Using My Functions Should Follow My Checks: Understanding and Detecting Insecure OpenZeppelin Code in Smart Contracts
Han Liu, Daoyuan Wu, Yuqiang Sun, Haijun Wang, Kaixuan Li, Yang Liu, Yixiang Chen
摘要
OpenZeppelin is a popular framework for building smart contracts. It provides common libraries (e.g., SafeMath), implementations of Ethereum standards (e.g., ERC20), and reusable components for access control and upgradability. However, unlike traditional software libraries, which are typically imported as static linking libraries or dynamic loading libraries, OpenZeppelin is utilized by Solidity contracts in the form of source code. As a result, developers often make custom modifications to their copies of OpenZeppelin code, which may lead to unintended security consequences. In this paper, we conduct the first systematic study on the security of OpenZeppelin code used in real-world contracts. Specifically, we focus on the security checks in the official OpenZeppelin library and examine whether they are faithfully enforced in the relevant OpenZeppelin functions of real contracts. To this end, we propose a novel tool named ZepScope that comprises two components: MINER and CHECKER. First, MINER analyzes the official OpenZeppelin functions to extract the facts of explicit checks (i.e., the checks defined within the functions) and implicit checks (i.e., the conditions of calling the functions). Second, based on the facts extracted by MINER, CHECKER examines real contracts to identify their OpenZeppelin functions, match their checks with those in the facts, and validate the consequences for those inconsistent checks. By overcoming multiple challenges in developing ZepScope, we obtain not only the first taxonomy of OpenZeppelin checks but also the comprehensive results of checking the top 35,882 contracts from three mainstream blockchains. * Work conducted by Han Liu and Kaixuan Li while they were visiting Ph.D. students at NTU.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- Have We Solved Access Control Vulnerability Detection in Smart Contracts? A Benchmark StudyHan Liu, Daoyuan Wu, Yuqiang Sun, Shuai Wang 等ASE 2025 · 被引用 1 次
- Demystifying OpenZeppelin's Own Vulnerabilities and Analyzing Their Propagation in Smart ContractsHan Liu, Daoyuan Wu, Yuqiang Sun, Shuai Wang 等ASE 2025 · 被引用 1 次
- TrapHunter: Exposing Covert Pathways in Trap Token ContractsYin Wu, Yixuan Liu, Yi Li, Chenyang Peng 等ISSTA 2026
- Tracing the Shadows: Automatic Tracking and Analysis of Crypto Money Laundering via Transaction Semantic AnalysisHao Wu, Haijun Wang, Shangwang Li, Yin Wu 等ISSTA 2026
- SymGPT: Auditing Smart Contracts via Combining Symbolic Execution with Large Language ModelsShihao Xia, Mengting He, Shuai Shao, Tingting Yu 等OOPSLA 2026
它引用的顶会 Paper16
- Securify: Practical Security Analysis of Smart ContractsPetar Tsankov, Andrei Marian Dan, Dana Drachsler-Cohen, Arthur Gervais 等CCS 2018 · 被引用 1,108 次
- ZEUS: Analyzing Safety of Smart ContractsSukrit Kalra, Seep Goel, Mohan Dhawan, Subodh SharmaNDSS 2018 · 被引用 595 次
- Empirical review of automated analysis tools on 47, 587 Ethereum smart contractsThomas Durieux, João F. Ferreira, Rui Abreu, Pedro CruzICSE 2020 · 被引用 373 次
- teEther: Gnawing at Ethereum to Automatically Exploit Smart ContractsJohannes Krupp, Christian RossowUSENIX Security 2018 · 被引用 345 次
- VerX: Safety Verification of Smart ContractsAnton Permenev, Dimitar Dimitrov, Petar Tsankov, Dana Drachsler-Cohen 等S&P 2020 · 被引用 251 次
相关 Paper
- Identifying Solidity Smart Contract API Documentation ErrorsChenguang Zhu, Ye Liu, Xiuheng Wu, Yi LiASE 2022 · 被引用 16 次
- Abusing the Ethereum Smart Contract Verification Services for Fun and ProfitPengxiang Ma, Ningyu He, Yuhua Huang, Haoyu Wang 等NDSS 2024
- TokenScope: Automatically Detecting Inconsistent Behaviors of Cryptocurrency Tokens in EthereumTing Chen, Yufei Zhang, Zihao Li, Xiapu Luo 等CCS 2019 · 被引用 140 次
- Revealing Hidden Threats: An Empirical Study of Library Misuse in Smart ContractsMingyuan Huang, Jiachi Chen, Zigui Jiang, Zibin ZhengICSE 2024 · 被引用 10 次
- Clone Detection for Smart Contracts: How Far Are We?Zuobin Wang, Zhiyuan Wan, Yujing Chen, Yun Zhang 等FSE 2025 · 被引用 1 次
