[Resource Topic] 2016/1007: A survey of attacks on Ethereum smart contracts

Welcome to the resource topic for 2016/1007

Title:
A survey of attacks on Ethereum smart contracts

Authors: Nicola Atzei, Massimo Bartoletti, Tiziana Cimoli

Abstract:

Smart contracts are computer programs that can be correctly executed by a network of mutually distrusting nodes, without the need of an external trusted authority. Since smart contracts handle and transfer assets of considerable value, besides their correct execution it is also crucial that their implementation is secure against attacks which aim at stealing or tampering the assets. We study this problem in Ethereum, the most well-known and used framework for smart contracts so far. We analyse the security vulnerabilities of Ethereum smart contracts, providing a taxonomy of common programming pitfalls which may lead to vulnerabilities. We show a series of attacks which exploit these vulnerabilities, allowing an adversary to steal money or cause other damage.

ePrint: https://eprint.iacr.org/2016/1007

See all topics related to this paper.

Feel free to post resources that are related to this paper below.

Example resources include: implementations, explanation materials, talks, slides, links to previous discussions on other websites.

For more information, see the rules for Resource Topics .