- ScaleBit has discovered a critical vulnerability in Uniswap’s Web3 wallet
- It could potentially allow the compromise of “all stored assets.”
- Vulnerability occurs if attackers have access to a physical device
On Jan. 13 ScaleBit, a subsidiary of security auditing firm BitsLab, made an important announcement about finding a critical vulnerability in Uniswap’s Web3 wallet if atackers have access to physical devices.
Details and Scope of the Uniswap’s Web3 Wallets Threat
To elaborate, the crux of this vulnerability is that if they have physical access to devices, attackers can bypass the wallet’s security authentication mechanism and extract the seed phrase. Once they get it, as Uniswap itself warns with every wallet installation – it becomes at the full disposal of the attacker.
This highlights two aspects, the first of which is the potential risk of completely losing all the assets stored in the wallet, pushing the risks to the max.
The second is that there is no solution yet and even the latest versions are vulnerable, and given Uniswap’s role for DeFi this is another massive threat.
“Anyone with access to an unlocked device can obtain the wallet’s mnemonic phrase in under three minutes. This vulnerability persists even in the latest version of the app.”
Conclusion
It seems that last year’s stats have not yet taken their time, with all those high-profile hacks, but the beginning of January has already contributed to the 2025 stats.
We will be watching very closely how Uniswap responds to the threat, and hopefully, that response won’t be long in coming.
Be aware and stay tuned.
The information provided in this article is for informational and educational purposes only and does not constitute financial, investment, or trading advice. Any actions you take based on the information provided are solely at your own risk. We are not responsible for any financial losses, damages, or consequences resulting from your use of this content. Always conduct your own research and consult a qualified financial advisor before making any investment decisions. Read more