arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.17902cs.CR

幽灵订单:非托管预测市场中原子性违规的检测与测试

Ghost-Filled Orders: Detecting and Testing Atomicity Violations in Non-Custodial Prediction Markets

Zhiyang Chen, Fan Long, Zhendong Su

首次发表
浏览论文内容

中文总结 AI 辅助

本研究通过Polymarket案例揭示非托管预测市场中链下接单与链上结算间的原子性缺口,量化其九个月影响,并测试另三个市场均存在同类漏洞,提出检测方法。

中文摘要 AI 辅助

基于区块链的预测市场将链下订单管理与链上结算相结合。这种架构支持用户托管的保管方式,因为用户将资金保留在钱包或智能合约中,同时向链下订单簿提交签名订单。然而,这造成了原子性缺口。订单在链下被接受或匹配时可能有效,但在相应的链上结算交易执行之前可能变得无效。这种行为通常被社区称为“幽灵订单”,可能导致看似已在链下成交的交易在链上失败。本文通过对Polymarket的案例研究来探讨这一原子性缺口。我们展示了链下订单接受与链上结算之间的延迟如何使攻击者能够在观察市场结果或价格变动后使不利订单失效。随后,我们使用涉及Polymarket官方智能合约的180万笔回滚交易,量化了2025年8月12日至2026年5月22日这九个月期间该行为的规模与财务影响。我们的分析将攻击者利润与市场和用户损失区分开来,并制定了保守的测量规则以避免夸大影响。我们进一步开发了一种测试其他基于区块链的预测市场的方法,并将其应用于另外三个市场。我们发现这三个市场都容易受到同类攻击,且其中一种设计能够直接产生攻击者利润。我们已将发现报告给这三个项目;在研究时,其中一个项目已确认该问题。

英文摘要

Blockchain based prediction markets combine offchain order management with onchain settlement. This architecture supports user controlled custody, since users keep funds in wallets or smart contracts while submitting signed orders to an offchain order book. However, it creates an atomicity gap. An order may be valid when accepted or matched offchain, but become invalid before the corresponding onchain settlement transaction is executed. This behavior, often called ghost filled orders by the community, can cause trades that appear filled offchain to fail onchain. This paper studies this atomicity gap through a case study of Polymarket. We show how the delay between offchain order acceptance and onchain settlement allows adversaries to invalidate unfavorable orders after observing market outcomes or price movements. We then quantify the scale and financial impact of this behavior over a nine-month period from August 12, 2025, to May 22, 2026, using 1.8 million reverted transactions involving Polymarket official smart contracts. Our analysis separates attacker profit from market and user loss, and develops conservative measurement rules to avoid overclaiming impact. We further develop a methodology for testing other blockchain based prediction markets and apply it to three additional markets. We find that all three are vulnerable to the same class of attack, and that one design enables direct attacker profit. We have reported the findings to all three projects; one project had acknowledged the issue at the time of the study.

发表机构

  • University of Toronto(多伦多大学)
  • ETH Zurich(苏黎世联邦理工学院)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑