Evil Under the Sun: Understanding and Discovering Attacks on Ethereum Decentralized Applications Liya Su1,2,3 ∗,† Xinyue Shen1,4∗,† Xiangyu Du1,2,3,∗ Xiaojing Liao1, XiaoFeng Wang1, Luyi Xing1, Baoxu Liu2,3 1Indiana University Bloomington, 2Institute of Information Engineering, Chinese Academy of Sciences, 3University of Chinese Academy of Sciences, 4Alibaba Group {liyasu, shen12, duxian}@iu.edu, {xliao, xw7, luyixing}@indiana.edu,
[email protected] Abstract the DAO attack that caused a loss over 50 million USD [39] in 2016, resulting in the hard-fork in Ethereum. Also found in The popularity of Ethereum decentralized applications our study is that miscreants took 14K Ethers from the victim (Dapps) also brings in new security risks: it has been re- Dapps with most financial losses (i.e., Fomo3D, Section 4.5). ported that these Dapps have been under various kinds of attacks from cybercriminals to gain profit. To the best of With this significant threat, the community’s understanding our knowledge, little has been done so far to understand this about the new type of cybercrimes is still very limited: to new cybercrime, in terms of its scope, criminal footprints the best of our knowledge, no extensive forensic analysis and attack operational intents, not to mention any efforts to on Dapp attacks has ever been reported, nor has any cyber investigate these attack incidents automatically on a large threat intelligence (CTI) been collected from them to find out scale. In this paper, we performed the first measurement study the perpetrator’s strategy, capability and infrastructure, not to on real-world Dapp attack instances to recover critical threat mention to utilize the knowledge to mitigate the threat.