• About
  • Coincu
  • Hot topics
  • Random
Sunday, February 5, 2023
CoinCu News
No Result
View All Result
  • Home
  • News
    • Bitcoin
    • Altcoins
    • Blockchain
  • Market
    • Analysis
  • Knowledge
    • Crypto 101
    • DeFi
  • Reviews
    • Exchange Reviews
    • DeFi Reviews
    • GameFi Reviews
    • Others Reviews
  • Recommended
    • Best Presale Cryptocurrencies
    • Best Bitcoin Casinos
    • Best Bitcoin Gambling Sites
  • Video
  • Live Prices
  • PR
    • Press Releases
    • Sponsored Articles
    • Advertise
  • Home
  • News
    • Bitcoin
    • Altcoins
    • Blockchain
  • Market
    • Analysis
  • Knowledge
    • Crypto 101
    • DeFi
  • Reviews
    • Exchange Reviews
    • DeFi Reviews
    • GameFi Reviews
    • Others Reviews
  • Recommended
    • Best Presale Cryptocurrencies
    • Best Bitcoin Casinos
    • Best Bitcoin Gambling Sites
  • Video
  • Live Prices
  • PR
    • Press Releases
    • Sponsored Articles
    • Advertise
No Result
View All Result
CoinCu News
No Result
View All Result
Home DeFi

Uniswap Detected Bug Doesn’t Refund Unspent ETH In Partial Swaps

January 22, 2023
in DeFi
394
93
SHARES
3.1k
VIEWS
Share on Facebook

Illuvium (ILV) Surges By More Than 30% This Week Amid A Flurry Of New Upgrades

Nearly 70% Of Dogecoin Holders Are Profitable While Most Shiba Inu Holders In Loss

Key Points:

  • A developer found a bug in the Uniswap core contract SwapRouter, and the unspent ETH in the transaction will remain in the SwapRouter contract and will not be refunded.
  • Additionally, SwapRouter allows anyone to withdraw ETH from the contract, and it could be an MEV bot or anyone calling for refunds after the transaction.
  • The developer said the vulnerability was discovered in December last year but was rejected by Uniswap security researchers after submitting a bug report.
A developer found a bug in the Uniswap core contract SwapRouter, and the unspent ETH in the transaction will remain in the SwapRouter contract and will not be refunded.
Uniswap Detected Bug Doesn't Refund Unspent ETH In Partial Swaps

In December 2022, @jeiwan7 found a bug in Uniswap’s SwapRouter contract.

Public Bug Report: Uniswap's SwapRouter doesn't refund unspent ETH in partial swapshttps://t.co/BYR8Ol7uR4

PoC:https://t.co/Ai7Uip93sA

I'll appreciate your thoughts in replies 👇 on whether this is a valid vulnerability or not.

— jeiwan.eth 🦇🔊 (@jeiwan7) January 22, 2023

The developer said the vulnerability was discovered but was rejected by Uniswap security researchers after submitting a bug report.

“You don’t really find critical and high severity bugs in projects like Uniswap, especially after they’ve run in production for several years. So I didn’t really had high expectations and I was sure I wouldn’t be awarded for the report. The bug looks real to me, and I wanted to figure out why would a project with high security standards leave it unfixed.

I submitted a bug report and after more than a month I received their response: they said the bug wasn’t an issue, and everything worked as expected. I cannot agree with this 🙂. Thus I decided to disclose it publicly for some of you to learn something new and for more experienced security researches to decide whether the bug is real or not.”

The bug allows users to lose funds while interacting with the contract in the standard way. Additionally, SwapRouter allows anyone to withdraw ETH from the contract; it could be an MEV bot or anyone calling for refunds after the transaction.

Uniswap Detected Bug Doesn't Refund Unspent ETH In Partial Swaps

The caller cannot know how much ETH will be spent on a swap, according to his blog post, since the Quoter contract, which is used to compute swaps before executing them, only returns the output amount and not the input amount. Even if the input amount computed by the pool had been returned, a slippage check would have been necessary on the input amount since a price change might have caused the calculated input amount to change at the time the transaction was executed.

Previously, Coincu also reported a critical vulnerability in Uniswap, which has been fixed that may have cost consumers millions of dollars. This bug was established due to Uniswap’s decision to introduce the Universal Router, which combines NFTs and ERC-20 tokens into a single swap router.

DISCLAIMER: The Information on this website is provided as general market commentary and does not constitute investment advice. We encourage you to do your own research before investing.

Join us to keep track of news: https://linktr.ee/coincu

Harold

Coincu News

Google Chrome Security Vulnerability Detected Could Lead To Crypto Wallet Stealing

45% Of Ethereum Validators Comply With US Sanctions

Defrost Finance Deploys Refund Contract

Lead XRPL Developer Shares Thoughts On XRP Twitter Tip Bot

Hackers With MEV Bot Make Thousands Of Dollars From Users Of Uniswap

The Core Scientific Inc. Class Action Lawsuit - CORZ

Tags: BugDeFiETHEthereumSwapRouterUniswap
Previous Post

Silvergate Claims Limited Exposure To Genesis

Next Post

El Salvador’s President Criticizes The Biased Reporting By “Legacy” Media Sources

Other Posts

Delphi Labs To Launch Passive Concentrated Liquidity For AMM
DeFi

Delphi Labs To Launch Passive Concentrated Liquidity For AMM

February 4, 2023
Rocket Pool Proposes To Self-Limiting Its Liquid Staking Growth
DeFi

Rocket Pool Proposes To Self-Limiting Its Liquid Staking Growth

February 2, 2023
Decentralized Exchange Dexalot Launches First Hybrid DeFi Subnet On Avalanche
DeFi

Decentralized Exchange Dexalot Launches First Hybrid DeFi Subnet On Avalanche

February 1, 2023
Mars Hub Mainnet Is Now Live With Securing By 50 Permissionless Validators
DeFi

Mars Hub Mainnet Is Now Live With Securing By 50 Permissionless Validators

February 1, 2023
zkSync 2.0-based Protocol. Increment Proposals To Launch INCR Governance Token
DeFi

zkSync 2.0-based Protocol. Increment Proposals To Launch INCR Governance Token

February 1, 2023
Arbitrum-based Vest Exchange Successfully Raised New Funds To Solve Liquidity Difficulties
DeFi

Arbitrum-based Vest Exchange Successfully Raised New Funds To Solve Liquidity Difficulties

January 29, 2023
Next Post
El Salvador’s President Criticizes The Biased Reporting By “Legacy” Media Sources

El Salvador's President Criticizes The Biased Reporting By "Legacy" Media Sources

  • Stronghold Digital Mining Posts Prospectus For Share Sale While It Works To Conserve Money

    Stronghold Digital Mining Posts Prospectus For Share Sale While It Works To Conserve Money

    141 shares
    Share 56 Tweet 35
  • Terra Classic Adopts New Proposal To “Re-Peg USTC With LUNC,” USTC Soars 30%

    120 shares
    Share 48 Tweet 30
  • Nearly 70% Of Dogecoin Holders Are Profitable While Most Shiba Inu Holders In Loss

    97 shares
    Share 39 Tweet 24
  • Solana DeFi Everlend Finance Terminates Its App Due To Lack Of Money

    142 shares
    Share 57 Tweet 36
  • ImmutableX Announcing Watch To Earn (W2E) As Its Whale Holdings IMX Tokens Gains 58%

    99 shares
    Share 40 Tweet 25
Currency.com Review: Top Secure Exchange

Currency.com Review: Top Secure Exchange

February 5, 2023
Illuvium (ILV) Surges By More Than 30% This Week Amid A Flurry Of New Upgrades

Illuvium (ILV) Surges By More Than 30% This Week Amid A Flurry Of New Upgrades

February 4, 2023
Nearly 70% Of Dogecoin Holders Are Profitable While Most Shiba Inu Holders In Loss

Nearly 70% Of Dogecoin Holders Are Profitable While Most Shiba Inu Holders In Loss

February 4, 2023
Gearbox Protocol Establishes The Gearbox Foundation To Promote Development

Gearbox Protocol Establishes The Gearbox Foundation To Promote Development

February 4, 2023
CoinFlex Mints $14 Million FLEX, Token Price Soars Over 90% After GTX News

CoinFlex Mints $14 Million FLEX, Token Price Soars Over 90% After GTX News

February 4, 2023
Aave Records 106 Transactions Worth $100,000 While LRC Network Surge In January

Aave Records 106 Transactions Worth $100,000 While LRC Network Surge In January

February 4, 2023
Delphi Labs To Launch Passive Concentrated Liquidity For AMM

Delphi Labs To Launch Passive Concentrated Liquidity For AMM

February 4, 2023
Andrew Griffith MP To Pass The Financial Services And Markets Bill In 2023

Andrew Griffith MP To Pass The Financial Services And Markets Bill In 2023

February 4, 2023
Many Things Make zkSync 2.0 Welcomed By the Community

Many Things Make zkSync 2.0 Welcomed By the Community

February 4, 2023
Genesis Global Bankruptcy Court Announcing 7 Members Committee To Represent Creditors

Genesis Global Bankruptcy Court Announcing 7 Members Committee To Represent Creditors

February 4, 2023
  • Live Prices
  • Binance
  • NFT
  • Solana
  • Metaverse
  • Polygon
  • Coinbase
  • Trending
  • LuxWorld
  • CryptoLinks

© 2021 COINCU Financial Group Inc. Address: Road Town, Tortola, British Virgin Islands. Email us: [email protected]

No Result
View All Result
  • Coincu
  • News
    • Bitcoin
    • Altcoins
    • Blockchain
    • Metaverse News
    • NFTs News
  • Market
    • Analysis
  • Knowledge
    • Crypto 101
    • DeFi
  • Reviews
    • Exchange Reviews
    • DeFi Reviews
    • GameFi Reviews
    • Others Reviews
  • Recommended
    • Best Presale Cryptocurrencies
    • Best Bitcoin Casinos
    • Best Bitcoin Gambling Sites
  • PR
    • Press Releases
    • Sponsored Articles
    • Advertise
  • Video
  • Live Prices

© 2021 COINCU Financial Group Inc. Address: Road Town, Tortola, British Virgin Islands. Email us: [email protected]

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In