Troubling Vulnerability in UniSwap Wallets
ScaleBit, a subsidiary of security firm BitsLab, has identified a potential vulnerability in Uniswap's Web3 wallets that could put all stored assets at risk.
In a statement, ScaleBit warned that attackers with physical access to a device could bypass authentication measures and directly extract the wallet's mnemonic phrase.
Also known as a seed phrase, this 12–24 word sequence grants full control over a wallet’s assets, making its exposure a critical security concern.
ScaleBit said:
“[A]nyone with access to an unlocked device can obtain the wallet's mnemonic phrase in under three minutes."
Adding that:
“…this version persists even in the latest version of the app.”
ScaleBit said Uniswap Wallet users should avoid lending devices to others as a precautionary measure until the vulnerability is patched.
Losses Due to Exploits: What's at Stake for DeFi?
In 2024, cybersecurity breaches in cryptocurrency led to a 40% increase in losses, reaching approximately $2.3 billion, according to Cyvers.
Deddy Lavid, Cyvers' co-founder and CEO, attributed the rise to a surge in access control breaches, particularly within centralised exchanges (CEXs) and crypto custodians.
However, the trend showed signs of slowing towards the end of the year.
December witnessed a significant drop in stolen funds, with $28.6 million in reported losses, compared to $63.8 million in November and $115.8 million in October, according to CertiK.
Similarly, PeckShield reported a 71% decrease in hack-related losses in December, amounting to $24.7 million.