019b3836-31af-72b7-bf61-1895287ad74d
Open this run to answer one question: is this real attacker-relevant behavior with real impact, or just normal contract plumbing?
| ID | Type | Status | Attempts | Heartbeat |
|---|---|---|---|---|
| 2827 | artifact.fetch | complete | 1 / 3 | 3 months ago |
| 2828 | tool.cast_disasm | complete | 1 / 3 | 3 months ago |
| 45820 | analysis.bundle | complete | 1 / 3 | 2 weeks ago |
| 45821 | capability.graph | complete | 1 / 3 | 2 weeks ago |
| 45822 | detector.run | complete | 1 / 3 | 2 weeks ago |
| 45823 | validation.fork | complete | 1 / 3 | 2 weeks ago |
No slither job recorded yet.
No codex job recorded yet.
00000000: PUSH1 0x60 00000002: PUSH1 0x40 00000004: MSTORE 00000005: CALLDATASIZE 00000006: ISZERO 00000007: PUSH2 0x006c 0000000a: JUMPI 0000000b: PUSH1 0xe0 0000000d: PUSH1 0x02 0000000f: EXP 00000010: PUSH1 0x00 00000012: CALLDATALOAD 00000013: DIV 00000014: PUSH4 0x13af4035 00000019: DUP2 0000001a: EQ 0000001b: PUSH2 0x0077 0000001e: JUMPI 0000001f: DUP1 00000020: PUSH4 0x35c1d349 00000025: EQ 00000026: PUSH2 0x00ac 00000029: JUMPI 0000002a: DUP1 0000002b: PUSH4 0x8da5cb5b 00000030: EQ 00000031: PUSH2 0x011f 00000034: JUMPI 00000035: DUP1 00000036: PUSH4 0x9003adfe 0000003b: EQ 0000003c: PUSH2 0x0131 0000003f: JUMPI 00000040: DUP1 00000041: PUSH4 0xa60f3588 00000046: EQ 00000047: PUSH2 0x013a 0000004a: JUMPI 0000004b: DUP1 0000004c: PUSH4 0xb69ef8a8 00000051: EQ 00000052: PUSH2 0x0143 00000055: JUMPI 00000056: DUP1 00000057: PUSH4 0xc8796572 0000005c: EQ 0000005d: PUSH2 0x014c 00000060: JUMPI 00000061: DUP1 00000062: PUSH4 0xe97dcb62 00000067: EQ 00000068: PUSH2 0x0176 0000006b: JUMPI 0000006c: JUMPDEST 0000006d: PUSH2 0x01b5 00000070: PUSH2 0x0174 00000073: PUSH2 0x017a 00000076: JUMP 00000077: JUMPDEST 00000078: PUSH2 0x01b5 0000007b: PUSH1 0x04 0000007d: CALLDATALOAD 0000007e: PUSH1 0x04 00000080: SLOAD 00000081: PUSH1 0x01 00000083: PUSH1 0xa0 00000085: PUSH1 0x02 00000087: EXP 00000088: SUB 00000089: SWAP1 0000008a: DUP2 0000008b: AND 0000008c: CALLER 0000008d: SWAP2 0000008e: SWAP1 0000008f: SWAP2 00000090: AND 00000091: EQ 00000092: ISZERO 00000093: PUSH2 0x00a9 00000096: JUMPI 00000097: PUSH1 0x04 00000099: DUP1 0000009a: SLOAD 0000009b: PUSH1 0x01 0000009d: PUSH1 0xa0 0000009f: PUSH1 0x02 000000a1: EXP 000000a2: SUB 000000a3: NOT 000000a4: AND 000000a5: DUP3 000000a6: OR 000000a7: SWAP1 000000a8: SSTORE 000000a9: JUMPDEST 000000aa: POP 000000ab: JUMP 000000ac: JUMPDEST 000000ad: PUSH2 0x01b7 000000b0: PUSH1 0x04 000000b2: CALLDATALOAD 000000b3: PUSH1 0x00 000000b5: DUP1 000000b6: SLOAD 000000b7: DUP3 000000b8: SWAP1 000000b9: DUP2 000000ba: LT 000000bb: ISZERO 000000bc: PUSH2 0x0002 000000bf: JUMPI 000000c0: POP 000000c1: DUP1 000000c2: MSTORE 000000c3: PUSH1 0x02 000000c5: MUL 000000c6: PUSH32 0x290decd9548b62a8d60345a988386fc84ba6bc95484008f6362f93160ef3e563 000000e7: DUP2 000000e8: ADD 000000e9: SLOAD 000000ea: PUSH32 0x290decd9548b62a8d60345a988386fc84ba6bc95484008f6362f93160ef3e564 0000010b: SWAP2 0000010c: SWAP1 0000010d: SWAP2 0000010e: ADD 0000010f: SLOAD 00000110: PUSH1 0x01 00000112: PUSH1 0xa0 00000114: PUSH1 0x02 00000116: EXP 00000117: SUB 00000118: SWAP2 00000119: SWAP1 0000011a: SWAP2 0000011b: AND 0000011c: SWAP1 0000011d: DUP3 0000011e: JUMP 0000011f: JUMPDEST 00000120: PUSH2 0x01dd 00000123: PUSH1 0x04 00000125: SLOAD 00000126: PUSH1 0x01 00000128: PUSH1 0xa0 0000012a: PUSH1 0x02 0000012c: EXP 0000012d: SUB 0000012e: AND 0000012f: DUP2 00000130: JUMP 00000131: JUMPDEST 00000132: PUSH2 0x01fa 00000135: PUSH1 0x02 00000137: SLOAD 00000138: DUP2 00000139: JUMP 0000013a: JUMPDEST 0000013b: PUSH2 0x01fa 0000013e: PUSH1 0x01 00000140: SLOAD 00000141: DUP2 00000142: JUMP 00000143: JUMPDEST 00000144: PUSH2 0x01fa 00000147: PUSH1 0x03 00000149: SLOAD 0000014a: DUP2 0000014b: JUMP 0000014c: JUMPDEST 0000014d: PUSH2 0x01b5 00000150: PUSH1 0x04 00000152: SLOAD 00000153: PUSH1 0x01 00000155: PUSH1 0xa0 00000157: PUSH1 0x02 00000159: EXP 0000015a: SUB 0000015b: SWAP1 0000015c: DUP2 0000015d: AND 0000015e: CALLER 0000015f: SWAP2 00000160: SWAP1 00000161: SWAP2 00000162: AND 00000163: EQ 00000164: ISZERO 00000165: PUSH2 0x0174 00000168: JUMPI 00000169: PUSH1 0x02 0000016b: SLOAD 0000016c: PUSH1 0x00 0000016e: EQ 0000016f: ISZERO 00000170: PUSH2 0x020c 00000173: JUMPI 00000174: JUMPDEST 00000175: JUMP 00000176: JUMPDEST 00000177: PUSH2 0x01b5 0000017a: JUMPDEST 0000017b: PUSH1 0x00 0000017d: PUSH1 0x00 0000017f: PUSH1 0x00 00000181: PUSH8 0x016345785d8a0000 0000018a: CALLVALUE 0000018b: LT 0000018c: ISZERO 0000018d: PUSH2 0x0237 00000190: JUMPI 00000191: PUSH1 0x40 00000193: MLOAD 00000194: PUSH1 0x01 00000196: PUSH1 0xa0 00000198: PUSH1 0x02 0000019a: EXP 0000019b: SUB 0000019c: CALLER 0000019d: AND 0000019e: SWAP1 0000019f: DUP3 000001a0: SWAP1 000001a1: CALLVALUE 000001a2: SWAP1 000001a3: DUP3 000001a4: DUP2 000001a5: DUP2 000001a6: DUP2 000001a7: DUP6 000001a8: DUP9 000001a9: DUP4 000001aa: CALL 000001ab: POP 000001ac: POP 000001ad: POP 000001ae: POP 000001af: POP 000001b0: JUMPDEST 000001b1: POP 000001b2: POP 000001b3: POP 000001b4: JUMP 000001b5: JUMPDEST 000001b6: STOP 000001b7: JUMPDEST 000001b8: PUSH1 0x40 000001ba: MLOAD 000001bb: DUP1 000001bc: DUP4 000001bd: PUSH1 0x01 000001bf: PUSH1 0xa0 000001c1: PUSH1 0x02 000001c3: EXP 000001c4: SUB 000001c5: AND 000001c6: DUP2 000001c7: MSTORE 000001c8: PUSH1 0x20 000001ca: ADD 000001cb: DUP3 000001cc: DUP2 000001cd: MSTORE 000001ce: PUSH1 0x20 000001d0: ADD 000001d1: SWAP3 000001d2: POP 000001d3: POP 000001d4: POP 000001d5: PUSH1 0x40 000001d7: MLOAD 000001d8: DUP1 000001d9: SWAP2 000001da: SUB 000001db: SWAP1 000001dc: RETURN 000001dd: JUMPDEST 000001de: PUSH1 0x40 000001e0: DUP1 000001e1: MLOAD 000001e2: PUSH1 0x01 000001e4: PUSH1 0xa0 000001e6: PUSH1 0x02 000001e8: EXP 000001e9: SUB 000001ea: SWAP3 000001eb: SWAP1 000001ec: SWAP3 000001ed: AND 000001ee: DUP3 000001ef: MSTORE 000001f0: MLOAD 000001f1: SWAP1 000001f2: DUP2 000001f3: SWAP1 000001f4: SUB 000001f5: PUSH1 0x20 000001f7: ADD 000001f8: SWAP1 000001f9: RETURN 000001fa: JUMPDEST 000001fb: PUSH1 0x40 000001fd: DUP1 000001fe: MLOAD 000001ff: SWAP2 00000200: DUP3 00000201: MSTORE 00000202: MLOAD 00000203: SWAP1 00000204: DUP2 00000205: SWAP1 00000206: SUB 00000207: PUSH1 0x20 00000209: ADD 0000020a: SWAP1 0000020b: RETURN 0000020c: JUMPDEST 0000020d: PUSH1 0x04 0000020f: SLOAD 00000210: PUSH1 0x02 00000212: SLOAD 00000213: PUSH1 0x40 00000215: MLOAD 00000216: PUSH1 0x01 00000218: PUSH1 0xa0 0000021a: PUSH1 0x02 0000021c: EXP 0000021d: SUB 0000021e: SWAP3 0000021f: SWAP1 00000220: SWAP3 00000221: AND 00000222: SWAP2 00000223: PUSH1 0x00 00000225: SWAP2 00000226: SWAP1 00000227: DUP3 00000228: DUP2 00000229: DUP2 0000022a: DUP2 0000022b: DUP6 0000022c: DUP9 0000022d: DUP4 0000022e: CALL 0000022f: POP 00000230: POP 00000231: POP 00000232: PUSH1 0x02 00000234: SSTORE 00000235: POP 00000236: JUMP 00000237: JUMPDEST 00000238: PUSH9 0x056bc75e2d63100000 00000242: CALLVALUE 00000243: GT 00000244: ISZERO 00000245: PUSH2 0x0286 00000248: JUMPI 00000249: PUSH1 0x40 0000024b: MLOAD 0000024c: PUSH1 0x01 0000024e: PUSH1 0xa0 00000250: PUSH1 0x02 00000252: EXP 00000253: SUB 00000254: CALLER 00000255: AND 00000256: SWAP1 00000257: PUSH1 0x00 00000259: SWAP1 0000025a: PUSH9 0x056bc75e2d630fffff 00000264: NOT 00000265: CALLVALUE 00000266: ADD 00000267: SWAP1 00000268: DUP3 00000269: DUP2 0000026a: DUP2 0000026b: DUP2 0000026c: DUP6 0000026d: DUP9 0000026e: DUP4 0000026f: CALL 00000270: POP 00000271: PUSH9 0x056bc75e2d63100000 0000027b: SWAP7 0000027c: POP 0000027d: PUSH2 0x028a 00000280: SWAP4 00000281: POP 00000282: POP 00000283: POP 00000284: POP 00000285: JUMP 00000286: JUMPDEST 00000287: CALLVALUE 00000288: SWAP3 00000289: POP 0000028a: JUMPDEST 0000028b: PUSH1 0x00 0000028d: DUP1 0000028e: SLOAD 0000028f: PUSH1 0x01 00000291: DUP2 00000292: ADD 00000293: DUP1 00000294: DUP4 00000295: SSTORE 00000296: SWAP1 00000297: SWAP4 00000298: POP 00000299: SWAP1 0000029a: DUP2 0000029b: DUP5 0000029c: DUP1 0000029d: ISZERO 0000029e: DUP3 0000029f: SWAP1 000002a0: GT 000002a1: PUSH2 0x02e5 000002a4: JUMPI 000002a5: PUSH1 0x02 000002a7: MUL 000002a8: DUP2 000002a9: PUSH1 0x02 000002ab: MUL 000002ac: DUP4 000002ad: PUSH1 0x00 000002af: MSTORE 000002b0: PUSH1 0x20 000002b2: PUSH1 0x00 000002b4: KECCAK256 000002b5: SWAP2 000002b6: DUP3 000002b7: ADD 000002b8: SWAP2 000002b9: ADD 000002ba: PUSH2 0x02e5 000002bd: SWAP2 000002be: SWAP1 000002bf: JUMPDEST 000002c0: DUP1 000002c1: DUP3 000002c2: GT 000002c3: ISZERO 000002c4: PUSH2 0x03d7 000002c7: JUMPI 000002c8: DUP1 000002c9: SLOAD 000002ca: PUSH1 0x01 000002cc: PUSH1 0xa0 000002ce: PUSH1 0x02 000002d0: EXP 000002d1: SUB 000002d2: NOT 000002d3: AND 000002d4: DUP2 000002d5: SSTORE 000002d6: PUSH1 0x00 000002d8: PUSH1 0x01 000002da: SWAP2 000002db: SWAP1 000002dc: SWAP2 000002dd: ADD 000002de: SWAP1 000002df: DUP2 000002e0: SSTORE 000002e1: PUSH2 0x02bf 000002e4: JUMP 000002e5: JUMPDEST 000002e6: POP 000002e7: POP 000002e8: POP 000002e9: POP 000002ea: CALLER 000002eb: PUSH1 0x00 000002ed: PUSH1 0x00 000002ef: POP 000002f0: DUP4 000002f1: DUP2 000002f2: SLOAD 000002f3: DUP2 000002f4: LT 000002f5: ISZERO 000002f6: PUSH2 0x0002 000002f9: JUMPI 000002fa: DUP2 000002fb: DUP1 000002fc: MSTORE 000002fd: PUSH1 0x02 000002ff: MUL 00000300: PUSH32 0x290decd9548b62a8d60345a988386fc84ba6bc95484008f6362f93160ef3e563 00000321: ADD 00000322: SWAP1 00000323: POP 00000324: DUP1 00000325: SLOAD 00000326: PUSH1 0x01 00000328: PUSH1 0xa0 0000032a: PUSH1 0x02 0000032c: EXP 0000032d: SUB 0000032e: NOT 0000032f: AND 00000330: SWAP1 00000331: SWAP2 00000332: OR 00000333: SWAP1 00000334: SSTORE 00000335: PUSH1 0x02 00000337: DUP1 00000338: SLOAD 00000339: PUSH1 0x0a 0000033b: DUP6 0000033c: DIV 0000033d: SWAP1 0000033e: DUP2 0000033f: ADD 00000340: SWAP1 00000341: SWAP2 00000342: SSTORE 00000343: PUSH1 0x03 00000345: DUP1 00000346: SLOAD 00000347: SWAP2 00000348: DUP6 00000349: SUB 0000034a: SWAP1 0000034b: SWAP2 0000034c: ADD 0000034d: SWAP1 0000034e: SSTORE 0000034f: JUMPDEST 00000350: PUSH1 0x03 00000352: SLOAD 00000353: PUSH1 0x64 00000355: DUP5 00000356: DIV 00000357: PUSH1 0xb4 00000359: MUL 0000035a: SWAP1 0000035b: GT 0000035c: ISZERO 0000035d: PUSH2 0x01b0 00000360: JUMPI 00000361: POP 00000362: PUSH1 0x01 00000364: SLOAD 00000365: PUSH1 0x00 00000367: DUP1 00000368: SLOAD 00000369: PUSH1 0x64 0000036b: DUP6 0000036c: DIV 0000036d: PUSH1 0xb4 0000036f: MUL 00000370: SWAP3 00000371: SWAP1 00000372: DUP2 00000373: LT 00000374: ISZERO 00000375: PUSH2 0x0002 00000378: JUMPI 00000379: DUP2 0000037a: DUP1 0000037b: MSTORE 0000037c: PUSH1 0x40 0000037e: MLOAD 0000037f: PUSH1 0x02 00000381: SWAP2 00000382: SWAP1 00000383: SWAP2 00000384: MUL 00000385: PUSH32 0x290decd9548b62a8d60345a988386fc84ba6bc95484008f6362f93160ef3e563 000003a6: ADD 000003a7: SLOAD 000003a8: PUSH1 0x01 000003aa: PUSH1 0xa0 000003ac: PUSH1 0x02 000003ae: EXP 000003af: SUB 000003b0: AND 000003b1: SWAP2 000003b2: SWAP1 000003b3: DUP4 000003b4: SWAP1 000003b5: DUP3 000003b6: DUP2 000003b7: DUP2 000003b8: DUP2 000003b9: DUP6 000003ba: DUP9 000003bb: DUP4 000003bc: CALL 000003bd: POP 000003be: POP 000003bf: PUSH1 0x03 000003c1: DUP1 000003c2: SLOAD 000003c3: SWAP2 000003c4: SWAP1 000003c5: SWAP2 000003c6: SUB 000003c7: SWAP1 000003c8: SSTORE 000003c9: POP 000003ca: POP 000003cb: PUSH1 0x01 000003cd: DUP1 000003ce: SLOAD 000003cf: DUP2 000003d0: ADD 000003d1: SWAP1 000003d2: SSTORE 000003d3: PUSH2 0x034f 000003d6: JUMP 000003d7: JUMPDEST 000003d8: POP 000003d9: SWAP1 000003da: JUMP
Warning: This is a nightly build of Foundry. It is recommended to use the latest stable version. To mute this warning set `FOUNDRY_DISABLE_NIGHTLY_WARNING` in your environment.
| Severity | Category | Tool | Title | Confidence | Validated | Confirmed | Details |
|---|---|---|---|---|---|---|---|
| high | other | detector | Untrusted CALL target/value reachable | 60 | no | no |
viewtrace_id: 0x6b5716146ec857543883909a37f9fa6fdc1ef1e9ed0a907b7934169df919dc74
call_targets:
0x40b88bbd78cb0441259de7a7d608a39b7388369a
target_varies:
no
classification:
constant_target
validation_json{
"sink": "CALL",
"errors": 0,
"status": "sink_reached",
"attempts": 1,
"trace_id": "0x6b5716146ec857543883909a37f9fa6fdc1ef1e9ed0a907b7934169df919dc74",
"confirmed": false,
"trace_mode": "callTracer",
"call_targets": [
"0x40b88bbd78cb0441259de7a7d608a39b7388369a"
],
"matched_probe": null,
"target_varies": false,
"classification": "constant_target"
}
witness_json{
"notes": "heuristic witness; entrypoints are best-effort selectors with zeroed calldata",
"constraints": [],
"entrypoints": [
{
"calldata": "0x13af4035",
"selector": "0x13af4035",
"calldata_variants": [
"0x13af4035",
"0x13af40350000000000000000000000000000000000000000000000000000000000000000"
]
},
{
"calldata": "0x35c1d349",
"selector": "0x35c1d349",
"calldata_variants": [
"0x35c1d349",
"0x35c1d3490000000000000000000000000000000000000000000000000000000000000000"
]
},
{
"calldata": "0x8da5cb5b",
"selector": "0x8da5cb5b",
"calldata_variants": [
"0x8da5cb5b",
"0x8da5cb5b0000000000000000000000000000000000000000000000000000000000000000"
]
},
{
"calldata": "0x9003adfe",
"selector": "0x9003adfe",
"calldata_variants": [
"0x9003adfe",
"0x9003adfe0000000000000000000000000000000000000000000000000000000000000000"
]
},
{
"calldata": "0xa60f3588",
"selector": "0xa60f3588",
"calldata_variants": [
"0xa60f3588",
"0xa60f35880000000000000000000000000000000000000000000000000000000000000000"
]
},
{
"calldata": "0xb69ef8a8",
"selector": "0xb69ef8a8",
"calldata_variants": [
"0xb69ef8a8",
"0xb69ef8a80000000000000000000000000000000000000000000000000000000000000000"
]
},
{
"calldata": "0xc8796572",
"selector": "0xc8796572",
"calldata_variants": [
"0xc8796572",
"0xc87965720000000000000000000000000000000000000000000000000000000000000000"
]
},
{
"calldata": "0xe97dcb62",
"selector": "0xe97dcb62",
"calldata_variants": [
"0xe97dcb62",
"0xe97dcb620000000000000000000000000000000000000000000000000000000000000000"
]
}
]
}
evidence_json{
"examples": [
{
"pc": 426,
"opcode": "CALL",
"returndata_checked": null,
"value_expression_category": "computed",
"target_expression_category": "computed"
},
{
"pc": 558,
"opcode": "CALL",
"returndata_checked": null,
"value_expression_category": "computed",
"target_expression_category": "computed"
},
{
"pc": 623,
"opcode": "CALL",
"returndata_checked": null,
"value_expression_category": "computed",
"target_expression_category": "computed"
}
],
"call_count": 4,
"guards_detected": [],
"untrusted_call_count": 4
}
|
| high | other | detector | ETH value transfer possible | 55 | no | no |
viewtrace_id: 0x6b5716146ec857543883909a37f9fa6fdc1ef1e9ed0a907b7934169df919dc74
call_targets:
0x40b88bbd78cb0441259de7a7d608a39b7388369a
target_varies:
no
classification:
constant_target
validation_json{
"sink": "CALL",
"errors": 0,
"status": "sink_reached",
"attempts": 1,
"trace_id": "0x6b5716146ec857543883909a37f9fa6fdc1ef1e9ed0a907b7934169df919dc74",
"confirmed": false,
"trace_mode": "callTracer",
"call_targets": [
"0x40b88bbd78cb0441259de7a7d608a39b7388369a"
],
"matched_probe": null,
"target_varies": false,
"classification": "constant_target"
}
witness_json{
"notes": "heuristic witness; entrypoints are best-effort selectors with zeroed calldata",
"constraints": [],
"entrypoints": [
{
"calldata": "0x13af4035",
"selector": "0x13af4035",
"calldata_variants": [
"0x13af4035",
"0x13af40350000000000000000000000000000000000000000000000000000000000000000"
]
},
{
"calldata": "0x35c1d349",
"selector": "0x35c1d349",
"calldata_variants": [
"0x35c1d349",
"0x35c1d3490000000000000000000000000000000000000000000000000000000000000000"
]
},
{
"calldata": "0x8da5cb5b",
"selector": "0x8da5cb5b",
"calldata_variants": [
"0x8da5cb5b",
"0x8da5cb5b0000000000000000000000000000000000000000000000000000000000000000"
]
},
{
"calldata": "0x9003adfe",
"selector": "0x9003adfe",
"calldata_variants": [
"0x9003adfe",
"0x9003adfe0000000000000000000000000000000000000000000000000000000000000000"
]
},
{
"calldata": "0xa60f3588",
"selector": "0xa60f3588",
"calldata_variants": [
"0xa60f3588",
"0xa60f35880000000000000000000000000000000000000000000000000000000000000000"
]
},
{
"calldata": "0xb69ef8a8",
"selector": "0xb69ef8a8",
"calldata_variants": [
"0xb69ef8a8",
"0xb69ef8a80000000000000000000000000000000000000000000000000000000000000000"
]
},
{
"calldata": "0xc8796572",
"selector": "0xc8796572",
"calldata_variants": [
"0xc8796572",
"0xc87965720000000000000000000000000000000000000000000000000000000000000000"
]
},
{
"calldata": "0xe97dcb62",
"selector": "0xe97dcb62",
"calldata_variants": [
"0xe97dcb62",
"0xe97dcb620000000000000000000000000000000000000000000000000000000000000000"
]
}
]
}
evidence_json{
"examples": [
{
"pc": 426,
"opcode": "CALL",
"returndata_checked": null,
"value_expression_category": "computed",
"target_expression_category": "computed"
},
{
"pc": 558,
"opcode": "CALL",
"returndata_checked": null,
"value_expression_category": "computed",
"target_expression_category": "computed"
},
{
"pc": 623,
"opcode": "CALL",
"returndata_checked": null,
"value_expression_category": "computed",
"target_expression_category": "computed"
}
],
"eth_value_calls": 4,
"guards_detected": []
}
|