When Contracts Meets Crypto: Exploring Developers' Struggles with Ethereum Cryptographic APIs
Jiashuo Zhang, Jiachi Chen, Zhiyuan Wan, Ting Chen, Jianbo Gao, Zhong Chen
摘要
To empower smart contracts with the promising capabilities of cryptography, Ethereum officially introduced a set of cryptographic APIs that facilitate basic cryptographic operations within smart contracts, such as elliptic curve operations. However, since developers are not necessarily cryptography experts, requiring them to directly interact with these basic APIs has caused real-world security issues and potential usability challenges. To guide future research and solutions to these challenges, we conduct the first empirical study on Ethereum cryptographic practices. Through the analysis of 91,484,856 Ethereum transactions, 500 crypto-related contracts, and 483 StackExchange posts, we provide the first in-depth look at cryptographic tasks developers need to accomplish and identify five categories of obstacles they encounter. Furthermore, we conduct an online survey with 78 smart contract practitioners to explore their perspectives on these obstacles and elicit the underlying reasons. We find that more than half of practitioners face more challenges in cryptographic tasks compared to general business logic in smart contracts. Their feedback highlights the gap between low-level cryptographic APIs and high-level tasks they need to accomplish, emphasizing the need for improved cryptographic APIs, task-based templates, and effective assistance tools. Based on these findings, we provide practical implications for further improvements and outline future research directions.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- Identifying Smart Contract Security Issues in Code Snippets from Stack OverflowJiachi Chen, Chong Chen, Jiang Hu, John C. Grundy 等ISSTA 2024 · 被引用 9 次
- FORGE: An LLM-driven Framework for Large-Scale Smart Contract Vulnerability Dataset ConstructionJiachi Chen, Yiming Shen, Jiashuo Zhang, Zihao Li 等ICSE 2026 · 被引用 3 次
- Demystifying and Detecting Cryptographic Defects in Ethereum Smart ContractsJiashuo Zhang, Yiming Shen, Jiachi Chen, Jianzhong Su 等ICSE 2025 · 被引用 2 次
- One Signature, Multiple Payments: Demystifying and Detecting Signature Replay Vulnerabilities in Smart ContractsZexu Wang, Jiachi Chen, Zewei Lin, Wenqing Chen 等ICSE 2026
- Copy-and-Paste? Identifying EVM-Inequivalent Code Smells in Multi-chain Reuse ContractsZexu Wang, Jiachi Chen, Tao Zhang, Yu Zhang 等ISSTA 2025
它引用的顶会 Paper9
- Comparing the Usability of Cryptographic APIsYasemin Acar, Michael Backes, Sascha Fahl, Simson L. Garfinkel 等S&P 2017 · 被引用 261 次
- zkay: Specifying and Enforcing Data Privacy in Smart ContractsSamuel Steffen, Benjamin Bichsel, Mario Gersbach, Noa Melchior 等CCS 2019 · 被引用 82 次
- Demystifying Exploitable Bugs in Smart ContractsZhuo Zhang, Brian Zhang, Wen Xu, Zhiqiang LinICSE 2023 · 被引用 80 次
- On How Zero-Knowledge Proof Blockchain Mixers Improve, and Worsen User PrivacyZhipeng Wang, Stefanos Chaliasos, Kaihua Qin, Liyi Zhou 等WWW 2023 · 被引用 69 次
- ZeeStar: Private Smart Contracts by Homomorphic Encryption and Zero-knowledge ProofsSamuel Steffen, Benjamin Bichsel, Roger Baumgartner, Martin T. VechevS&P 2022 · 被引用 64 次
相关 Paper
- A Mixed-Methods Study of Security Practices of Smart Contract DevelopersTanusree Sharma, Kyrie Zhixuan Zhou, Andrew Miller, Yang WangUSENIX Security 2023
- "I'm Pretty Expert and I Still Screw It Up": Qualitative Insights into Experiences and Challenges of Designing and Implementing Cryptographic Library APIsJuliane Schmüser, Philip Klostermeyer, Kay Friedrich, Sascha FahlS&P 2025
- "You have to read 50 different RFCs that contradict each other": An Interview Study on the Experiences of Implementing Cryptographic StandardsNicolas Huaman, Jacques Suray, Jan H. Klemmer, Marcel Fourné 等USENIX Security 2024 · 被引用 5 次
- Characterizing Transaction-Reverting Statements in Ethereum Smart ContractsLu Liu, Lili Wei, Wuqi Zhang, Ming Wen 等ASE 2021 · 被引用 25 次
- "That's my perspective from 30 years of doing this": An Interview Study on Practices, Experiences, and Challenges of Updating Cryptographic CodeAlexander Krause, Harjot Kaur, Jan H. Klemmer, Oliver Wiese 等USENIX Security 2025
