. Universal Router when integrated with Permit2, creates the possibility for the users to swap multiple tokens and NFTs in one single swap; thus helping in saving on gas fees.

            As a mean to make sure that the protocol is safe and has a smoother user interface, the Uniswap protocol also advertised a lucrative bug bounty program to identify potential vulnerabilities in its smart contracts around the end of 2022. This was also a step towards ensuring the safety and efficacy of the protocol.

            The Dedaub team has disclosed a Critical vulnerability to the Uniswap team!

            Funds are safe – Uniswap addressed the issue and redeployed the Universal Router smart contracts on all its chains 👏

            The vulnerability allows re-entertrancy to drain the user’s funds, mid-tx.

            🧵 pic.twitter.com/wFSFsohPvy

            — Dedaub (@dedaub) January 2, 2023

            Soon after the launching of the bug bounty; Dedaub, a smart contract security, and auditing firm disclosed that it had received a bug bounty after pointing out a vulnerability in the Universal Router smart contract of Uniswap. This bug could have affected the smart contract in a way that would have allowed reentrancy to drain user funds mid-transaction. The bug that Dedaub identified was a vulnerability through which a third-party code was seen during the transfer. This allowed the code to re-enter the Universal Router along with claiming any tokens that were temporarily in the contract.

            As a solution to the problem, Dedaub suggested a straightforward antidote. They advised adding a reentrancy lock to the core execution of the new router to the Uniswap team. As a result of finding out the problem and the solution that they suggested, Uniswap awarded the auditing firm a total of $40,000. The reward amount also included a whopping 33% bonus for reporting the issue during Uniswap’s bonus period in November 2022.

            According to Dedaub, the possibility of a user sending NFTs to an untrusted recipient directly was considered a user error.

            Source: Cointelegraph

            Additional Read: Why did Solana Price fall by over 65% in the Last 30 Days?

            Share
            CoinDCX
            CoinDCX

            Related posts

            Bitcoin Price Hits New All-Time High Following Fed’s 25-Basis-Point Rate Cut

            Fed’s interest rate cut spurs crypto momentum, boosting Bitcoin and Ethereum prices.


            Read more
            8 Nov 2024
              | 4 min read

            Blum Secures Major Investment from TOP to Strengthen DeFi Presence in TON Ecosystem

            TOP’s backing aims to accelerate Blum’s multi-blockchain expansion.


            Read more
            7 Nov 2024
              | 5 min read
            Logo_CoinDCX
            Company
            • About Us
            • Blog
            • Careers
            • Fees
            • Media Kit
            • Proof of Reserves
            • Partners
            • Bug Bounty
            • Community
            • Policy
            Product
            • Spot Trading
            • Margin Trading
            • Convert
            • Futures Trading
            • Earn
            • VIP
            Support
            • 24/7 Chat Support
            • Support Center
            • Terms of Use
            • Privacy Policy
            • Risk Disclosures
            • Security
            • Terms of Use: Web3 Wallet
            Business
            • OTC
            • API Broker
            • Enterprise
            • New Coin Listing
            • Ventures
            • Affiliate
            Crypto Prices
            • Bitcoin Price
            • Ethereum Price
            • Ripple XRP Price
            • Dogecoin Price
            • Solana Price
            • Litecoin Price
            • All Crypto Prices
            Contact Us

            For grievance redressal write to Grievance Officer - Mr. M Jain (grievance@coindcx.com)
            Regulatory Authority write to legal@coindcx.com
            Press Enquiries write to media.queries@coindcx.com

            Disclaimer

            Crypto products & NFTs are unregulated and can be highly risky. There may be no regulatory recourse for any loss from such transactions. The information and material contained herein are subject to change without prior notice including prices which may fluctuate based on market demand and supply. The material available on the site is proprietary to CoinDCX, its parent, Licensor and/or its affiliates and is for informational purposes and informed investors only. This material is not: (i) an offer, or solicitation of an offer, to invest in, or to buy or sell, any interests or shares, or to participate in any investment or trading strategy, or (ii) intended to provide accounting, legal, or tax advice, or investment recommendations.

            *Data sourced from Looker app as on 01st May,2023
            *Data as on 01st May,2023
            *Quarterly trading volume for Q2 FY'23. Currency conversion rate applied as in data capturing period
            *FIU Registered entity, NEBLIO TECHNOLOGIES PVT LTD
            *Certified in India for May 2023-24

            © 2024 All rights reserved

            Visit CoinDCX
                      No results See all results
                        Download App