读书笔记(九)-- Ethereum contract attack

本文探讨了Ethereum智能合约的安全问题,包括可能出现的攻击类型及其后果。作者指出,由于Solidity语言和合约设计的弱点,智能合约易受攻击,如未知调用、异常混乱、无gas发送等。文章列举了12种漏洞,并提供了一些攻击实例。此外,还讨论了目前智能合约检查的方法不足,强调了智能合约审计的重要性,尤其是在快速发展的区块链行业中。
摘要由CSDN通过智能技术生成

Atzei, Nicola, Massimo Bartoletti, and Tiziana Cmoli. "A survey of
attacks on Ethereum smart contracts."IACR Cryptology ePrint
Archive 2016 (2016): 1007.

A. Problem Statement

The paper targets the problem of Ethereum contract attack. Particularly, how to avoid some of the weaknesses in the Ethereum s mart contract design that could lead to security issues?

B. Problem Significance

Ethereum is an open source public blockchain platform with smart contract functionality. Smart contracts based on blockchains can be seen by all users on the blockchain. However, this can result in all vulnerabilities, including security holes, being visible. If the smart contract developer is negligent or under-tested, and the code of the smart contract is flawed, it is very easy to be exploited and attacked by the hacker. And the more powerful the smart contract, the more logical it is, and the more likely it is to have a logical loophole. At the same time, the smart contract language Solidity itself and the contract design may have loopholes.
Many Ethereum s mart contracts control digital assets with real value. The security of s mart contracts is a hot topic in blockchain security, but in fact, many smart contracts have loopholes. Therefore, it is very important to ensure that there are no security breaches in the contract. W i

评论 1
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值