Level 1
Noob Hacker
Ethernaut 18
Recovery
0 / 100 EXP
100 EXP to Junior Hacker
0%
Unlocked hints
Recovery
0/3
Unlock a hint to view it here.
// SPDX-License-Identifier: MIT
pragma solidity ^0.8.0;
contract SimpleToken {
string public name;
mapping(address => uint256) public balances;
address public owner;
constructor(string memory tokenName, address creator, uint256 initialSupply) payable {
name = tokenName;
balances[creator] = initialSupply;
owner = creator;
}
function destroy(address payable recipient) external {
require(msg.sender == owner, "SimpleToken: owner only");
selfdestruct(recipient);
}
}
/// @notice Adapted from OpenZeppelin Ethernaut level 17. A generated token has
/// no retained address; learners must derive its CREATE address.
contract Recovery {
function generateToken(string memory name, uint256 initialSupply) external payable {
new SimpleToken{value: msg.value}(name, msg.sender, initialSupply);
}
}
Starter exploit
Exploit.s.sol
// TODO: implement the exploit.
function run() external {
vm.startBroadcast(PLAYER_PRIVATE_KEY);
vm.stopBroadcast();
}
Ready to test your exploit?
The starter code is yours to inspect. Sign in to edit it, run Foundry, and keep every clear.
Contract line
Add audit note
0 / 300
CTF tour
Exploit Challenge
This is your guided Solidity CTF workspace.
Keep your audit trail
Sign in to save private notes on contract lines and continue your review later.
Delete this audit note?
This removes it permanently from your private workspace.
