USENIX Security2023Top-tier venue
Panda: Security Analysis of Algorand Smart Contracts
Zhiyuan Sun, Xiapu Luo, Yinqian Zhang
Abstract
Algorand has recently grown rapidly as a representative of the new generation of pure-proof-of-stake (PPoS) blockchains. At the same time, Algorand has also attracted more and more users to use it as a trading platform for non-fungible tokens. However, similar to traditional programs, the incorrect way of programming will lead to critical security vulnerabilities in Algorand smart contracts. In this paper, we first analyze the semantics of Algorand smart contracts and find 9 types of generic vulnerabilities. Next, we propose Panda, the first extensible static analysis framework that can automatically detect such vulnerabilities in Algorand smart contracts, and formally define the vulnerability detection rules. We also construct the first benchmark dataset to evaluate Panda. Finally, we used Panda to conduct a vulnerability assessment on all smart contracts on the Algorand blockchain and found 80,515 (10.38%) vulnerable smart signatures and 150,676 (27.73%) vulnerable applications. Of the vulnerable applications, 4,008 (4.04%) are still on the blockchain and have not been deleted. In the disclosure process, the vulnerabilities found by Panda have been acknowledged by many projects, including some critical blockchain infrastructures such as the decentralized exchange and the NFT auction platform.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers3
- Semantic Sleuth: Identifying Ponzi Contracts via Large Language ModelsCong Wu, Jing Chen, Ziwei Wang, Ruichao Liang et al.ASE 2024 · 29 citations
- Towards Automatic Discovery of Denial of Service Weaknesses in Blockchain Resource ModelsFeng Luo, Huangkun Lin, Zihao Li, Xiapu Luo et al.CCS 2024 · 4 citations
- DoubleUp Roll: Double-spending in Arbitrum by Rolling It BackZhiyuan Sun, Zihao Li, Xinghao Peng, Xiapu Luo et al.CCS 2024 · 3 citations
Builds on13
- Making Smart Contracts SmarterLoi Luu, Duc-Hiep Chu, Hrishi Olickel, Prateek Saxena et al.CCS 2016 · 2,306 citations
- Securify: Practical Security Analysis of Smart ContractsPetar Tsankov, Andrei Marian Dan, Dana Drachsler-Cohen, Arthur Gervais et al.CCS 2018 · 1,108 citations
- LAVA: Large-Scale Automated Vulnerability AdditionBrendan Dolan-Gavitt, Patrick Hulin, Engin Kirda, Tim Leek et al.S&P 2016 · 354 citations
- Learning to Fuzz from Symbolic Execution with Application to Smart ContractsJingxuan He, Mislav Balunovic, Nodar Ambroladze, Petar Tsankov et al.CCS 2019 · 288 citations
- TokenScope: Automatically Detecting Inconsistent Behaviors of Cryptocurrency Tokens in EthereumTing Chen, Yufei Zhang, Zihao Li, Xiapu Luo et al.CCS 2019 · 140 citations
Related papers
- EOSAFE: Security Analysis of EOSIO Smart ContractsNingyu He, Ruiyi Zhang, Haoyu Wang, Lei Wu et al.USENIX Security 2021 · 69 citations
- On Identifying Sound Conditions for Frontrunning ResistanceSebastian Holler, Anna Piscitelli, Jannik Albrecht, Stephan Dübler et al.CCS 2026
- SmartDagger: a bytecode-based static analysis approach for detecting cross-contract vulnerabilityZeqin Liao, Zibin Zheng, Xiao Chen, Yuhong NanISSTA 2022 · 64 citations
- An empirical study of blockchain system vulnerabilities: modules, types, and patternsXiao Yi, Daoyuan Wu, Lingxiao Jiang, Yuzhou Fang et al.FSE 2022 · 22 citations
- VERISMART: A Highly Precise Safety Verifier for Ethereum Smart ContractsSunbeom So, Myungho Lee, Jisu Park, Heejo Lee et al.S&P 2020 · 133 citations
