019b3844-9720-70e6-bb96-ef142221d971
Open this run to answer one question: is this real attacker-relevant behavior with real impact, or just normal contract plumbing?
| ID | Type | Status | Attempts | Heartbeat |
|---|---|---|---|---|
| 13667 | artifact.fetch | complete | 1 / 3 | 4 months ago |
| 13668 | tool.cast_disasm | complete | 1 / 3 | 4 months ago |
| 56853 | analysis.bundle | complete | 1 / 3 | 2 weeks ago |
| 56854 | capability.graph | complete | 1 / 3 | 2 weeks ago |
| 56855 | detector.run | complete | 1 / 3 | 2 weeks ago |
| 56856 | validation.fork | complete | 1 / 3 | 2 weeks ago |
No slither job recorded yet.
No codex job recorded yet.
00000000: PUSH1 0x80 00000002: PUSH1 0x40 00000004: MSTORE 00000005: PUSH1 0x04 00000007: CALLDATASIZE 00000008: LT 00000009: PUSH2 0x005e 0000000c: JUMPI 0000000d: PUSH1 0x00 0000000f: CALLDATALOAD 00000010: PUSH1 0xe0 00000012: SHR 00000013: DUP1 00000014: PUSH4 0x4f1ef286 00000019: GT 0000001a: PUSH2 0x0043 0000001d: JUMPI 0000001e: DUP1 0000001f: PUSH4 0x4f1ef286 00000024: EQ 00000025: PUSH2 0x00f3 00000028: JUMPI 00000029: DUP1 0000002a: PUSH4 0x5c60da1b 0000002f: EQ 00000030: PUSH2 0x01b6 00000033: JUMPI 00000034: DUP1 00000035: PUSH4 0xf1739cae 0000003a: EQ 0000003b: PUSH2 0x01cb 0000003e: JUMPI 0000003f: PUSH2 0x006d 00000042: JUMP 00000043: JUMPDEST 00000044: DUP1 00000045: PUSH4 0x025313a2 0000004a: EQ 0000004b: PUSH2 0x0075 0000004e: JUMPI 0000004f: DUP1 00000050: PUSH4 0x3659cfe6 00000055: EQ 00000056: PUSH2 0x00b3 00000059: JUMPI 0000005a: PUSH2 0x006d 0000005d: JUMP 0000005e: JUMPDEST 0000005f: CALLDATASIZE 00000060: PUSH2 0x006d 00000063: JUMPI 00000064: PUSH2 0x006b 00000067: PUSH2 0x020b 0000006a: JUMP 0000006b: JUMPDEST 0000006c: STOP 0000006d: JUMPDEST 0000006e: PUSH2 0x006b 00000071: PUSH2 0x020b 00000074: JUMP 00000075: JUMPDEST 00000076: CALLVALUE 00000077: DUP1 00000078: ISZERO 00000079: PUSH2 0x0081 0000007c: JUMPI 0000007d: PUSH1 0x00 0000007f: DUP1 00000080: REVERT 00000081: JUMPDEST 00000082: POP 00000083: PUSH2 0x008a 00000086: PUSH2 0x025c 00000089: JUMP 0000008a: JUMPDEST 0000008b: PUSH1 0x40 0000008d: DUP1 0000008e: MLOAD 0000008f: PUSH20 0xffffffffffffffffffffffffffffffffffffffff 000000a4: SWAP1 000000a5: SWAP3 000000a6: AND 000000a7: DUP3 000000a8: MSTORE 000000a9: MLOAD 000000aa: SWAP1 000000ab: DUP2 000000ac: SWAP1 000000ad: SUB 000000ae: PUSH1 0x20 000000b0: ADD 000000b1: SWAP1 000000b2: RETURN 000000b3: JUMPDEST 000000b4: CALLVALUE 000000b5: DUP1 000000b6: ISZERO 000000b7: PUSH2 0x00bf 000000ba: JUMPI 000000bb: PUSH1 0x00 000000bd: DUP1 000000be: REVERT 000000bf: JUMPDEST 000000c0: POP 000000c1: PUSH2 0x006b 000000c4: PUSH1 0x04 000000c6: DUP1 000000c7: CALLDATASIZE 000000c8: SUB 000000c9: PUSH1 0x20 000000cb: DUP2 000000cc: LT 000000cd: ISZERO 000000ce: PUSH2 0x00d6 000000d1: JUMPI 000000d2: PUSH1 0x00 000000d4: DUP1 000000d5: REVERT 000000d6: JUMPDEST 000000d7: POP 000000d8: CALLDATALOAD 000000d9: PUSH20 0xffffffffffffffffffffffffffffffffffffffff 000000ee: AND 000000ef: PUSH2 0x0281 000000f2: JUMP 000000f3: JUMPDEST 000000f4: PUSH2 0x006b 000000f7: PUSH1 0x04 000000f9: DUP1 000000fa: CALLDATASIZE 000000fb: SUB 000000fc: PUSH1 0x40 000000fe: DUP2 000000ff: LT 00000100: ISZERO 00000101: PUSH2 0x0109 00000104: JUMPI 00000105: PUSH1 0x00 00000107: DUP1 00000108: REVERT 00000109: JUMPDEST 0000010a: PUSH20 0xffffffffffffffffffffffffffffffffffffffff 0000011f: DUP3 00000120: CALLDATALOAD 00000121: AND 00000122: SWAP2 00000123: SWAP1 00000124: DUP2 00000125: ADD 00000126: SWAP1 00000127: PUSH1 0x40 00000129: DUP2 0000012a: ADD 0000012b: PUSH1 0x20 0000012d: DUP3 0000012e: ADD 0000012f: CALLDATALOAD 00000130: PUSH5 0x0100000000 00000136: DUP2 00000137: GT 00000138: ISZERO 00000139: PUSH2 0x0141 0000013c: JUMPI 0000013d: PUSH1 0x00 0000013f: DUP1 00000140: REVERT 00000141: JUMPDEST 00000142: DUP3 00000143: ADD 00000144: DUP4 00000145: PUSH1 0x20 00000147: DUP3 00000148: ADD 00000149: GT 0000014a: ISZERO 0000014b: PUSH2 0x0153 0000014e: JUMPI 0000014f: PUSH1 0x00 00000151: DUP1 00000152: REVERT 00000153: JUMPDEST 00000154: DUP1 00000155: CALLDATALOAD 00000156: SWAP1 00000157: PUSH1 0x20 00000159: ADD 0000015a: SWAP2 0000015b: DUP5 0000015c: PUSH1 0x01 0000015e: DUP4 0000015f: MUL 00000160: DUP5 00000161: ADD 00000162: GT 00000163: PUSH5 0x0100000000 00000169: DUP4 0000016a: GT 0000016b: OR 0000016c: ISZERO 0000016d: PUSH2 0x0175 00000170: JUMPI 00000171: PUSH1 0x00 00000173: DUP1 00000174: REVERT 00000175: JUMPDEST 00000176: SWAP2 00000177: SWAP1 00000178: DUP1 00000179: DUP1 0000017a: PUSH1 0x1f 0000017c: ADD 0000017d: PUSH1 0x20 0000017f: DUP1 00000180: SWAP2 00000181: DIV 00000182: MUL 00000183: PUSH1 0x20 00000185: ADD 00000186: PUSH1 0x40 00000188: MLOAD 00000189: SWAP1 0000018a: DUP2 0000018b: ADD 0000018c: PUSH1 0x40 0000018e: MSTORE 0000018f: DUP1 00000190: SWAP4 00000191: SWAP3 00000192: SWAP2 00000193: SWAP1 00000194: DUP2 00000195: DUP2 00000196: MSTORE 00000197: PUSH1 0x20 00000199: ADD 0000019a: DUP4 0000019b: DUP4 0000019c: DUP1 0000019d: DUP3 0000019e: DUP5 0000019f: CALLDATACOPY 000001a0: PUSH1 0x00 000001a2: SWAP3 000001a3: ADD 000001a4: SWAP2 000001a5: SWAP1 000001a6: SWAP2 000001a7: MSTORE 000001a8: POP 000001a9: SWAP3 000001aa: SWAP6 000001ab: POP 000001ac: PUSH2 0x02cc 000001af: SWAP5 000001b0: POP 000001b1: POP 000001b2: POP 000001b3: POP 000001b4: POP 000001b5: JUMP 000001b6: JUMPDEST 000001b7: CALLVALUE 000001b8: DUP1 000001b9: ISZERO 000001ba: PUSH2 0x01c2 000001bd: JUMPI 000001be: PUSH1 0x00 000001c0: DUP1 000001c1: REVERT 000001c2: JUMPDEST 000001c3: POP 000001c4: PUSH2 0x008a 000001c7: PUSH2 0x03f6 000001ca: JUMP 000001cb: JUMPDEST 000001cc: CALLVALUE 000001cd: DUP1 000001ce: ISZERO 000001cf: PUSH2 0x01d7 000001d2: JUMPI 000001d3: PUSH1 0x00 000001d5: DUP1 000001d6: REVERT 000001d7: JUMPDEST 000001d8: POP 000001d9: PUSH2 0x006b 000001dc: PUSH1 0x04 000001de: DUP1 000001df: CALLDATASIZE 000001e0: SUB 000001e1: PUSH1 0x20 000001e3: DUP2 000001e4: LT 000001e5: ISZERO 000001e6: PUSH2 0x01ee 000001e9: JUMPI 000001ea: PUSH1 0x00 000001ec: DUP1 000001ed: REVERT 000001ee: JUMPDEST 000001ef: POP 000001f0: CALLDATALOAD 000001f1: PUSH20 0xffffffffffffffffffffffffffffffffffffffff 00000206: AND 00000207: PUSH2 0x041b 0000020a: JUMP 0000020b: JUMPDEST 0000020c: PUSH1 0x00 0000020e: PUSH2 0x0215 00000211: PUSH2 0x03f6 00000214: JUMP 00000215: JUMPDEST 00000216: SWAP1 00000217: POP 00000218: PUSH20 0xffffffffffffffffffffffffffffffffffffffff 0000022d: DUP2 0000022e: AND 0000022f: PUSH2 0x0237 00000232: JUMPI 00000233: PUSH1 0x00 00000235: DUP1 00000236: REVERT 00000237: JUMPDEST 00000238: PUSH1 0x40 0000023a: MLOAD 0000023b: CALLDATASIZE 0000023c: PUSH1 0x00 0000023e: DUP3 0000023f: CALLDATACOPY 00000240: PUSH1 0x00 00000242: DUP1 00000243: CALLDATASIZE 00000244: DUP4 00000245: DUP6 00000246: GAS 00000247: DELEGATECALL 00000248: RETURNDATASIZE 00000249: DUP1 0000024a: PUSH1 0x00 0000024c: DUP5 0000024d: RETURNDATACOPY 0000024e: DUP2 0000024f: DUP1 00000250: ISZERO 00000251: PUSH2 0x0258 00000254: JUMPI 00000255: DUP2 00000256: DUP5 00000257: RETURN 00000258: JUMPDEST 00000259: DUP2 0000025a: DUP5 0000025b: REVERT 0000025c: JUMPDEST 0000025d: PUSH32 0x337c729c04082e3bdd94ba7d2b5a8a642f3a138702366a91707825373a2029ba 0000027e: SLOAD 0000027f: SWAP1 00000280: JUMP 00000281: JUMPDEST 00000282: PUSH2 0x0289 00000285: PUSH2 0x025c 00000288: JUMP 00000289: JUMPDEST 0000028a: PUSH20 0xffffffffffffffffffffffffffffffffffffffff 0000029f: AND 000002a0: CALLER 000002a1: PUSH20 0xffffffffffffffffffffffffffffffffffffffff 000002b6: AND 000002b7: EQ 000002b8: PUSH2 0x02c0 000002bb: JUMPI 000002bc: PUSH1 0x00 000002be: DUP1 000002bf: REVERT 000002c0: JUMPDEST 000002c1: PUSH2 0x02c9 000002c4: DUP2 000002c5: PUSH2 0x04db 000002c8: JUMP 000002c9: JUMPDEST 000002ca: POP 000002cb: JUMP 000002cc: JUMPDEST 000002cd: PUSH2 0x02d4 000002d0: PUSH2 0x025c 000002d3: JUMP 000002d4: JUMPDEST 000002d5: PUSH20 0xffffffffffffffffffffffffffffffffffffffff 000002ea: AND 000002eb: CALLER 000002ec: PUSH20 0xffffffffffffffffffffffffffffffffffffffff 00000301: AND 00000302: EQ 00000303: PUSH2 0x030b 00000306: JUMPI 00000307: PUSH1 0x00 00000309: DUP1 0000030a: REVERT 0000030b: JUMPDEST 0000030c: PUSH2 0x0314 0000030f: DUP3 00000310: PUSH2 0x0281 00000313: JUMP 00000314: JUMPDEST 00000315: PUSH1 0x00 00000317: ADDRESS 00000318: PUSH20 0xffffffffffffffffffffffffffffffffffffffff 0000032d: AND 0000032e: CALLVALUE 0000032f: DUP4 00000330: PUSH1 0x40 00000332: MLOAD 00000333: DUP1 00000334: DUP3 00000335: DUP1 00000336: MLOAD 00000337: SWAP1 00000338: PUSH1 0x20 0000033a: ADD 0000033b: SWAP1 0000033c: DUP1 0000033d: DUP4 0000033e: DUP4 0000033f: JUMPDEST 00000340: PUSH1 0x20 00000342: DUP4 00000343: LT 00000344: PUSH2 0x037c 00000347: JUMPI 00000348: DUP1 00000349: MLOAD 0000034a: DUP3 0000034b: MSTORE 0000034c: PUSH32 0xffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffe0 0000036d: SWAP1 0000036e: SWAP3 0000036f: ADD 00000370: SWAP2 00000371: PUSH1 0x20 00000373: SWAP2 00000374: DUP3 00000375: ADD 00000376: SWAP2 00000377: ADD 00000378: PUSH2 0x033f 0000037b: JUMP 0000037c: JUMPDEST 0000037d: PUSH1 0x01 0000037f: DUP4 00000380: PUSH1 0x20 00000382: SUB 00000383: PUSH2 0x0100 00000386: EXP 00000387: SUB 00000388: DUP1 00000389: NOT 0000038a: DUP3 0000038b: MLOAD 0000038c: AND 0000038d: DUP2 0000038e: DUP5 0000038f: MLOAD 00000390: AND 00000391: DUP1 00000392: DUP3 00000393: OR 00000394: DUP6 00000395: MSTORE 00000396: POP 00000397: POP 00000398: POP 00000399: POP 0000039a: POP 0000039b: POP 0000039c: SWAP1 0000039d: POP 0000039e: ADD 0000039f: SWAP2 000003a0: POP 000003a1: POP 000003a2: PUSH1 0x00 000003a4: PUSH1 0x40 000003a6: MLOAD 000003a7: DUP1 000003a8: DUP4 000003a9: SUB 000003aa: DUP2 000003ab: DUP6 000003ac: DUP8 000003ad: GAS 000003ae: CALL 000003af: SWAP3 000003b0: POP 000003b1: POP 000003b2: POP 000003b3: RETURNDATASIZE 000003b4: DUP1 000003b5: PUSH1 0x00 000003b7: DUP2 000003b8: EQ 000003b9: PUSH2 0x03de 000003bc: JUMPI 000003bd: PUSH1 0x40 000003bf: MLOAD 000003c0: SWAP2 000003c1: POP 000003c2: PUSH1 0x1f 000003c4: NOT 000003c5: PUSH1 0x3f 000003c7: RETURNDATASIZE 000003c8: ADD 000003c9: AND 000003ca: DUP3 000003cb: ADD 000003cc: PUSH1 0x40 000003ce: MSTORE 000003cf: RETURNDATASIZE 000003d0: DUP3 000003d1: MSTORE 000003d2: RETURNDATASIZE 000003d3: PUSH1 0x00 000003d5: PUSH1 0x20 000003d7: DUP5 000003d8: ADD 000003d9: RETURNDATACOPY 000003da: PUSH2 0x03e3 000003dd: JUMP 000003de: JUMPDEST 000003df: PUSH1 0x60 000003e1: SWAP2 000003e2: POP 000003e3: JUMPDEST 000003e4: POP 000003e5: POP 000003e6: SWAP1 000003e7: POP 000003e8: DUP1 000003e9: PUSH2 0x03f1 000003ec: JUMPI 000003ed: PUSH1 0x00 000003ef: DUP1 000003f0: REVERT 000003f1: JUMPDEST 000003f2: POP 000003f3: POP 000003f4: POP 000003f5: JUMP 000003f6: JUMPDEST 000003f7: PUSH32 0x7050c9e0f4ca769c69bd3a8ef740bc37934f8e2c036e5a723fd8ee048ed3f8c3 00000418: SLOAD 00000419: SWAP1 0000041a: JUMP 0000041b: JUMPDEST 0000041c: PUSH2 0x0423 0000041f: PUSH2 0x025c 00000422: JUMP 00000423: JUMPDEST 00000424: PUSH20 0xffffffffffffffffffffffffffffffffffffffff 00000439: AND 0000043a: CALLER 0000043b: PUSH20 0xffffffffffffffffffffffffffffffffffffffff 00000450: AND 00000451: EQ 00000452: PUSH2 0x045a 00000455: JUMPI 00000456: PUSH1 0x00 00000458: DUP1 00000459: REVERT 0000045a: JUMPDEST 0000045b: PUSH20 0xffffffffffffffffffffffffffffffffffffffff 00000470: DUP2 00000471: AND 00000472: PUSH2 0x047a 00000475: JUMPI 00000476: PUSH1 0x00 00000478: DUP1 00000479: REVERT 0000047a: JUMPDEST 0000047b: PUSH32 0x5a3e66efaa1e445ebd894728a69d6959842ea1e97bd79b892797106e270efcd9 0000049c: PUSH2 0x04a3 0000049f: PUSH2 0x025c 000004a2: JUMP 000004a3: JUMPDEST 000004a4: PUSH1 0x40 000004a6: DUP1 000004a7: MLOAD 000004a8: PUSH20 0xffffffffffffffffffffffffffffffffffffffff 000004bd: SWAP3 000004be: DUP4 000004bf: AND 000004c0: DUP2 000004c1: MSTORE 000004c2: SWAP2 000004c3: DUP5 000004c4: AND 000004c5: PUSH1 0x20 000004c7: DUP4 000004c8: ADD 000004c9: MSTORE 000004ca: DUP1 000004cb: MLOAD 000004cc: SWAP2 000004cd: DUP3 000004ce: SWAP1 000004cf: SUB 000004d0: ADD 000004d1: SWAP1 000004d2: LOG1 000004d3: PUSH2 0x02c9 000004d6: DUP2 000004d7: PUSH2 0x056e 000004da: JUMP 000004db: JUMPDEST 000004dc: PUSH1 0x00 000004de: PUSH2 0x04e5 000004e1: PUSH2 0x03f6 000004e4: JUMP 000004e5: JUMPDEST 000004e6: SWAP1 000004e7: POP 000004e8: DUP2 000004e9: PUSH20 0xffffffffffffffffffffffffffffffffffffffff 000004fe: AND 000004ff: DUP2 00000500: PUSH20 0xffffffffffffffffffffffffffffffffffffffff 00000515: AND 00000516: EQ 00000517: ISZERO 00000518: PUSH2 0x0520 0000051b: JUMPI 0000051c: PUSH1 0x00 0000051e: DUP1 0000051f: REVERT 00000520: JUMPDEST 00000521: PUSH2 0x0529 00000524: DUP3 00000525: PUSH2 0x0592 00000528: JUMP 00000529: JUMPDEST 0000052a: PUSH1 0x40 0000052c: MLOAD 0000052d: PUSH20 0xffffffffffffffffffffffffffffffffffffffff 00000542: DUP4 00000543: AND 00000544: SWAP1 00000545: PUSH32 0xbc7cd75a20ee27fd9adebab32041f755214dbc6bffa90cc0225b39da2e5c2d3b 00000566: SWAP1 00000567: PUSH1 0x00 00000569: SWAP1 0000056a: LOG2 0000056b: POP 0000056c: POP 0000056d: JUMP 0000056e: JUMPDEST 0000056f: PUSH32 0x337c729c04082e3bdd94ba7d2b5a8a642f3a138702366a91707825373a2029ba 00000590: SSTORE 00000591: JUMP 00000592: JUMPDEST 00000593: PUSH32 0x7050c9e0f4ca769c69bd3a8ef740bc37934f8e2c036e5a723fd8ee048ed3f8c3 000005b4: SSTORE 000005b5: JUMP 000005b6: INVALID 000005b7: LOG2 000005b8: PUSH5 0x6970667358 000005be: UNKNOWN(0x22) 000005bf: SLT 000005c0: KECCAK256 000005c1: UNKNOWN(0xF8) 000005c2: UNKNOWN(0xC6) 000005c3: JUMPDEST 000005c4: PUSH29 0xbfe4f6ad1566e8960f452411065b8d9ce5dc55efee716cf2fa3798e564 000005e2: PUSH20
Warning: This is a nightly build of Foundry. It is recommended to use the latest stable version. To mute this warning set `FOUNDRY_DISABLE_NIGHTLY_WARNING` in your environment.
| Severity | Category | Tool | Title | Confidence | Validated | Confirmed | Details |
|---|---|---|---|---|---|---|---|
| high | upgradeability | detector | Untrusted DELEGATECALL target reachable | 55 | no | no |
viewtrace_id: 0x184ca8a3549726ed2e98b06415f4a8c90dad60a0948f70bc8e3bf8deb75f98fc
validation_json{
"sink": "DELEGATECALL",
"errors": 0,
"status": "unknown",
"attempts": 60,
"trace_id": "0x184ca8a3549726ed2e98b06415f4a8c90dad60a0948f70bc8e3bf8deb75f98fc",
"confirmed": false,
"trace_mode": "callTracer",
"call_targets": null,
"matched_probe": null,
"target_varies": null,
"classification": "no_sink"
}
witness_json{
"notes": "heuristic witness; entrypoints are best-effort selectors with zeroed calldata",
"constraints": [],
"entrypoints": [
{
"calldata": "0x4f1ef286",
"selector": "0x4f1ef286",
"calldata_variants": [
"0x4f1ef286",
"0x4f1ef2860000000000000000000000000000000000000000000000000000000000000000"
]
},
{
"calldata": "0x5c60da1b",
"selector": "0x5c60da1b",
"calldata_variants": [
"0x5c60da1b",
"0x5c60da1b0000000000000000000000000000000000000000000000000000000000000000"
]
},
{
"calldata": "0xf1739cae",
"selector": "0xf1739cae",
"calldata_variants": [
"0xf1739cae",
"0xf1739cae0000000000000000000000000000000000000000000000000000000000000000"
]
},
{
"calldata": "0x025313a2",
"selector": "0x025313a2",
"calldata_variants": [
"0x025313a2",
"0x025313a20000000000000000000000000000000000000000000000000000000000000000"
]
},
{
"calldata": "0x3659cfe6",
"selector": "0x3659cfe6",
"calldata_variants": [
"0x3659cfe6",
"0x3659cfe60000000000000000000000000000000000000000000000000000000000000000"
]
}
]
}
evidence_json{
"examples": [
{
"pc": 583,
"opcode": "DELEGATECALL",
"returndata_checked": null,
"value_expression_category": "n/a",
"target_expression_category": "computed"
}
],
"guards_detected": [
{
"pc": 672,
"type": "msg_sender_eq_const",
"value": "0xffffffffffffffffffffffffffffffffffffffff"
},
{
"pc": 747,
"type": "msg_sender_eq_const",
"value": "0xffffffffffffffffffffffffffffffffffffffff"
},
{
"pc": 1082,
"type": "msg_sender_eq_const",
"value": "0xffffffffffffffffffffffffffffffffffffffff"
}
],
"delegatecall_count": 1,
"untrusted_delegatecall_count": 1
}
|
| medium | other | detector | ETH value transfer possible | 40 | no | no |
viewtrace_id: 0xce99d54b527a1a8502015c3d483a3ed25dabef66e055d187a6180f224de4785e
call_targets:
0x0baba1ad5be3a5c0a66e7ac838a129bf948f1ea4
target_varies:
no
classification:
constant_target
validation_json{
"sink": "CALL",
"errors": 0,
"status": "sink_reached",
"attempts": 1,
"trace_id": "0xce99d54b527a1a8502015c3d483a3ed25dabef66e055d187a6180f224de4785e",
"confirmed": false,
"trace_mode": "callTracer",
"call_targets": [
"0x0baba1ad5be3a5c0a66e7ac838a129bf948f1ea4"
],
"matched_probe": null,
"target_varies": false,
"classification": "constant_target"
}
witness_json{
"notes": "heuristic witness; entrypoints are best-effort selectors with zeroed calldata",
"constraints": [],
"entrypoints": [
{
"calldata": "0x4f1ef286",
"selector": "0x4f1ef286",
"calldata_variants": [
"0x4f1ef286",
"0x4f1ef2860000000000000000000000000000000000000000000000000000000000000000"
]
},
{
"calldata": "0x5c60da1b",
"selector": "0x5c60da1b",
"calldata_variants": [
"0x5c60da1b",
"0x5c60da1b0000000000000000000000000000000000000000000000000000000000000000"
]
},
{
"calldata": "0xf1739cae",
"selector": "0xf1739cae",
"calldata_variants": [
"0xf1739cae",
"0xf1739cae0000000000000000000000000000000000000000000000000000000000000000"
]
},
{
"calldata": "0x025313a2",
"selector": "0x025313a2",
"calldata_variants": [
"0x025313a2",
"0x025313a20000000000000000000000000000000000000000000000000000000000000000"
]
},
{
"calldata": "0x3659cfe6",
"selector": "0x3659cfe6",
"calldata_variants": [
"0x3659cfe6",
"0x3659cfe60000000000000000000000000000000000000000000000000000000000000000"
]
}
]
}
evidence_json{
"examples": [
{
"pc": 942,
"opcode": "CALL",
"returndata_checked": null,
"value_expression_category": "computed",
"target_expression_category": "computed"
}
],
"eth_value_calls": 1,
"guards_detected": [
{
"pc": 672,
"type": "msg_sender_eq_const",
"value": "0xffffffffffffffffffffffffffffffffffffffff"
},
{
"pc": 747,
"type": "msg_sender_eq_const",
"value": "0xffffffffffffffffffffffffffffffffffffffff"
},
{
"pc": 1082,
"type": "msg_sender_eq_const",
"value": "0xffffffffffffffffffffffffffffffffffffffff"
}
]
}
|
| medium | other | detector | Untrusted CALL target/value reachable | 45 | no | no |
viewtrace_id: 0xce99d54b527a1a8502015c3d483a3ed25dabef66e055d187a6180f224de4785e
call_targets:
0x0baba1ad5be3a5c0a66e7ac838a129bf948f1ea4
target_varies:
no
classification:
constant_target
validation_json{
"sink": "CALL",
"errors": 0,
"status": "sink_reached",
"attempts": 1,
"trace_id": "0xce99d54b527a1a8502015c3d483a3ed25dabef66e055d187a6180f224de4785e",
"confirmed": false,
"trace_mode": "callTracer",
"call_targets": [
"0x0baba1ad5be3a5c0a66e7ac838a129bf948f1ea4"
],
"matched_probe": null,
"target_varies": false,
"classification": "constant_target"
}
witness_json{
"notes": "heuristic witness; entrypoints are best-effort selectors with zeroed calldata",
"constraints": [],
"entrypoints": [
{
"calldata": "0x4f1ef286",
"selector": "0x4f1ef286",
"calldata_variants": [
"0x4f1ef286",
"0x4f1ef2860000000000000000000000000000000000000000000000000000000000000000"
]
},
{
"calldata": "0x5c60da1b",
"selector": "0x5c60da1b",
"calldata_variants": [
"0x5c60da1b",
"0x5c60da1b0000000000000000000000000000000000000000000000000000000000000000"
]
},
{
"calldata": "0xf1739cae",
"selector": "0xf1739cae",
"calldata_variants": [
"0xf1739cae",
"0xf1739cae0000000000000000000000000000000000000000000000000000000000000000"
]
},
{
"calldata": "0x025313a2",
"selector": "0x025313a2",
"calldata_variants": [
"0x025313a2",
"0x025313a20000000000000000000000000000000000000000000000000000000000000000"
]
},
{
"calldata": "0x3659cfe6",
"selector": "0x3659cfe6",
"calldata_variants": [
"0x3659cfe6",
"0x3659cfe60000000000000000000000000000000000000000000000000000000000000000"
]
}
]
}
evidence_json{
"examples": [
{
"pc": 942,
"opcode": "CALL",
"returndata_checked": null,
"value_expression_category": "computed",
"target_expression_category": "computed"
}
],
"call_count": 1,
"guards_detected": [
{
"pc": 672,
"type": "msg_sender_eq_const",
"value": "0xffffffffffffffffffffffffffffffffffffffff"
},
{
"pc": 747,
"type": "msg_sender_eq_const",
"value": "0xffffffffffffffffffffffffffffffffffffffff"
},
{
"pc": 1082,
"type": "msg_sender_eq_const",
"value": "0xffffffffffffffffffffffffffffffffffffffff"
}
],
"untrusted_call_count": 1
}
|