Inspiration

Web3 has a graveyard problem. Thousands of DeFi contracts, DAOs, and dApps are still live on-chain — still holding withdrawable funds, still technically usable — but their frontends have gone down, their teams have disappeared, and their source code was never verified or published. The contract didn't die. The interface did. We wanted to build something that could bring those contracts back to life for anyone with a wallet, without needing the original team, the original frontend, or even the original source code.

What it does

Zombie Remote takes any smart contract address and reconstructs a usable interface for it on the spot. It pulls the contract's bytecode, scans it for function selectors (PUSH4 opcodes) to guess at an ABI when no verified source exists, and checks known EIP-1967 storage slots to detect if the contract is a proxy — resolving to the real implementation before decoding. From there, it builds a dynamic UI so a user can connect their own wallet and call the contract's functions directly, signing every transaction themselves.

How we built it

The frontend is vanilla JS/HTML/CSS with no framework overhead, kept intentionally lightweight so it can run anywhere. Wallet connection follows the standard EIP-1193 provider flow. Etherscan's API is used first to pull verified source/ABI when it's available, with our own bytecode decoder (abi-decoder.js) as a fallback when it isn't — parsing raw bytecode for function selectors and constructing a "best guess" ABI from scratch.

Challenges we ran into

Decoding function selectors from raw bytecode with no source of truth was the hardest technical piece — matching PUSH4 selectors against known signature databases and handling contracts that don't match anything cleanly. Proxy contracts added another layer: calling a proxy's own bytecode gives you nothing useful, so we had to detect EIP-1967 implementation/admin/beacon slots and resolve to the real logic contract before decoding.

We also caught a credential-hygiene issue in our own repo during a pre-submission review — our public "example" config and personal working config needed to be clearly separated so a real API key never ends up committed to the public GitHub repo. Worth calling out as a reminder to double check .gitignore actually points at the file you think it does before pushing anything to a public hackathon repo.

Accomplishments that we're proud of

  • A working fallback ABI decoder that doesn't depend on the contract being verified on Etherscan
  • Proxy detection that correctly resolves EIP-1967 implementation contracts before decoding
  • A wallet flow that never touches funds on the user's behalf — every transaction is signed by the user, for the user
  • Catching and fixing our own credential-separation issue before it became a real leak

What we learned

A lot about EVM bytecode structure, function selector hashing, and how proxy patterns actually work at the storage-slot level. We also came away with a much sharper eye for repo hygiene — the difference between a file that's actually gitignored and one you just assume is, and why it's worth verifying that with git check-ignore rather than trusting a filename.

What's next for Zombie Remote

  • Multi-chain support beyond Ethereum mainnet (Polygon, Arbitrum, Base, etc.)
  • A community-sourced registry of known abandoned contracts worth reviving
  • Contract-risk warnings (e.g. flagging honeypots or contracts with no withdrawal functions) before a user connects a wallet
  • Signature-database expansion to improve fallback ABI decoding accuracy

Built With

Share this project:

Updates

Submission history