New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

Things you didn't know about contract deployment by Theresa Wakonig | Devcon SEA

DevconTue, Oct 7, 2025, 12:00 AM

In this session we will explore some of the lesser-known facts around contract deployment. To make the presentation accessible to all technical levels, the talk will start by recapping the three ways to start contract deployment (deployment tx, CREATE, CREATE2). Following this, we will delve deeper into the topic and highlight some interesting facts around contract deployment, including what happens when an address already has code, ETH, or state entries at deployment. Speaker(s): Theresa Wakonig Skill level: Intermediate Track: Core Protocol Keywords: deployment Follow us: https://twitter.com/efdevcon, https://twitter.com/ethereum, https://warpcast.com/devcon Learn more about devcon: https://www.devcon.org/ Learn more about ethereum: https://ethereum.org/ Visit the https://archive.devcon.org/ to gain access to the entire library of Devcon talks with the ease of filtering, playlists, personalized suggestions, decentralized access on Swarm, IPFS and more. Devcon is the Ethereum conference for developers, researchers, thinkers, and makers. Devcon SEA was held in Bangkok, Thailand on Nov 12 - Nov 15, 2024. Devcon is organized and presented by the Ethereum Foundation. To find out more, please visit https://ethereum.foundation/

Transcript

[Music] hi everyone good morning my name is Teresa I am a smart contract auditor at chain security uh and today I'll talk about things you didn't know about contract deployment so uh I suppose many of you have deployed a smart contract at some point and this session aims to take a behind the scenes look at what happens at this process um so as a short recap these are the three ways to to deploy uh to initiate smart contract deployment on ethereum so either via the creation transaction or the create or create two op codes um all of these will um trigger the evm um to execute execute the init code so will it will trigger um constru uh execution now the question becomes what if we want to deploy a contract at an address of an already existing account can we do that and for that we must understand what it means for a cont contract um for an account to exist so let's um recap that every account holds a state um we have a state that contains four Fields uh the nons the balance the storage route and the code hash and for account existence let's go all the way back to EIP 161 that specifies prior to the execution of the init code uh the nons is incremented by one so this means for an address um of a non-zero nons we can say an account exists at that address all right but uh what what does this mean what are the implications on contract deployment can we deploy at an address with uh um nonzero noner nonzero code hash um well we can't there's EAP 684 that will revert if you try to um initiate creation on an at an address with nonzero nons and non-zero code hash um what about the storage do we need to care about the storage route um interesting interestingly yes there's also a check on that and this has more of a historic flavor there are still a few contracts on Main net that have um zero nons zero code hash but nonzero storage and these are from before EIP 161 that I just mentioned on the previous slides all right and what about the balance um can we create at an address with non-zero balance yes yes we can and then um that number of way is just owned by the address all right um now during contract construction um there's quite a specific behavior of the evm um so usually when you um when you measure the code size of a contract from within a contract and externally it should give you the same size the same bite length um interestingly during deployment during contract construction this does not hold so measuring um the code size from within and uh from externally will give you different um values and this is uh an important detail to know um and one important aspect I would also want to shed light on is the the values xcode hash can take and this is specifically important if you do eoa checks using xcode hash you must know um what states you can be in and what values xcode hash can take so for an empty account uh so to recap xcode hash returns um the code hash of the address you query so for an empty account that will be um the value on the top right the Zero by string now if we deploy successfully to an empty address this will just take any value the hash of of of the code deployed um all right now how can we get from the zero address from an empty account to the hash of the empty string this is if you just send if to a random address where no contract lives um excode hash will return um the hash of the empty string and also during contract construction this will be returned then from the from this value you can of course then create on this contract because the non is still at this account uh at this address sorry because the non is still set to zero so you can create on that now um I want to finish off by asking if this is the complete picture and in interest of time I'm taking this away for you um well no you can still still after Cancun this still holds so you must not rely when you do an EA check that um once you get the result of a random a random bite string that this will hold because within the same transaction contract State can still be deleted um yeah so don't let yourself be deceived by the return value of xcode hash um so in summary we've seen that for account existence the non is incremented and this is done before Constructor execution we learned that you cannot create on existing accounts or an EAS and there exists still some Legacy contracts with nonzero storage but zero nons and zero code and for the xcode has transitions I really encourage you to try it out yourself we set up this remix workspace and uh where you can measure um the output of the op codes and um yeah play around with that to really understand um the transitions thank you very much for your attention and if you want to reach out to us I'm happy to chat after this talk uh and you can also do so via the platforms thank you thank you Teresa question time the one I love the most who is going first question for oh okay ah I'll try thank yeah so how would this uh EA check transform after the EIP 7702 where they implement the aop code and then EOS can also have EXT code P um I'm not sure could you specify which EIP uh the 7702 the aop code EIP um where we can delegate uh EU to contract I see um I'm not entirely sure about that but what is important for for now during um after the Cancun upgrade is that within the same transaction um well you can have a creation and you can have any function execution and then still the self-destruct and that is um I think uh for right now what is often left out of sight is that um yeah it's still the same transaction and SAR can still occur last question one more question no more question oh okay Teresa thank you

Automatic transcript — names and jargon may be misspelled.