BitsLab's ScaleBit security team discovered a zero-day vulnerability that could transfer all assets on Uniswap Wallet
Recently, BitsLab's ScaleBit security team discovered a vulnerability in Uniswap Wallet (version iOS), which BitsLab named "mnemonic unauthorized access". The vulnerability allows an attacker with physical access to the device to bypass the wallet's authentication mechanism and directly access the mnemonic stored in the device. This means that anyone with access to the unlocked device can obtain the wallet's mnemonic within 3 minutes. In daily life scenarios, briefly borrowing someone else's mobile phone is not uncommon, especially between couples and friends. But under the influence of this vulnerability, this seemingly harmless borrowing behavior may directly lead to the leakage of wallet mnemonics.