官方的 MASTR 标志 MASTR 支持这项工作
目录
← 知识库首页

Technical reference

ERC-1967: finding the implementation behind a proxy address

The address users recognise can remain unchanged while the code they execute changes.

Source-based reference · Updated 12 September 2026

研究文章和参考条目以英语发布。导航提供七种语言。

本文目录
  1. Three important storage locations
  2. Snapshot the code that actually ran
  3. Authority is a separate investigation
  4. Sources

Three important storage locations

ERC-1967 specifies storage locations for implementation, beacon and administrator information used by compatible proxies. These slots help tools discover delegated code without relying solely on a frontend label. A beacon-based proxy obtains its implementation through the beacon, adding another contract to inspect.

Snapshot the code that actually ran

A finding should record the chain, proxy address, block and implementation active at that block. Reviewing today's implementation against yesterday's transaction can produce a false explanation. Upgrade-related events are useful leads, but the corresponding state and executed call path matter too.

Authority is a separate investigation

Knowing the implementation does not identify every person able to replace it. Follow ownership, access-control roles, timelocks and any upgrade mechanism in the relevant contracts. The proxy standard gives a storage convention, not a guarantee of decentralised administration or an audit of the implementation. An unchanged token address is therefore not proof of unchanged behaviour.

Sources

相关阅读

钱包与安全

Proxy-upgrade rugs

A proxy delegates calls to implementation code replaceable by an administrator.

MASTR

支持独立研究

这里的调查、原始证据和指南均可免费阅读。自愿捐赠帮助支付研究成本,让 MASTR 能够继续提供工具。

打开钱包