{
  "id": 12237359,
  "title": "Security Audit Report: Reentrancy & Access Control Review: Uniswap V3",
  "url": "https://urgent.news/2026/10/05/security-audit-report-reentrancy-access-control-review-uniswap-v3",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-05T21:56:12.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/dannydoes_2abdf9c/security-audit-report-reentrancy-access-control-review-uniswap-v3-45c5"
  },
  "original_language": "en",
  "account": "Security Audit Report: Uniswap V3\n\nUniswap V3, a prominent automated market maker (AMM) built on Ethereum, specializes in concentrated liquidity, tiered fees, and advanced features like flash swaps and NFT-based position management. The protocol's architecture ensures that user-controlled logic (swap, mint, burn) is separated from privileged administrative functions, employing the checks-effects-interactions pattern with reentrancy guards to mitigate security risks. Our audit focused on reentrancy-related state mutations and access control vulnerabilities within the core smart contract suite, which includes the router, periphery components, pool management, factory functions, and related libraries.\n\nKey Findings:\n1. The UniswapV3Pool.swap function is susceptible to reentrancy via a malicious token callback, allowing attackers to manipulate the pool's state and potentially front-run users.\n2. The NonfungiblePositionManager.mint and increaseLiquidity functions can be exploited by malicious ERC-721 token receivers, leading to double-counting of liquidity and inflated position sizes.\n3. The UniswapV3Factory.createPool function lacks a timelock mechanism for transferring ownership, posing a risk of unauthorized pool creation if the owner's private key is compromised.\n4. The SwapRouter.exactInputSingle function can be manipulated through token callbacks, allowing attackers to overwrite internal accounting and underpay fees.\n5. TickBitmap updates in UniswapV3Pool may suffer from reentrancy state races, resulting in off-by-one tick shifts and skewed price calculations.\n6. The UniswapV3Pool.initialize function, while limited to a single call, lacks an explicit onlyOwner guard, potentially allowing malicious constructors to manipulate pool pricing.\n7. The Multicall peripheral component aggregates a batch of calls, which could be exploited by attackers to bypass per-call reentrancy guards and bypass internal security measures.\n\nNo critical vulnerabilities with a severity score of 9 or higher were discovered that could potentially drain the entire protocol value (TVL of approximately $1.71 billion). However, the identified issues pose significant financial risks, including the potential for users to steal fees, manipulate price ticks, and create unauthorized pools. While the audit did not uncover any critical vulnerabilities, these findings underscore the importance of addressing these vulnerabilities to maintain the integrity and security of the Uniswap V3 ecosystem.",
  "summary": "Security Audit Report: Reentrancy & Access Control Review: Uniswap V3 Target Protocol : Uniswap V3 (TVL: $1707.6M) Security Audit Report – Reentrancy & Access‑Control Review Protocol: Uniswap V3 (TVL: ≈ $1.71 B across Ethereum & L2s) Audit Scope: Core smart‑contract suite (router, periphery, pool, factory, and related libraries) – focus on reentrancy‑related state‑mutations and…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}