VETEOS: Statically Vetting EOSIO Contracts for the "Groundhog Day" Vulnerabilities
Levi Taiji Li, Ningyu He, Haoyu Wang, Mu Zhang
Abstract
—In this paper, we propose V ET EOS, a static vetting tool for the “Groundhog Day” vulnerabilities in EOSIO contracts. In a “Groundhog Day” attack, culprits leverage the distinctive rollback issue in EOSIO contracts, which allows them to persistently execute identical contract code with varying inputs. By using the information exposed in prior executions, these attackers unlawfully amass insights about the target contract, thereby figuring out a reliable method to generate unauthorized profits. To tackle this problem, we formally define this unique vulnerability as a control and data dependency problem, and develop a custom static analysis tool, V ET EOS, that can precisely discover such bugs directly from EOSIO WebAssembly (WASM) bytecode. V ET EOS has detected 735 new vulnerabilities in the wild and outperforms the state-of-the-art EOSIO contract analyzer.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4c2359f2-37bc-433d-8a5e-274723cc0ca0Builds on12
- Making Smart Contracts SmarterLoi Luu, Duc-Hiep Chu, Hrishi Olickel, Prateek Saxena et al.CCS 2016 · 2,306 citations
- Securify: Practical Security Analysis of Smart ContractsPetar Tsankov, Andrei Marian Dan, Dana Drachsler-Cohen, Arthur Gervais et al.CCS 2018 · 1,108 citations
- ZEUS: Analyzing Safety of Smart ContractsSukrit Kalra, Seep Goel, Mohan Dhawan, Subodh SharmaNDSS 2018 · 595 citations
- teEther: Gnawing at Ethereum to Automatically Exploit Smart ContractsJohannes Krupp, Christian RossowUSENIX Security 2018 · 345 citations
- Sereum: Protecting Existing Smart Contracts Against Re-Entrancy AttacksMichael Rodler, Wenting Li, Ghassan O. Karame, Lucas DaviNDSS 2019 · 298 citations
Related papers
- EOSAFE: Security Analysis of EOSIO Smart ContractsNingyu He, Ruiyi Zhang, Haoyu Wang, Lei Wu et al.USENIX Security 2021 · 69 citations
- WASAI: uncovering vulnerabilities in Wasm smart contractsWeimin Chen, Zihan Sun, Haoyu Wang, Xiapu Luo et al.ISSTA 2022 · 43 citations
- eTainter: detecting gas-related vulnerabilities in smart contractsAsem Ghaleb, Julia Rubin, Karthik PattabiramanISSTA 2022 · 57 citations
- Uncover the Premeditated Attacks: Detecting Exploitable Reentrancy Vulnerabilities by Identifying Attacker ContractsShuo Yang, Jiachi Chen, Mingyuan Huang, Zibin Zheng et al.ICSE 2024 · 24 citations
- Nyx: Detecting Exploitable Front-Running Vulnerabilities in Smart ContractsWuqi Zhang, Zhuo Zhang, Qingkai Shi, Lu Liu et al.S&P 2024 · 23 citations
