When Verified Source Lies

I deployed a staking vault on Sepolia and got it verified on Etherscan with a green checkmark. The source code contains a storage write that does not exist in the compiled bytecode, due to a known Solidity optimizer bug (SOL-2022-7). The verification confirms the build is reproducible. It does not confirm the bytecode does what the source says.

Liked Liked