arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2607.18753cs.SE

TrapHunter:揭露陷阱代币合约中的隐蔽路径

TrapHunter: Exposing Covert Pathways in Trap Token Contracts

Yin Wu, Yixuan Liu, Yi Li, Chenyang Peng, Hao Wu, Ming Fan, Ting Liu, Haijun Wang

首次发表
浏览论文内容

中文总结 AI 辅助

研究针对攻击者利用标准化代币合约伪装恶意陷阱代币的问题,提出TrapHunter框架,通过新分类法系统化陷阱格局,利用统一语义表示、大语言模型及动态验证来识别陷阱和揭露隐蔽路径,实验证明其性能优于现有工具。

中文摘要 AI 辅助

标准化代币合约(如ERC-20)是数字资产的基础。但攻击者利用其标准化伪装恶意陷阱代币,采用“欺骗性遵守”策略。为此,我们先通过从代币固有功能生命周期提出新分类法来系统化陷阱格局。接着提出TrapHunter框架,通过意图偏差分析识别陷阱并揭露隐蔽路径。它引入统一语义表示,利用大语言模型弥合语义差距并经基于分叉的动态验证。对269个真实合约实验表明,TrapHunter能有效检测所有六类陷阱,平均精度81.8%,召回率85.4%,显著优于现有工具。

英文摘要

Standardized token contracts (e.g., ERC-20) form the foundation of digital assets. However, attackers increasingly abuse this standardization to disguise malicious trap tokens. Unlike obvious violations, these contracts employ a strategy of "deceptive adherence": they strictly adhere to standard protocols to evade detection while embedding covert logic to defraud users. To address this, we first systematize the trap landscape by proposing a novel taxonomy derived from the intrinsic functional lifecycle of tokens (Generation, Circulation, Persistence, and Observation). We then propose TrapHunter, a framework designed to identify these traps and expose covert pathways within these deceptive contracts via intent deviation analysis. Specifically, TrapHunter introduces a unified semantic representation combining Abstract Behavior Trees (ABTs) and Augmented Path Graphs (APGs) to normalize intra-procedural syntax and reveal hidden execution paths driven by inter-procedural state dependencies. Crucially, it bridges the semantic gap by leveraging LLMs to reason about the behavioral intent of deviations from reference implementations, followed by fork-based dynamic validation to confirm exploitability. Experimental evaluation on 269 real-world contracts with three LLMs (DeepSeek, GPT, and Gemini) demonstrates that TrapHunter effectively detects all six categories of traps, achieving an average precision of 81.8% and recall of 85.4%, significantly outperforming state-of-the-art tools.

补充信息

↑