Gait recognition has emerged as a promising biometric for long-distance, low-resolution, and non-cooperative scenarios. Recent deep models achieve impressive accuracy from silhouette sequences, yet their robustness and security remain far from fully understood. In this paper, we study a particularly challenging and practically relevant threat: query-free black-box universal adversarial attacks against silhouette-based gait recognition. We adopt a strict query-free black-box setting, where the attacker has no access to the target model and cannot query the deployed system for any feedback. The goal is to learn a universal perturbation that is shared across subjects, walking conditions, and sequences, and that transfers to unknown models and datasets while remaining visually imperceptible on silhouettes. To this end, we propose GaitUAA, a universal attack framework that learns a single-frame perturbation template on surrogate models and then broadcasts it to entire silhouette sequences. Our design combines a retrieval-oriented attack objective with an edge-aware parameterization: the perturbation magnitude is constrained by an upper bound, and an edge threshold restricts perturbations to silhouette boundaries. Extensive experiments on multiple benchmarks and architectures show that GaitUAA consistently causes substantial performance degradation under cross-dataset, cross-model, and cross-dataset-and-model protocols, driving the rank-1 accuracy of several state-of-the-art models (e.g., DeepGaitV2-2D/3D/P3D, SwinGait) down to single-digit levels in the most challenging settings. These results underscore the urgent need for architecture-aware defenses and robustness-oriented design in future gait recognition systems.