Security Audit Report: Reentrancy & Access Control Review: Uniswap V3
Security Audit Report: Reentrancy & Access Control Review: Uniswap V3 Target Protocol : Uniswap V3 (TVL: $1707.6M) Security Audit Report – Reentrancy & Access‑Control Review Protocol: Uniswap V3 (TVL: ≈ $1.71 B across Ethereum & L2s) Audit Scope: Core smart‑contract suite (router, periphery, pool, factory, and related libraries) – focus on reentrancy‑related state‑mutations and…
Security Audit Report: Uniswap V3
Uniswap V3, a prominent automated market maker (AMM) built on Ethereum, specializes in concentrated liquidity, tiered fees, and advanced features like flash swaps and NFT-based position management. The protocol's architecture ensures that user-controlled logic (swap, mint, burn) is separated from privileged administrative functions, employing the checks-effects-interactions pattern with reentrancy guards to mitigate security risks.
Our audit focused on reentrancy-related state mutations and access control vulnerabilities within the core smart contract suite, which includes the router, periphery components, pool management, factory functions, and related libraries.
Key Findings:
1. The UniswapV3Pool.swap function is susceptible to reentrancy via a malicious token callback, allowing attackers to manipulate the pool's state and potentially front-run users.
2. The NonfungiblePositionManager.mint and increaseLiquidity functions can be exploited by malicious ERC-721 token receivers, leading to double-counting of liquidity and inflated position sizes.
3. The UniswapV3Factory.createPool function lacks a timelock mechanism for transferring ownership, posing a risk of unauthorized pool creation if the owner's private key is compromised.
4. The SwapRouter.exactInputSingle function can be manipulated through token callbacks, allowing attackers to overwrite internal accounting and underpay fees.
5. TickBitmap updates in UniswapV3Pool may suffer from reentrancy state races, resulting in off-by-one tick shifts and skewed price calculations.
6. The UniswapV3Pool.initialize function, while limited to a single call, lacks an explicit onlyOwner guard, potentially allowing malicious constructors to manipulate pool pricing.
7. The Multicall peripheral component aggregates a batch of calls, which could be exploited by attackers to bypass per-call reentrancy guards and bypass internal security measures.
No critical vulnerabilities with a severity score of 9 or higher were discovered that could potentially drain the entire protocol value (TVL of approximately $1.71 billion). However, the identified issues pose significant financial risks, including the potential for users to steal fees, manipulate price ticks, and create unauthorized pools.
While the audit did not uncover any critical vulnerabilities, these findings underscore the importance of addressing these vulnerabilities to maintain the integrity and security of the Uniswap V3 ecosystem.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.