019b3836-5565-71d5-b51e-3f66b2137f7b
Open this run to answer one question: is this real attacker-relevant behavior with real impact, or just normal contract plumbing?
| ID | Type | Status | Attempts | Heartbeat |
|---|---|---|---|---|
| 8261 | artifact.fetch | complete | 1 / 3 | 3 months ago |
| 8262 | tool.cast_disasm | complete | 1 / 3 | 3 months ago |
| 98138 | analysis.bundle | complete | 1 / 3 | 1 week ago |
| 98139 | capability.graph | complete | 1 / 3 | 1 week ago |
| 98140 | detector.run | complete | 1 / 3 | 1 week ago |
| 98141 | validation.fork | complete | 1 / 3 | 1 week ago |
No slither job recorded yet.
No codex job recorded yet.
00000000: PUSH1 0x60 00000002: PUSH1 0x40 00000004: MSTORE 00000005: CALLDATASIZE 00000006: ISZERO 00000007: PUSH2 0x0082 0000000a: JUMPI 0000000b: PUSH1 0xe0 0000000d: PUSH1 0x02 0000000f: EXP 00000010: PUSH1 0x00 00000012: CALLDATALOAD 00000013: DIV 00000014: PUSH4 0x205c2878 00000019: DUP2 0000001a: EQ 0000001b: PUSH2 0x0101 0000001e: JUMPI 0000001f: DUP1 00000020: PUSH4 0x5fe22e5a 00000025: EQ 00000026: PUSH2 0x0126 00000029: JUMPI 0000002a: DUP1 0000002b: PUSH4 0x641ad3aa 00000030: EQ 00000031: PUSH2 0x014d 00000034: JUMPI 00000035: DUP1 00000036: PUSH4 0x853828b6 0000003b: EQ 0000003c: PUSH2 0x0156 0000003f: JUMPI 00000040: DUP1 00000041: PUSH4 0x8da5cb5b 00000046: EQ 00000047: PUSH2 0x0172 0000004a: JUMPI 0000004b: DUP1 0000004c: PUSH4 0x9a551d7c 00000051: EQ 00000052: PUSH2 0x0184 00000055: JUMPI 00000056: DUP1 00000057: PUSH4 0xb69ef8a8 0000005c: EQ 0000005d: PUSH2 0x0197 00000060: JUMPI 00000061: DUP1 00000062: PUSH4 0xcbf69555 00000067: EQ 00000068: PUSH2 0x01a0 0000006b: JUMPI 0000006c: DUP1 0000006d: PUSH4 0xd4b83992 00000072: EQ 00000073: PUSH2 0x01b4 00000076: JUMPI 00000077: DUP1 00000078: PUSH4 0xdc6bc6f3 0000007d: EQ 0000007e: PUSH2 0x01c6 00000081: JUMPI 00000082: JUMPDEST 00000083: PUSH2 0x01e7 00000086: PUSH1 0x01 00000088: SLOAD 00000089: PUSH1 0x00 0000008b: SWAP1 0000008c: DUP2 0000008d: SWAP1 0000008e: PUSH1 0xff 00000090: PUSH1 0xa0 00000092: PUSH1 0x02 00000094: EXP 00000095: SWAP1 00000096: SWAP2 00000097: DIV 00000098: AND 00000099: ISZERO 0000009a: PUSH2 0x01e9 0000009d: JUMPI 0000009e: PUSH1 0x03 000000a0: SLOAD 000000a1: PUSH1 0x01 000000a3: SWAP1 000000a4: GT 000000a5: ISZERO 000000a6: PUSH2 0x01f6 000000a9: JUMPI 000000aa: PUSH1 0x03 000000ac: SLOAD 000000ad: PUSH1 0x02 000000af: DUP1 000000b0: SLOAD 000000b1: CALLVALUE 000000b2: SWAP1 000000b3: DUP2 000000b4: ADD 000000b5: SWAP1 000000b6: SWAP2 000000b7: SSTORE 000000b8: DIV 000000b9: SWAP2 000000ba: POP 000000bb: JUMPDEST 000000bc: PUSH1 0x03 000000be: SLOAD 000000bf: DUP2 000000c0: LT 000000c1: ISZERO 000000c2: PUSH2 0x0237 000000c5: JUMPI 000000c6: PUSH1 0x01 000000c8: SLOAD 000000c9: PUSH1 0x40 000000cb: MLOAD 000000cc: PUSH1 0x01 000000ce: PUSH1 0xa0 000000d0: PUSH1 0x02 000000d2: EXP 000000d3: SUB 000000d4: SWAP2 000000d5: SWAP1 000000d6: SWAP2 000000d7: AND 000000d8: SWAP1 000000d9: PUSH1 0x00 000000db: SWAP1 000000dc: DUP5 000000dd: SWAP1 000000de: DUP3 000000df: DUP2 000000e0: DUP2 000000e1: DUP2 000000e2: DUP6 000000e3: DUP9 000000e4: DUP4 000000e5: CALL 000000e6: SWAP4 000000e7: POP 000000e8: POP 000000e9: POP 000000ea: POP 000000eb: ISZERO 000000ec: PUSH2 0x00f9 000000ef: JUMPI 000000f0: PUSH1 0x02 000000f2: DUP1 000000f3: SLOAD 000000f4: DUP4 000000f5: SWAP1 000000f6: SUB 000000f7: SWAP1 000000f8: SSTORE 000000f9: JUMPDEST 000000fa: PUSH1 0x01 000000fc: ADD 000000fd: PUSH2 0x00bb 00000100: JUMP 00000101: JUMPDEST 00000102: PUSH2 0x01e7 00000105: PUSH1 0x04 00000107: CALLDATALOAD 00000108: PUSH1 0x24 0000010a: CALLDATALOAD 0000010b: JUMPDEST 0000010c: PUSH1 0x00 0000010e: SLOAD 0000010f: CALLER 00000110: PUSH1 0x01 00000112: PUSH1 0xa0 00000114: PUSH1 0x02 00000116: EXP 00000117: SUB 00000118: SWAP1 00000119: DUP2 0000011a: AND 0000011b: SWAP2 0000011c: AND 0000011d: EQ 0000011e: PUSH2 0x028d 00000121: JUMPI 00000122: PUSH2 0x0002 00000125: JUMP 00000126: JUMPDEST 00000127: PUSH2 0x01e7 0000012a: PUSH1 0x04 0000012c: CALLDATALOAD 0000012d: PUSH1 0x24 0000012f: CALLDATALOAD 00000130: PUSH1 0x44 00000132: CALLDATALOAD 00000133: PUSH1 0x00 00000135: SLOAD 00000136: CALLER 00000137: PUSH1 0x01 00000139: PUSH1 0xa0 0000013b: PUSH1 0x02 0000013d: EXP 0000013e: SUB 0000013f: SWAP1 00000140: DUP2 00000141: AND 00000142: SWAP2 00000143: AND 00000144: EQ 00000145: PUSH2 0x02d0 00000148: JUMPI 00000149: PUSH2 0x0002 0000014c: JUMP 0000014d: JUMPDEST 0000014e: PUSH2 0x024a 00000151: PUSH1 0x03 00000153: SLOAD 00000154: DUP2 00000155: JUMP 00000156: JUMPDEST 00000157: PUSH2 0x01e7 0000015a: PUSH1 0x01 0000015c: SLOAD 0000015d: PUSH1 0x02 0000015f: SLOAD 00000160: PUSH2 0x033a 00000163: SWAP2 00000164: PUSH1 0x01 00000166: PUSH1 0xa0 00000168: PUSH1 0x02 0000016a: EXP 0000016b: SUB 0000016c: AND 0000016d: SWAP1 0000016e: PUSH2 0x010b 00000171: JUMP 00000172: JUMPDEST 00000173: PUSH2 0x025c 00000176: PUSH1 0x00 00000178: SLOAD 00000179: PUSH1 0x01 0000017b: PUSH1 0xa0 0000017d: PUSH1 0x02 0000017f: EXP 00000180: SUB 00000181: AND 00000182: DUP2 00000183: JUMP 00000184: JUMPDEST 00000185: PUSH2 0x0279 00000188: PUSH1 0x01 0000018a: SLOAD 0000018b: PUSH1 0xa8 0000018d: PUSH1 0x02 0000018f: EXP 00000190: SWAP1 00000191: DIV 00000192: PUSH1 0xff 00000194: AND 00000195: DUP2 00000196: JUMP 00000197: JUMPDEST 00000198: PUSH2 0x024a 0000019b: PUSH1 0x02 0000019d: SLOAD 0000019e: DUP2 0000019f: JUMP 000001a0: JUMPDEST 000001a1: PUSH2 0x0279 000001a4: PUSH1 0x01 000001a6: SLOAD 000001a7: PUSH1 0xff 000001a9: PUSH1 0xa0 000001ab: PUSH1 0x02 000001ad: EXP 000001ae: SWAP1 000001af: SWAP2 000001b0: DIV 000001b1: AND 000001b2: DUP2 000001b3: JUMP 000001b4: JUMPDEST 000001b5: PUSH2 0x025c 000001b8: PUSH1 0x01 000001ba: SLOAD 000001bb: PUSH1 0x01 000001bd: PUSH1 0xa0 000001bf: PUSH1 0x02 000001c1: EXP 000001c2: SUB 000001c3: AND 000001c4: DUP2 000001c5: JUMP 000001c6: JUMPDEST 000001c7: PUSH2 0x01e7 000001ca: PUSH1 0x04 000001cc: CALLDATALOAD 000001cd: PUSH1 0x00 000001cf: SLOAD 000001d0: CALLER 000001d1: PUSH1 0x01 000001d3: PUSH1 0xa0 000001d5: PUSH1 0x02 000001d7: EXP 000001d8: SUB 000001d9: SWAP1 000001da: DUP2 000001db: AND 000001dc: SWAP2 000001dd: AND 000001de: EQ 000001df: PUSH2 0x033c 000001e2: JUMPI 000001e3: PUSH2 0x0002 000001e6: JUMP 000001e7: JUMPDEST 000001e8: STOP 000001e9: JUMPDEST 000001ea: PUSH1 0x02 000001ec: DUP1 000001ed: SLOAD 000001ee: CALLVALUE 000001ef: ADD 000001f0: SWAP1 000001f1: SSTORE 000001f2: JUMPDEST 000001f3: POP 000001f4: POP 000001f5: JUMP 000001f6: JUMPDEST 000001f7: PUSH1 0x01 000001f9: SLOAD 000001fa: PUSH1 0x40 000001fc: MLOAD 000001fd: PUSH1 0x01 000001ff: PUSH1 0xa0 00000201: PUSH1 0x02 00000203: EXP 00000204: SUB 00000205: SWAP1 00000206: SWAP2 00000207: AND 00000208: SWAP1 00000209: PUSH1 0x00 0000020b: SWAP1 0000020c: CALLVALUE 0000020d: SWAP1 0000020e: DUP3 0000020f: DUP2 00000210: DUP2 00000211: DUP2 00000212: DUP6 00000213: DUP9 00000214: DUP4 00000215: CALL 00000216: SWAP4 00000217: POP 00000218: POP 00000219: POP 0000021a: POP 0000021b: ISZERO 0000021c: ISZERO 0000021d: PUSH2 0x0245 00000220: JUMPI 00000221: PUSH1 0x01 00000223: SLOAD 00000224: PUSH1 0xa8 00000226: PUSH1 0x02 00000228: EXP 00000229: SWAP1 0000022a: DIV 0000022b: PUSH1 0xff 0000022d: AND 0000022e: ISZERO 0000022f: PUSH2 0x023c 00000232: JUMPI 00000233: PUSH2 0x0002 00000236: JUMP 00000237: JUMPDEST 00000238: PUSH2 0x0245 0000023b: JUMP 0000023c: JUMPDEST 0000023d: PUSH1 0x02 0000023f: DUP1 00000240: SLOAD 00000241: CALLVALUE 00000242: ADD 00000243: SWAP1 00000244: SSTORE 00000245: JUMPDEST 00000246: PUSH2 0x01f2 00000249: JUMP 0000024a: JUMPDEST 0000024b: PUSH1 0x40 0000024d: DUP1 0000024e: MLOAD 0000024f: SWAP2 00000250: DUP3 00000251: MSTORE 00000252: MLOAD 00000253: SWAP1 00000254: DUP2 00000255: SWAP1 00000256: SUB 00000257: PUSH1 0x20 00000259: ADD 0000025a: SWAP1 0000025b: RETURN 0000025c: JUMPDEST 0000025d: PUSH1 0x40 0000025f: DUP1 00000260: MLOAD 00000261: PUSH1 0x01 00000263: PUSH1 0xa0 00000265: PUSH1 0x02 00000267: EXP 00000268: SUB 00000269: SWAP3 0000026a: SWAP1 0000026b: SWAP3 0000026c: AND 0000026d: DUP3 0000026e: MSTORE 0000026f: MLOAD 00000270: SWAP1 00000271: DUP2 00000272: SWAP1 00000273: SUB 00000274: PUSH1 0x20 00000276: ADD 00000277: SWAP1 00000278: RETURN 00000279: JUMPDEST 0000027a: PUSH1 0x40 0000027c: DUP1 0000027d: MLOAD 0000027e: SWAP2 0000027f: ISZERO 00000280: ISZERO 00000281: DUP3 00000282: MSTORE 00000283: MLOAD 00000284: SWAP1 00000285: DUP2 00000286: SWAP1 00000287: SUB 00000288: PUSH1 0x20 0000028a: ADD 0000028b: SWAP1 0000028c: RETURN 0000028d: JUMPDEST 0000028e: DUP1 0000028f: PUSH1 0x00 00000291: EQ 00000292: DUP1 00000293: PUSH2 0x02b9 00000296: JUMPI 00000297: POP 00000298: PUSH1 0x40 0000029a: MLOAD 0000029b: PUSH1 0x01 0000029d: PUSH1 0xa0 0000029f: PUSH1 0x02 000002a1: EXP 000002a2: SUB 000002a3: DUP4 000002a4: AND 000002a5: SWAP1 000002a6: PUSH1 0x00 000002a8: SWAP1 000002a9: DUP4 000002aa: SWAP1 000002ab: DUP3 000002ac: DUP2 000002ad: DUP2 000002ae: DUP2 000002af: DUP6 000002b0: DUP9 000002b1: DUP4 000002b2: CALL 000002b3: SWAP4 000002b4: POP 000002b5: POP 000002b6: POP 000002b7: POP 000002b8: ISZERO 000002b9: JUMPDEST 000002ba: ISZERO 000002bb: PUSH2 0x02c3 000002be: JUMPI 000002bf: PUSH2 0x0002 000002c2: JUMP 000002c3: JUMPDEST 000002c4: PUSH1 0x02 000002c6: DUP1 000002c7: SLOAD 000002c8: DUP3 000002c9: SWAP1 000002ca: SUB 000002cb: SWAP1 000002cc: SSTORE 000002cd: POP 000002ce: POP 000002cf: JUMP 000002d0: JUMPDEST 000002d1: PUSH1 0x01 000002d3: DUP1 000002d4: SLOAD 000002d5: PUSH1 0xa8 000002d7: PUSH1 0x02 000002d9: EXP 000002da: DUP4 000002db: MUL 000002dc: PUSH1 0xa0 000002de: PUSH1 0x02 000002e0: EXP 000002e1: DUP6 000002e2: MUL 000002e3: PUSH20 0xffffffffffffffffffffffffffffffffffffffff 000002f8: NOT 000002f9: SWAP1 000002fa: SWAP3 000002fb: AND 000002fc: DUP7 000002fd: OR 000002fe: PUSH21 0xff0000000000000000000000000000000000000000 00000314: NOT 00000315: AND 00000316: SWAP2 00000317: SWAP1 00000318: SWAP2 00000319: OR 0000031a: PUSH22 0xff000000000000000000000000000000000000000000 00000331: NOT 00000332: AND 00000333: OR 00000334: SWAP1 00000335: SSTORE 00000336: POP 00000337: POP 00000338: POP 00000339: JUMP 0000033a: JUMPDEST 0000033b: JUMP 0000033c: JUMPDEST 0000033d: DUP1 0000033e: PUSH1 0x00 00000340: EQ 00000341: ISZERO 00000342: PUSH2 0x034a 00000345: JUMPI 00000346: PUSH2 0x0002 00000349: JUMP 0000034a: JUMPDEST 0000034b: PUSH1 0x03 0000034d: SSTORE 0000034e: JUMP
Warning: This is a nightly build of Foundry. It is recommended to use the latest stable version. To mute this warning set `FOUNDRY_DISABLE_NIGHTLY_WARNING` in your environment.
| Severity | Category | Tool | Title | Confidence | Validated | Confirmed | Details |
|---|---|---|---|---|---|---|---|
| high | other | detector | Untrusted CALL target/value reachable | 60 | no | no |
viewtrace_id: 0x33fdfa5b9cb7b47bb02df2d68a98e527e57e60925e156f3b482460a1cca30b52
call_targets:
0x617abf540091cda7920e8ade927fdea897b16539
target_varies:
no
classification:
constant_target
validation_json{
"sink": "CALL",
"errors": 0,
"status": "sink_reached",
"attempts": 1,
"trace_id": "0x33fdfa5b9cb7b47bb02df2d68a98e527e57e60925e156f3b482460a1cca30b52",
"confirmed": false,
"trace_mode": "callTracer",
"call_targets": [
"0x617abf540091cda7920e8ade927fdea897b16539"
],
"matched_probe": null,
"target_varies": false,
"classification": "constant_target"
}
witness_json{
"notes": "heuristic witness; entrypoints are best-effort selectors with zeroed calldata",
"constraints": [],
"entrypoints": [
{
"calldata": "0x205c2878",
"selector": "0x205c2878",
"calldata_variants": [
"0x205c2878",
"0x205c28780000000000000000000000000000000000000000000000000000000000000000"
]
},
{
"calldata": "0x5fe22e5a",
"selector": "0x5fe22e5a",
"calldata_variants": [
"0x5fe22e5a",
"0x5fe22e5a0000000000000000000000000000000000000000000000000000000000000000"
]
},
{
"calldata": "0x641ad3aa",
"selector": "0x641ad3aa",
"calldata_variants": [
"0x641ad3aa",
"0x641ad3aa0000000000000000000000000000000000000000000000000000000000000000"
]
},
{
"calldata": "0x853828b6",
"selector": "0x853828b6",
"calldata_variants": [
"0x853828b6",
"0x853828b60000000000000000000000000000000000000000000000000000000000000000"
]
},
{
"calldata": "0x8da5cb5b",
"selector": "0x8da5cb5b",
"calldata_variants": [
"0x8da5cb5b",
"0x8da5cb5b0000000000000000000000000000000000000000000000000000000000000000"
]
},
{
"calldata": "0x9a551d7c",
"selector": "0x9a551d7c",
"calldata_variants": [
"0x9a551d7c",
"0x9a551d7c0000000000000000000000000000000000000000000000000000000000000000"
]
},
{
"calldata": "0xb69ef8a8",
"selector": "0xb69ef8a8",
"calldata_variants": [
"0xb69ef8a8",
"0xb69ef8a80000000000000000000000000000000000000000000000000000000000000000"
]
},
{
"calldata": "0xcbf69555",
"selector": "0xcbf69555",
"calldata_variants": [
"0xcbf69555",
"0xcbf695550000000000000000000000000000000000000000000000000000000000000000"
]
}
]
}
evidence_json{
"examples": [
{
"pc": 229,
"opcode": "CALL",
"returndata_checked": null,
"value_expression_category": "computed",
"target_expression_category": "computed"
},
{
"pc": 533,
"opcode": "CALL",
"returndata_checked": null,
"value_expression_category": "computed",
"target_expression_category": "computed"
},
{
"pc": 690,
"opcode": "CALL",
"returndata_checked": null,
"value_expression_category": "computed",
"target_expression_category": "computed"
}
],
"call_count": 3,
"guards_detected": [],
"untrusted_call_count": 3
}
|
| high | other | detector | ETH value transfer possible | 55 | no | no |
viewtrace_id: 0x33fdfa5b9cb7b47bb02df2d68a98e527e57e60925e156f3b482460a1cca30b52
call_targets:
0x617abf540091cda7920e8ade927fdea897b16539
target_varies:
no
classification:
constant_target
validation_json{
"sink": "CALL",
"errors": 0,
"status": "sink_reached",
"attempts": 1,
"trace_id": "0x33fdfa5b9cb7b47bb02df2d68a98e527e57e60925e156f3b482460a1cca30b52",
"confirmed": false,
"trace_mode": "callTracer",
"call_targets": [
"0x617abf540091cda7920e8ade927fdea897b16539"
],
"matched_probe": null,
"target_varies": false,
"classification": "constant_target"
}
witness_json{
"notes": "heuristic witness; entrypoints are best-effort selectors with zeroed calldata",
"constraints": [],
"entrypoints": [
{
"calldata": "0x205c2878",
"selector": "0x205c2878",
"calldata_variants": [
"0x205c2878",
"0x205c28780000000000000000000000000000000000000000000000000000000000000000"
]
},
{
"calldata": "0x5fe22e5a",
"selector": "0x5fe22e5a",
"calldata_variants": [
"0x5fe22e5a",
"0x5fe22e5a0000000000000000000000000000000000000000000000000000000000000000"
]
},
{
"calldata": "0x641ad3aa",
"selector": "0x641ad3aa",
"calldata_variants": [
"0x641ad3aa",
"0x641ad3aa0000000000000000000000000000000000000000000000000000000000000000"
]
},
{
"calldata": "0x853828b6",
"selector": "0x853828b6",
"calldata_variants": [
"0x853828b6",
"0x853828b60000000000000000000000000000000000000000000000000000000000000000"
]
},
{
"calldata": "0x8da5cb5b",
"selector": "0x8da5cb5b",
"calldata_variants": [
"0x8da5cb5b",
"0x8da5cb5b0000000000000000000000000000000000000000000000000000000000000000"
]
},
{
"calldata": "0x9a551d7c",
"selector": "0x9a551d7c",
"calldata_variants": [
"0x9a551d7c",
"0x9a551d7c0000000000000000000000000000000000000000000000000000000000000000"
]
},
{
"calldata": "0xb69ef8a8",
"selector": "0xb69ef8a8",
"calldata_variants": [
"0xb69ef8a8",
"0xb69ef8a80000000000000000000000000000000000000000000000000000000000000000"
]
},
{
"calldata": "0xcbf69555",
"selector": "0xcbf69555",
"calldata_variants": [
"0xcbf69555",
"0xcbf695550000000000000000000000000000000000000000000000000000000000000000"
]
}
]
}
evidence_json{
"examples": [
{
"pc": 229,
"opcode": "CALL",
"returndata_checked": null,
"value_expression_category": "computed",
"target_expression_category": "computed"
},
{
"pc": 533,
"opcode": "CALL",
"returndata_checked": null,
"value_expression_category": "computed",
"target_expression_category": "computed"
},
{
"pc": 690,
"opcode": "CALL",
"returndata_checked": null,
"value_expression_category": "computed",
"target_expression_category": "computed"
}
],
"eth_value_calls": 3,
"guards_detected": []
}
|