Verifying Economic Security of Smart Contracts via Unintended Return
Yi Rong, Xupeng Li, Ronghui Gu
摘要
We propose CMod, an economic model for analyzing the economic security of decentralized finance (DeFi) smart contract code. CMod defines the notions of economic value, intended-return conditions, and unintended single-transaction return, and reasons about economic security by proving the absence of unintended single-transaction return. Based on CMod, we co-design CSol, an automated verification tool for Solidity that reasons about path properties in multi-contract environments via bounded symbolic execution. CSol incorporates three categories of optimizations: CMod-oriented path pruning and inductive verification, proof-goal simplification, and solver acceleration. Our evaluation shows that CMod and CSol can be applied to real-world contract code and characterize economically exploitable vulnerabilities. CSol verifies 245 real-world contracts, identifies 6 live scam contracts, detects 16 of 18 real-world exploits and 92 of 104 audit-stage findings, and exposes one misidentification in an existing tool's benchmark.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- Clockwork Finance: Automated Analysis of Economic Security in Smart ContractsKushal Babel, Philip Daian, Mahimna Kelkar, Ari JuelsS&P 2023
- FORAY: Towards Effective Attack Synthesis against Deep Logical Vulnerabilities in DeFi ProtocolsHongbo Wen, Hanzhi Liu, Jiaxin Song, Yanju Chen 等CCS 2024 · 被引用 6 次
- Automated Inference on Financial Security of Ethereum Smart ContractsWansen Wang, Wenchao Huang, Zhaoyi Meng, Yan Xiong 等USENIX Security 2023
- SmarTest: Effectively Hunting Vulnerable Transaction Sequences in Smart Contracts through Language Model-Guided Symbolic ExecutionSunbeom So, Seongjoon Hong, Hakjoo OhUSENIX Security 2021 · 被引用 118 次
- Automated Attack Synthesis for Constant Product Market MakersSujin Han, Jinseo Kim, Sung-Ju Lee, Insu YunISSTA 2025
