Lune

NDSS2024Top-tier venue

VETEOS: Statically Vetting EOSIO Contracts for the "Groundhog Day" Vulnerabilities

Levi Taiji Li, Ningyu He, Haoyu Wang, Mu Zhang

2024Year

Abstract

—In this paper, we propose V ET EOS, a static vetting tool for the “Groundhog Day” vulnerabilities in EOSIO contracts. In a “Groundhog Day” attack, culprits leverage the distinctive rollback issue in EOSIO contracts, which allows them to persistently execute identical contract code with varying inputs. By using the information exposed in prior executions, these attackers unlawfully amass insights about the target contract, thereby figuring out a reliable method to generate unauthorized profits. To tackle this problem, we formally define this unique vulnerability as a control and data dependency problem, and develop a custom static analysis tool, V ET EOS, that can precisely discover such bugs directly from EOSIO WebAssembly (WASM) bytecode. V ET EOS has detected 735 new vulnerabilities in the wild and outperforms the state-of-the-art EOSIO contract analyzer.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext 4c2359f2-37bc-433d-8a5e-274723cc0ca0

Builds on12

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines