Skip to content

Instantly share code, notes, and snippets.

@ColonelJ
Created April 1, 2021 00:08
Show Gist options
  • Save ColonelJ/3488235303d228a26c7ad99a47166133 to your computer and use it in GitHub Desktop.
Save ColonelJ/3488235303d228a26c7ad99a47166133 to your computer and use it in GitHub Desktop.
ERC20 approval frontrunning prevention detector
// SPDX-License-Identifier: MIT
pragma solidity ^0.7.0;
/**
* @dev Interface of the ERC20 standard as defined in the EIP.
*/
interface IERC20 {
/**
* @dev Returns the amount of tokens in existence.
*/
function totalSupply() external view returns (uint256);
/**
* @dev Returns the amount of tokens owned by `account`.
*/
function balanceOf(address account) external view returns (uint256);
/**
* @dev Moves `amount` tokens from the caller's account to `recipient`.
*
* Returns a boolean value indicating whether the operation succeeded.
*
* Emits a {Transfer} event.
*/
function transfer(address recipient, uint256 amount) external returns (bool);
/**
* @dev Returns the remaining number of tokens that `spender` will be
* allowed to spend on behalf of `owner` through {transferFrom}. This is
* zero by default.
*
* This value changes when {approve} or {transferFrom} are called.
*/
function allowance(address owner, address spender) external view returns (uint256);
/**
* @dev Sets `amount` as the allowance of `spender` over the caller's tokens.
*
* Returns a boolean value indicating whether the operation succeeded.
*
* IMPORTANT: Beware that changing an allowance with this method brings the risk
* that someone may use both the old and the new allowance by unfortunate
* transaction ordering. One possible solution to mitigate this race
* condition is to first reduce the spender's allowance to 0 and set the
* desired value afterwards:
* https://github.com/ethereum/EIPs/issues/20#issuecomment-263524729
*
* Emits an {Approval} event.
*/
function approve(address spender, uint256 amount) external returns (bool);
/**
* @dev Moves `amount` tokens from `sender` to `recipient` using the
* allowance mechanism. `amount` is then deducted from the caller's
* allowance.
*
* Returns a boolean value indicating whether the operation succeeded.
*
* Emits a {Transfer} event.
*/
function transferFrom(address sender, address recipient, uint256 amount) external returns (bool);
/**
* @dev Emitted when `value` tokens are moved from one account (`from`) to
* another (`to`).
*
* Note that `value` may be zero.
*/
event Transfer(address indexed from, address indexed to, uint256 value);
/**
* @dev Emitted when the allowance of a `spender` for an `owner` is set by
* a call to {approve}. `value` is the new allowance.
*/
event Approval(address indexed owner, address indexed spender, uint256 value);
}
contract ApprovalChecker {
function isContract(address addr) private view returns (bool) {
uint256 size;
assembly { size := extcodesize(addr) }
return size > 0;
}
function doApproval(IERC20 token, uint256 amount) private returns (bool) {
(bool success, bytes memory returndata) = address(token).call(
abi.encodeWithSelector(
token.approve.selector,
address(0x1111111111111111111111111111111111111111),
amount
)
);
return success && (returndata.length == 0 || abi.decode(returndata, (bool)));
}
function checkApproval(IERC20 token) external returns (uint256) {
if (!isContract(address(token))) {
return 0;
}
if (!doApproval(token, 1)) {
return 0;
}
if (doApproval(token, 2)) {
require(doApproval(token, 0));
return 1;
}
require(doApproval(token, 0));
if (doApproval(token, 2)) {
require(doApproval(token, 0));
return 2;
}
return 0;
}
}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment