PrettySmart: Detecting Permission Re-delegation Vulnerability for Token Behaviors in Smart Contracts
Zhijie Zhong, Zibin Zheng, Hong-Ning Dai, Qing Xue, Junjia Chen, Yuhong Nan
摘要
As an essential component in Ethereum and other blockchains, token assets have been interacted with by diverse smart contracts. Effective permission policies of smart contracts must prevent token assets from being manipulated by unauthorized adversaries. Recent efforts have studied the accessibility of privileged functions or state variables to unauthorized users. However, little attention is paid to how publicly accessible functions of smart contracts can be manipulated by adversaries to steal users' digital assets. This attack is mainly caused by the permission re-delegation (PRD) vulnerability. In this work, we propose PrettySmart, a bytecode-level Permission re-delegation vulnerability detector for Smart contracts. Our study begins with an empirical study on 0.43 million open-source smart contracts, revealing that five types of widely-used permission constraints dominate 98% of the studied contracts. Accordingly, we propose a mechanism to infer these permission constraints, as well as an algorithm to identify constraints that can be bypassed by unauthorized adversaries. Based on the identification of permission constraints, we propose to detect whether adversaries could manipulate the privileged token management functionalities of smart contracts. The experimental results on real-world datasets demonstrate the effectiveness of the proposed PrettySmart, which achieves the highest precision score and detects 118 new PRD vulnerabilities.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper6
- OpDiffer: LLM-Assisted Opcode-Level Differential Testing of Ethereum Virtual MachineJie Ma, Ningyu He, Jinwen Xi, Mingzhe Xing 等ISSTA 2025 · 被引用 2 次
- The Incredible Shrinking Context... in a Decompiler Near YouSifis Lagouvardos, Yannis Bollanos, Neville Grech, Yannis SmaragdakisISSTA 2025 · 被引用 1 次
- Have We Solved Access Control Vulnerability Detection in Smart Contracts? A Benchmark StudyHan Liu, Daoyuan Wu, Yuqiang Sun, Shuai Wang 等ASE 2025 · 被引用 1 次
- BreakFAST: Confused Deputy Attack on Infinity Fabric to Break AMD SEV-SNPPhilipp Giersfeld, Benedict Schlüter, Shweta ShindeS&P 2026 · 被引用 1 次
- EventSpec: Defining and Detecting Event-Semantic Issues in Blockchain EcosystemsYixuan Liu, Yuxin Dong, Ye Liu, Yin Wu 等ISSTA 2026
相关 Paper
- SmartState: Detecting State-Reverting Vulnerabilities in Smart Contracts via Fine-Grained State-Dependency AnalysisZeqin Liao, Sicheng Hao, Yuhong Nan, Zibin ZhengISSTA 2023 · 被引用 22 次
- AChecker: Statically Detecting Smart Contract Access Control VulnerabilitiesAsem Ghaleb, Julia Rubin, Karthik PattabiramanICSE 2023 · 被引用 63 次
- eTainter: detecting gas-related vulnerabilities in smart contractsAsem Ghaleb, Julia Rubin, Karthik PattabiramanISSTA 2022 · 被引用 57 次
- Precise static modeling of Ethereum "memory"Sifis Lagouvardos, Neville Grech, Ilias Tsatiris, Yannis SmaragdakisOOPSLA 2020 · 被引用 23 次
- Characterizing Ethereum Upgradable Smart Contracts and Their Security ImplicationsXiaofan Li, Jin Yang, Jiaqi Chen, Yuzhe Tang 等WWW 2024 · 被引用 23 次
