Verifying Economic Security of Smart Contracts via Unintended Return
Yi Rong, Xupeng Li, Ronghui Gu
Abstract
We propose CMod, an economic model for analyzing the economic security of decentralized finance (DeFi) smart contract code. CMod defines the notions of economic value, intended-return conditions, and unintended single-transaction return, and reasons about economic security by proving the absence of unintended single-transaction return. Based on CMod, we co-design CSol, an automated verification tool for Solidity that reasons about path properties in multi-contract environments via bounded symbolic execution. CSol incorporates three categories of optimizations: CMod-oriented path pruning and inductive verification, proof-goal simplification, and solver acceleration. Our evaluation shows that CMod and CSol can be applied to real-world contract code and characterize economically exploitable vulnerabilities. CSol verifies 245 real-world contracts, identifies 6 live scam contracts, detects 16 of 18 real-world exploits and 92 of 104 audit-stage findings, and exposes one misidentification in an existing tool's benchmark.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 741b434e-595a-446e-a4a3-2fd96166c43aRelated papers
- Clockwork Finance: Automated Analysis of Economic Security in Smart ContractsKushal Babel, Philip Daian, Mahimna Kelkar, Ari JuelsS&P 2023
- FORAY: Towards Effective Attack Synthesis against Deep Logical Vulnerabilities in DeFi ProtocolsHongbo Wen, Hanzhi Liu, Jiaxin Song, Yanju Chen et al.CCS 2024 · 6 citations
- Automated Inference on Financial Security of Ethereum Smart ContractsWansen Wang, Wenchao Huang, Zhaoyi Meng, Yan Xiong et al.USENIX Security 2023
- SmarTest: Effectively Hunting Vulnerable Transaction Sequences in Smart Contracts through Language Model-Guided Symbolic ExecutionSunbeom So, Seongjoon Hong, Hakjoo OhUSENIX Security 2021 · 118 citations
- Automated Attack Synthesis for Constant Product Market MakersSujin Han, Jinseo Kim, Sung-Ju Lee, Insu YunISSTA 2025
