AI 中文总结
研究人员发现交易模拟功能可被利用,提出SIMGUARD系统检测到4000余个相关钓鱼合约,致5700余名受害者损失约348万美元,暴露钱包防御漏洞并呼吁优化模拟机制。
AI 中文摘要
加密货币用户正日益成为钓鱼和诈骗攻击的目标。为缓解这些威胁,主流加密钱包(如MetaMask)推出了交易模拟功能,可在链上执行前预览交易的余额变化。尽管该功能对传统资金 draining 攻击有效,但我们证明这种防御本身可被一种新的钓鱼技术利用,我们将其命名为交易模拟钓鱼。该攻击使用精心设计的智能合约,其执行依赖动态区块链状态,导致模拟显示良性或盈利结果,而实际链上执行会将用户资金重定向至攻击者控制的地址。我们对交易模拟钓鱼展开了首次全面研究:首先构建了可用于实施该攻击的钓鱼合约分类;随后提出SIMGUARD,这是一种结合静态与动态程序分析的字节码级检测系统,用于识别钓鱼合约。将SIMGUARD应用于以太坊、币安智能链、Avalanche及Polygon,我们检测到2024年8月至2025年6月间部署的超过4000个钓鱼合约。分析发现超过5700名受害者,损失约348万美元,其中91.5%发生在以太坊;聚类结果显示最大的钓鱼合约集群单独占总损失的约83%。这些结果揭示了当前钱包防御的关键弱点,凸显了亟需更稳健的交易模拟机制。
英文摘要
Cryptocurrency users have increasingly become targets of phishing and scam attacks. To mitigate these threats, leading crypto wallets (e.g., MetaMask) have introduced transaction simulation, which previews a transaction's balance changes before on-chain execution. While effective against traditional fund-draining attacks, we show that this defense can itself be exploited by a new phishing technique, which we term transaction simulation phishing. This attack uses carefully crafted smart contracts whose execution depends on dynamic blockchain state, causing simulations to display benign or profitable outcomes while the actual on-chain execution redirects users' funds to attacker-controlled addresses. We present the first comprehensive study of transaction simulation phishing. We first develop a taxonomy of phishing contracts that can be utilized to facilitate this attack. Then, we propose SIMGUARD, a bytecode-level detection system that combines static and dynamic program analysis to identify phishing contracts. Applying SIMGUARD to Ethereum, Binance Smart Chain, Avalanche, and Polygon, we detect over 4,000 phishing contracts deployed between August 2024 and June 2025. Our analysis identifies more than 5,700 victims and approximately $3.48 million USD in losses, 91.5% of which occurred on Ethereum. Moreover, our clustering result reveals that the largest phishing contract cluster alone accounts for about 83% of the total losses. These results expose a critical weakness in current wallet defenses and highlight the urgent need for more robust transaction simulation mechanisms.
Comments15 pages, 7 figures