arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

关于识别抢先交易抵抗的可靠条件

On Identifying Sound Conditions for Frontrunning Resistance

Sebastian Holler, Anna Piscitelli, Jannik Albrecht, Stephan Dübler, Ghassan Karame, Clara Schneidewind

arXiv 2609.11535首次发表:更新:

发表机构

MPI-SP; Ruhr University Bochum(马克斯·普朗克安全与隐私研究所; 波鸿鲁尔大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对区块链抢先交易攻击,提出首个正式漏洞定义,指出抵抗性取决于用户交互,并开发可靠算法合成安全条件,在审计合约中发现新漏洞。

AI 中文摘要

区块链通过智能合约——即通过共识执行的交互式程序——实现去中心化应用。然而,区块链交易排序固有的异步性引入了一类称为抢先交易攻击的漏洞,这些漏洞已在以太坊等主要区块链中造成数百万美元的损失。抢先交易攻击的产生是因为用户通过交易与智能合约交互,而这些交易由称为矿工的指定节点添加到区块链中。矿工可以利用其重新排序、延迟或插入交易的能力,相对于诚实用户获得优势,从而有效地抢先交易他们。然而,迄今为止,该领域缺乏对合约抵抗此类攻击意味着什么的严格定义。更糟糕的是,我们表明现有的动态检测方法从根本上是不充分的:在一项包含287次智能合约审计的大规模研究中,领先智能合约审计师报告的393个漏洞中有55%超出了最先进检测标准的范围。为解决这一差距,我们提出了智能合约抢先交易漏洞的首个正式定义。我们的定义捕捉了一个关键见解:对抢先交易的抵抗并非合约本身的固有属性,而是关键地取决于诚实用户如何与之交互。基于这一观察,我们开发了一种用于综合安全交互条件的可靠算法,并附带一个原型实现,我们将其应用于经过审计的真实世界合约——揭示了两个以太坊合约中先前未发现的漏洞。

英文摘要

Blockchains enable decentralized applications through smart contracts---interactive programs executed through consensus. However, the inherently asynchronous nature of blockchain transaction ordering introduces a class of vulnerabilities known as frontrunning attacks, which have caused millions of dollars in losses in major blockchains, such as Ethereum. Frontrunning attacks arise because users interact with smart contracts through transactions, which are added to the blockchain by designated nodes called miners. Miners can exploit their ability to reorder, delay, or insert transactions to gain an advantage over honest users, effectively frontrunning them. Yet, to date, the field lacks a rigorous definition of what it even means for a contract to resist such attacks. Worse, we show that existing dynamic detection approaches are fundamentally inadequate: in a large-scale study comprising 287 smart contract audits, 55% of the 393 reported vulnerabilities identified by leading smart contract auditors fall outside the scope of state-of-the-art detection criteria. To address this gap, we propose the first formal definition of frontrunning vulnerability for smart contracts. Our definition captures a key insight: resistance to frontrunning is not an intrinsic property of a contract alone, but depends critically on how honest users interact with it. Grounded in this observation, we develop a sound algorithm for synthesizing secure interaction conditions, alongside a prototype implementation that we apply to audited real-world contracts---revealing previously undiscovered vulnerabilities in two Ethereum contracts.

CommentsAccepted for CCS 2026

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑