Lune

CCS2026顶会

Insecurity Through Obscurity: Veiled Vulnerabilities in Closed-Source Contracts

Sen Yang, Kaihua Qin, Aviv Yaish, Fan Zhang

2026年份
3被引次数

摘要

Most blockchains cannot hide the binary code of programs (i.e., smart contracts) running on them. To conceal proprietary business logic and to potentially deter attacks, many smart contracts are closed-source and in many cases exhibit code obfuscation, either intentionally introduced to hide internal logic or unintentionally produced by optimizations. However, we demonstrate that such obfuscation can obscure critical vulnerabilities rather than enhance security, a phenomenon known as insecurity through obscurity. To systematically analyze these risks on a large scale, we present skanf, a novel EVM bytecode analysis tool tailored for closed-source and obfuscated contracts. skanf combines control-flow deobfuscation with symbolic execution based on historical transactions to identify and exploit asset management vulnerabilities. Our evaluation on real-world Maximal Extractable Value (MEV) bots reveals that skanf detects vulnerabilities in 1,046 contracts and successfully generates exploits for 394 of them, with potential losses of 10.6M.Additionally,weuncover104real−worldMEVbotattacksthatcollectivelyresultedin10.6M. Additionally, we uncover 104 real-world MEV bot attacks that collectively resulted in 2.76M in losses. CCS Concepts • Security and privacy → Distributed systems security.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

它引用的顶会 Paper39

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖