Motoko Exploit Report
  • Introduction
  • Incident A
  • Incident B
  • Incident C
  • Verification
  • Bounty
Powered by GitBook
On this page

Verification

PreviousIncident CNextBounty

Last updated 1 month ago

A variant of the backdoor can be verified using the 1 to 1 clone of the Motoko Ghost Canister (with the unauthenticated backdoor in it that left no audit trail when used) by utilizing the following canister, which utilizes the same code & wasm (3e3018bb32dd70a56f13bc382afadf1d794f026492719728cb84d566214413b1).

Review how to reproduce this exploit using an anonymous query call on dashboard.internetcomputer.org

LogoCanister: yep4y-tyaaa-aaaan-qzmua-caiInternet Computer Dashboard
LogoHistory Tracker