Capture The Flag
-
#3. Burn Mandiri Token Anak Bangsat !!!
https://goerli.etherscan.io/address/0x4f252dbe5fd366b38842cd500281932746047299
Exploit in Forge = $150 (+ $100 for publish and exploit in goerli)
Helper:
1. You can use the sample format https://github.com/sysfixed/forge_solidity_exploit_format_example (forge for virtual simulation transaction, don't forget to change the block that will be used)
2. You are asked to {save or exploit} liquidity before the dev (minimum 0.9 ETH from swap profits include fee)
3. A valid exploit must be executed in 1 transaction (at least you can run it in a virtual forge)
4. If the amount of liquidity decreases, you can still use the save block 8500065 "goerli" (the block after the Token Anak Bangsat contract is created)
5. Prizes are only given to the fastest, (can be 2 people because it's on virtual forge ($150) and published to goerli ($100))
6. Smart contract made in forge and goerli will allow different
7. To claim a prize, you must make a valid PoC first !Clue:
1. You have to use Flashloan / Flashswap
2. Use your math logicExample of a valid exploit result:
Winner(Forge + Goerli = $250) : https://gist.github.com/MrFatoni/65a72805475e866225c2c91f02d48b5a (M Rizky Fathoni)
Tx Goerli : https://goerli.etherscan.io/tx/0x1b88590c515e492e15c06b2b65c60adcf87ef057c67912e545f98bb2cc4e4ec8
-
#2. Save the Evil Badex {WETH} Liquidity ~ Take it before the dev
https://goerli.etherscan.io/address/0x9255590C2e66aBb441A9b19A8c518E12FBD5c4d3
Exploit in Forge = $150 (+ $50 for publish and exploit in goerli) (Link Post)
Helper:
1. You can use the sample format https://github.com/sysfixed/forge_solidity_exploit_format_example (forge for virtual simulation transaction)
2. You are asked to {save or exploit} liquidity before the dev (minimum 0.08 ETH (80%) from swap profits)
3. A valid exploit must be executed in 1 transaction (at least you can run it in a virtual forge)
4. If the amount of liquidity decreases, you can still use the save block 8489831 "goerli" (the block after the Evil Badex contract is created)
5. Prizes are only given to the fastest, (can be 2 people because it's on virtual forge ($150) and published to goerli ($50))
6. Smart contract made in forge and goerli will allow different
7. To claim a prize, you must make a valid PoC first !Example of a valid exploit result:
Winner 1 (Forge -> $150) : https://gist.github.com/MrFatoni/da7a66e2a1f4e76b2db1aa643c35858f (M Rizky Fathoni)
Writeup 1 : https://gist.github.com/MrFatoni/e6014a0643c6c5632ef38057c5368756
Winner 2 (Goerli -> $50) : https://goerli.etherscan.io/tx/0x50cefde65fb27d2fab5fccc9f8044815e471d9afe85269c9f16c99735165f052 (Prada)
-
#1. Get the Badex Token
https://goerli.etherscan.io/token/0x0c8ac4d5b1e6717d7fd0476dc84249f8de6a54ea#balances
1 Badex Token = $150 USDT (only 1 fastest person / Link Post)
Winner : https://goerli.etherscan.io/tx/0x332957f84eb375d626e75bac779d3fab110491f5c595373feeabcbf86db85c61 (M Rizky Fathoni)
Writeup : https://mirror.xyz/mrfatoni.eth/5BPFoGJSmTfBJeuAA_8aFkERLZY7cXHbB0r6Y2Ej-QA