Decentralized finance (DeFi), which is a promising domain since the era of blockchain 2.0, locked \$200 billion in April 2022. However, it quickly dropped to \$100 billion in May 2022, which makes us realize that security issues in this area are still a challenging job. DeFi is more complex than traditional finance because it is decentralized through blockchain and without a trustworthy third-party institution to act as a guarantee. So it owns not only financial properties but also technical aspects. Existing synthesis work for DeFi tends to ignore the relevance of various layers of security for the whole system. In addition, distinct layers have different means of protection against specific vulnerabilities, which is not considered by existing analytical work. In this paper, we perform a vulnerability analysis for the entire technology layer of the DeFi application, and then we collect the most impactive attacks in recent years. Finally, we summarize the existing optimization approaches for different layers and provide some challenges and future directions.
翻译:分散金融(DeFi)是自20世纪20世纪20世纪20年代以来的一个充满希望的领域,在2022年4月锁定了2,000亿美元。然而,在2022年5月迅速下降到1000亿美元。这使我们认识到该领域的安全问题仍是一项具有挑战性的工作。 DeFi比传统金融更加复杂,因为它通过块链分散,没有值得信赖的第三方机构作为担保。因此它不仅拥有财务特性,还拥有技术方面。DFi的现有综合工作往往忽视了不同层次安全对整个系统的相关性。此外,不同的层次有不同的保护手段来防止特定脆弱性,而现有的分析工作并没有考虑到这一点。我们在本文件中,对DeFi应用的整个技术层面进行了脆弱性分析,然后我们收集了近年来最具影响力的攻击。最后,我们总结了不同层次的现有优化方法,并提出了一些挑战和未来方向。