Demystifying OpenZeppelin's Own Vulnerabilities and Analyzing Their Propagation in Smart Contracts
Han Liu, Daoyuan Wu, Yuqiang Sun, Shuai Wang, Yang Liu, Yixiang Chen
Abstract
OpenZeppelin is a building block for many smart contracts on Ethereum-compatible blockchains. It provides modular and reusable libraries for various Ethereum standards (e.g., ERC20 and ERC721) and common functionalities such as upgradeable contracts. Little research has been done on Open-Zeppelin security except for a recent study, which focused only on the misuse of OpenZeppelin code, assuming OpenZeppelin itself is secure but contract developers may not follow OpenZeppelin's function checks appropriately. We argue that, despite appearing robust, OpenZeppelin itself could have many vulnerabilities, and these library-level vulnerabilities could inadvertently affect thirdparty smart contracts, even without misuse from developers.
We present ZEPCOMPARE, the first end-to-end system for demystifying OpenZeppelin's own vulnerabilities and analyzing their propagation in third-party smart contracts. ZEPCOMPARE incorporates a manual analysis stage where we review OpenZeppelin's 64 historical releases, identifying 109 vulnerable-fixed code pairs, exposing flaws in cryptographic utilities, access control, etc. Leveraging these pairs, ZEPCOMPARE introduces facts of changes, a novel structure capturing vulnerable and fixed code contexts for flexible matching. Evaluated across 88,605 contracts from three Ethereum-compatible chains, ZEPCOMPARE detects 4,708 instances of OpenZeppelin-derived vulnerabilities. Manual sampling and a ground-truth experiment confirm that ZEPCOM-PARE achieves 86.7% precision and 77.1% recall. Our findings reveal significant security risks in both historical and the latest versions of OpenZeppelin libraries, underscoring the urgent need for systematic auditing of foundational contracts components.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 76e8be1e-e29a-4103-80ba-8616687aad95Cited by top-tier papers1
Ask how each one uses itBuilds on20
- Securify: Practical Security Analysis of Smart ContractsPetar Tsankov, Andrei Marian Dan, Dana Drachsler-Cohen, Arthur Gervais et al.CCS 2018 · 1,108 citations
- ZEUS: Analyzing Safety of Smart ContractsSukrit Kalra, Seep Goel, Mohan Dhawan, Subodh SharmaNDSS 2018 · 595 citations
- Empirical review of automated analysis tools on 47, 587 Ethereum smart contractsThomas Durieux, João F. Ferreira, Rui Abreu, Pedro CruzICSE 2020 · 373 citations
- teEther: Gnawing at Ethereum to Automatically Exploit Smart ContractsJohannes Krupp, Christian RossowUSENIX Security 2018 · 345 citations
- Understanding Security Issues in the NFT EcosystemDipanjan Das, Priyanka Bose, Nicola Ruaro, Christopher Kruegel et al.CCS 2022 · 173 citations
Related papers
- Using My Functions Should Follow My Checks: Understanding and Detecting Insecure OpenZeppelin Code in Smart ContractsHan Liu, Daoyuan Wu, Yuqiang Sun, Haijun Wang et al.USENIX Security 2024 · 11 citations
- Identifying Solidity Smart Contract API Documentation ErrorsChenguang Zhu, Ye Liu, Xiuheng Wu, Yi LiASE 2022 · 16 citations
- Characterizing Ethereum Upgradable Smart Contracts and Their Security ImplicationsXiaofan Li, Jin Yang, Jiaqi Chen, Yuzhe Tang et al.WWW 2024 · 23 citations
- Revealing Hidden Threats: An Empirical Study of Library Misuse in Smart ContractsMingyuan Huang, Jiachi Chen, Zigui Jiang, Zibin ZhengICSE 2024 · 10 citations
- Abusing the Ethereum Smart Contract Verification Services for Fun and ProfitPengxiang Ma, Ningyu He, Yuhua Huang, Haoyu Wang et al.NDSS 2024
