Automated and Accurate Token Transfer Identification and Its Applications in Cryptocurrency Security
Shuwei Song, Ting Chen, Ao Qiao, Xiapu Luo, Leqing Wang, Zheyuan He, Ting Wang, Xiaodong Lin, Peng He, Wensheng Zhang, Xiaosong Zhang
Abstract
Cryptocurrency tokens, implemented by smart contracts, are prime targets for attackers due to their substantial monetary value. To illicitly gain profit, attackers often embed malicious code or exploit vulnerabilities within token contracts. Token transfer identification is crucial for detecting malicious and vulnerable token contracts. However, existing methods suffer from high false positives or false negatives due to invalid assumptions or reliance on limited patterns. This paper introduces a novel approach that captures the essential principles of token contracts, which are independent of programming languages and token standards, and presents a new tool, CRYPTO-SCOUT. CRYPTO-SCOUT automatically and accurately identifies token transfers, enabling the detection of various malicious and vulnerable token contracts. CRYPTO-SCOUT's core innovation is its capability to automatically identify complex container-type variables used by token contracts for storing holder information. It processes the bytecode of smart contracts written in the two most widely-used languages, Solidity and Vyper, and supports the three most popular token standards, ERC20, ERC721, and ERC1155. Furthermore, CRYPTO-SCOUT detects four types of malicious and vulnerable token contracts and is designed to be extensible. Extensive experiments show that CRYPTO-SCOUT outperforms existing approaches and uncovers over 21,000 malicious/vulnerable token contracts and more than 12,000 transactions triggering them.
CCS Concepts: • Security and privacy → Software and application security.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 9fad513b-e114-448a-9b9a-225080f3e55bBuilds on9
- Making Smart Contracts SmarterLoi Luu, Duc-Hiep Chu, Hrishi Olickel, Prateek Saxena et al.CCS 2016 · 2,306 citations
- TokenScope: Automatically Detecting Inconsistent Behaviors of Cryptocurrency Tokens in EthereumTing Chen, Yufei Zhang, Zihao Li, Xiapu Luo et al.CCS 2019 · 140 citations
- Traveling the token world: A graph analysis of Ethereum ERC20 token ecosystemWeili Chen, Tuo Zhang, Zhiguang Chen, Zibin Zheng et al.WWW 2020 · 110 citations
- Erays: Reverse Engineering Ethereum's Opaque Smart ContractsYi Zhou, Deepak Kumar, Surya Bakshi, Joshua Mason et al.USENIX Security 2018 · 107 citations
- Temporal Analysis of the Entire Ethereum Blockchain NetworkLin Zhao, Sourav Sen Gupta, Arijit Khan, Robby LuoWWW 2021 · 80 citations
Related papers
- TokenScout: Early Detection of Ethereum Scam Tokens via Temporal Graph LearningCong Wu, Jing Chen, Ziming Zhao, Kun He et al.CCS 2024 · 35 citations
- Smarter Contracts: Detecting Vulnerabilities in Smart Contracts with Deep Transfer LearningChristoph Sendner, Huili Chen, Hossein Fereidooni, Lukas Petzi et al.NDSS 2023
- Approve Once, Regret Forever: On the Exploitation of Ethereum's Approve-TransferFrom EcosystemNicola Ruaro, Fabio Gritti, Dongyu Meng, Robert McLaughlin et al.USENIX Security 2025
- Interface Illusions: Uncovering the Rise of Visual Scams in Cryptocurrency WalletsGuoyi Ye, Geng Hong, Yuan Zhang, Min YangWWW 2024 · 7 citations
- teEther: Gnawing at Ethereum to Automatically Exploit Smart ContractsJohannes Krupp, Christian RossowUSENIX Security 2018 · 345 citations
