DeFiWarder: Protecting DeFi Apps from Token Leaking Vulnerabilities
Jianzhong Su, Xingwei Lin, Zhiyuan Fang, Zhirong Zhu, Jiachi Chen, Zibin Zheng, Wei Lv, Jiashui Wang
摘要
Decentralized Finance (DeFi) apps have rapidly proliferated with the development of blockchain and smart contracts, whose maximum total value locked (TVL) has exceeded 100 billion dollars in the past few years. These apps allow users to interact and perform complicated financial activities. However, the vulnerabilities hiding in the smart contracts of DeFi apps have resulted in numerous security incidents, with most of them leading to funds (tokens) leaking and resulting in severe financial loss. In this paper, we summarize Token Leaking vulnerability of DeFi apps, which enable someone to abnormally withdraw funds that far exceed their deposits. Due to the massive amount of funds in DeFi apps, it is crucial to protect DeFi apps from Token Leaking vulnerabilities. Unfortunately, existing tools have limitations in addressing this vulnerability. To address this issue, we propose DeFiWarder, a tool that traces on-chain transactions and protects DeFi apps from Token Leaking vulnerabilities. Specifically, DeFiWarder first records the execution logs (traces) of smart contracts. It then accurately recovers token transfers within transactions to catch the funds flow between users and DeFi apps, as well as the relations between users based on role mining. Finally, DeFiWarder utilizes anomaly detection to reveal Token Leaking vulnerabilities and related attack behaviors. We conducted experiments to demonstrate the effectiveness and efficiency of DeFiWarder. Specifically, DeFi-Warder successfully revealed 25 Token Leaking vulnerabilities from 30 Defi apps. Moreover, its efficiency supports real-time detection of token leaking within on-chain transactions. In addition, we summarize five major reasons for Token Leaking vulnerability to assist DeFi apps in protecting their funds.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper4
- Identifying Smart Contract Security Issues in Code Snippets from Stack OverflowJiachi Chen, Chong Chen, Jiang Hu, John C. Grundy 等ISSTA 2024 · 被引用 9 次
- Quantitative Runtime Monitoring of Ethereum Transaction AttacksXinyao Xu, Ziyu Mao, Jianzhong Su, Xingwei Lin 等WWW 2025 · 被引用 1 次
- Smart Contract Fuzzing Towards Profitable VulnerabilitiesZiqiao Kong, Cen Zhang, Maoyi Xie, Ming Hu 等FSE 2025 · 被引用 1 次
- Tracing the Shadows: Automatic Tracking and Analysis of Crypto Money Laundering via Transaction Semantic AnalysisHao Wu, Haijun Wang, Shangwang Li, Yin Wu 等ISSTA 2026
相关 Paper
- HOUSTON: Real-Time Anomaly Detection of Attacks against Ethereum DeFi ProtocolsDongyu Meng, Fabio Gritti, Robert McLaughlin, Nicola Ruaro 等NDSS 2026 · 被引用 2 次
- Evil Under the Sun: Understanding and Discovering Attacks on Ethereum Decentralized ApplicationsLiya Su, Xinyue Shen, Xiangyu Du, Xiaojing Liao 等USENIX Security 2021 · 被引用 74 次
- DeFort: Automatic Detection and Analysis of Price Manipulation Attacks in DeFi ApplicationsMaoyi Xie, Ming Hu, Ziqiao Kong, Cen Zhang 等ISSTA 2024 · 被引用 9 次
- FairChecker: Detecting Fund-Stealing Bugs in DeFi Protocols via Fairness ValidationYi Sun, Zhuo Zhang, Xiangyu ZhangICSE 2025
- SoK: Decentralized Finance (DeFi) AttacksLiyi Zhou, Xihan Xiong, Jens Ernstberger, Stefanos Chaliasos 等S&P 2023
