Santa's List

AI First Flight #3
Beginner FriendlyFoundry
EXP
View results
Submission Details
Impact: low
Likelihood: low
Invalid

Solidity version `0.8.22` targets an EVM version incompatible with Arbitrum at time of deployment

[L-02] Solidity version 0.8.22 targets an EVM version incompatible with Arbitrum at time of deployment

Description:

SantasList.sol and SantaToken.sol are locked to pragma solidity 0.8.22. By default, solc versions 0.8.20 and above target the Shanghai EVM version, which emits the PUSH0 opcode. At the time this codebase targeted deployment, some L2s — including Arbitrum — had not yet upgraded their EVM to support PUSH0, meaning contracts compiled with default settings for 0.8.22 would fail to deploy (or deploy with unusable bytecode) on those chains unless the compiler's evmVersion was explicitly pinned to a pre-Shanghai target (e.g. paris).

Risk Analysis:

  • Impact: Low — deployment simply fails outright during testing/deployment on the affected chain; no funds are ever at risk, and the issue is caught before any live usage.

  • Likelihood: Low — only manifests if the team actually attempts deployment to a chain that lags in EVM-version support, and is trivially fixed by pinning evmVersion.

Proof of Concept:

This is a compiler/deployment-configuration issue rather than something demonstrable via a Foundry unit test. It is confirmed by inspecting the compiled artifact for the PUSH0 opcode (0x5f) and cross-referencing it against the target chain's supported EVM version, or by attempting deployment to the target chain's testnet and observing the deployment revert.

evm_version = "paris"
pragma solidity 0.8.22;

Recommended Mitigation:

Update the foundry.toml settings with solidity compiler version along with the evm_version.

# foundry.toml
[profile.default]
+ solc = "0.8.22"
evm_version = "paris"
Updates

Lead Judging Commences

ai-first-flight-judge Lead Judge 14 days ago
Submission Judgement Published
Invalidated
Reason: Incorrect statement

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.

Give us feedback!