SoK: Decentralized Finance (DeFi) Attacks
Liyi Zhou, Xihan Xiong, Jens Ernstberger, Stefanos Chaliasos, Zhipeng Wang, Ye Wang, Kaihua Qin, Roger Wattenhofer, Dawn Song, Arthur Gervais
Abstract
Within just four years, the blockchain-based Decentralized Finance (DeFi) ecosystem has accumulated a peak total value locked (TVL) of more than 253 billion USD. This surge in DeFi’s popularity has, unfortunately, been accompanied by many impactful incidents. According to our data, users, liquidity providers, speculators, and protocol operators suffered a total loss of at least 3.24 billion USD from Apr 30, 2018 to Apr 30, 2022. Given the blockchain’s transparency and increasing incident frequency, two questions arise: How can we systematically measure, evaluate, and compare DeFi incidents? How can we learn from past attacks to strengthen DeFi security?In this paper, we introduce a common reference frame to systematically evaluate and compare DeFi incidents, including both attacks and accidents. We investigate 77 academic papers, 30 audit reports, and 181 real-world incidents. Our data reveals several gaps between academia and the practitioners’ community. For example, few academic papers address "price oracle attacks" and "permissonless interactions", while our data suggests that they are the two most frequent incident types (15% and 10.5% correspondingly). We also investigate potential defenses, and find that: (i) 103 (56%) of the attacks are not executed atomically, granting a rescue time frame for defenders; (ii) bytecode similarity analysis can at least detect 31 vulnerable/23 adversarial contracts; and (iii) 33 (15.3%) of the adversaries leak potentially identifiable information by interacting with centralized exchanges.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 61cf577e-4ad9-45a7-9664-6276f60d6f3cCited by top-tier papers40
- GPTScan: Detecting Logic Vulnerabilities in Smart Contracts by Combining GPT with Program AnalysisYuqiang Sun, Daoyuan Wu, Yue Xue, Han Liu et al.ICSE 2024 · 131 citations
- SoK: Security and Privacy of Blockchain InteroperabilityAndré Augusto, Rafael Belchior, Miguel Correia, André Vasconcelos et al.S&P 2024 · 90 citations
- Blockchain CensorshipAnton Wahrstätter, Jens Ernstberger, Aviv Yaish, Liyi Zhou et al.WWW 2024 · 60 citations
- SoK: What don't we know? Understanding Security Vulnerabilities in SNARKsStefanos Chaliasos, Jens Ernstberger, David Theodore, David Wong et al.USENIX Security 2024 · 32 citations
- Efficiently Detecting Reentrancy Vulnerabilities in Complex Smart ContractsZexu Wang, Jiachi Chen, Yanlin Wang, Yu Zhang et al.FSE 2024 · 27 citations
Builds on66
- Making Smart Contracts SmarterLoi Luu, Duc-Hiep Chu, Hrishi Olickel, Prateek Saxena et al.CCS 2016 · 2,306 citations
- On the Security and Performance of Proof of Work BlockchainsArthur Gervais, Ghassan O. Karame, Karl Wüst, Vasileios Glykantzis et al.CCS 2016 · 1,668 citations
- A Secure Sharding Protocol For Open BlockchainsLoi Luu, Viswesh Narayanan, Chaodong Zheng, Kunal Baweja et al.CCS 2016 · 1,392 citations
- OmniLedger: A Secure, Scale-Out, Decentralized Ledger via ShardingEleftherios Kokoris-Kogias, Philipp Jovanovic, Linus Gasser, Nicolas Gailly et al.S&P 2018 · 1,145 citations
- Securify: Practical Security Analysis of Smart ContractsPetar Tsankov, Andrei Marian Dan, Dana Drachsler-Cohen, Arthur Gervais et al.CCS 2018 · 1,108 citations
Related papers
- Smart Contract and DeFi Security Tools: Do They Meet the Needs of Practitioners?Stefanos Chaliasos, Marcos Antonios Charalambous, Liyi Zhou, Rafaila Galanopoulou et al.ICSE 2024 · 49 citations
- Toward Automated Detecting Unanticipated Price Feed in Smart ContractYifan Mo, Jiachi Chen, Yanlin Wang, Zibin ZhengISSTA 2023 · 7 citations
- I Experienced More than 10 DeFi Scams: On DeFi Users' Perception of Security Breaches and CountermeasuresMingyi Liu, Jun Ho Huh, HyungSeok Han, Jaehyuk Lee et al.USENIX Security 2024 · 6 citations
- HOUSTON: Real-Time Anomaly Detection of Attacks against Ethereum DeFi ProtocolsDongyu Meng, Fabio Gritti, Robert McLaughlin, Nicola Ruaro et al.NDSS 2026 · 2 citations
- GenDetect: Generalizing Reactive Detection for Resilience Against Imitative DeFi Attack CascadeBowen Cai, Weiheng Bai, Youshui Lu, Haoran Xu et al.ICSE 2026
