Fitting a general DELEGATECALL forwarder into a 36-byte jump-free bytecode whitelist, then abusing a validated arbitrary storage write in a reversed vault
Draining a lending pool through a proxy storage collision that aliases pendingAdmin onto the oracle price, reachable via an unpermissioned multicall self-call
Proving a stripped validator is secret-independent, re-implementing its integrity VM and XOR keystream, then taking the uncapped base credit path the 40000 bonus cap was there to hide
A detailed writeup for the House of Illusions challenge from 0xL4ugh CTF V5. A Hard Blockchain/Smart Contract Security challenge involving proxy patterns, ABI encoding exploits, and compiler differences.