Time-manipulation Attack: Breaking Fairness against Proof of Authority Aura
Xinrui Zhang, Rujia Li, Qin Wang, Qi Wang, Sisi Duan
Abstract
As blockchain-based commercial projects and startups flourish, efficiency becomes one of the critical metrics in designing blockchain systems. Due to its high efficiency, Proof of Authority (PoA) Aura has become one of the most widely adopted consensus solutions for blockchains. Our research finds over 4, 000 projects have used Aura and its variants. In this paper, we provide a rigorous analysis of Aura. We propose three types of time-manipulation attacks, where a malicious leader simply needs to modify the timestamp in its proposed block or delay it to extract extra benefits. These attacks can easily break the legal leader election, thus directly harming the fairness of the block proposal. We apply our attacks to a mature Aura project called OpenEthereum. By repeatedly conducting our attacks 1 over 15 days, we find that an adversary can gain on average 200% mining rewards of their fair shares. Furthermore, such attacks can even indirectly break the finality of blocks and the safety of the system. Based on the deployment of Aura as of September 2022, the potentially affected market cap is up to 2.13 billion USD. As a by-product, we further discuss solutions to mitigate such issues and report our observations to official teams. CCS CONCEPTS • Security and privacy → Distributed systems security;
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 62843b4d-75a2-4fe7-bd70-3377b5c016b6Cited by top-tier papers1
Ask how each one uses itBuilds on4
- Flash Boys 2.0: Frontrunning in Decentralized Exchanges, Miner Extractable Value, and Consensus InstabilityPhilip Daian, Steven Goldfeder, Tyler Kell, Yunqi Li et al.S&P 2020 · 607 citations
- Order-Fairness for Byzantine ConsensusMahimna Kelkar, Fan Zhang, Steven Goldfeder, Ari JuelsCRYPTO 2020 · 152 citations
- Game-Theoretic Fairness Meets Multi-party Protocols: The Case of Leader ElectionKai-Min Chung, T.-H. Hubert Chan, Ting Wen, Elaine ShiCRYPTO 2021 · 13 citations
- The Attack of the Clones Against Proof-of-AuthorityParinya Ekparinya, Vincent Gramoli, Guillaume JourjonNDSS 2020
Related papers
- Multi-Certificate Attacks against Proof-of-Elapsed-Time and Their CountermeasuresHuibo Wang, Guoxing Chen, Yinqian Zhang, Zhiqiang LinNDSS 2022
- Uncle Maker: (Time)Stamping Out The Competition in EthereumAviv Yaish, Gilad Stern, Aviv ZoharCCS 2023 · 19 citations
- Available Attestation: Towards a Reorg-Resilient Solution for Ethereum Proof-of-StakeMingfei Zhang, Rujia Li, Xueqian Lu, Sisi DuanUSENIX Security 2025
- DoubleUp Roll: Double-spending in Arbitrum by Rolling It BackZhiyuan Sun, Zihao Li, Xinghao Peng, Xiapu Luo et al.CCS 2024 · 3 citations
- Forking the RANDAO: Manipulating Ethereum's Distributed Randomness BeaconÁbel Nagy, János Tapolcai, István András Seres, Bence LadóczkiCCS 2025 · 2 citations
