DoubleUp Roll: Double-spending in Arbitrum by Rolling It Back
Zhiyuan Sun, Zihao Li, Xinghao Peng, Xiapu Luo, Muhui Jiang, Hao Zhou, Yinqian Zhang
Abstract
Optimistic rollup protocols are widely adopted as the most popular blockchain scaling solutions. As a dominant implementation, Arbitrum has boasted a total locked value exceeding 18 billion USD, highlighting the significance of optimistic rollups in blockchain ecosystem. Despite their popularity, little research has been done on the security of optimistic rollup protocols, and potential vulnerabilities on them remain unknown. In this work, we unveil three novel double spending attacks on Arbitrum, each enabling an attacker to steal funds from cross-chain applications on Arbitrum. To facilitate these double spending attacks, we introduce an attack to induce manipulable delays in the transaction rollup process and propose a cost optimization solution to reduce further transaction fees associated with the attacks. Our investigations broaden the exploitation of our double spending attacks to another leading optimistic rollup protocol, Optimism, highlighting the generability of our proposed attacks. Through extensive experiments on a local test network, we demonstrated that our attacks lead to severe malicious effects, such as fund losses from double spending. From late 2022 to early 2023, we reported these vulnerabilities to the Arbitrum and Optimism teams. All the issues were acknowledged and resolved, and our research safeguarded billions of dollars at risk, earning us half a million dollars in bug bounty rewards.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d82e4aaa-9e7c-4d40-abd9-db742a3b4754Cited by top-tier papers2
- fAmulet: Finding Finalization Failure Bugs in Polygon zkRollupZihao Li, Xinghao Peng, Zheyuan He, Xiapu Luo et al.CCS 2024 · 5 citations
- Is My RPC Response Reliable? Detecting RPC Bugs in Blockchain Client under ContextZhijie Zhong, Yuhong Nan, Mingxi Ye, Qing Xue et al.ICSE 2026
Builds on10
- Anonymous Multi-Hop Locks for Blockchain Scalability and InteroperabilityGiulio Malavolta, Pedro Moreno-Sanchez, Clara Schneidewind, Aniket Kate et al.NDSS 2019 · 305 citations
- Finding Consensus Bugs in Ethereum via Multi-transaction Differential FuzzingYoungseok Yang, Taesoo Kim, Byung-Gon ChunOSDI 2021 · 57 citations
- SCVHunter: Smart Contract Vulnerability Detection Based on Heterogeneous Graph Attention NetworkFeng Luo, Ruijie Luo, Ting Chen, Ao Qiao et al.ICSE 2024 · 38 citations
- DETER: Denial of Ethereum Txpool sERvicesKai Li, Yibo Wang, Yuzhe TangCCS 2021 · 26 citations
- DeepInfer: Deep Type Inference from Smart Contract BytecodeKunsong Zhao, Zihao Li, Jianfeng Li, He Ye et al.FSE 2023 · 24 citations
Related papers
- Rolling in the Shadows: Analyzing the Extraction of MEV Across Layer-2 RollupsChristof Ferreira Torres, Albin Mamuti, Ben Weintraub, Cristina Nita-Rotaru et al.CCS 2024 · 12 citations
- Specular: Towards Secure, Trust-minimized Optimistic Blockchain ExecutionZhe Ye, Ujval Misra, Jiajun Cheng, Wenyang Zhou et al.S&P 2024 · 9 citations
- A Two-Layer Blockchain Sharding Protocol Leveraging Safety and Liveness for Enhanced PerformanceYibin Xu, Jingyi Zheng, Boris Düdder, Tijs Slaats et al.NDSS 2024
- The Attack of the Clones Against Proof-of-AuthorityParinya Ekparinya, Vincent Gramoli, Guillaume JourjonNDSS 2020
- Smart Contract and DeFi Security Tools: Do They Meet the Needs of Practitioners?Stefanos Chaliasos, Marcos Antonios Charalambous, Liyi Zhou, Rafaila Galanopoulou et al.ICSE 2024 · 49 citations
