DeFi

Uniswap Detected Bug Doesn’t Refund Unspent ETH In Partial Swaps

Key Points:

  • A developer found a bug in the Uniswap core contract SwapRouter, and the unspent ETH in the transaction will remain in the SwapRouter contract and will not be refunded.
  • Additionally, SwapRouter allows anyone to withdraw ETH from the contract, and it could be an MEV bot or anyone calling for refunds after the transaction.
  • The developer said the vulnerability was discovered in December last year but was rejected by Uniswap security researchers after submitting a bug report.
A developer found a bug in the Uniswap core contract SwapRouter, and the unspent ETH in the transaction will remain in the SwapRouter contract and will not be refunded.

In December 2022, @jeiwan7 found a bug in Uniswap’s SwapRouter contract.

The developer said the vulnerability was discovered but was rejected by Uniswap security researchers after submitting a bug report.

“You don’t really find critical and high severity bugs in projects like Uniswap, especially after they’ve run in production for several years. So I didn’t really had high expectations and I was sure I wouldn’t be awarded for the report. The bug looks real to me, and I wanted to figure out why would a project with high security standards leave it unfixed.

I submitted a bug report and after more than a month I received their response: they said the bug wasn’t an issue, and everything worked as expected. I cannot agree with this ????. Thus I decided to disclose it publicly for some of you to learn something new and for more experienced security researches to decide whether the bug is real or not.”

The bug allows users to lose funds while interacting with the contract in the standard way. Additionally, SwapRouter allows anyone to withdraw ETH from the contract; it could be an MEV bot or anyone calling for refunds after the transaction.

The caller cannot know how much ETH will be spent on a swap, according to his blog post, since the Quoter contract, which is used to compute swaps before executing them, only returns the output amount and not the input amount. Even if the input amount computed by the pool had been returned, a slippage check would have been necessary on the input amount since a price change might have caused the calculated input amount to change at the time the transaction was executed.

Previously, Coincu also reported a critical vulnerability in Uniswap, which has been fixed that may have cost consumers millions of dollars. This bug was established due to Uniswap’s decision to introduce the Universal Router, which combines NFTs and ERC-20 tokens into a single swap router.

DISCLAIMER: The Information on this website is provided as general market commentary and does not constitute investment advice. We encourage you to do your own research before investing.

Join us to keep track of news: https://linktr.ee/coincu

Harold

Coincu News

Harold

With a passion for untangling the complexities of the financial world, I've spent over four years in financial journalism, covering everything from traditional equities to the cutting edge of venture capital. "The financial markets are a fascinating puzzle," I often say, "and I love helping people make sense of them." That's what drives me to bring clear and insightful financial journalism to the readers of Coincu.

Recent Posts

Solana memecoins crash while DTX Exchange hits 100,000 TPS on layer-1 blockchain

Discover how DTX Exchange's historic achievement of 100,000 transactions per second on a layer-1 blockchain…

14 minutes ago

Strategic Bitcoin Reserve Expected to Cut 35% of US National Debt by 2049

VanEck suggests the U.S. could reduce its national debt by 35% by 2050 through a…

20 minutes ago

The New Lead of Presidential Crypto Council Appointed by Trump Is Bo Hines

President-elect Donald Trump named Bo Hines as the executive director of the presidential crypto council.

45 minutes ago

Best New Meme Coins with 1000X Potential: BTFD Coin’s Hot BIG50 Discount As Baby Doge Coin, Dogs Takes Gaming to the Next Level

Explore the best new meme coins with 1000X potential. Learn how BTFD Coin leads with…

2 hours ago

BlockDAG Surges Past $170M as BDAG250 Bonus End Countdown Begins – Aave Targets $400 & Solana Shines with Scalability

BlockDAG crosses $170.5M in presale success with BDAG250 bonus and Whitepaper V3 launch! Solana grows…

3 hours ago

Qubetics Presale Price Surge Approaches: The Best Coins to Invest in Right Now While Toncoin, and XRP Gain Traction

Discover why Qubetics, Toncoin, and XRP are the best coins to invest in right now.…

4 hours ago

This website uses cookies.