BitsLab’s ScaleBit flags ‘alarming’ Uniswap Wallet vulnerability
Attackers with physical access to a user’s device may be able to see the wallet’s seed phrase, the security firm said.
ScaleBit, a subsidiary of security auditor BitsLab, has flagged a purported vulnerability that could potentially compromise “all stored assets” in decentralized exchange (DEX) Uniswap’s Web3 wallets, ScaleBit told Cointelegraph on Jan. 13.
The alleged “flaw enables attackers with physical access to the device to bypass the wallet’s authentication mechanisms and directly retrieve the mnemonic phrase stored on the device,” ScaleBit said in a statement.
A Web3 wallet’s mnemonic phrase, also known as a “seed phrase,” is a string of typically 12–24 random words that grants full control over a wallet’s assets from any device.
Go to Source
Author: Alex O’Donnell