logo

Introducing CertiK’s CREATE2 Audit Tool

ID: ae4c170f-1e09-51f9-b6ba-8bb4a31c4b23

STIX ID: report--ae4c170f-1e09-51f9-b6ba-8bb4a31c4b23

Feed Name: CertiK Blog

Threat Score
55/100

Date Published: 2019-11-13

Date Updated: 2026-06-11

...
...

CertiK warns that Ethereum's CREATE2 opcode can enable malicious actors to replace deployed contract code (when SELFDESTRUCT or DELEGATECALL are present), allowing redeployment at the same address and potential fund theft. The advisory explains the CREATE2 address derivation differences, demonstrates attack scenarios, notes detection challenges for contracts created in creation-chains, and promotes CertiK's CREATE2 Audit Tool and code audits as mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.