Skip to content
Blockchain

Why does a routine proxy upgrade silently corrupt state that five audits approved?

81

Szansa

Upgradeable proxy contracts are standard infrastructure, but when a new implementation adds, removes, or reorders storage variables without preserving the prior layout, state from the old version silently maps to wrong slots in the new one. The corruption produces no revert, no error event, and no on-chain signal, just a balance that is suddenly a wrong number or an access control slot that now points to an attacker address. The Kinto Protocol lost $1.55M in July 2025 when an uninitialized proxy was taken over through this vector, and a broader automated campaign in 2025 scanned newly deployed proxies across EVM chains to initialize them with malicious implementations before developers could act. OWASP's Smart Contract Top 10 for 2026 formally catalogs proxy and upgradeability vulnerabilities as SC10, confirming the category is recognized and still routinely exploited. Namespaced storage

Dlaczego to ważne

Storage layout compatibility is never checked at compile or deploy time, so every upgrade to a live contract ships with an assumption that no tooling currently verifies.

Jak oceniam szansę

Wskaźnik Szansy to mój własny odczyt, a nie pomiar: jak bardzo boli, jak często daje się we znaki i jak niewiele istnieje dziś, by to rozwiązać. Wyższy wynik oznacza, że uważam problem za bardziej warty zbudowania.

Dotkliwość8/10

Ile bólu sprawia, gdy się pojawia.

Częstotliwość8/10

Jak często ludzie faktycznie na to trafiają.

Białe znaki7/10

Jak mało dobrych narzędzi istnieje dla tego dziś.

Więcej problemów wartych rozwiązania

Blockchain

Dlaczego nie mogę udowodnić swojej wypłacalności bez ujawniania salda?

Blockchain

Dlaczego przenoszenie pieniędzy między łańcuchami wciąż budzi więcej obaw niż wczesny internet?

Blockchain

Dlaczego zgodność z przepisami wciąż oznacza PDF i modlitwę?

Blockchain

Dlaczego samodzielne przechowywanie aktywów wciąż sprowadza się do wyboru między utratą kluczy a zaufaniem do firmy?

Blockchain

Dlaczego tokenizacja realnego aktywa nadal wymaga dziesięciu pośredników?

Blockchain

Stablecoins run on blockchains, and blockchains have three hard requirements that all need internet: **1. Broadcasting the transaction** A payment is just a signed message. To actually move funds, that message must be submitted to the network so nodes can receive it. **2. Consensus and finality** Validators/miners must include the transaction in a block and reach agreement that it happened. Without connectivity, no block, no settlement. **3. Verifying the sender's balance** The current state of who owns what lives on the network. Without querying it, you can't confirm the sender hasn't already spent those funds elsewhere -- the classic double-spend problem. --- **Why this is harder than it looks** Cash works offline because a physical note is self-proving and self-transferring. A stablecoin balance isn't held in a device -- it's an entry in a global ledger. "Paying" offline would mean handing over a signed promise, but the recipient has no way to know that promise isn't already spent until they reconnect. --- **Partial workarounds being explored** - **Hardware security chips** (used in some CBDC pilots, e.g. the ECB's digital euro research) -- a tamper-resistant chip holds a balance offline; the chip enforces spend limits and prevents double-spend locally, then settles when reconnected - **Lightning Network** -- payment channels allow off-chain transfers, but channel setup/teardown still needs the base layer - **Signed IOUs** -- parties can exchange cryptographic promises offline and settle later, but this reintroduces counterparty trust None of these are production stablecoin rails today. For now, no internet means no confirmed stablecoin payment.