Validity Is Not Enough: Uncovering the Security Pitfall in Chainlink's Off-Chain Reporting Protocol
Di Zhai, Jiashuo Zhang, Jianbo Gao, Tianhao Liu, Tao Zhang, Jian Wang, Jiqiang Liu
摘要
Blockchain oracles play a crucial role in delivering price data from off-chain exchanges to smart contracts, enabling automated financial services. Chainlink, the dominant oracle service provider, employs Decentralized Oracle Networks (DONs) to provide price feeds. In Chainlink's DON, multiple oracle nodes independently observe the price of a cryptocurrency and run the Off-Chain Reporting (OCR) protocol to determine a unique price from their observation values. Price deviations originating from the OCR protocol will pose security risks. To prevent arbitrary price deviations induced by Byzantine oracle nodes, OCR's validity property guarantees that the determined price is bounded by honest observation values. However, this bound in real-world settings remains unclear, and it is unknown how much price deviation Byzantine behaviors can still induce. In this paper, we conduct an in-depth study of the potential impacts of Byzantine behaviors on the determined price in the OCR protocol, through both empirical and theoretical analyses. First, our empirical analysis reveals that, in real-world settings, Byzantine behaviors still have ample space to sway the determined price in the OCR protocol. We then detail Byzantine behaviors that strategically sway the determined price and formally model their impacts. Furthermore, we evaluate the impacts of these Byzantine behaviors using Chainlink’s real-world price data. Our experimental results show that the price deviation induced by Byzantine behaviors can reach up to 8.47% of the ETH price. Our case studies further indicate that the downstream financial impacts of a price value swayed by Byzantine behaviors can be on the order of USD, and the cumulative impacts of such price values may reach millions of USD. In summary, this work uncovers that Byzantine behaviors can still cause non-negligible impacts on the determined price in the OCR protocol, even under the validity guarantee. We have ethically reported our findings to Chainlink, aiming to support the security of the OCR protocol.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper11
- Town Crier: An Authenticated Data Feed for Smart ContractsFan Zhang, Ethan Cecchetti, Kyle Croman, Ari Juels 等CCS 2016 · 被引用 668 次
- Frontrunner Jones and the Raiders of the Dark Forest: An Empirical Study of Frontrunning on the Ethereum BlockchainChristof Ferreira Torres, Ramiro Camino, Radu StateUSENIX Security 2021 · 被引用 179 次
- A Decentralized Truth Discovery Approach to the Blockchain Oracle ProblemYang Xiao, Ning Zhang, Wenjing Lou, Y. Thomas HouINFOCOM 2023 · 被引用 14 次
- Safeguarding DeFi Smart Contracts against Oracle DeviationsXun Deng, Sidi Mohamed Beillahi, Cyrus Minwalla, Han Du 等ICSE 2024 · 被引用 12 次
- Toward Automated Detecting Unanticipated Price Feed in Smart ContractYifan Mo, Jiachi Chen, Yanlin Wang, Zibin ZhengISSTA 2023 · 被引用 7 次
相关 Paper
- ACon2: Adaptive Conformal Consensus for Provable Blockchain OraclesSangdon Park, Osbert Bastani, Taesoo KimUSENIX Security 2023
- Lay Down the Common Metrics: Evaluating Proof-of-Work Consensus Protocols' SecurityRen Zhang, Bart PreneelS&P 2019 · 被引用 113 次
- As Strong As Its Weakest Link: How to Break Blockchain DApps at RPC ServiceKai Li, Jiaqi Chen, Xianghong Liu, Yuzhe Richard Tang 等NDSS 2021
- Abusing the Ethereum Smart Contract Verification Services for Fun and ProfitPengxiang Ma, Ningyu He, Yuhua Huang, Haoyu Wang 等NDSS 2024
- DoubleUp Roll: Double-spending in Arbitrum by Rolling It BackZhiyuan Sun, Zihao Li, Xinghao Peng, Xiapu Luo 等CCS 2024 · 被引用 3 次
