DoubleUp Roll: Double-spending in Arbitrum by Rolling It Back
Zhiyuan Sun, Zihao Li, Xinghao Peng, Xiapu Luo, Muhui Jiang, Hao Zhou, Yinqian Zhang
摘要
Optimistic rollup protocols are widely adopted as the most popular blockchain scaling solutions. As a dominant implementation, Arbitrum has boasted a total locked value exceeding 18 billion USD, highlighting the significance of optimistic rollups in blockchain ecosystem. Despite their popularity, little research has been done on the security of optimistic rollup protocols, and potential vulnerabilities on them remain unknown. In this work, we unveil three novel double spending attacks on Arbitrum, each enabling an attacker to steal funds from cross-chain applications on Arbitrum. To facilitate these double spending attacks, we introduce an attack to induce manipulable delays in the transaction rollup process and propose a cost optimization solution to reduce further transaction fees associated with the attacks. Our investigations broaden the exploitation of our double spending attacks to another leading optimistic rollup protocol, Optimism, highlighting the generability of our proposed attacks. Through extensive experiments on a local test network, we demonstrated that our attacks lead to severe malicious effects, such as fund losses from double spending. From late 2022 to early 2023, we reported these vulnerabilities to the Arbitrum and Optimism teams. All the issues were acknowledged and resolved, and our research safeguarded billions of dollars at risk, earning us half a million dollars in bug bounty rewards.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- fAmulet: Finding Finalization Failure Bugs in Polygon zkRollupZihao Li, Xinghao Peng, Zheyuan He, Xiapu Luo 等CCS 2024 · 被引用 5 次
- Is My RPC Response Reliable? Detecting RPC Bugs in Blockchain Client under ContextZhijie Zhong, Yuhong Nan, Mingxi Ye, Qing Xue 等ICSE 2026
它引用的顶会 Paper10
- Anonymous Multi-Hop Locks for Blockchain Scalability and InteroperabilityGiulio Malavolta, Pedro Moreno-Sanchez, Clara Schneidewind, Aniket Kate 等NDSS 2019 · 被引用 305 次
- Finding Consensus Bugs in Ethereum via Multi-transaction Differential FuzzingYoungseok Yang, Taesoo Kim, Byung-Gon ChunOSDI 2021 · 被引用 57 次
- SCVHunter: Smart Contract Vulnerability Detection Based on Heterogeneous Graph Attention NetworkFeng Luo, Ruijie Luo, Ting Chen, Ao Qiao 等ICSE 2024 · 被引用 38 次
- DETER: Denial of Ethereum Txpool sERvicesKai Li, Yibo Wang, Yuzhe TangCCS 2021 · 被引用 26 次
- DeepInfer: Deep Type Inference from Smart Contract BytecodeKunsong Zhao, Zihao Li, Jianfeng Li, He Ye 等FSE 2023 · 被引用 24 次
相关 Paper
- Rolling in the Shadows: Analyzing the Extraction of MEV Across Layer-2 RollupsChristof Ferreira Torres, Albin Mamuti, Ben Weintraub, Cristina Nita-Rotaru 等CCS 2024 · 被引用 12 次
- Specular: Towards Secure, Trust-minimized Optimistic Blockchain ExecutionZhe Ye, Ujval Misra, Jiajun Cheng, Wenyang Zhou 等S&P 2024 · 被引用 9 次
- A Two-Layer Blockchain Sharding Protocol Leveraging Safety and Liveness for Enhanced PerformanceYibin Xu, Jingyi Zheng, Boris Düdder, Tijs Slaats 等NDSS 2024
- The Attack of the Clones Against Proof-of-AuthorityParinya Ekparinya, Vincent Gramoli, Guillaume JourjonNDSS 2020
- Smart Contract and DeFi Security Tools: Do They Meet the Needs of Practitioners?Stefanos Chaliasos, Marcos Antonios Charalambous, Liyi Zhou, Rafaila Galanopoulou 等ICSE 2024 · 被引用 49 次
