USENIX Security2023Top-tier venue
Confusum Contractum: Confused Deputy Vulnerabilities in Ethereum Smart Contracts
Fabio Gritti, Nicola Ruaro, Robert McLaughlin, Priyanka Bose, Dipanjan Das, Ilya Grishchenko, Christopher Kruegel, Giovanni Vigna
Abstract
Smart contracts are immutable programs executed in the context of a globally distributed system known as a blockchain. They enable the decentralized implementation of many interesting applications, such as financial protocols, voting systems, and supply-chain management. In many cases, multiple smart contracts need to work together and communicate with one another to implement complex business logic. However, these smart contracts must take special care to guard against malicious interactions that might lead to the violation of a contract's security properties and possibly result in substantial financial losses. In this paper, we introduce a class of inter-program communication flaws that we call confused contract vulnerabilities. This type of bug is an instance of the confused deputy vulnerability, set in the new context of smart contract inter-communication. When exploiting a confused contract bug, an attacker is able to divert a remote (inter-contract) call in a confused (victim) contract to a target contract and function of the attacker's choosing. The call performs sensitive operations on behalf of the confused contract, which can result in financial loss or malicious modifications of the persistent storage of the involved contracts. To identify opportunities for confused contract attacks at scale, we implemented JACKAL, a system that is able to automatically identify and exploit confused contracts and candidate target contracts on the Ethereum mainnet. We leveraged JACKAL to analyze a total of 2,335,193 smart contracts deployed in the past two years, and we identified 529 potential confused contracts for which we were able to generate 31 working exploits. When investigating the impact of our exploits, we discovered past and present opportunities for confused contract attacks that could have compromised digital assets worth more than one million US dollars.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4f5b4f96-8e6a-4f72-9781-e48b041e7030Cited by top-tier papers12
- All Your Tokens are Belong to Us: Demystifying Address Verification Vulnerabilities in Solidity Smart ContractsTianle Sun, Ningyu He, Jiang Xiao, Yinliang Yue et al.USENIX Security 2024 · 11 citations
- Pulling Off The Mask: Forensic Analysis of the Deceptive Creator Wallets Behind Smart Contract FraudMingxuan Yao, Runze Zhang, Haichuan Xu, Shih-Huan Chou et al.S&P 2024 · 10 citations
- Phishing in Wonderland: Evaluating Learning-Based Ethereum Phishing Transaction Detection and PitfallsAhod Alghuried, David MohaisenNDSS 2026 · 4 citations
- Insecurity Through Obscurity: Veiled Vulnerabilities in Closed-Source ContractsSen Yang, Kaihua Qin, Aviv Yaish, Fan ZhangCCS 2026 · 3 citations
- Precise Static Identification of Ethereum Storage VariablesSifis Lagouvardos, Yannis Bollanos, Michael Debono, Neville Grech et al.ICSE 2026 · 2 citations
Builds on16
- Making Smart Contracts SmarterLoi Luu, Duc-Hiep Chu, Hrishi Olickel, Prateek Saxena et al.CCS 2016 · 2,306 citations
- Securify: Practical Security Analysis of Smart ContractsPetar Tsankov, Andrei Marian Dan, Dana Drachsler-Cohen, Arthur Gervais et al.CCS 2018 · 1,108 citations
- teEther: Gnawing at Ethereum to Automatically Exploit Smart ContractsJohannes Krupp, Christian RossowUSENIX Security 2018 · 345 citations
- Learning to Fuzz from Symbolic Execution with Application to Smart ContractsJingxuan He, Mislav Balunovic, Nodar Ambroladze, Petar Tsankov et al.CCS 2019 · 288 citations
- sFuzz: an efficient adaptive fuzzer for solidity smart contractsTai D. Nguyen, Long H. Pham, Jun Sun, Yun Lin et al.ICSE 2020 · 260 citations
Related papers
- Not your Type! Detecting Storage Collision Vulnerabilities in Ethereum Smart ContractsNicola Ruaro, Fabio Gritti, Robert McLaughlin, Ilya Grishchenko et al.NDSS 2024
- Approve Once, Regret Forever: On the Exploitation of Ethereum's Approve-TransferFrom EcosystemNicola Ruaro, Fabio Gritti, Dongyu Meng, Robert McLaughlin et al.USENIX Security 2025
- Reentrancy Vulnerability Detection and Localization: A Deep Learning Based Two-phase ApproachZhuo Zhang, Yan Lei, Meng Yan, Yue Yu et al.ASE 2022 · 56 citations
- The Art of The Scam: Demystifying Honeypots in Ethereum Smart ContractsChristof Ferreira Torres, Mathis Steichen, Radu StateUSENIX Security 2019 · 239 citations
- Smart Contract Vulnerabilities: Vulnerable Does Not Imply ExploitedDaniel Perez, Benjamin LivshitsUSENIX Security 2021 · 150 citations
