Lune

CCS2026Top-tier venue

Insecurity Through Obscurity: Veiled Vulnerabilities in Closed-Source Contracts

Sen Yang, Kaihua Qin, Aviv Yaish, Fan Zhang

2026Year
3Citations

Abstract

Most blockchains cannot hide the binary code of programs (i.e., smart contracts) running on them. To conceal proprietary business logic and to potentially deter attacks, many smart contracts are closed-source and in many cases exhibit code obfuscation, either intentionally introduced to hide internal logic or unintentionally produced by optimizations. However, we demonstrate that such obfuscation can obscure critical vulnerabilities rather than enhance security, a phenomenon known as insecurity through obscurity. To systematically analyze these risks on a large scale, we present skanf, a novel EVM bytecode analysis tool tailored for closed-source and obfuscated contracts. skanf combines control-flow deobfuscation with symbolic execution based on historical transactions to identify and exploit asset management vulnerabilities. Our evaluation on real-world Maximal Extractable Value (MEV) bots reveals that skanf detects vulnerabilities in 1,046 contracts and successfully generates exploits for 394 of them, with potential losses of 10.6M.Additionally,weuncover104real−worldMEVbotattacksthatcollectivelyresultedin10.6M. Additionally, we uncover 104 real-world MEV bot attacks that collectively resulted in 2.76M in losses. CCS Concepts • Security and privacy → Distributed systems security.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext 6c043796-499e-4873-9d2a-5b3c927f101b

Builds on39

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines