Nyx: Detecting Exploitable Front-Running Vulnerabilities in Smart Contracts
Wuqi Zhang, Zhuo Zhang, Qingkai Shi, Lu Liu, Lili Wei, Yepang Liu, Xiangyu Zhang, Shing-Chi Cheung
摘要
Smart contracts are susceptible to front-running attacks, in which malicious users leverage prior knowledge of upcoming transactions to execute attack transactions in advance and benefit their own portfolios. Existing contract analysis techniques raise a number of false positives and false negatives in that they simplistically treat data races in a contract as front-running vulnerabilities and can only analyze contracts in isolation. In this work, we formalize the definition of exploitable front-running vulnerabilities based on previous empirical studies on historical attacks, and present Nyx, a novel static analyzer to detect them. Nyx features a Datalog-based preprocessing procedure that efficiently and soundly prunes a large part of the search space, followed by a symbolic validation engine that precisely locates vulnerabilities with an SMT solver. We evaluate Nyx using a large dataset that comprises 513 real-world front-running attacks in smart contracts. Compared to six state-of-the-art techniques, Nyx surpasses them by 32.64%-90.19% in terms of recall and 2.89%-70.89% in terms of precision. Nyx has also identified four zero-days in real-world smart contracts.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper9
- An Empirical Study of Proxy Contracts at the Ethereum Ecosystem ScaleMengya Zhang, Preksha Shukla, Wuqi Zhang, Zhuo Zhang 等ICSE 2025 · 被引用 5 次
- Smartreco: Detecting Read-Only Reentrancy via Fine-Grained Cross-DApp AnalysisJingwen Zhang, Zibin Zheng, Yuhong Nan, Mingxi Ye 等ICSE 2025 · 被引用 4 次
- OpDiffer: LLM-Assisted Opcode-Level Differential Testing of Ethereum Virtual MachineJie Ma, Ningyu He, Jinwen Xi, Mingzhe Xing 等ISSTA 2025 · 被引用 2 次
- NESA: Relational Neuro-Symbolic Static Program AnalysisChengpeng Wang, Yifei Gao, Wuqi Zhang, Xuwei Liu 等FSE 2026 · 被引用 1 次
- Chord: Towards a Unified Detection of Blockchain Transaction Parallelism BugsYuanhang Zhou, Zhen Yan, Yuanliang Chen, Fuchen Ma 等ICSE 2025 · 被引用 1 次
它引用的顶会 Paper12
- Making Smart Contracts SmarterLoi Luu, Duc-Hiep Chu, Hrishi Olickel, Prateek Saxena 等CCS 2016 · 被引用 2,306 次
- Securify: Practical Security Analysis of Smart ContractsPetar Tsankov, Andrei Marian Dan, Dana Drachsler-Cohen, Arthur Gervais 等CCS 2018 · 被引用 1,108 次
- Empirical review of automated analysis tools on 47, 587 Ethereum smart contractsThomas Durieux, João F. Ferreira, Rui Abreu, Pedro CruzICSE 2020 · 被引用 373 次
- Quantifying Blockchain Extractable Value: How dark is the forest?Kaihua Qin, Liyi Zhou, Arthur GervaisS&P 2022 · 被引用 336 次
- High-Frequency Trading on Decentralized On-Chain ExchangesLiyi Zhou, Kaihua Qin, Christof Ferreira Torres, Duc Viet Le 等S&P 2021 · 被引用 243 次
相关 Paper
- On Identifying Sound Conditions for Frontrunning ResistanceSebastian Holler, Anna Piscitelli, Jannik Albrecht, Stephan Dübler 等CCS 2026
- SmarTest: Effectively Hunting Vulnerable Transaction Sequences in Smart Contracts through Language Model-Guided Symbolic ExecutionSunbeom So, Seongjoon Hong, Hakjoo OhUSENIX Security 2021 · 被引用 118 次
- Surviving in Dark Forest: Towards Evading the Attacks from Front-Running Bots in Application LayerZuchao Ma, Muhui Jiang, Feng Luo, Xiapu Luo 等USENIX Security 2025
- AdvSCanner: Generating Adversarial Smart Contracts to Exploit Reentrancy Vulnerabilities Using LLM and Static AnalysisYin Wu, Xiaofei Xie, Chenyang Peng, Dijun Liu 等ASE 2024 · 被引用 9 次
- Your Exploit is Mine: Instantly Synthesizing Counterattack Smart ContractZhuo Zhang, Zhiqiang Lin, Marcelo Morales, Xiangyu Zhang 等USENIX Security 2023
