TokenScope: Automatically Detecting Inconsistent Behaviors of Cryptocurrency Tokens in Ethereum
Ting Chen, Yufei Zhang, Zihao Li, Xiapu Luo, Ting Wang, Rong Cao, Xiuzhuo Xiao, Xiaosong Zhang
Abstract
Motivated by the success of Bitcoin, lots of cryptocurrencies have been created, the majority of which were implemented as smart contracts running on Ethereum and called tokens. To regulate the interaction between these tokens and users as well as third-party tools (e.g., wallets, exchange markets, etc.), several standards have been proposed for the implementation of token contracts. Although existing tokens involve lots of money, little is known whether or not their behaviors are consistent with the standards. Inconsistent behaviors can lead to user confusion and financial loss, because users/third-party tools interact with token contracts by invoking standard interfaces and listening to standard events. In this work, we take the first step to investigate such inconsistent token behaviors with regard to ERC-20, the most popular token standard. We propose a novel approach to automatically detect such inconsistency by contrasting the behaviors derived from three different sources, including the manipulations of core data structures recording the token holders and their shares, the actions indicated by standard interfaces, and the behaviors suggested by standard events. We implement our approach in a new tool named TokenScope and use it to inspect all transactions sent to the deployed tokens. We detected 3,259,001 transactions that trigger inconsistent behaviors, and these behaviors resulted from 7,472 tokens. By manually examining all (2,353) open-source tokens having inconsistent behaviors, we found that the precision of TokenScope is above 99.9%. Moreover, we revealed 11 major reasons behind the inconsistency, e.g., flawed tokens, standard methods missing, lack of standard events, etc. In particular, we discovered 50 unreported flawed tokens.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 5e86cf63-bf22-4e70-8d28-76184ca58d72Cited by top-tier papers25
- WASAI: uncovering vulnerabilities in Wasm smart contractsWeimin Chen, Zihan Sun, Haoyu Wang, Xiapu Luo et al.ISSTA 2022 · 43 citations
- Demystifying DeFi MEV Activities in Flashbots BundleZihao Li, Jianfeng Li, Zheyuan He, Xiapu Luo et al.CCS 2023 · 29 citations
- Efficiently Detecting Reentrancy Vulnerabilities in Complex Smart ContractsZexu Wang, Jiachi Chen, Yanlin Wang, Yu Zhang et al.FSE 2024 · 27 citations
- An Off-The-Chain Execution Environment for Scalable Testing and Profiling of Smart ContractsYeonsoo Kim, Seongho Jeong, Kamil Jezek, Bernd Burgstaller et al.USENIX ATC 2021 · 27 citations
- Are We There Yet? Unraveling the State-of-the-Art Smart Contract FuzzersShuohan Wu, Zihao Li, Luyi Yan, Weimin Chen et al.ICSE 2024 · 24 citations
Builds on5
- Making Smart Contracts SmarterLoi Luu, Duc-Hiep Chu, Hrishi Olickel, Prateek Saxena et al.CCS 2016 · 2,306 citations
- Securify: Practical Security Analysis of Smart ContractsPetar Tsankov, Andrei Marian Dan, Dana Drachsler-Cohen, Arthur Gervais et al.CCS 2018 · 1,108 citations
- ZEUS: Analyzing Safety of Smart ContractsSukrit Kalra, Seep Goel, Mohan Dhawan, Subodh SharmaNDSS 2018 · 595 citations
- teEther: Gnawing at Ethereum to Automatically Exploit Smart ContractsJohannes Krupp, Christian RossowUSENIX Security 2018 · 345 citations
- Sereum: Protecting Existing Smart Contracts Against Re-Entrancy AttacksMichael Rodler, Wenting Li, Ghassan O. Karame, Lucas DaviNDSS 2019 · 298 citations
Related papers
- SmartCoCo: Checking Comment-Code Inconsistency in Smart Contracts via Constraint Propagation and BindingSicheng Hao, Yuhong Nan, Zibin Zheng, Xiaohui LiuASE 2023 · 7 citations
- Empirical evaluation of smart contract testing: what is the best choice?Meng Ren, Zijing Yin, Fuchen Ma, Zhenyang Xu et al.ISSTA 2021 · 83 citations
- Using My Functions Should Follow My Checks: Understanding and Detecting Insecure OpenZeppelin Code in Smart ContractsHan Liu, Daoyuan Wu, Yuqiang Sun, Haijun Wang et al.USENIX Security 2024 · 11 citations
- Automated and Accurate Token Transfer Identification and Its Applications in Cryptocurrency SecurityShuwei Song, Ting Chen, Ao Qiao, Xiapu Luo et al.FSE 2025
- BlockScope: Detecting and Investigating Propagated Vulnerabilities in Forked Blockchain ProjectsXiao Yi, Yuzhou Fang, Daoyuan Wu, Lingxiao JiangNDSS 2023
