If you enjoyed this, you might also like the (much more technical) writeup of the Ethereum pinball machine - https://medium.com/@kanewallmann_71759/an-untrustworthy-pinb...
It may assume some knowledge of things like etherscan and the EVM though.
It may assume some knowledge of things like etherscan and the EVM though.
It was a scam.
I wonder how it was done, Etherscan didn't show anything and compiling it led to a few bytes of difference between what was compiled and what was deployed.
Fortunately, there are tools like Ganache, which you can run with `ganache-cli --fork` to reliably emulate locally what will happen when transactions are sent to mainnet. I would accept no substitute approach when dealing with suspect contracts.
[1]: Like this Unicode RLO exploit for instance: https://krebsonsecurity.com/2021/11/trojan-source-bug-threat...
[2]: https://tenderly.co or mainnet forking using hardhat are convenient ways to achieve this.