-
Notifications
You must be signed in to change notification settings - Fork 7
token transfer from SA COA to fraudulentFlowTokenReceiver vault #432
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
vishalchangrani
wants to merge
2
commits into
main
Choose a base branch
from
vishal/jan-29-token-transfer
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
Changes from all commits
Commits
Show all changes
2 commits
Select commit
Hold shift + click to select a range
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,7 @@ | ||
| ## Jan 29th - Service account token transfers | ||
|
|
||
| ## Transaction to move all FLOW from the Service Account COA to its cadence vault | ||
|
|
||
| ### Result | ||
| Failure: | ||
| Success:https://www.flowscan.io/tx/18534e04ed3fa66d2e9f11cfa011d501adeac8006bd0a72a105c6968ed73a343 |
30 changes: 30 additions & 0 deletions
30
transactions/withdraw-fraudulent-tokens/jan-29/withdraw_FLOW_from_coa.cdc
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,30 @@ | ||
| import EVM from 0xe467b9dd11fa00df | ||
| import FungibleToken from 0xf233dcee88fe0abe | ||
| import FlowToken from 0x1654653399040a61 | ||
| transaction() { | ||
| let sentVault: @FlowToken.Vault | ||
| let receiver: &{FungibleToken.Receiver} | ||
|
|
||
| prepare(signer: auth(BorrowValue) &Account) { | ||
| // Borrow a reference to the COA from the storage location we saved it to with the `EVM.Withdraw` entitlement | ||
| let coa = signer.storage.borrow<auth(EVM.Withdraw) &EVM.CadenceOwnedAccount>( | ||
| from: /storage/evm | ||
| ) ?? panic("Could not borrow reference to the signer's CadenceOwnedAccount (COA). " | ||
| .concat("Ensure the signer account has a COA stored in the canonical /storage/evm path")) | ||
|
|
||
| // We must create a `EVM.Balance` struct to represent the amount of Flow tokens to withdraw | ||
| let withdrawBalance = coa.balance() | ||
|
|
||
| // Withdraw the balance from the COA, we will use this later to deposit into the receiving account | ||
| self.sentVault <- coa.withdraw(balance: withdrawBalance) as! @FlowToken.Vault | ||
|
|
||
| // Borrow the public capability to the receiving account (in this case the signer's own Vault) | ||
| // This script could be modified to deposit into any account with a `FungibleToken.Receiver` capability | ||
| self.receiver = signer.capabilities.borrow<&{FungibleToken.Receiver}>(/public/fraudulentFlowTokenReceiver)! | ||
| } | ||
|
|
||
| execute { | ||
| // Deposit the withdrawn tokens into the receiving vault | ||
| self.receiver.deposit(from: <-self.sentVault) | ||
| } | ||
| } | ||
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Are we sure that the entire balance of the service account COA is FLOW that we want to destroy? Is there any non-fraudulent FLOW in there?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
yes. we've only transferred fraudulent tokens into the COA. these tokens were the proceeds from swapping USD stables that were originally bought with counterfeit flow