{teEther}: Gnawing at ethereum to automatically exploit smart contracts

J Krupp, C Rossow - … USENIX security symposium (USENIX Security 18), 2018 - usenix.org
27th USENIX security symposium (USENIX Security 18), 2018usenix.org
Cryptocurrencies like Bitcoin not only provide a decentralized currency, but also provide a
programmatic way to process transactions. Ethereum, the second largest cryptocurrency
next to Bitcoin, is the first to provide a Turing-complete language to specify transaction
processing, thereby enabling so-called smart contracts. This provides an opportune setting
for attackers, as security vulnerabilities are tightly intertwined with financial gain. In this
paper, we consider the problem of automatic vulnerability identification and exploit …
Abstract
Cryptocurrencies like Bitcoin not only provide a decentralized currency, but also provide a programmatic way to process transactions. Ethereum, the second largest cryptocurrency next to Bitcoin, is the first to provide a Turing-complete language to specify transaction processing, thereby enabling so-called smart contracts. This provides an opportune setting for attackers, as security vulnerabilities are tightly intertwined with financial gain. In this paper, we consider the problem of automatic vulnerability identification and exploit generation for smart contracts. We develop a generic definition of vulnerable contracts and use this to build teEther, a tool that allows creating an exploit for a contract given only its binary bytecode. We perform a large-scale analysis of all 38,757 unique Ethereum contracts, 815 out of which our tool finds working exploits for—completely automated.
usenix.org
Showing the best result for this search. See all results