The Eye of Horus: Spotting and Analyzing Attacks on Ethereum Smart\n Contracts
Abstract
In recent years, Ethereum gained tremendously in popularity, growing from a\ndaily transaction average of 10K in January 2016 to an average of 500K in\nJanuary 2020. Similarly, smart contracts began to carry more value, making them\nappealing targets for attackers. As a result, they started to become victims of\nattacks, costing millions of dollars. In response to these attacks, both\nacademia and industry proposed a plethora of tools to scan smart contracts for\nvulnerabilities before deploying them on the blockchain. However, most of these\ntools solely focus on detecting vulnerabilities and not attacks, let alone\nquantifying or tracing the number of stolen assets. In this paper, we present\nHorus, a framework that empowers the automated detection and investigation of\nsmart contract attacks based on logic-driven and graph-driven analysis of\ntransactions. Horus provides quick means to quantify and trace the flow of\nstolen assets across the Ethereum blockchain. We perform a large-scale analysis\nof all the smart contracts deployed on Ethereum until May 2020. We identified\n1,888 attacked smart contracts and 8,095 adversarial transactions in the wild.\nOur investigation shows that the number of attacks did not necessarily decrease\nover the past few years, but for some vulnerabilities remained constant.\nFinally, we also demonstrate the practicality of our framework via an in-depth\nanalysis on the recent Uniswap and Lendf.me attacks.\n
Community
0 commentsNo discussion yet
Be the first to share a question or observation.