Insecurity Through Obscurity: Veiled Vulnerabilities in Closed-Source Contracts
Sen Yang, Kaihua Qin, Aviv Yaish, Fan Zhang
摘要
Most blockchains cannot hide the binary code of programs (i.e., smart contracts) running on them. To conceal proprietary business logic and to potentially deter attacks, many smart contracts are closed-source and in many cases exhibit code obfuscation, either intentionally introduced to hide internal logic or unintentionally produced by optimizations. However, we demonstrate that such obfuscation can obscure critical vulnerabilities rather than enhance security, a phenomenon known as insecurity through obscurity. To systematically analyze these risks on a large scale, we present skanf, a novel EVM bytecode analysis tool tailored for closed-source and obfuscated contracts. skanf combines control-flow deobfuscation with symbolic execution based on historical transactions to identify and exploit asset management vulnerabilities. Our evaluation on real-world Maximal Extractable Value (MEV) bots reveals that skanf detects vulnerabilities in 1,046 contracts and successfully generates exploits for 394 of them, with potential losses of 2.76M in losses. CCS Concepts • Security and privacy → Distributed systems security.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper39
- Making Smart Contracts SmarterLoi Luu, Duc-Hiep Chu, Hrishi Olickel, Prateek Saxena 等CCS 2016 · 被引用 2,306 次
- Securify: Practical Security Analysis of Smart ContractsPetar Tsankov, Andrei Marian Dan, Dana Drachsler-Cohen, Arthur Gervais 等CCS 2018 · 被引用 1,108 次
- Flash Boys 2.0: Frontrunning in Decentralized Exchanges, Miner Extractable Value, and Consensus InstabilityPhilip Daian, Steven Goldfeder, Tyler Kell, Yunqi Li 等S&P 2020 · 被引用 607 次
- teEther: Gnawing at Ethereum to Automatically Exploit Smart ContractsJohannes Krupp, Christian RossowUSENIX Security 2018 · 被引用 345 次
- Quantifying Blockchain Extractable Value: How dark is the forest?Kaihua Qin, Liyi Zhou, Arthur GervaisS&P 2022 · 被引用 336 次
相关 Paper
- Large-Scale Study of Vulnerability Scanners for Ethereum Smart ContractsChristoph Sendner, Lukas Petzi, Jasper Stang, Alexandra DmitrienkoS&P 2024 · 被引用 19 次
- Cross-Modality Mutual Learning for Enhancing Smart Contract Vulnerability Detection on BytecodePeng Qian, Zhenguang Liu, Yifang Yin, Qinming HeWWW 2023 · 被引用 91 次
- Light into Darkness: Demystifying Profit Strategies Throughout the MEV Bot LifecycleFeng Luo, Zihao Li, Wenxuan Luo, Zheyuan He 等NDSS 2026 · 被引用 4 次
- Abusing the Ethereum Smart Contract Verification Services for Fun and ProfitPengxiang Ma, Ningyu He, Yuhua Huang, Haoyu Wang 等NDSS 2024
- Surviving in Dark Forest: Towards Evading the Attacks from Front-Running Bots in Application LayerZuchao Ma, Muhui Jiang, Feng Luo, Xiapu Luo 等USENIX Security 2025
