FairChecker: Detecting Fund-Stealing Bugs in DeFi Protocols via Fairness Validation
Yi Sun, Zhuo Zhang, Xiangyu Zhang
摘要
Decentralized Finance (DeFi) is an emerging paradigm within the blockchain space that aims to revolutionize conventional financial systems by applying blockchain technology. The substantial value of digital assets managed by DeFi protocols makes it a lucrative target for attacks. Despite the human resources and the application of automated tools, frequent attacks still cause significant fund losses to DeFi participants. Existing tools primarily rely on oracles similar to those used in traditional software analysis, making it challenging for them to detect functional bugs specific to the DeFi domain. Since blockchain functions as a distributed ledger system, the foundation of any DeFi protocol is the accurate maintenance of key state variables representing user funds. If these variables are not properly updated or designed to reflect the intended flow of funds, attackers can exploit these flaws to steal assets. From the study of popular DeFi protocols, we observe that, in DeFi systems, to ensure a transaction does not misappropriate someone's fund, the direction of changes (increase or decrease) of values associated with the amount of asset or debt of a user has to adhere to some fairness properties. We propose a concept called fairness bug which allows attackers to gain profit without cost. We propose an inter-procedural and inter-contract static analysis technique that utilizes symbolic execution and an SMT solver to automatically detect fairness bugs in DeFi smart contracts. We have implemented our fairness-checking approach in our tool, named FairChecker. We evaluate our tool on a benchmark of 113 real-world DeFi protocols with 34 fairness bugs. The results show that our tool can detect 32 bugs with a recall of 94.1 % and a precision of 46.4 %, demonstrating its effectiveness.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- FORAY: Towards Effective Attack Synthesis against Deep Logical Vulnerabilities in DeFi ProtocolsHongbo Wen, Hanzhi Liu, Jiaxin Song, Yanju Chen 等CCS 2024 · 被引用 6 次
- Safeguarding DeFi Smart Contracts against Oracle DeviationsXun Deng, Sidi Mohamed Beillahi, Cyrus Minwalla, Han Du 等ICSE 2024 · 被引用 12 次
- HOUSTON: Real-Time Anomaly Detection of Attacks against Ethereum DeFi ProtocolsDongyu Meng, Fabio Gritti, Robert McLaughlin, Nicola Ruaro 等NDSS 2026 · 被引用 2 次
- Nyx: Detecting Exploitable Front-Running Vulnerabilities in Smart ContractsWuqi Zhang, Zhuo Zhang, Qingkai Shi, Lu Liu 等S&P 2024 · 被引用 23 次
- DeFiTainter: Detecting Price Manipulation Vulnerabilities in DeFi ProtocolsQueping Kong, Jiachi Chen, Yanlin Wang, Zigui Jiang 等ISSTA 2023 · 被引用 31 次
