Warning! The Timeout T Cannot Protect You From Losing Coins: PipeSwap: Forcing the Timely Release of a Secret for Atomic Cross-Chain Swaps
Peifang Ni, Anqi Tian, Jing Xu
Abstract
Atomic cross-chain swaps mitigate the interoper-ability challenges faced by current cryptocurrencies, thereby facilitating inter-currency exchange and trading between the distrusting users. Although numerous atomic swaps protocols utilizing Hash Timelock Contracts have been deployed and put into practice, they are substantially far from universality due to their inherent dependence of rich scripting language supported by the underlying blockchains. The recently proposed Universal Atomic Swaps protocol [IEEE S&P'22] represents a significant advancement in the field of scriptless cross-chain swaps by ingeniously delegating scripting functionalities to cryptographic locking mechanisms, particularly the adaptor signatures and timed commitment schemes. However, we identify a new form of attack termed the double-claiming attack that leverages these scriptless functionalities to undermine atomicity with a high probability. This attack is inherent to the designs adopted by the existing scriptless cross-chain swaps protocols as well as the payment channel networks. We further quantify the severity of this attack based on real-word swap transactions processed by the most widely deployed decentralized exchange platforms, highlighting the critical challenges in designing universal atomic swaps. To address the double-claiming attack while ensuring both security and practical universality, we also present a cross-chain swaps protocol called PipeSwap. Specifically, PipeSwap protects the frozen coins from being double-claimed by a novelly designed paradigm of pipelined coins flow that utilizes the techniques of two-hop swap and two-hop refund. In addition to a comprehensive security analysis in the Universal Composability framework, we develop a proof-of-concept implementation of PipeSwap with Schnorr/ECDSA signatures, and conduct extensive experiments to evaluate the overhead. The experimental results show that PipeSwap can be performed in less than 1.7 seconds while maintaining less than 7 kb of communication overhead on commodity machines.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext ad0d9a34-2902-4463-b3e7-910242a9bd36Cited by top-tier papers1
Ask how each one uses itBuilds on18
- Concurrency and Privacy with Payment-Channel NetworksGiulio Malavolta, Pedro Moreno-Sanchez, Aniket Kate, Matteo Maffei et al.CCS 2017 · 307 citations
- Anonymous Multi-Hop Locks for Blockchain Scalability and InteroperabilityGiulio Malavolta, Pedro Moreno-Sanchez, Clara Schneidewind, Aniket Kate et al.NDSS 2019 · 305 citations
- Revive: Rebalancing Off-Blockchain Payment NetworksRami Khalil, Arthur GervaisCCS 2017 · 259 citations
- General State Channel NetworksStefan Dziembowski, Sebastian Faust, Kristina HostákováCCS 2018 · 249 citations
- FairSwap: How To Fairly Exchange Digital GoodsStefan Dziembowski, Lisa Eckey, Sebastian FaustCCS 2018 · 229 citations
Related papers
- Parallelizing Universal Atomic Swaps for Multi-Chain Cryptocurrency ExchangesDanlei Xiao, Chuan Zhang, Haotian Deng, Jinwen Liang et al.USENIX Security 2025
- Universal Atomic Swaps: Secure Exchange of Coins Across All BlockchainsSri Aravinda Krishnan Thyagarajan, Giulio Malavolta, Pedro Moreno-SanchezS&P 2022 · 112 citations
- XCLAIM: Trustless, Interoperable, Cryptocurrency-Backed AssetsAlexei Zamyatin, Dominik Harz, Joshua Lind, Panayiotis Panayiotou et al.S&P 2019 · 222 citations
- Atomic Commitment Across BlockchainsVictor Zakhary, Divy Agrawal, Amr El AbbadiVLDB 2020 · 107 citations
- LedgerLocks: A Security Framework for Blockchain Protocols Based on Adaptor SignaturesErkan Tairi, Pedro Moreno-Sanchez, Clara SchneidewindCCS 2023 · 10 citations
