Compositional Security for Reentrant Applications
Ethan Cecchetti, Siqiu Yao, Haobin Ni, Andrew C. Myers
Abstract
The disastrous vulnerabilities in smart contracts sharply remind us of our ignorance: we do not know how to write code that is secure in composition with malicious code. Information flow control has long been proposed as a way to achieve compositional security, offering strong guarantees even when combining software from different trust domains. Unfortunately, this appealing story breaks down in the presence of reentrancy attacks. We formalize a general definition of reentrancy and introduce a security condition that allows software modules like smart contracts to protect their key invariants while retaining the expressive power of safe forms of reentrancy. We present a security type system that provably enforces secure information flow; in conjunction with run-time mechanisms, it enforces secure reentrancy even in the presence of unknown code; and it helps locate and correct recent high-profile vulnerabilities.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers9
- SAILFISH: Vetting Smart Contract State-Inconsistency Bugs in SecondsPriyanka Bose, Dipanjan Das, Yanju Chen, Yu Feng et al.S&P 2022 · 142 citations
- Efficiently Detecting Reentrancy Vulnerabilities in Complex Smart ContractsZexu Wang, Jiachi Chen, Yanlin Wang, Yu Zhang et al.FSE 2024 · 27 citations
- Lanturn: Measuring Economic Security of Smart Contracts Through Adaptive LearningKushal Babel, Mojan Javaheripi, Yan Ji, Mahimna Kelkar et al.CCS 2023 · 18 citations
- Detecting Smart Contract State-Inconsistency Bugs via Flow Divergence and Multiplex Symbolic ExecutionYinxi Liu, Wei Meng, Yinqian ZhangFSE 2025 · 1 citation
- Enhancing Smart Contract Security Analysis with Execution Property GraphsKaihua Qin, Zhe Ye, Zhun Wang, Weilin Li et al.ISSTA 2025 · 1 citation
Builds on7
- Making Smart Contracts SmarterLoi Luu, Duc-Hiep Chu, Hrishi Olickel, Prateek Saxena et al.CCS 2016 · 2,306 citations
- Town Crier: An Authenticated Data Feed for Smart ContractsFan Zhang, Ethan Cecchetti, Kyle Croman, Ari Juels et al.CCS 2016 · 668 citations
- teEther: Gnawing at Ethereum to Automatically Exploit Smart ContractsJohannes Krupp, Christian RossowUSENIX Security 2018 · 345 citations
- Ethainter: a smart contract security analyzer for composite vulnerabilitiesLexi Brent, Neville Grech, Sifis Lagouvardos, Bernhard Scholz et al.PLDI 2020 · 163 citations
- Securing smart contract with runtime validationAo Li, Jemin Andrew Choi, Fan LongPLDI 2020 · 60 citations
Related papers
- AdvSCanner: Generating Adversarial Smart Contracts to Exploit Reentrancy Vulnerabilities Using LLM and Static AnalysisYin Wu, Xiaofei Xie, Chenyang Peng, Dijun Liu et al.ASE 2024 · 9 citations
- SmartIFSyn: Automated Information Flow Security Policy Synthesis for Smart ContractsYinghao Wu, Miaomiao Zhang, Fu Song, John W. Baugh Jr.FSE 2026
- Sereum: Protecting Existing Smart Contracts Against Re-Entrancy AttacksMichael Rodler, Wenting Li, Ghassan O. Karame, Lucas DaviNDSS 2019 · 298 citations
- Reentrancy Vulnerability Detection and Localization: A Deep Learning Based Two-phase ApproachZhuo Zhang, Yan Lei, Meng Yan, Yue Yu et al.ASE 2022 · 56 citations
- Uncover the Premeditated Attacks: Detecting Exploitable Reentrancy Vulnerabilities by Identifying Attacker ContractsShuo Yang, Jiachi Chen, Mingyuan Huang, Zibin Zheng et al.ICSE 2024 · 24 citations
