Dynamic Analysis for the Detection of Locked Ether Smart Contracts
Abstract
Ethereum Smart Contract (SC) is a sophisticated technology that enhances the scope of BlockChain automation. However, SCs’ vulnerable programs have marred BlockChain’s nascent technology’s brighter aspects. Two critical hacks, the DAO attack, caused by reentrancy vulnerability, and the Parity attack, caused by unprotected selfdestruct and frozen Ether vulnerabilities, are famous for their historical cryptocurrency frauds. DAO attack robbed a sixty million dollar amount of cryptocurrency from the victim’s account. But the Parity attack created a new trend in software vulnerabilities by freezing a thirty million dollar amount of Ether. In fact, the Parity attack wiped out the library SC. Subsequently, all the SCs, depending upon the library functions (e.g., the Parity SC’s Ether transfer), became paralyzed, which locked the investors’ funds. This paper enhances our dynamic analysis tool, TechyTech, to detect the Locked Ether (i.e., Frozen Ether) vulnerability. Furthermore, TechyTech adopts a transfer-based approach and uses case studies to compare TechyTech’s performance with Remix.
Community
0 commentsNo discussion yet
Be the first to share a question or observation.