Loading player…

Double entry point issues - From breaking Compound to Uniswap v4 by Jota Carpanelli | Devcon SEA

DevconYouTube

Thu, Oct 2, 2025, 12:00 AM

A short explanation of a critical-severity vulnerability we found in the Uniswap V4 core contracts that would have caused a ~$15M loss in Uniswap's pools. The goal is to explain the risks of double entry points, from the $30M+ TUSD issue in Compound to the Uniswap V4-specific case where protocols use native tokens and operate on chains where the native token has a corresponding ERC-20 token, and how to prevent them. Speaker(s): Jota Carpanelli Skill level: Intermediate Track: Security Keywords: Security, Bug, Bounties, contest, Architecture, Auditing Follow us: https://twitter.com/efdevcon, https://twitter.com/ethereum, https://warpcast.com/devcon Learn more about devcon: https://www.devcon.org/ Learn more about ethereum: https://ethereum.org/ Visit the https://archive.devcon.org/ to gain access to the entire library of Devcon talks with the ease of filtering, playlists, personalized suggestions, decentralized access on Swarm, IPFS and more. Devcon is the Ethereum conference for developers, researchers, thinkers, and makers. Devcon SEA was held in Bangkok, Thailand on Nov 12 - Nov 15, 2024. Devcon is organized and presented by the Ethereum Foundation. To find out more, please visit https://ethereum.foundation/

Speakers

Formerly a Smart Contract Auditor, I'm the Head of Security Services at OpenZeppelin. I started working in crypto 6 years ago as a Smart Contract Developer, building OpenZeppelin contracts and development tools. I transitioned into a Security Researcher and have led over 60 audits, discovered more than 30 critical-severity issues, and helped protect over $1 billion in funds, including live protocols.