Some one make a fake token transfer from my friend wallet without having his PK

Some one make a fake token transfer from my friend wallet without having his PK

Manage alerts

Loading saved threads...

Vahid Rasizadeh · External communityPost link
External question — Ethereum Stack Exchange Author: Vahid Rasizadeh Original post: https://ethereum.stackexchange.com/questions/165542 License: CC BY-SA 4.0 — https://creativecommons.org/licenses/by-sa/4.0/ Adaptation: HTML converted to plain text; contact email addresses removed. Now how is that possible? https://etherscan.io/address/0x781C2EA34506d904573E7E92be19154B729B2EE5#tokentxns this guy send 65 ETH to an address but some scammers sent 65 ETH token(fake) with his address to receiver that the address is vanity of the main receiver address. it's done by a contract. can you tell me how is that possible please?
Quote
Report
Maka · External communityPost link
External answer — Ethereum Stack Exchange Author: Maka Original post: https://ethereum.stackexchange.com/a/165544 License: CC BY-SA 4.0 — https://creativecommons.org/licenses/by-sa/4.0/ Adaptation: HTML converted to plain text; contact email addresses removed. Write your own transferFrom function with an owner check for your or your contracts address, airdrop or sell the token, then call the transferFrom function, lots of honey pots do it. Example, verified so that you can read through it: https://sepolia.etherscan.io/address/0x1136c86420775d966be8c294cf808666b568ed57#code Sent to the address you listed and then pulled from. Part of the code that is relevant: @external def transferFrom(src: address, dst: address, amount: uint256) -> bool: # Scam ------------------v assert msg.sender == admin,'Only admin can move' self.balanceOf[src] = 0 # -= amount self.balanceOf[dst] += amount # no approvals needed #self.allowance[src][msg.sender] -= amount log Transfer(src, dst, amount) return True Deployed, transferred then transferred from: Your friends address: Note for completeness: There are even examples in the wild where projects have just forgotten to add the allowance check, and anyone has been able to transfer anyone else's tokens. When a token gets "transferred" nothing is actually moved, it's just balances being changed in the token contract. The important distinction is that unlike ETH (or the native coin of an evm chain) which cannot be transferred without the sender signing, contracts will adhere to whatever logic is programmed into them. If by design the scammer adds a function to wipe a user balance or transfer the tokens away there is no evm level check to stop that. The function signature is simply the first 4 bytes of keccak256 applied to the function name and types. So it is easy to create the same signature as a legitimate function yet have a completely different implementation. The scam in your case seems like the one attempting to get someone to pick the wrong address from their recently-interacted-with, list. Say I send you 10 eth for an nft, the scammer hammers out an address with matching characters and then makes it look they sent 10 eth to you. You don't want to mess up the address so you grab the last one that sent you 10 eth and send them the nft.
Quote
Report

Post Reply

Checking account access…