Speculative Denial-of-Service Attacks In Ethereum
Aviv Yaish, Kaihua Qin, Liyi Zhou, Aviv Zohar, Arthur Gervais
摘要
Transaction fees compensate actors for resources expended on transactions and can only be charged from transactions included in blocks. But, the expressiveness of Turing-complete contracts implies that verifying if transactions can be included requires executing them on the current blockchain state. In this work, we show that adversaries can craft malicious transactions that decouple the work imposed on blockchain actors from the compensation offered in return. We introduce three attacks: (i) ConditionalExhaust, a conditional resource exhaustion attack (REA) against blockchain actors. (ii) Mem-Purge, an attack for evicting transactions from actors' mempools. (iii) GhostTX, an attack on the reputation system used in Ethereum's proposer-builder separation (PBS) ecosystem. We evaluate our attacks on an Ethereum testnet and find that by combining ConditionalExhaust and MemPurge, adversaries can simultaneously burden victims' computational resources and clog their mempools to the point where victims are unable to include transactions in blocks. Thus, victims create empty blocks, thereby hurting the system's liveness. The attack's expected cost is $376, but becomes cheaper if adversaries are validators. For other attackers, costs decrease if censorship is prevalent in the network. ConditionalExhaust and MemPurge are made possible by inherent features of Turing-complete blockchains, and potential mitigations may result in reducing a ledger's scalability.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper10
- Nurgle: Exacerbating Resource Consumption in Blockchain State Storage via MPT ManipulationZheyuan He, Zihao Li, Ao Qiao, Xiapu Luo 等S&P 2024 · 被引用 21 次
- Understanding Ethereum Mempool Security under Asymmetric DoS by Symbolized Stateful FuzzingYibo Wang, Yuzhe Tang, Kai Li, Wanning Ding 等USENIX Security 2024 · 被引用 9 次
- BunnyFinder: Finding Incentive Flaws for Ethereum ConsensusRujia Li, Mingfei Zhang, Xueqian Lu, Wenbo Xu 等NDSS 2026 · 被引用 5 次
- Perils of Parallelism: Transaction Fee Mechanisms under Execution UncertaintySarisht Wadhwa, Aviv Yaish, Fan Zhang, Kartik NayakUSENIX Security 2026 · 被引用 3 次
- Insecurity Through Obscurity: Veiled Vulnerabilities in Closed-Source ContractsSen Yang, Kaihua Qin, Aviv Yaish, Fan ZhangCCS 2026 · 被引用 3 次
它引用的顶会 Paper5
- Flash Boys 2.0: Frontrunning in Decentralized Exchanges, Miner Extractable Value, and Consensus InstabilityPhilip Daian, Steven Goldfeder, Tyler Kell, Yunqi Li 等S&P 2020 · 被引用 607 次
- DETER: Denial of Ethereum Txpool sERvicesKai Li, Yibo Wang, Yuzhe TangCCS 2021 · 被引用 26 次
- A study of inline assembly in solidity smart contractsStefanos Chaliasos, Arthur Gervais, Benjamin LivshitsOOPSLA 2022 · 被引用 22 次
- BDoS: Blockchain Denial-of-ServiceMichael Mirkin, Yan Ji, Jonathan Pang, Ariah Klages-Mundt 等CCS 2020 · 被引用 1 次
- Broken Metre: Attacking Resource Metering in EVMDaniel Perez, Benjamin LivshitsNDSS 2020
相关 Paper
- eTainter: detecting gas-related vulnerabilities in smart contractsAsem Ghaleb, Julia Rubin, Karthik PattabiramanISSTA 2022 · 被引用 57 次
- Auspex: Unveiling Inconsistency Bugs of Transaction Fee Mechanism in BlockchainZheyuan He, Zihao Li, Jiahao Luo, Feng Luo 等USENIX Security 2025
- Precise static modeling of Ethereum "memory"Sifis Lagouvardos, Neville Grech, Ilias Tsatiris, Yannis SmaragdakisOOPSLA 2020 · 被引用 23 次
- Asymmetric Mempool DoS Security: Formal Definitions and Provable Secure DesignsWanning Ding, Yuzhe Tang, Yibo WangS&P 2025
- POMABuster: Detecting Price Oracle Manipulation Attacks in Decentralized FinanceRui Xi, Zehua Wang, Karthik PattabiramanS&P 2024 · 被引用 13 次
