To understand why this is a backdoor we need to look at more code:
modifier ifAdmin() {
if (msg.sender == _admin()) {
_; // run the rest of the function being modified
} else {
// for our case this essentially does nothing
_fallback();
}
}
// imagine the code inside the function in place of the _ in ifAdmin
function upgradeTo(address newImplementation) external ifAdmin {
// actually upgrades the contract in place
_upgradeTo(newImplementation);
}
So this smart contract has the ability to upgrade itself in place if it is called by the administrator. This is widely accepted and normally a useful feature. As a gesture of goodwill a developer will relinquish control of the contract for a set amount of time via a timelock. During this time users can use the smart contract without worry that the developer will maliciously upgrade and steal their funds.
This can be seen here: https://bscscan.com/tx/0xecd169b3a299d28495cbc9bd22b5690e263...
So here it looks like the administrator was changed but as we know it actually didn't. Now users begin to use the platform and deposit funds.
Since the admin hasn't changed the developer calls upgradeTo and deploys a malicious change, seen here: https://bscscan.com/tx/0xf19fa4bcff4adaebeddd28c851458ba0f01...
This contract (https://bscscan.com/address/0xb2603fc47331e3500eaf053bd7a971...) is compiled so we can't easily see the source. This doesn't matter as we can easily see the resulting transactions (https://bscscan.com/tx/0x1332fadcc5378b1cc90159e603b99e0b73a... and https://bscscan.com/tx/0xd8145dfe255a671428b9c082a006a145fe5...).
Whats especially clever about this rug pull scam is that it is self contained. Instead of selling your tokens at an exchange which risks low liquidity and front running, the developer is in control the whole time and could have done this whenever he thought the deposits were enough.