Definition and Detection of Defects in NFT Smart Contracts
Shuo Yang, Jiachi Chen, Zibin Zheng
摘要
In recent years, security incidents stemming from centralization defects in smart contracts have led to substantial financial losses. A centralization defect refers to any error, flaw, or fault in a smart contract's design or development stage that introduces a single point of failure. Such defects allow a specific account or user to disrupt the normal operations of smart contracts, potentially causing malfunctions or even complete project shutdowns. Despite the significance of this issue, most current smart contract analyses overlook centralization defects, focusing primarily on other types of defects. To address this gap, our paper introduces six types of centralization defects in smart contracts by manually analyzing 597 Stack Exchange posts and 117 audit reports. For each defect, we provide a detailed description and code examples to illustrate its characteristics and potential impacts. Additionally, we introduce a tool named CDRipper (Centralization Defects Ripper) designed to identify the defined centralization defects. Specifically, CDRipper constructs a permission dependency graph (PDG) and extracts the permission dependencies of functions from the source code of smart contracts. It then detects the sensitive operations in functions and identifies centralization defects based on predefined patterns. We conduct a large-scale experiment using CDRipper on 244,424 real-world smart contracts and evaluate the results based on a manually labeled dataset. Our findings reveal that 82,446 contracts contain at least one of the six centralization defects, with our tool achieving an overall precision of 93.7%.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper14
- Uncover the Premeditated Attacks: Detecting Exploitable Reentrancy Vulnerabilities by Identifying Attacker ContractsShuo Yang, Jiachi Chen, Mingyuan Huang, Zibin Zheng 等ICSE 2024 · 被引用 24 次
- Identifying Smart Contract Security Issues in Code Snippets from Stack OverflowJiachi Chen, Chong Chen, Jiang Hu, John C. Grundy 等ISSTA 2024 · 被引用 9 次
- When Contracts Meets Crypto: Exploring Developers' Struggles with Ethereum Cryptographic APIsJiashuo Zhang, Jiachi Chen, Zhiyuan Wan, Ting Chen 等ICSE 2024 · 被引用 9 次
- Hyperion: Unveiling DApp Inconsistencies Using LLM and Dataflow-Guided Symbolic ExecutionShuo Yang, Xingwei Lin, Jiachi Chen, Qingyuan Zhong 等ICSE 2025 · 被引用 6 次
- Enhancing the Open Network: Definition and Automated Detection of Smart Contract DefectsHao Song, Teng Li, Jiachi Chen, Ting Chen 等ICSE 2025 · 被引用 5 次
它引用的顶会 Paper9
- Making Smart Contracts SmarterLoi Luu, Duc-Hiep Chu, Hrishi Olickel, Prateek Saxena 等CCS 2016 · 被引用 2,306 次
- Securify: Practical Security Analysis of Smart ContractsPetar Tsankov, Andrei Marian Dan, Dana Drachsler-Cohen, Arthur Gervais 等CCS 2018 · 被引用 1,108 次
- ZEUS: Analyzing Safety of Smart ContractsSukrit Kalra, Seep Goel, Mohan Dhawan, Subodh SharmaNDSS 2018 · 被引用 595 次
- Ethainter: a smart contract security analyzer for composite vulnerabilitiesLexi Brent, Neville Grech, Sifis Lagouvardos, Bernhard Scholz 等PLDI 2020 · 被引用 163 次
- Finding permission bugs in smart contracts with role miningYe Liu, Yi Li, Shang-Wei Lin, Cyrille ArthoISSTA 2022 · 被引用 54 次
相关 Paper
- Definition and Detection of Centralization Defects in Smart ContractsZewei Lin, Jiachi Chen, Jiajing Wu, Weizhe Zhang 等ICSE 2025 · 被引用 2 次
- Demystifying and Detecting Cryptographic Defects in Ethereum Smart ContractsJiashuo Zhang, Yiming Shen, Jiachi Chen, Jianzhong Su 等ICSE 2025 · 被引用 2 次
- SSR: Safeguarding Staking Rewards by Defining and Detecting Logical Defects in DeFi StakingZewei Lin, Jiachi Chen, Jingwen Zhang, Zexu Wang 等ASE 2025 · 被引用 1 次
- Towards Finding Accounting Errors in Smart ContractsBrian ZhangICSE 2024 · 被引用 8 次
- PrettySmart: Detecting Permission Re-delegation Vulnerability for Token Behaviors in Smart ContractsZhijie Zhong, Zibin Zheng, Hong-Ning Dai, Qing Xue 等ICSE 2024 · 被引用 12 次
