Following Devils' Footprint: Towards Real-time Detection of Price Manipulation Attacks
Bosi Zhang, Ningyu He, Xiaohui Hu, Kai Ma, Haoyu Wang
摘要
Price manipulation attack is one of the notorious threats in decentralized finance (DeFi) applications, which allows attackers to exchange tokens at an extensively deviated price from the market. Existing efforts usually rely on reactive methods to identify such kind of attacks after they have happened, e.g., detecting attack transactions in the post-attack stage, which cannot mitigate or prevent price manipulation attacks timely. From the perspective of attackers, they usually need to deploy attack contracts in the pre-attack stage. Thus, if we can identify these attack contracts in a proactive manner, we can raise alarms and mitigate the threats. With the core idea in mind, in this work, we shift our attention from the victims to the attackers. Specifically, we propose SMARTCAT, a novel approach for identifying price manipulation attacks in the pre-attack stage proactively. For generality, it conducts analysis on bytecode and does not require any source code and transaction data. For accuracy, it depicts the control- and data-flow dependency relationships among function calls into a token flow graph. For scalability, it filters out those suspicious paths, in which it conducts inter-contract analysis as necessary. To this end, SMARTCAT can pinpoint attacks in real time once they have been deployed on a chain. The evaluation results illustrate that SMARTCAT significantly outperforms existing baselines with 91.6% recall and 100% precision. Moreover, SMARTCAT also uncovers 616 attack contracts in-the-wild, accounting for $9.25M financial losses, with only 19 cases publicly reported. By applying SMARTCAT as a real-time detector in Ethereum and Binance Smart Chain, it has raised 14 alarms 99 seconds after the corresponding deployment on average. These attacks have already led to $641K financial losses, and seven of them are still waiting for their ripe time.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- Insecurity Through Obscurity: Veiled Vulnerabilities in Closed-Source ContractsSen Yang, Kaihua Qin, Aviv Yaish, Fan ZhangCCS 2026 · 被引用 3 次
- Detecting Various DeFi Price Manipulations with LLM ReasoningJuantao Zhong, Daoyuan Wu, Ye Liu, Maoyi Xie 等ASE 2025 · 被引用 3 次
- TrapHunter: Exposing Covert Pathways in Trap Token ContractsYin Wu, Yixuan Liu, Yi Li, Chenyang Peng 等ISSTA 2026
它引用的顶会 Paper22
- Making Smart Contracts SmarterLoi Luu, Duc-Hiep Chu, Hrishi Olickel, Prateek Saxena 等CCS 2016 · 被引用 2,306 次
- Securify: Practical Security Analysis of Smart ContractsPetar Tsankov, Andrei Marian Dan, Dana Drachsler-Cohen, Arthur Gervais 等CCS 2018 · 被引用 1,108 次
- Learning to Fuzz from Symbolic Execution with Application to Smart ContractsJingxuan He, Mislav Balunovic, Nodar Ambroladze, Petar Tsankov 等CCS 2019 · 被引用 288 次
- Ethainter: a smart contract security analyzer for composite vulnerabilitiesLexi Brent, Neville Grech, Sifis Lagouvardos, Bernhard Scholz 等PLDI 2020 · 被引用 163 次
- SAILFISH: Vetting Smart Contract State-Inconsistency Bugs in SecondsPriyanka Bose, Dipanjan Das, Yanju Chen, Yu Feng 等S&P 2022 · 被引用 142 次
相关 Paper
- DeFort: Automatic Detection and Analysis of Price Manipulation Attacks in DeFi ApplicationsMaoyi Xie, Ming Hu, Ziqiao Kong, Cen Zhang 等ISSTA 2024 · 被引用 9 次
- DeFiTainter: Detecting Price Manipulation Vulnerabilities in DeFi ProtocolsQueping Kong, Jiachi Chen, Yanlin Wang, Zigui Jiang 等ISSTA 2023 · 被引用 31 次
- FORAY: Towards Effective Attack Synthesis against Deep Logical Vulnerabilities in DeFi ProtocolsHongbo Wen, Hanzhi Liu, Jiaxin Song, Yanju Chen 等CCS 2024 · 被引用 6 次
- LookAhead: Preventing DeFi Attacks via Unveiling Adversarial ContractsShoupeng Ren, Lipeng He, Tianyu Tu, Di Wu 等FSE 2025 · 被引用 3 次
- HOUSTON: Real-Time Anomaly Detection of Attacks against Ethereum DeFi ProtocolsDongyu Meng, Fabio Gritti, Robert McLaughlin, Nicola Ruaro 等NDSS 2026 · 被引用 2 次
