USENIX Security2018Top-tier venue
Enter the Hydra: Towards Principled Bug Bounties and Exploit-Resistant Smart Contracts
Lorenz Breidenbach, Philip Daian, Florian Tramèr, Ari Juels
Abstract
Bug bounties are a popular tool to help prevent software exploits. Yet, they lack rigorous principles for setting bounty amounts and require high payments to attract economically rational hackers. Rather than claim bounties for serious bugs, hackers often sell or exploit them. We present the Hydra Framework, the first general, principled approach to modeling and administering bug bounties that incentivize bug disclosure. Our key idea is an exploit gap, a program transformation that enables runtime detection, and rewarding, of critical bugs. Our framework transforms programs via N-of-N-version programming, a variant of classical N-version programming that runs multiple independent program instances. We apply the Hydra Framework to smart contracts, small programs that execute on blockchains. We show how Hydra contracts greatly amplify the power of bounties to incentivize bug disclosure by economically rational adversaries, establishing the first framework for rigorous economic evaluation of smart contract security. We also model powerful adversaries capable of bug withholding, exploiting race conditions in blockchains to claim bounties before honest users can. We present Submarine Commitments, a countermeasure of independent interest that conceals transactions on blockchains. We design a simple, automated version of the Hydra Framework for Ethereum (ethereum.org) and implement two Hydra contracts, an ERC20 standard token and a Monty-Hall game. We evaluate our implementation for completeness and soundness with the official Ethereum virtual machine test suite and live blockchain data.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 73269937-e2b8-4c7c-a75f-8c382719dd20Cited by top-tier papers19
- teEther: Gnawing at Ethereum to Automatically Exploit Smart ContractsJohannes Krupp, Christian RossowUSENIX Security 2018 · 345 citations
- High-Frequency Trading on Decentralized On-Chain ExchangesLiyi Zhou, Kaihua Qin, Christof Ferreira Torres, Duc Viet Le et al.S&P 2021 · 243 citations
- Frontrunner Jones and the Raiders of the Dark Forest: An Empirical Study of Frontrunning on the Ethereum BlockchainChristof Ferreira Torres, Ramiro Camino, Radu StateUSENIX Security 2021 · 179 citations
- Redactable Blockchain in the Permissionless SettingDominic Deuber, Bernardo Magri, Sri Aravinda Krishnan ThyagarajanS&P 2019 · 153 citations
- On the Just-In-Time Discovery of Profit-Generating Transactions in DeFi ProtocolsLiyi Zhou, Kaihua Qin, Antoine Cully, Benjamin Livshits et al.S&P 2021 · 148 citations
Builds on2
Related papers
- The Art of The Scam: Demystifying Honeypots in Ethereum Smart ContractsChristof Ferreira Torres, Mathis Steichen, Radu StateUSENIX Security 2019 · 239 citations
- SmartInv: Multimodal Learning for Smart Contract Invariant InferenceSally Junsong Wang, Kexin Pei, Junfeng YangS&P 2024 · 38 citations
- A Mixed-Methods Study of Security Practices of Smart Contract DevelopersTanusree Sharma, Kyrie Zhixuan Zhou, Andrew Miller, Yang WangUSENIX Security 2023
- ZEUS: Analyzing Safety of Smart ContractsSukrit Kalra, Seep Goel, Mohan Dhawan, Subodh SharmaNDSS 2018 · 595 citations
- SGUARD: Towards Fixing Vulnerable Smart Contracts AutomaticallyTai D. Nguyen, Long H. Pham, Jun SunS&P 2021 · 69 citations
