Confusum Contractum: Confused Deputy Vulnerabilities in Ethereum Smart Contracts
Fabio Gritti, Nicola Ruaro, Robert McLaughlin, Priyanka Bose, Dipanjan Das, Ilya Grishchenko, Christopher Kruegel, Giovanni Vigna
摘要
Smart contracts are immutable programs executed in the context of a globally distributed system known as a blockchain. They enable the decentralized implementation of many interesting applications, such as financial protocols, voting systems, and supply-chain management. In many cases, multiple smart contracts need to work together and communicate with one another to implement complex business logic. However, these smart contracts must take special care to guard against malicious interactions that might lead to the violation of a contract's security properties and possibly result in substantial financial losses. In this paper, we introduce a class of inter-program communication flaws that we call confused contract vulnerabilities. This type of bug is an instance of the confused deputy vulnerability, set in the new context of smart contract inter-communication. When exploiting a confused contract bug, an attacker is able to divert a remote (inter-contract) call in a confused (victim) contract to a target contract and function of the attacker's choosing. The call performs sensitive operations on behalf of the confused contract, which can result in financial loss or malicious modifications of the persistent storage of the involved contracts. To identify opportunities for confused contract attacks at scale, we implemented JACKAL, a system that is able to automatically identify and exploit confused contracts and candidate target contracts on the Ethereum mainnet. We leveraged JACKAL to analyze a total of 2,335,193 smart contracts deployed in the past two years, and we identified 529 potential confused contracts for which we were able to generate 31 working exploits. When investigating the impact of our exploits, we discovered past and present opportunities for confused contract attacks that could have compromised digital assets worth more than one million US dollars.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper12
- All Your Tokens are Belong to Us: Demystifying Address Verification Vulnerabilities in Solidity Smart ContractsTianle Sun, Ningyu He, Jiang Xiao, Yinliang Yue 等USENIX Security 2024 · 被引用 11 次
- Pulling Off The Mask: Forensic Analysis of the Deceptive Creator Wallets Behind Smart Contract FraudMingxuan Yao, Runze Zhang, Haichuan Xu, Shih-Huan Chou 等S&P 2024 · 被引用 10 次
- Phishing in Wonderland: Evaluating Learning-Based Ethereum Phishing Transaction Detection and PitfallsAhod Alghuried, David MohaisenNDSS 2026 · 被引用 4 次
- Insecurity Through Obscurity: Veiled Vulnerabilities in Closed-Source ContractsSen Yang, Kaihua Qin, Aviv Yaish, Fan ZhangCCS 2026 · 被引用 3 次
- Precise Static Identification of Ethereum Storage VariablesSifis Lagouvardos, Yannis Bollanos, Michael Debono, Neville Grech 等ICSE 2026 · 被引用 2 次
它引用的顶会 Paper16
- Making Smart Contracts SmarterLoi Luu, Duc-Hiep Chu, Hrishi Olickel, Prateek Saxena 等CCS 2016 · 被引用 2,306 次
- Securify: Practical Security Analysis of Smart ContractsPetar Tsankov, Andrei Marian Dan, Dana Drachsler-Cohen, Arthur Gervais 等CCS 2018 · 被引用 1,108 次
- teEther: Gnawing at Ethereum to Automatically Exploit Smart ContractsJohannes Krupp, Christian RossowUSENIX Security 2018 · 被引用 345 次
- Learning to Fuzz from Symbolic Execution with Application to Smart ContractsJingxuan He, Mislav Balunovic, Nodar Ambroladze, Petar Tsankov 等CCS 2019 · 被引用 288 次
- sFuzz: an efficient adaptive fuzzer for solidity smart contractsTai D. Nguyen, Long H. Pham, Jun Sun, Yun Lin 等ICSE 2020 · 被引用 260 次
相关 Paper
- Not your Type! Detecting Storage Collision Vulnerabilities in Ethereum Smart ContractsNicola Ruaro, Fabio Gritti, Robert McLaughlin, Ilya Grishchenko 等NDSS 2024
- Approve Once, Regret Forever: On the Exploitation of Ethereum's Approve-TransferFrom EcosystemNicola Ruaro, Fabio Gritti, Dongyu Meng, Robert McLaughlin 等USENIX Security 2025
- Reentrancy Vulnerability Detection and Localization: A Deep Learning Based Two-phase ApproachZhuo Zhang, Yan Lei, Meng Yan, Yue Yu 等ASE 2022 · 被引用 56 次
- The Art of The Scam: Demystifying Honeypots in Ethereum Smart ContractsChristof Ferreira Torres, Mathis Steichen, Radu StateUSENIX Security 2019 · 被引用 239 次
- Smart Contract Vulnerabilities: Vulnerable Does Not Imply ExploitedDaniel Perez, Benjamin LivshitsUSENIX Security 2021 · 被引用 150 次
