Liquidity Mining as an Attack Surface: Incentive-Induced Liquidity Attacks in Concentrated Liquidity Market Makers
Nora Sinong Lu, Chon Kit Lao, Yunlong Mao, Xiaobo Zhou, Ruizhe Jia, Kanye Ye Wang
摘要
Decentralized finance (DeFi) platforms commonly deploy volume-based incentive programs to bootstrap liquidity and improve market efficiency. We show that such subsidies, while well-intentioned, can create an underexplored economic attack surface in concentrated liquidity market makers (CLMMs). These subsidies enable a novel manipulation strategy. Attackers attract subsidized trading volume by providing highly concentrated liquidity, artificially inflating yields and luring victim liquidity providers into narrow price ranges. Once sufficient victim liquidity has accumulated, the attacker induces a price crash to extract value. We formalize this behavior as an incentive-induced liquidity attack and prove that it arises endogenously whenever subsidy intensity and volume caps exceed critical thresholds. Although subsidies are intended to bootstrap liquidity, these attacks ultimately lead to substantial liquidity depletion, causing platforms to incur incentive costs while market liquidity deteriorates. We conduct a large-scale measurement study on incentivized CLMM pools on BSC that are tied to Binance Alpha programs. We identify 29 attack events across 18 pools with 99 positive-loss victim addresses across 13 loss-bearing episodes and $2.87M in measured victim loss. These measurements show that incentive programs can amplify manipulation by introducing externalities that enable new extraction opportunities. Based on our findings, we propose mitigation strategies that reshape incentive parameters and information disclosure to reduce liquidity-provider exposure to incentive-induced attacks. Our findings show that incentive mechanisms designed to improve market quality can instead create the security vulnerabilities they aim to prevent.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper16
- Making Smart Contracts SmarterLoi Luu, Duc-Hiep Chu, Hrishi Olickel, Prateek Saxena 等CCS 2016 · 被引用 2,306 次
- Quantifying Blockchain Extractable Value: How dark is the forest?Kaihua Qin, Liyi Zhou, Arthur GervaisS&P 2022 · 被引用 336 次
- High-Frequency Trading on Decentralized On-Chain ExchangesLiyi Zhou, Kaihua Qin, Christof Ferreira Torres, Duc Viet Le 等S&P 2021 · 被引用 243 次
- Frontrunner Jones and the Raiders of the Dark Forest: An Empirical Study of Frontrunning on the Ethereum BlockchainChristof Ferreira Torres, Ramiro Camino, Radu StateUSENIX Security 2021 · 被引用 179 次
- The Anatomy of a Cryptocurrency Pump-and-Dump SchemeJiahua Xu, Benjamin LivshitsUSENIX Security 2019 · 被引用 146 次
相关 Paper
- DeFort: Automatic Detection and Analysis of Price Manipulation Attacks in DeFi ApplicationsMaoyi Xie, Ming Hu, Ziqiao Kong, Cen Zhang 等ISSTA 2024 · 被引用 9 次
- Following Devils' Footprint: Towards Real-time Detection of Price Manipulation AttacksBosi Zhang, Ningyu He, Xiaohui Hu, Kai Ma 等USENIX Security 2025
- Serial Scammers and Attack of the Clones: How Scammers Coordinate Multiple Rug Pulls on Decentralized ExchangesPhuong Duy Huynh, Son Hoang Dau, Nicholas Huppert, Joshua Cervenjak 等WWW 2025 · 被引用 6 次
- I Experienced More than 10 DeFi Scams: On DeFi Users' Perception of Security Breaches and CountermeasuresMingyi Liu, Jun Ho Huh, HyungSeok Han, Jaehyuk Lee 等USENIX Security 2024 · 被引用 6 次
- On the Just-In-Time Discovery of Profit-Generating Transactions in DeFi ProtocolsLiyi Zhou, Kaihua Qin, Antoine Cully, Benjamin Livshits 等S&P 2021 · 被引用 148 次
