Security Evaluation of Smart Contract-Based On-chain Ethereum Wallets

被引:12
|
作者
Praitheeshan, Purathani [1 ]
Pan, Lei [1 ]
Doss, Robin [1 ]
机构
[1] Deakin Univ, Sch IT, Geelong, Vic 3220, Australia
来源
关键词
On-chain wallet; Security; Smart contract; Vulnerability;
D O I
10.1007/978-3-030-65745-1_2
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Ethereum is a leading blockchain platform that supports decentralised applications (Dapps) using smart contract programs. It executes cryptocurrency transactions between user accounts or smart contract accounts. Wallets are utilised to integrate with Dapps to manage and hold users' transactions and private keys securely and effectively. Ethereum wallets are available in different forms, and we especially examine on-chain smart contract wallets to measure their safeness property. We have conducted an exploratory study on 86 distinct bytecode versions of Ethereum smart contract wallets and analysed them using four popular security scanning tools. We have identified that, on average, 10.2% of on-chain wallets on the Ethereum platform are vulnerable to different problems. We propose a novel analysis framework to classify the security problems in smart contract wallets using the experimental data. Most of the vulnerabilities detected from smart contract wallets are related to security issues in programming code and interaction with external sources. Our experimental results and analysis data are available at https://github.com/ppraithe/on-chain-wallet-contracts.
引用
收藏
页码:22 / 41
页数:20
相关论文
共 50 条
  • [41] Smart contract-based approach for efficient shipment management
    Hasan, Haya
    AlHadhrami, Esra
    AlDhaheri, Alia
    Salah, Khaled
    Jayaraman, Raja
    COMPUTERS & INDUSTRIAL ENGINEERING, 2019, 136 : 149 - 159
  • [42] Formal Modeling of Smart Contract-based Trading System
    Park, Woong Sub
    Lee, Hyuk
    Choi, Jin-Young
    2022 24TH INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION TECHNOLOGY (ICACT): ARITIFLCIAL INTELLIGENCE TECHNOLOGIES TOWARD CYBERSECURITY, 2022, : 48 - +
  • [43] Smart Contract-Based Access Control for the Internet of Things
    Zhang, Yuanyu
    Kasahara, Shoji
    Shen, Yulong
    Jiang, Xiaohong
    Wan, Jianxiong
    IEEE INTERNET OF THINGS JOURNAL, 2019, 6 (02): : 1594 - 1605
  • [44] A review of smart contract-based platforms, applications, and challenges
    Pratima Sharma
    Rajni Jindal
    Malaya Dutta Borah
    Cluster Computing, 2023, 26 : 395 - 421
  • [45] Smart Contract-Based Access Control for the Vehicular Networks
    Kchaou, Amira
    Ayed, Samiha
    Abassi, Ryma
    El Fatmi, Sihem Guemara
    2020 28TH INTERNATIONAL CONFERENCE ON SOFTWARE, TELECOMMUNICATIONS AND COMPUTER NETWORKS (SOFTCOM), 2020, : 264 - 269
  • [46] A Smart Contract-Based Access Control Framework For Smart Healthcare Systems
    Abid, Amal
    Cheikhrouhou, Saoussen
    Kallel, Slim
    Tari, Zahir
    Jmaiel, Mohamed
    COMPUTER JOURNAL, 2024, 67 (02): : 407 - 422
  • [47] PaySwitch: Smart Contract-Based Payment Switch for Off-Chain Payment Channel Networks
    Jin, Anan
    Ye, Yuhang
    Lee, Brian
    Li, Xiang
    Qiao, Yuansong
    IEEE ACCESS, 2025, 13 : 14837 - 14856
  • [48] A fair multi-party contract signing scheme based on off-chain protocols and on-chain smart contracts
    Jiang, Rong
    Li, Yulin
    Pu, Xuetao
    Wang, Xueke
    Niu, Wenyu
    Song, Zhiming
    JOURNAL OF SUPERCOMPUTING, 2025, 81 (02):
  • [49] The Design and Implementation of a Secure Datastore Based on Ethereum Smart Contract
    Aldyaflah, Izdehar M.
    Zhao, Wenbing
    Upadhyay, Himanshu
    Lagos, Leonel
    APPLIED SCIENCES-BASEL, 2023, 13 (09):
  • [50] Simulative Evaluation of Contract-based Change Management
    Oertel, Markus
    Gerwinn, Sebastian
    Rettberg, Achim
    2014 12TH IEEE INTERNATIONAL CONFERENCE ON INDUSTRIAL INFORMATICS (INDIN), 2014, : 16 - +