Demystifying OpenZeppelin's Own Vulnerabilities and Analyzing Their Propagation in Smart Contracts
Han Liu, Daoyuan Wu, Yuqiang Sun, Shuai Wang, Yang Liu, Yixiang Chen
摘要
OpenZeppelin is a building block for many smart contracts on Ethereum-compatible blockchains. It provides modular and reusable libraries for various Ethereum standards (e.g., ERC20 and ERC721) and common functionalities such as upgradeable contracts. Little research has been done on Open-Zeppelin security except for a recent study, which focused only on the misuse of OpenZeppelin code, assuming OpenZeppelin itself is secure but contract developers may not follow OpenZeppelin's function checks appropriately. We argue that, despite appearing robust, OpenZeppelin itself could have many vulnerabilities, and these library-level vulnerabilities could inadvertently affect thirdparty smart contracts, even without misuse from developers.
We present ZEPCOMPARE, the first end-to-end system for demystifying OpenZeppelin's own vulnerabilities and analyzing their propagation in third-party smart contracts. ZEPCOMPARE incorporates a manual analysis stage where we review OpenZeppelin's 64 historical releases, identifying 109 vulnerable-fixed code pairs, exposing flaws in cryptographic utilities, access control, etc. Leveraging these pairs, ZEPCOMPARE introduces facts of changes, a novel structure capturing vulnerable and fixed code contexts for flexible matching. Evaluated across 88,605 contracts from three Ethereum-compatible chains, ZEPCOMPARE detects 4,708 instances of OpenZeppelin-derived vulnerabilities. Manual sampling and a ground-truth experiment confirm that ZEPCOM-PARE achieves 86.7% precision and 77.1% recall. Our findings reveal significant security risks in both historical and the latest versions of OpenZeppelin libraries, underscoring the urgent need for systematic auditing of foundational contracts components.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper20
- Securify: Practical Security Analysis of Smart ContractsPetar Tsankov, Andrei Marian Dan, Dana Drachsler-Cohen, Arthur Gervais 等CCS 2018 · 被引用 1,108 次
- ZEUS: Analyzing Safety of Smart ContractsSukrit Kalra, Seep Goel, Mohan Dhawan, Subodh SharmaNDSS 2018 · 被引用 595 次
- Empirical review of automated analysis tools on 47, 587 Ethereum smart contractsThomas Durieux, João F. Ferreira, Rui Abreu, Pedro CruzICSE 2020 · 被引用 373 次
- teEther: Gnawing at Ethereum to Automatically Exploit Smart ContractsJohannes Krupp, Christian RossowUSENIX Security 2018 · 被引用 345 次
- Understanding Security Issues in the NFT EcosystemDipanjan Das, Priyanka Bose, Nicola Ruaro, Christopher Kruegel 等CCS 2022 · 被引用 173 次
相关 Paper
- Using My Functions Should Follow My Checks: Understanding and Detecting Insecure OpenZeppelin Code in Smart ContractsHan Liu, Daoyuan Wu, Yuqiang Sun, Haijun Wang 等USENIX Security 2024 · 被引用 11 次
- Identifying Solidity Smart Contract API Documentation ErrorsChenguang Zhu, Ye Liu, Xiuheng Wu, Yi LiASE 2022 · 被引用 16 次
- Characterizing Ethereum Upgradable Smart Contracts and Their Security ImplicationsXiaofan Li, Jin Yang, Jiaqi Chen, Yuzhe Tang 等WWW 2024 · 被引用 23 次
- Revealing Hidden Threats: An Empirical Study of Library Misuse in Smart ContractsMingyuan Huang, Jiachi Chen, Zigui Jiang, Zibin ZhengICSE 2024 · 被引用 10 次
- Abusing the Ethereum Smart Contract Verification Services for Fun and ProfitPengxiang Ma, Ningyu He, Yuhua Huang, Haoyu Wang 等NDSS 2024
