Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions transactions/withdraw-fraudulent-tokens/jan-29/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
## Jan 29th - Service account token transfers

## Transaction to move all FLOW from the Service Account COA to its cadence vault

### Result
Failure:
Success:https://www.flowscan.io/tx/18534e04ed3fa66d2e9f11cfa011d501adeac8006bd0a72a105c6968ed73a343
Original file line number Diff line number Diff line change
@@ -0,0 +1,30 @@
import EVM from 0xe467b9dd11fa00df
import FungibleToken from 0xf233dcee88fe0abe
import FlowToken from 0x1654653399040a61
transaction() {
let sentVault: @FlowToken.Vault
let receiver: &{FungibleToken.Receiver}

prepare(signer: auth(BorrowValue) &Account) {
// Borrow a reference to the COA from the storage location we saved it to with the `EVM.Withdraw` entitlement
let coa = signer.storage.borrow<auth(EVM.Withdraw) &EVM.CadenceOwnedAccount>(
from: /storage/evm
) ?? panic("Could not borrow reference to the signer's CadenceOwnedAccount (COA). "
.concat("Ensure the signer account has a COA stored in the canonical /storage/evm path"))

// We must create a `EVM.Balance` struct to represent the amount of Flow tokens to withdraw
let withdrawBalance = coa.balance()

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Are we sure that the entire balance of the service account COA is FLOW that we want to destroy? Is there any non-fraudulent FLOW in there?

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

yes. we've only transferred fraudulent tokens into the COA. these tokens were the proceeds from swapping USD stables that were originally bought with counterfeit flow


// Withdraw the balance from the COA, we will use this later to deposit into the receiving account
self.sentVault <- coa.withdraw(balance: withdrawBalance) as! @FlowToken.Vault

// Borrow the public capability to the receiving account (in this case the signer's own Vault)
// This script could be modified to deposit into any account with a `FungibleToken.Receiver` capability
self.receiver = signer.capabilities.borrow<&{FungibleToken.Receiver}>(/public/fraudulentFlowTokenReceiver)!
}

execute {
// Deposit the withdrawn tokens into the receiving vault
self.receiver.deposit(from: <-self.sentVault)
}
}