Characterizing Ethereum Upgradable Smart Contracts and Their Security Implications
Xiaofan Li, Jin Yang, Jiaqi Chen, Yuzhe Tang, Xing Gao
Abstract
Upgradeable smart contracts (USCs) have been widely adopted to enable modifying deployed smart contracts. While USCs bring great flexibility to developers, improper usage might introduce new security issues, potentially allowing attackers to hijack USCs and their users. In this paper, we conduct a large-scale measurement study to characterize USCs and their security implications in the wild. We summarize six commonly used USC patterns and develop a tool, USCDetector, to identify USCs without needing source code. Particularly, USCDetector collects various information such as bytecode and transaction information to construct upgrade chains for USCs and disclose potentially vulnerable ones. We evaluate USCDetector using verified smart contracts (i.e., with source code) as ground truth and show that USCDetector can achieve high accuracy with a precision of 96.26%. We then use USCDetector to conduct a large-scale study on Ethereum, covering a total of 60,251,064 smart contracts. USCDetecor constructs 10,218 upgrade chains and discloses multiple real-world USCs with potential security issues.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers1
Ask how each one uses itBuilds on16
- Making Smart Contracts SmarterLoi Luu, Duc-Hiep Chu, Hrishi Olickel, Prateek Saxena et al.CCS 2016 · 2,306 citations
- teEther: Gnawing at Ethereum to Automatically Exploit Smart ContractsJohannes Krupp, Christian RossowUSENIX Security 2018 · 345 citations
- Quantifying Blockchain Extractable Value: How dark is the forest?Kaihua Qin, Liyi Zhou, Arthur GervaisS&P 2022 · 336 citations
- Sereum: Protecting Existing Smart Contracts Against Re-Entrancy AttacksMichael Rodler, Wenting Li, Ghassan O. Karame, Lucas DaviNDSS 2019 · 298 citations
- sFuzz: an efficient adaptive fuzzer for solidity smart contractsTai D. Nguyen, Long H. Pham, Jun Sun, Yun Lin et al.ICSE 2020 · 260 citations
Related papers
- Proxy Hunting: Understanding and Characterizing Proxy-based Upgradeable Smart Contracts in BlockchainsWilliam Edward Bodell III, Sajad Meisami, Yue DuanUSENIX Security 2023
- An Empirical Study of Proxy Contracts at the Ethereum Ecosystem ScaleMengya Zhang, Preksha Shukla, Wuqi Zhang, Zhuo Zhang et al.ICSE 2025 · 5 citations
- Abusing the Ethereum Smart Contract Verification Services for Fun and ProfitPengxiang Ma, Ningyu He, Yuhua Huang, Haoyu Wang et al.NDSS 2024
- The Art of The Scam: Demystifying Honeypots in Ethereum Smart ContractsChristof Ferreira Torres, Mathis Steichen, Radu StateUSENIX Security 2019 · 239 citations
- All Your Tokens are Belong to Us: Demystifying Address Verification Vulnerabilities in Solidity Smart ContractsTianle Sun, Ningyu He, Jiang Xiao, Yinliang Yue et al.USENIX Security 2024 · 11 citations
