密码学安全并不足够:Renegade 去中心化暗池中的隐私漏洞
Cryptographic Security Is Not Enough: Privacy Gaps in the Renegade Decentralized Dark Pool
- IMDEA Networks Institute(IMDEA网络研究所)
- EPFL(洛桑联邦理工学院)
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
研究发现 Renegade 去中心化暗池的密码学保证未能实现交易前隐私、活跃性和交易后保密性,存在公平性、意图泄露、griefing 攻击及网络中心化等问题,需额外协议级保障。
AI中文摘要:
暗池旨在提供交易前隐私、活跃性和交易后保密性——在执行前隐藏订单流,并在执行后限制信息泄露。去中心化暗池(如 Renegade)旨在无需托管风险的情况下复制这些特性,使用安全多方计算(MPC)和零知识证明来实现私有订单匹配和可验证结算。我们表明,Renegade 的密码学保证在实践中并未实现这些暗池特性。带中止的 MPC 确保了正确性但未确保公平性:一方可能获知匹配结果并无惩罚地中止,从而破坏交易前隐私。我们证明,该协议的发现层在 MPC 开始之前就进一步泄露了交易意图,并且通过选择性中止进行持续探测可以概率性地重建对手方订单历史,威胁交易后保密性。我们还表明,在 MPC 执行之前缺乏输入一致性检查,使得一种使用无效状态承诺的 griefing 攻击成为可能,该攻击无需持有真实代币即可持续锁定诚实用户的钱包并浪费计算资源,在持续条件下破坏活跃性。我们进一步分析了 Base 上超过 700,000 笔 Renegade 交易,并探测了 P2P 层,发现该网络实际上已中心化:88% 的流量通过少数几个中继器路由,仅有四个节点维持 P2P 层。由于中继器以明文形式持有其用户的钱包状态,这种集中意味着该系统在实践中作为中心化订单簿运行——在链下重现了暗池旨在消除的信息不对称。综合来看,我们的结果表明,密码学隐私并不意味着暗池安全:交易前隐私、活跃性和交易后保密性各自需要超越 MPC 正确性的额外协议级保证。
英文摘要:
Dark pools are designed to provide pre-trade privacy, liveness, and post-trade confidentiality - concealing order flow before execution and limiting information leakage after. Decentralized dark pools, such as Renegade, aim to replicate these properties without custodial risk, using secure multi-party computation (MPC) and zero-knowledge proofs for private order matching and verifiable settlement. We show that Renegade's cryptographic guarantees do not deliver these dark pool properties in practice. MPC-with-abort ensures correctness but not fairness: a party may learn the match result and abort without penalty, breaking pre-trade privacy. We demonstrate that the protocol's discovery layer further leaks trading intent before MPC even begins, and that sustained probing via selective abort can probabilistically reconstruct counterparty order history, threatening post-trade confidentiality. We also show that the absence of input-consistency checks prior to MPC execution enables a griefing attack using invalid state commitments requiring no real token holdings that continuously locks honest users' wallets and wastes compute, breaking liveness under sustained conditions. We further analyze over 700,000 Renegade transactions on Base and probe the P2P layer, finding that the network is effectively centralized: 88% of traffic routes through a handful of relayers, with only four nodes sustaining the P2P layer. Since relayers hold their users' wallet state in plaintext, this concentration means the system operates as a centralized orderbook in practice - reproducing off-chain the information asymmetry that dark pools are designed to eliminate. Together, our results show that cryptographic privacy does not imply dark pool security: pre-trade privacy, liveness, and post-trade confidentiality each require additional protocol-level guarantees beyond MPC correctness.