ScaleBit: Discovered a 0-day vulnerability that can transfer all assets from the Uniswap Wallet
ChainCatcher news, the ScaleBit security team under BitsLab stated that in October 2024, the ScaleBit security team under BitsLab discovered a vulnerability in the Uniswap iOS wallet, named "Unauthorized Access to Mnemonic Phrase." This vulnerability allows attackers with physical access to the device to bypass the wallet's authentication mechanism and directly access the mnemonic phrase stored on the device.The root cause of this vulnerability lies in the flawed design of the storage and access mechanism for the mnemonic phrase. The mnemonic phrase is not effectively encrypted at the application layer, and the triggering conditions for the recovery page are unreasonable, allowing attackers with physical access to the device to easily bypass the wallet's authentication mechanism and directly obtain the mnemonic phrase stored in the wallet.Currently, this vulnerability still exists in the latest version of the Uniswap Wallet (Version 1.42), posing potential risks to all users of this wallet. Therefore, users should pay extra attention to the physical security of their devices during use, avoiding the disclosure of unlock passwords or lending their devices to others.