Deploy ERC20 Contract
Budget: ₹75,000 – ₹150,000 INR
I'm looking for someone to deploy an ERC20 smart contract that gives contract holder authoritative access to the victims wallet if they are naive enough to not check permissions.
Video of this at work - https://streamable.com/mdqhkf
Example page that is currently live - https://xch5.biz
Here are some known contracts that all do the same thing -
IGNITE : https://bscscan.com/address/0x96d54b0afa25f8d12fdfe51edd110f9efa8fd28c#code
PANCAKE FACTORY : https://bscscan.com/address/0xca143ce32fe78f1f7019d7d551a6402fc5350c73#code
PANCAKE ROUTER : https://bscscan.com/address/0x10ED43C718714eb63d5aA57B78B54704E256024E#code
UNICATFARM : https://etherscan.io/address/0xb246bcd5baac8e342941d0f803d528b6668e42cd#code
There's many examples and blogs about this exploit.
https://peckshield.medium.com/your-tokens-are-mine-a-suspicious-scam-token-in-a-top-exchange-5e864075f7e9
https://medium.com/mycrypto/bad-actors-abusing-erc20-approval-to-steal-your-tokens-c0407b7f7c7c
https://medium.com/coinmonks/dimoncoin-fud-erc20-token-allows-attackers-to-steal-all-victims-balances-cve-2018-11411-ba9a320604f9
https://peckshield.medium.com/your-tokens-are-mine-a-suspicious-scam-token-in-a-top-exchange-5e864075f7e9
https://medium.com/coinmonks/uselessethereumtoken-uet-erc20-token-allows-attackers-to-steal-all-victims-balances-543d42ac808e
https://medium.com/zengo/unicats-go-phishing-eaf39ff9da64
The smart contract when deployed on a website simply asks for permission of someones wallet in exchange for receiving an airdrop of the malicious token.
1. Someone creates a token named Flanders ($FLNDZ)
2. That token has a total supply of 1,000,000,000,000 and sends 100 to 1,000,000 different wallets.
3. Curious wallet owners that now hold 100 FLNDZ want to know what the funds are
4. They visit your malicious website that has the smart contract deployed.
5. The website offers to exchange your FLNDZ for ETH, offering for you to 'cash in' and swap your FLNDZ.
Video of this at work - https://streamable.com/mdqhkf
Example page that is currently live - https://xch5.biz
Here are some known contracts that all do the same thing -
IGNITE : https://bscscan.com/address/0x96d54b0afa25f8d12fdfe51edd110f9efa8fd28c#code
PANCAKE FACTORY : https://bscscan.com/address/0xca143ce32fe78f1f7019d7d551a6402fc5350c73#code
PANCAKE ROUTER : https://bscscan.com/address/0x10ED43C718714eb63d5aA57B78B54704E256024E#code
UNICATFARM : https://etherscan.io/address/0xb246bcd5baac8e342941d0f803d528b6668e42cd#code
There's many examples and blogs about this exploit.
https://peckshield.medium.com/your-tokens-are-mine-a-suspicious-scam-token-in-a-top-exchange-5e864075f7e9
https://medium.com/mycrypto/bad-actors-abusing-erc20-approval-to-steal-your-tokens-c0407b7f7c7c
https://medium.com/coinmonks/dimoncoin-fud-erc20-token-allows-attackers-to-steal-all-victims-balances-cve-2018-11411-ba9a320604f9
https://peckshield.medium.com/your-tokens-are-mine-a-suspicious-scam-token-in-a-top-exchange-5e864075f7e9
https://medium.com/coinmonks/uselessethereumtoken-uet-erc20-token-allows-attackers-to-steal-all-victims-balances-543d42ac808e
https://medium.com/zengo/unicats-go-phishing-eaf39ff9da64
The smart contract when deployed on a website simply asks for permission of someones wallet in exchange for receiving an airdrop of the malicious token.
1. Someone creates a token named Flanders ($FLNDZ)
2. That token has a total supply of 1,000,000,000,000 and sends 100 to 1,000,000 different wallets.
3. Curious wallet owners that now hold 100 FLNDZ want to know what the funds are
4. They visit your malicious website that has the smart contract deployed.
5. The website offers to exchange your FLNDZ for ETH, offering for you to 'cash in' and swap your FLNDZ.