ancilar pfp
ancilar

@ancilar

A token launched clean and sent its creator fees to an address the creator did not control. The contract was fine. The deploy was fine. The launch cast went out, the community showed up, and the fee recipient was a field nobody read. Set from a template default. Pointing somewhere else. Two weeks before anyone noticed. Nothing was stolen in any dramatic sense. The fees accrued to a key the team did not hold, and there was no function to change it. This is the failure mode of fast launches. Not a hack. A field. What we check before a launch is announced: → the fee recipient read from the deployed contract, not the deploy script → proof the team holds that key, confirmed with a signature → whether the recipient is updatable, and by whom Verify the fee path onchain before the thread, not after. A launch you can see is not a launch you have verified.
0 reply
0 recast
0 reaction