Demystifying Random Numbers in Smart Contracts: A Novel and High-Efficiency Approach for Attacking Ethereum Contracts
Abstract
As blockchain adoption accelerates, smart contracts have become attractive targets for attackers, often resulting in significant financial losses. While many studies focus on well-known vulnerabilities like reentrancy or integer overflows, weaknesses in pseudo-random number generation (PRNG) remain a persistent and critical challenge despite their role in decentralized applications such as lotteries, games, and token distribution. In Ethereum, randomness is often derived from predictable environmental variables like block timestamps or sender addresses, making these systems vulnerable to manipulation. This paper presents a rigorous investigation into PRNG vulnerabilities in Ethereum smart contracts and introduces two practical attack strategies. The first method relies on brute-force contract deployment to obtain a desired output, incurring high gas costs. The second approach leverages the CREATE2 opcode to precompute candidate contract addresses off-chain, reducing gas usage by over 90%. However, since final outcome prediction depends on block.timestamp at execution time, attack success is contingent on network timing stability and validator behavior. Through formal analysis and empirical evaluation on a controlled local test network, we demonstrate success rates of 100% for Method 1 and 98% for Method 2 under fixed-timestamp conditions. Under simulated live-network congestion, Method 2 success drops to 87% due to block.timestamp sensitivity. Our findings highlight the urgent need for secure randomness solutions, such as verifiable random functions (VRFs) and decentralized randomness beacons. Without adopting such mechanisms, blockchain applications across Ethereum and other EVM-compatible platforms remain exposed to critical security risks.
Community
0 commentsNo discussion yet
Be the first to share a question or observation.