Get the free 30-day AI Mastery series 💌: https://insights.gradientlabs.co/
Work with me 💪: https://offerings.gradientlabs.co/ Next up! Level 6 - Delegation
In this CTF series, we’re going to learn more about the practical side of smart contract auditing and security.
If you’re interested in more/similar content, checkout my channel or website below.
My digital dumping ground - dylandavis.net
Additional Resources
Ethernaut CTF - https://ethernaut.openzeppelin.com/
Web3 Blockchain Developer (Delegation challenge) - • Smart Contract Security - Ethernaut Challe...
Sigma Prime Delegatecall vulnerabilities - https://blog.sigmaprime.io/solidity-s...
Mastering Ethereum Book (same as above) - https://github.com/ethereumbook/ether...
Smart Contract Developer (2-part series) - • Unsafe Delegatecall (part 1) | Hack Solidi...
Code for above 2-part series - https://solidity-by-example.org/hacks...
Blog for exploiting delegate call - https://www.derekarends.com/solidity-...
Corresponding video for above blog - • Solidity: delegatecall vulnerabilities
Delegatecall Solidity Docs - https://docs.soliditylang.org/en/v0.8...
Stack Exchange (best definition) - https://ethereum.stackexchange.com/qu...
Proxy Contracts (upgradable contracts) - https://blog.openzeppelin.com/proxy-p...
Flaws in proxy pattern (Trail of bits) - https://blog.trailofbits.com/2018/09/...
State variable ordering explanation - https://blockchain-academy.hs-mittwei...
Timeline
00:00 - Intro to challenge
01:37 - Resource sharing
05:52 - Delegatecalls explained
09:06 - How is delegatecall used
12:13 - Flaws in delegatecall
16:58 - Code Review
21:18 - Solving challenge
26:25 - Outro