USENIX Security2024Top-tier venue
Speculative Denial-of-Service Attacks In Ethereum
Aviv Yaish, Kaihua Qin, Liyi Zhou, Aviv Zohar, Arthur Gervais
Abstract
Transaction fees compensate actors for resources expended on transactions and can only be charged from transactions included in blocks. But, the expressiveness of Turing-complete contracts implies that verifying if transactions can be included requires executing them on the current blockchain state. In this work, we show that adversaries can craft malicious transactions that decouple the work imposed on blockchain actors from the compensation offered in return. We introduce three attacks: (i) ConditionalExhaust, a conditional resource exhaustion attack (REA) against blockchain actors. (ii) Mem-Purge, an attack for evicting transactions from actors' mempools. (iii) GhostTX, an attack on the reputation system used in Ethereum's proposer-builder separation (PBS) ecosystem. We evaluate our attacks on an Ethereum testnet and find that by combining ConditionalExhaust and MemPurge, adversaries can simultaneously burden victims' computational resources and clog their mempools to the point where victims are unable to include transactions in blocks. Thus, victims create empty blocks, thereby hurting the system's liveness. The attack's expected cost is $376, but becomes cheaper if adversaries are validators. For other attackers, costs decrease if censorship is prevalent in the network. ConditionalExhaust and MemPurge are made possible by inherent features of Turing-complete blockchains, and potential mitigations may result in reducing a ledger's scalability.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 1cfbbf12-b526-475e-8abc-7f77f6aab82cCited by top-tier papers10
- Nurgle: Exacerbating Resource Consumption in Blockchain State Storage via MPT ManipulationZheyuan He, Zihao Li, Ao Qiao, Xiapu Luo et al.S&P 2024 · 21 citations
- Understanding Ethereum Mempool Security under Asymmetric DoS by Symbolized Stateful FuzzingYibo Wang, Yuzhe Tang, Kai Li, Wanning Ding et al.USENIX Security 2024 · 9 citations
- BunnyFinder: Finding Incentive Flaws for Ethereum ConsensusRujia Li, Mingfei Zhang, Xueqian Lu, Wenbo Xu et al.NDSS 2026 · 5 citations
- Perils of Parallelism: Transaction Fee Mechanisms under Execution UncertaintySarisht Wadhwa, Aviv Yaish, Fan Zhang, Kartik NayakUSENIX Security 2026 · 3 citations
- Insecurity Through Obscurity: Veiled Vulnerabilities in Closed-Source ContractsSen Yang, Kaihua Qin, Aviv Yaish, Fan ZhangCCS 2026 · 3 citations
Builds on5
- Flash Boys 2.0: Frontrunning in Decentralized Exchanges, Miner Extractable Value, and Consensus InstabilityPhilip Daian, Steven Goldfeder, Tyler Kell, Yunqi Li et al.S&P 2020 · 607 citations
- DETER: Denial of Ethereum Txpool sERvicesKai Li, Yibo Wang, Yuzhe TangCCS 2021 · 26 citations
- A study of inline assembly in solidity smart contractsStefanos Chaliasos, Arthur Gervais, Benjamin LivshitsOOPSLA 2022 · 22 citations
- BDoS: Blockchain Denial-of-ServiceMichael Mirkin, Yan Ji, Jonathan Pang, Ariah Klages-Mundt et al.CCS 2020 · 1 citation
- Broken Metre: Attacking Resource Metering in EVMDaniel Perez, Benjamin LivshitsNDSS 2020
Related papers
- eTainter: detecting gas-related vulnerabilities in smart contractsAsem Ghaleb, Julia Rubin, Karthik PattabiramanISSTA 2022 · 57 citations
- Auspex: Unveiling Inconsistency Bugs of Transaction Fee Mechanism in BlockchainZheyuan He, Zihao Li, Jiahao Luo, Feng Luo et al.USENIX Security 2025
- Precise static modeling of Ethereum "memory"Sifis Lagouvardos, Neville Grech, Ilias Tsatiris, Yannis SmaragdakisOOPSLA 2020 · 23 citations
- Asymmetric Mempool DoS Security: Formal Definitions and Provable Secure DesignsWanning Ding, Yuzhe Tang, Yibo WangS&P 2025
- POMABuster: Detecting Price Oracle Manipulation Attacks in Decentralized FinanceRui Xi, Zehua Wang, Karthik PattabiramanS&P 2024 · 13 citations
