Skip to content
Blockchain

Why does a routine proxy upgrade silently corrupt state that five audits approved?

81

机会

Upgradeable proxy contracts are standard infrastructure, but when a new implementation adds, removes, or reorders storage variables without preserving the prior layout, state from the old version silently maps to wrong slots in the new one. The corruption produces no revert, no error event, and no on-chain signal, just a balance that is suddenly a wrong number or an access control slot that now points to an attacker address. The Kinto Protocol lost $1.55M in July 2025 when an uninitialized proxy was taken over through this vector, and a broader automated campaign in 2025 scanned newly deployed proxies across EVM chains to initialize them with malicious implementations before developers could act. OWASP's Smart Contract Top 10 for 2026 formally catalogs proxy and upgradeability vulnerabilities as SC10, confirming the category is recognized and still routinely exploited. Namespaced storage

为什么重要

Storage layout compatibility is never checked at compile or deploy time, so every upgrade to a live contract ships with an assumption that no tooling currently verifies.

我如何评估机会

机会评分是我的个人判断,而非量化指标:痛苦程度、发生频率,以及当前解决方案的匮乏程度。分数越高,意味着我认为越值得去构建。

严重性8/10

出现时造成的痛苦程度。

频率8/10

人们实际遇到它的频率。

空白空间7/10

当前针对它的优质工具有多匮乏。

更多值得解决的问题