SigScope: Detecting and Understanding Off-Chain Message Signing-related Vulnerabilities in Decentralized Applications
Sajad Meisami, Hugo Dabadie, Song Li, Yuzhe Tang, Yue Duan
Abstract
In Web 3.0, an emerging paradigm of building decentralized applications or DApps is off-chain message signing, which has advantages in performance, cost efficiency, and usability compared to conventional transaction-signing schemes. However, message signing burdens DApp developers with extra coding complexity and message designing, leading to new security risks. This paper presents the first systematic study to uncover and characterize the security issues in off-chain message signing schemes and the DApps built atop them. We present a holistic static-analysis framework, SigScope, that uniquely combines the insights extracted from DApp front-end code (HTML and Javascript) off-chain and back-end smart contracts on-chain. We evaluate SigScope using the top 100 DApps to showcase its effectiveness and efficiency. Further, we leverage SigScope to study a large dataset of 4937 real-world DApps and show that 1579 DApps (including 73% of the top 100) rely on the off-chain message signing feature, and 1154 contain vulnerabilities. Finally, we use two real-world vulnerabilities in popular DApps to showcase our findings. CCS Concepts • Security and privacy → Software and application security.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 6b07cba4-c348-4191-9e7b-24a4a7e64465Builds on20
- Making Smart Contracts SmarterLoi Luu, Duc-Hiep Chu, Hrishi Olickel, Prateek Saxena et al.CCS 2016 · 2,306 citations
- Securify: Practical Security Analysis of Smart ContractsPetar Tsankov, Andrei Marian Dan, Dana Drachsler-Cohen, Arthur Gervais et al.CCS 2018 · 1,108 citations
- ZEUS: Analyzing Safety of Smart ContractsSukrit Kalra, Seep Goel, Mohan Dhawan, Subodh SharmaNDSS 2018 · 595 citations
- sFuzz: an efficient adaptive fuzzer for solidity smart contractsTai D. Nguyen, Long H. Pham, Jun Sun, Yun Lin et al.ICSE 2020 · 260 citations
- VerX: Safety Verification of Smart ContractsAnton Permenev, Dimitar Dimitrov, Petar Tsankov, Dana Drachsler-Cohen et al.S&P 2020 · 251 citations
Related papers
- AUTHSCOPE: Towards Automatic Discovery of Vulnerable Authorizations in Online ServicesChaoshun Zuo, Qingchuan Zhao, Zhiqiang LinCCS 2017 · 59 citations
- Stealing Trust: Unraveling Blind Message Attacks in Web3 AuthenticationKailun Yan, Xiaokuan Zhang, Wenrui DiaoCCS 2024 · 5 citations
- Detecting State Inconsistency Bugs in DApps via On-Chain Transaction Replay and FuzzingMingxi Ye, Yuhong Nan, Zibin Zheng, Dongpeng Wu et al.ISSTA 2023 · 24 citations
- Evil Under the Sun: Understanding and Discovering Attacks on Ethereum Decentralized ApplicationsLiya Su, Xinyue Shen, Xiangyu Du, Xiaojing Liao et al.USENIX Security 2021 · 74 citations
- Finding Insecure State Dependency in DApps via Multi-Source Tracing and Semantic EnrichmentJingwen Zhang, Yuhong Nan, Wei Li, Kaiwen Ning et al.ASE 2025 · 1 citation
