Time-manipulation Attack: Breaking Fairness against Proof of Authority Aura
Xinrui Zhang, Rujia Li, Qin Wang, Qi Wang, Sisi Duan
摘要
As blockchain-based commercial projects and startups flourish, efficiency becomes one of the critical metrics in designing blockchain systems. Due to its high efficiency, Proof of Authority (PoA) Aura has become one of the most widely adopted consensus solutions for blockchains. Our research finds over 4, 000 projects have used Aura and its variants. In this paper, we provide a rigorous analysis of Aura. We propose three types of time-manipulation attacks, where a malicious leader simply needs to modify the timestamp in its proposed block or delay it to extract extra benefits. These attacks can easily break the legal leader election, thus directly harming the fairness of the block proposal. We apply our attacks to a mature Aura project called OpenEthereum. By repeatedly conducting our attacks 1 over 15 days, we find that an adversary can gain on average 200% mining rewards of their fair shares. Furthermore, such attacks can even indirectly break the finality of blocks and the safety of the system. Based on the deployment of Aura as of September 2022, the potentially affected market cap is up to 2.13 billion USD. As a by-product, we further discuss solutions to mitigate such issues and report our observations to official teams. CCS CONCEPTS • Security and privacy → Distributed systems security;
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper4
- Flash Boys 2.0: Frontrunning in Decentralized Exchanges, Miner Extractable Value, and Consensus InstabilityPhilip Daian, Steven Goldfeder, Tyler Kell, Yunqi Li 等S&P 2020 · 被引用 607 次
- Order-Fairness for Byzantine ConsensusMahimna Kelkar, Fan Zhang, Steven Goldfeder, Ari JuelsCRYPTO 2020 · 被引用 152 次
- Game-Theoretic Fairness Meets Multi-party Protocols: The Case of Leader ElectionKai-Min Chung, T.-H. Hubert Chan, Ting Wen, Elaine ShiCRYPTO 2021 · 被引用 13 次
- The Attack of the Clones Against Proof-of-AuthorityParinya Ekparinya, Vincent Gramoli, Guillaume JourjonNDSS 2020
相关 Paper
- Multi-Certificate Attacks against Proof-of-Elapsed-Time and Their CountermeasuresHuibo Wang, Guoxing Chen, Yinqian Zhang, Zhiqiang LinNDSS 2022
- Uncle Maker: (Time)Stamping Out The Competition in EthereumAviv Yaish, Gilad Stern, Aviv ZoharCCS 2023 · 被引用 19 次
- Available Attestation: Towards a Reorg-Resilient Solution for Ethereum Proof-of-StakeMingfei Zhang, Rujia Li, Xueqian Lu, Sisi DuanUSENIX Security 2025
- DoubleUp Roll: Double-spending in Arbitrum by Rolling It BackZhiyuan Sun, Zihao Li, Xinghao Peng, Xiapu Luo 等CCS 2024 · 被引用 3 次
- Forking the RANDAO: Manipulating Ethereum's Distributed Randomness BeaconÁbel Nagy, János Tapolcai, István András Seres, Bence LadóczkiCCS 2025 · 被引用 2 次
