019b477e-aa69-7298-a3c6-e52bd14408f9
Open this run to answer one question: is this real attacker-relevant behavior with real impact, or just normal contract plumbing?
| ID | Type | Status | Attempts | Heartbeat |
|---|---|---|---|---|
| 20823 | artifact.fetch | complete | 1 / 3 | 3 months ago |
| 20824 | tool.cast_disasm | complete | 1 / 3 | 3 months ago |
| 64274 | analysis.bundle | complete | 1 / 3 | 1 week ago |
| 64275 | capability.graph | complete | 1 / 3 | 1 week ago |
| 64276 | detector.run | complete | 1 / 3 | 1 week ago |
| 64277 | validation.fork | complete | 1 / 3 | 1 week ago |
No slither job recorded yet.
No codex job recorded yet.
00000000: PUSH1 0x60 00000002: PUSH1 0x40 00000004: MSTORE 00000005: CALLDATASIZE 00000006: ISZERO 00000007: PUSH2 0x003f 0000000a: JUMPI 0000000b: PUSH1 0x00 0000000d: CALLDATALOAD 0000000e: PUSH29 0x0100000000000000000000000000000000000000000000000000000000 0000002c: SWAP1 0000002d: DIV 0000002e: PUSH4 0xffffffff 00000033: AND 00000034: DUP1 00000035: PUSH4 0x6ea056a9 0000003a: EQ 0000003b: PUSH2 0x0043 0000003e: JUMPI 0000003f: JUMPDEST 00000040: JUMPDEST 00000041: JUMPDEST 00000042: STOP 00000043: JUMPDEST 00000044: CALLVALUE 00000045: ISZERO 00000046: PUSH2 0x004e 00000049: JUMPI 0000004a: PUSH1 0x00 0000004c: DUP1 0000004d: REVERT 0000004e: JUMPDEST 0000004f: PUSH2 0x0083 00000052: PUSH1 0x04 00000054: DUP1 00000055: DUP1 00000056: CALLDATALOAD 00000057: PUSH20 0xffffffffffffffffffffffffffffffffffffffff 0000006c: AND 0000006d: SWAP1 0000006e: PUSH1 0x20 00000070: ADD 00000071: SWAP1 00000072: SWAP2 00000073: SWAP1 00000074: DUP1 00000075: CALLDATALOAD 00000076: SWAP1 00000077: PUSH1 0x20 00000079: ADD 0000007a: SWAP1 0000007b: SWAP2 0000007c: SWAP1 0000007d: POP 0000007e: POP 0000007f: PUSH2 0x009d 00000082: JUMP 00000083: JUMPDEST 00000084: PUSH1 0x40 00000086: MLOAD 00000087: DUP1 00000088: DUP3 00000089: ISZERO 0000008a: ISZERO 0000008b: ISZERO 0000008c: ISZERO 0000008d: DUP2 0000008e: MSTORE 0000008f: PUSH1 0x20 00000091: ADD 00000092: SWAP2 00000093: POP 00000094: POP 00000095: PUSH1 0x40 00000097: MLOAD 00000098: DUP1 00000099: SWAP2 0000009a: SUB 0000009b: SWAP1 0000009c: RETURN 0000009d: JUMPDEST 0000009e: PUSH1 0x00 000000a0: DUP1 000000a1: DUP1 000000a2: SWAP1 000000a3: SLOAD 000000a4: SWAP1 000000a5: PUSH2 0x0100 000000a8: EXP 000000a9: SWAP1 000000aa: DIV 000000ab: PUSH20 0xffffffffffffffffffffffffffffffffffffffff 000000c0: AND 000000c1: PUSH20 0xffffffffffffffffffffffffffffffffffffffff 000000d6: AND 000000d7: PUSH4 0x3c18d318 000000dc: DUP5 000000dd: PUSH1 0x00 000000df: PUSH1 0x40 000000e1: MLOAD 000000e2: PUSH1 0x20 000000e4: ADD 000000e5: MSTORE 000000e6: PUSH1 0x40 000000e8: MLOAD 000000e9: DUP3 000000ea: PUSH4 0xffffffff 000000ef: AND 000000f0: PUSH29 0x0100000000000000000000000000000000000000000000000000000000 0000010e: MUL 0000010f: DUP2 00000110: MSTORE 00000111: PUSH1 0x04 00000113: ADD 00000114: DUP1 00000115: DUP3 00000116: PUSH20 0xffffffffffffffffffffffffffffffffffffffff 0000012b: AND 0000012c: PUSH20 0xffffffffffffffffffffffffffffffffffffffff 00000141: AND 00000142: DUP2 00000143: MSTORE 00000144: PUSH1 0x20 00000146: ADD 00000147: SWAP2 00000148: POP 00000149: POP 0000014a: PUSH1 0x20 0000014c: PUSH1 0x40 0000014e: MLOAD 0000014f: DUP1 00000150: DUP4 00000151: SUB 00000152: DUP2 00000153: PUSH1 0x00 00000155: DUP8 00000156: DUP1 00000157: EXTCODESIZE 00000158: ISZERO 00000159: ISZERO 0000015a: PUSH2 0x0162 0000015d: JUMPI 0000015e: PUSH1 0x00 00000160: DUP1 00000161: REVERT 00000162: JUMPDEST 00000163: PUSH2 0x02c6 00000166: GAS 00000167: SUB 00000168: CALL 00000169: ISZERO 0000016a: ISZERO 0000016b: PUSH2 0x0173 0000016e: JUMPI 0000016f: PUSH1 0x00 00000171: DUP1 00000172: REVERT 00000173: JUMPDEST 00000174: POP 00000175: POP 00000176: POP 00000177: PUSH1 0x40 00000179: MLOAD 0000017a: DUP1 0000017b: MLOAD 0000017c: SWAP1 0000017d: POP 0000017e: PUSH20 0xffffffffffffffffffffffffffffffffffffffff 00000193: AND 00000194: PUSH1 0x00 00000196: CALLDATASIZE 00000197: PUSH1 0x40 00000199: MLOAD 0000019a: DUP1 0000019b: DUP4 0000019c: DUP4 0000019d: DUP1 0000019e: DUP3 0000019f: DUP5 000001a0: CALLDATACOPY 000001a1: DUP3 000001a2: ADD 000001a3: SWAP2 000001a4: POP 000001a5: POP 000001a6: SWAP3 000001a7: POP 000001a8: POP 000001a9: POP 000001aa: PUSH1 0x00 000001ac: PUSH1 0x40 000001ae: MLOAD 000001af: DUP1 000001b0: DUP4 000001b1: SUB 000001b2: DUP2 000001b3: DUP6 000001b4: PUSH2 0x646e 000001b7: GAS 000001b8: SUB 000001b9: DELEGATECALL 000001ba: SWAP2 000001bb: POP 000001bc: POP 000001bd: SWAP1 000001be: POP 000001bf: JUMPDEST 000001c0: SWAP3 000001c1: SWAP2 000001c2: POP 000001c3: POP 000001c4: JUMP 000001c5: STOP 000001c6: LOG1 000001c7: PUSH6 0x627a7a723058 000001ce: KECCAK256 000001cf: PUSH17 0xfb89734e986e0a9047d4f31a852f7dee61 000001e1: UNKNOWN(0xDF) 000001e2: PUSH2 0x445b 000001e5: UNKNOWN(0xAD) 000001e6: UNKNOWN(0x24) 000001e7: DUP5 000001e8: REVERT 000001e9: PUSH11
| Severity | Category | Tool | Title | Confidence | Validated | Confirmed | Details |
|---|---|---|---|---|---|---|---|
| critical | upgradeability | detector | Untrusted DELEGATECALL target reachable | 70 | no | no |
viewtrace_id: 0xaef514227ccf3793440fbf3e9465dcf12db72699c21cd4a17027592dc1b388de
call_targets:
0x48cd9c3eab67c535291250b8e785fb6d43b1dba9
target_varies:
no
classification:
constant_target
validation_json{
"sink": "DELEGATECALL",
"errors": 0,
"status": "sink_reached",
"attempts": 13,
"trace_id": "0xaef514227ccf3793440fbf3e9465dcf12db72699c21cd4a17027592dc1b388de",
"confirmed": false,
"trace_mode": "callTracer",
"call_targets": [
"0x48cd9c3eab67c535291250b8e785fb6d43b1dba9"
],
"matched_probe": null,
"target_varies": false,
"classification": "constant_target"
}
witness_json{
"notes": "heuristic witness; entrypoints are best-effort selectors with zeroed calldata",
"constraints": [],
"entrypoints": [
{
"calldata": "0xffffffff",
"selector": "0xffffffff",
"calldata_variants": [
"0xffffffff",
"0xffffffff0000000000000000000000000000000000000000000000000000000000000000"
]
},
{
"calldata": "0x6ea056a9",
"selector": "0x6ea056a9",
"calldata_variants": [
"0x6ea056a9",
"0x6ea056a90000000000000000000000000000000000000000000000000000000000000000"
]
}
]
}
evidence_json{
"examples": [
{
"pc": 441,
"opcode": "DELEGATECALL",
"returndata_checked": null,
"value_expression_category": "n/a",
"target_expression_category": "computed"
}
],
"guards_detected": [],
"delegatecall_count": 1,
"untrusted_delegatecall_count": 1
}
|
| high | other | detector | Untrusted CALL target/value reachable | 60 | no | no |
viewtrace_id: 0xb675ffc6c25e79e0e358a4ea3272ddecdd2c183e07698b8f58e5aa05c34b53e3
call_targets:
0xebf0a2db8d62f8ee659c40ba050551ed899b85af
target_varies:
no
classification:
constant_target
validation_json{
"sink": "CALL",
"errors": 0,
"status": "sink_reached",
"attempts": 1,
"trace_id": "0xb675ffc6c25e79e0e358a4ea3272ddecdd2c183e07698b8f58e5aa05c34b53e3",
"confirmed": false,
"trace_mode": "callTracer",
"call_targets": [
"0xebf0a2db8d62f8ee659c40ba050551ed899b85af"
],
"matched_probe": null,
"target_varies": false,
"classification": "constant_target"
}
witness_json{
"notes": "heuristic witness; entrypoints are best-effort selectors with zeroed calldata",
"constraints": [],
"entrypoints": [
{
"calldata": "0xffffffff",
"selector": "0xffffffff",
"calldata_variants": [
"0xffffffff",
"0xffffffff0000000000000000000000000000000000000000000000000000000000000000"
]
},
{
"calldata": "0x6ea056a9",
"selector": "0x6ea056a9",
"calldata_variants": [
"0x6ea056a9",
"0x6ea056a90000000000000000000000000000000000000000000000000000000000000000"
]
}
]
}
evidence_json{
"examples": [
{
"pc": 360,
"opcode": "CALL",
"returndata_checked": null,
"value_expression_category": "computed",
"target_expression_category": "computed"
}
],
"call_count": 1,
"guards_detected": [],
"untrusted_call_count": 1
}
|
| high | other | detector | ETH value transfer possible | 55 | no | no |
viewtrace_id: 0xb675ffc6c25e79e0e358a4ea3272ddecdd2c183e07698b8f58e5aa05c34b53e3
call_targets:
0xebf0a2db8d62f8ee659c40ba050551ed899b85af
target_varies:
no
classification:
constant_target
validation_json{
"sink": "CALL",
"errors": 0,
"status": "sink_reached",
"attempts": 1,
"trace_id": "0xb675ffc6c25e79e0e358a4ea3272ddecdd2c183e07698b8f58e5aa05c34b53e3",
"confirmed": false,
"trace_mode": "callTracer",
"call_targets": [
"0xebf0a2db8d62f8ee659c40ba050551ed899b85af"
],
"matched_probe": null,
"target_varies": false,
"classification": "constant_target"
}
witness_json{
"notes": "heuristic witness; entrypoints are best-effort selectors with zeroed calldata",
"constraints": [],
"entrypoints": [
{
"calldata": "0xffffffff",
"selector": "0xffffffff",
"calldata_variants": [
"0xffffffff",
"0xffffffff0000000000000000000000000000000000000000000000000000000000000000"
]
},
{
"calldata": "0x6ea056a9",
"selector": "0x6ea056a9",
"calldata_variants": [
"0x6ea056a9",
"0x6ea056a90000000000000000000000000000000000000000000000000000000000000000"
]
}
]
}
evidence_json{
"examples": [
{
"pc": 360,
"opcode": "CALL",
"returndata_checked": null,
"value_expression_category": "computed",
"target_expression_category": "computed"
}
],
"eth_value_calls": 1,
"guards_detected": []
}
|