학술논문

Understanding the Security Risks of Decentralized Exchanges by Uncovering Unfair Trades in the Wild
Document Type
Conference
Source
2023 IEEE 8th European Symposium on Security and Privacy (EuroS&P) EUROSP Security and Privacy (EuroS&P), 2023 IEEE 8th European Symposium on. :332-351 Jul, 2023
Subject
Communication, Networking and Broadcast Technologies
Components, Circuits, Devices and Systems
Computing and Processing
Robotics and Control Systems
Protocols
Finance
Decentralized applications
Loss measurement
Blockchains
Security
DeFi
fairness
DEX
Theft
Ethereum
blockchain
Language
Abstract
DEX, or decentralized exchange, is a prominent class of decentralized finance (DeFi) applications on blockchains, attracting a total locked value worth tens of billions of USD today.This paper presents the first large-scale empirical study that uncovers unfair trades on popular DEX services on Ethereum and Binance Smart Chain (BSC). By joining and analyzing 60 million transactions, we find 671, 400 unfair trades on all six measured DEXes, including Uniswap, Balancer, and Curve. Out of these unfair trades, we attribute 55, 000 instances, with high confidence, to token thefts that cause a value loss of more than 3.88 million USD. Furthermore, the measurement study uncovers previously unknown causes of extractable value and real-world adaptive strategies to these causes. Finally, we propose countermeasures to redesign secure DEX protocols and to harden deployed services against the discovered security risks.