A set of challenges to hack implementations of DeFi in Ethereum.
Featuring flash loans, price oracles, governance, NFTs, lending pools, smart contract wallets, timelocks, and more!
Created by @tinchoabbate
Visit damnvulnerabledefi.xyz
- Created by @tinchoabbate
- Foundry
- Foundry Book
curl -L https://foundry.paradigm.xyz | bash
foundryup
git clone [email protected]:StErMi/forge-damn-vulnerable-defi.git
cd forge-damn-vulnerable-defi
git submodule update --init --recursive
# example forge test --match-contract PuppetTest
forge test --match-contract NAME_OF_THE_TEST
Create a new test CHALLENGE.t.sol
in the src/test/
directory and inherit from BaseTest.sol
.
// SPDX-License-Identifier: UNLICENSED
pragma solidity 0.8.10;
import {stdError} from "forge-std/stdlib.sol";
import {Utilities} from "../utils/Utilities.sol";
import {BaseTest} from "../BaseTest.sol";
// ADD ALL YOUR IMPORTS HERE
contract TrusterTest is BaseTest {
// ADD ALL YOUR VARIABLES HERE
// attacker adddress
address payable attacker;
constructor() {
// setup the needed user accordly
string[] memory labels = new string[](1);
labels[0] = "Attacker";
preSetup(1, labels);
}
function setUp() public override {
super.setUp();
attacker = users[0];
// setup contracts
}
function test_Exploit() public {
// don't change this
runTest();
}
function exploit() internal override {
/** CODE YOUR EXPLOIT HERE */
// add your attack code here
}
function success() internal override {
/** SUCCESS CONDITIONS */
// import your success conditions asserts here
}
}
What you need to do:
- Add as many users as needed for the test in the
constructor
- Replace
// setup contracts
insetUp()
with all the test environment setup. Deploy your contract, setup the users funds, etc. - Replace
// add your attack code here
inexploit()
with your exploit code. - Replace
// import your success conditions asserts here
insuccess()
with your success conditions asserts.
All Solidity code, practices and patterns in this repository are DAMN VULNERABLE and for educational purposes only.
DO NOT USE IN PRODUCTION.