Xscope: Hunting for Cross-Chain Bridge Attacks

08/15/2022
by   Jiashuo Zhang, et al.
0

Cross-Chain bridges have become the most popular solution to support asset interoperability between heterogeneous blockchains. However, while providing efficient and flexible cross-chain asset transfer, the complex workflow involving both on-chain smart contracts and off-chain programs causes emerging security issues. In the past year, there have been more than ten severe attacks against cross-chain bridges, causing billions of loss. With few studies focusing on the security of cross-chain bridges, the community still lacks the knowledge and tools to mitigate this significant threat. To bridge the gap, we conduct the first study on the security of cross-chain bridges. We document three new classes of security bugs and propose a set of security properties and patterns to characterize them. Based on those patterns, we design Xscope, an automatic tool to find security violations in cross-chain bridges and detect real-world attacks. We evaluate Xscope on four popular cross-chain bridges. It successfully detects all known attacks and finds suspicious attacks unreported before. A video of Xscope is available at https://youtu.be/vMRO_qOqtXY.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
08/31/2020

SuSy: a blockchain-agnostic cross-chain asset transfer gateway protocol based on Gravity

This document is a specialized technical description of one of the poten...
research
05/08/2020

Human Error in IT Security

This paper details on the analysis of human error, an IT security issue,...
research
02/09/2023

Fee-Redistribution Smart Contracts for Transaction-Fee-Based Regime of Blockchains with the Longest Chain Rule

In this paper, we review the undercutting attacks in the transaction-fee...
research
10/28/2022

SoK: Not Quite Water Under the Bridge: Review of Cross-Chain Bridge Hacks

The blockchain ecosystem has evolved into a multi-chain world with vario...
research
10/01/2022

zkBridge: Trustless Cross-chain Bridges Made Practical

Blockchains have seen growing traction with cryptocurrencies reaching a ...
research
12/31/2021

SOK: On the Analysis of Web Browser Security

Web browsers are integral parts of everyone's daily life. They are commo...
research
10/26/2021

LayerZero: Trustless Omnichain Interoperability Protocol

The proliferation of blockchains has given developers a variety of platf...

Please sign up or login with your details

Forgot password? Click here to reset