Flash Crash for Cash: Cyber Threats in Decentralized Finance

06/20/2021
by   Kris Oosthoek, et al.
0

Decentralized Finance (DeFi) took shape in 2020. An unprecedented amount of over 14 billion USD moved into DeFi projects offering trading, loans and insurance. But its growth has also drawn the attention of malicious actors. Many projects were exploited as quickly as they launched and millions of USD were lost. While many developers understand integer overflows and reentrancy attacks, security threats to the DeFi ecosystem are more complex and still poorly understood. In this paper we provide the first overview of in-the-wild DeFi security incidents. We observe that many of these exploits are market attacks, weaponizing weakly implemented business logic in one protocol with credit provided by another to inflate appropriations. Rather than misusing individual protocols, attackers increasingly use DeFi's strength of permissionless composability against itself. By providing the first holistic analysis of real-world security incidents within the nascent financial ecosystem DeFi is, we hope to inform threat modeling in decentralized cryptoeconomic initiatives in the years ahead.

READ FULL TEXT
research
01/11/2023

Electric Vehicles Security and Privacy: Challenges, Solutions, and Future Needs

Electric Vehicles (EVs) share common technologies with classical fossil-...
research
01/21/2021

SoK: Decentralized Finance (DeFi)

Decentralized Finance (DeFi), a blockchain powered peer-to-peer financia...
research
12/27/2022

Financial Crimes in Web3-empowered Metaverse: Taxonomy, Countermeasures, and Opportunities

At present, the concept of metaverse has sparked widespread attention fr...
research
04/06/2023

Smart Contract and DeFi Security: Insights from Tool Evaluations and Practitioner Surveys

The growth of the decentralized finance (DeFi) ecosystem built on blockc...
research
11/17/2021

Understanding Security Issues in the NFT Ecosystem

Non-Fungible Tokens (NFTs) have emerged as a way to collect digital art ...
research
08/23/2019

Adversary-resilient Inference and Machine Learning: From Distributed to Decentralized

While the last few decades have witnessed a huge body of work devoted to...
research
06/15/2021

CeFi vs. DeFi – Comparing Centralized to Decentralized Finance

To non-experts, the traditional Centralized Finance (CeFi) ecosystem may...

Please sign up or login with your details

Forgot password? Click here to reset