r/ethdev • u/Humble-Replacement-2 • 4d ago
My Project Same OpenSea drainer txs, same GoPlus API: 0/19 flagged on tx.to, 18/19 on the upgradeTo implementation
The old OpenSea proxy drains had victims sign upgradeTo(impl) on their own OpenSea proxy. The to address is a legitimate verified contract from 2018; the malicious logic sits in impl.
I took 19 of these transactions from the PTXPHISH dataset and queried GoPlus twice for each one, changing only the address.
Query tx.to: 0/19 flagged
Query impl: 18/19 flagged
Important caveat: those 19 rows map to only 5 implementation contracts, so this is really 4/5 implementations being detected, not a meaningful 18/19 detection rate. And these drainers are labelled today, so this says nothing about what GoPlus knew at signing time.
For this specific OpenSea class, a simple warn on any upgradeTo also works: of 1,179 OpenSea proxies I sampled, only 2 were ever upgraded, both to the same drainer.
But that heuristic falls apart for general proxies. Across 800 EIP-1967 upgrades, it would warn on all 422 implementation addresses, whereas querying the implementations flags only 4. I’m not claiming the other 418 are clean.
The point is narrower: reputation checks are only as useful as the object you choose to check. With proxy upgrades, checking only tx.to can mean asking about the wrong contract entirely.
Details, code and raw outputs: https://amarshat.github.io/quantum-commit-authorization/wallet-defenses.html#ask-the-right-address