USENIX Security2021Top-tier venue
EOSAFE: Security Analysis of EOSIO Smart Contracts
Ningyu He, Ruiyi Zhang, Haoyu Wang, Lei Wu, Xiapu Luo, Yao Guo, Ting Yu, Xuxian Jiang
Abstract
The EOSIO blockchain, one of the representative Delegated Proof-of-Stake (DPoS) blockchain platforms, has grown rapidly recently. Meanwhile, a number of vulnerabilities and high-profile attacks against top EOSIO DApps and their smart contracts have also been discovered and observed in the wild, resulting in serious financial damages. Most of the EOSIO smart contracts are not open-sourced and typically compiled to WebAssembly (Wasm) bytecode, thus making it challenging to analyze and detect the presence of possible vulnerabilities. In this paper, we propose EOSAFE, the first static analysis framework that can be used to automatically detect vulnerabilities in EOSIO smart contracts at the bytecode level. Our framework includes a practical symbolic execution engine for Wasm, a customized library emulator for EOSIO smart contracts, and four heuristic-driven detectors to identify the presence of the four most popular vulnerabilities in EO-SIO smart contracts. Experiments have shown that EOSAFE achieves promising results in detecting vulnerabilities, with an F1-measure of 98%. We have applied EOSAFE to all active 53,666 smart contracts in the ecosystem (as of November 15, 2019). Our results show that over 25% of the smart contracts are labeled vulnerable. We further analyze possible exploitation attempts on these vulnerable smart contracts and identify 48 in-the-wild attacks (27 of them have been confirmed by DApp developers), which have resulted in financial loss of at least 1.7 million USD.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext bdf8bbf1-c012-48e7-aa74-488d918eb8daCited by top-tier papers15
- Park: accelerating smart contract vulnerability detection via parallel-fork symbolic executionPeilin Zheng, Zibin Zheng, Xiapu LuoISSTA 2022 · 46 citations
- WASAI: uncovering vulnerabilities in Wasm smart contractsWeimin Chen, Zihan Sun, Haoyu Wang, Xiapu Luo et al.ISSTA 2022 · 43 citations
- Are We There Yet? Unraveling the State-of-the-Art Smart Contract FuzzersShuohan Wu, Zihao Li, Luyi Yan, Weimin Chen et al.ICSE 2024 · 24 citations
- SmartState: Detecting State-Reverting Vulnerabilities in Smart Contracts via Fine-Grained State-Dependency AnalysisZeqin Liao, Sicheng Hao, Yuhong Nan, Zibin ZhengISSTA 2023 · 22 citations
- How Hard is Takeover in DPoS Blockchains? Understanding the Security of Coin-based Voting GovernanceChao Li, Balaji Palanisamy, Runhua Xu, Li Duan et al.CCS 2023 · 17 citations
Builds on2
Related papers
- VETEOS: Statically Vetting EOSIO Contracts for the "Groundhog Day" VulnerabilitiesLevi Taiji Li, Ningyu He, Haoyu Wang, Mu ZhangNDSS 2024
- SymWeb: Feedback-Driven Context Exploration and Context-Aware Symbolic Execution for Browser-Embedded WebAssembly Vulnerability DetectionYuanpeng Wang, Yeqi Fu, Zhineng Zhong, Zhenkai Liang et al.ISSTA 2026
- eTainter: detecting gas-related vulnerabilities in smart contractsAsem Ghaleb, Julia Rubin, Karthik PattabiramanISSTA 2022 · 57 citations
- Panda: Security Analysis of Algorand Smart ContractsZhiyuan Sun, Xiapu Luo, Yinqian ZhangUSENIX Security 2023
- FairChecker: Detecting Fund-Stealing Bugs in DeFi Protocols via Fairness ValidationYi Sun, Zhuo Zhang, Xiangyu ZhangICSE 2025
