All - Activity - pheathwa - Algorand

Protecting Funds in Smart Signature Contract Accounts

Ok great, so just to clarify, everything pretty much stays the same except for how the keypairs get generated, i.e. no need to use nacltweet directly, just use the equivalent algorand account functionality, which includes wrappers to nacltweet. So, the current approach seems OK, the above is more o…


I believe I am already doing this one " You can also have the smart signature takes as input a signature of the recipient address, signed under a public key stored in the contract." - see code section below. The contract is setup such that the secret key is known only to the recipient, which is use…


Thanks for these insights - not what I expected, and very edge case, but obviously needs to be respected. My scenario involves only knowing who the receiver is AFTER funds are already in the contract account. So, in an attempt to wrap this up, please clarify whether following is an accurate statement…


Really appreciate you leaning into this. To unpack this a bit … The TEAL is written to distribute all funds to the recipient (and close out the account) when the recipient submits the transaction using the correct secret key (signature). So, in order to break this, the attacker would have to obser…


Using smart signatures as escrow contract accounts seems to be generally discouraged, and for good reasons, but with the relatively new opcode (ed25519verify_bare), my article discusses an approach for going there! Feedback/comments welcome.


Yes - that appears to be it. The TEAL is unchanged, but it worked after replacing: const signature = nacl.sign.detached(Buffer.from(recipientAddress), secretKeyBytes); with: const signature = nacl.sign.detached( algosdk.decodeAddress(recipientAddress).publicKey, secretKeyBytes); So, the lesson i…


Have implemented a smart signature contract account where funds in the escrow can be pulled by the receiver only if the receiver’s address has been signed by a secret key, yielding a signature, which is then verified against the related public key (embedded in the contract). Following are the relevant…


It seems Walletconnect returns an empty array entry for those that were submitted with signers: . With the additional check bolded below, this all seems to work, including having logicsigs with user-signed sigs in an atomic transaction - pretty cool. // signedTxns contains empty rows where any sub…


Trying to do an atomic transaction consisting of: logicsig tx user-signed tx via walletconnect logicsig tx The walletconnect docs say to return “signers: ” for those transactions to be ignored, ie. 1 & 3 Walletconnect allows me to sign, returns a list of txs as you’d expect, with the txn: ‘xxxx…


Looking for referrals for any individuals or companies that can do smart contract audits. I have a stateful escrow-type contract, written in TEAL. Seeking a sanity check on any potential vulnerabilities. Suggestions welcome!


Cloud sandbox with screens to “goal-lessly” inspect and manipulate accounts, debug teal, all to speed iteration. I’ve been thinking about writing an article on all the techniques required to do an end-to-end solution, such as (1) integration with wallets (2) integration with AWS lambda (3) serializ…


Super helpful - following is my abbreviated working example. Thank you!

callsub handle_sub1
handle_sub1:
 load 2
 pushint 0
 <=
 bnz handle_retsub // Early return
 // Do other stuff here
 retsub // Normal return
handle_retsub:
 retsub

Similar to branching (bnz, bz etc) is there a way to do conditional callsubs (or retsubs) or can you offer a technique to accomplish the same?


I got it working as below. I re-read the docs and the reminder (for me) was that for Inner Transactions, the Sender defaults to the Application (Smart Contract) itself. But, when trying to use the AssetSender explicitly, it thinks it is a clawback. So, the below facilitates the Application Optin to …


Trying to use following smart contract TEAL code for the App to optin to an asset. The app is called where the Sender is another account, but the idea is that (1) The App Opts in to Asset A and then directly below it (2) The Sender transfers Y amount of the asset into the App (Escrow) txna Assets …


I have saved a string in local state, which represents several distinct values, e.g. “abc123|5010” where “|” is the delimiter and the 2 fields are variable in length. I’d prefer to save the embedded values in a more structured way (e.g. as an Object) via app_local_put as usual, but failing that w…


Want to create a funded logicsig and then return the funds to the funding account if the logicsig funds have not been taken, after a period of time. Seems that HTLC needs to know who the funds are ultimately intended for, and my use case is that the ultimate recipient is not known at time of logics…


Looking for some direction on how to programmatically send USDC to wallets on various exchanges (coinbase, kraken etc.) where user is not required to know anything about Algorand. I imagine this can be done using circle API, but looking to figure out if I can just do direct on Algorand? Thanks