Back to Home

Crowdsale

Utility
0xb83820aac41f...edb085872c31
HomesteadSource VerifiedEdit this contract
Deployed March 24, 2016 (10 years ago)Block 1,210,088

The ethereum.org crowdsale tutorial: contributions run to a deadline against a goal, pay out a separate reward token, and are refunded if the goal is missed.

Homestead EraVerified Source

Historical Significance

The ethereum.org crowdsale tutorial was the worked example most token sales of the period started from, and its shape, a deadline, a goal, a fixed price and a refund if the goal is missed, is the one the sales of the following two years repeated. The flaws are instructive too: unchecked send() calls and an unbounded refund loop are exactly the failures auditors spent the next years writing up.

Context

Deployed ten days after the Homestead fork of March 2016, when the ethereum.org tutorial had been rewritten around the transfer interface ERC-20 was standardising and its crowdsale took the funding goal and token price in whole ether rather than wei.

Key Facts
Deployment Block
1,210,088
Deployment Date
Mar 24, 2016, 06:47 PM
Code Size
2.0 KB
Transactions by Year
20162

Description

The crowdfunding contract from the ethereum.org tutorial. Its constructor fixes the beneficiary, the funding goal in whole ether, the length of the campaign in minutes, the price of one reward token in whole ether, and the token contract that pays contributors. None of them can be changed afterwards.

Contributions arrive through the fallback function, which records the sender and amount in a public funders array and calls transfer on the reward token for the amount divided by the price. After the deadline anyone may call checkGoalReached(): if the goal was met the balance is sent to the beneficiary, otherwise the contract loops over the funders and refunds them, and in both cases whatever remains is swept to the beneficiary and the sale is closed.

The reward tokens must already be held by this contract when the sale opens, and nothing checks that they are. The refund loop is unbounded and no send() return value is checked, so a campaign with many contributors can leave funds it cannot pay out.

Heuristic Analysis

The following characteristics were detected through bytecode analysis and may not be accurate.

Detected Type: Utility

Bytecode Overview

Opcodes2,062
Unique Opcodes119
Jump Instructions63
Storage Operations45

External Links

Related contracts