Decentralized Finance (DeFi) took shape in 2020. An unprecedented amount of over 14 billion USD moved into DeFi projects offering trading, loans and insurance. But its growth has also drawn the attention of malicious actors. Many projects were exploited as quickly as they launched and millions of USD were lost. While many developers understand integer overflows and reentrancy attacks, security threats to the DeFi ecosystem are more complex and still poorly understood. In this paper we provide the first overview of in-the-wild DeFi security incidents. We observe that many of these exploits are market attacks, weaponizing weakly implemented business logic in one protocol with credit provided by another to inflate appropriations. Rather than misusing individual protocols, attackers increasingly use DeFi's strength of permissionless composability against itself. By providing the first holistic analysis of real-world security incidents within the nascent financial ecosystem DeFi is, we hope to inform threat modeling in decentralized cryptoeconomic initiatives in the years ahead.
翻译:2020年,分权金融(DeFi)的形成史无前例地超过140亿美元进入提供贸易、贷款和保险的DeFi项目。但增长也引起了恶意行为者的注意。许多项目在启动时被迅速开发,损失了数百万美元。虽然许多开发商理解整数溢出和耐用性袭击,但对DeFi生态系统的安全威胁更为复杂,仍然不甚明了。在本文件中,我们首次概述了在世间发生的DeFi安全事件。我们发现,其中许多开发活动是市场攻击,在一项协议中将执行不力的商业逻辑武器化,用另一个协议提供的信贷来充斥拨款。攻击者没有滥用单个协议,而是越来越多地使用DeFi的无许可折合能力来对付自己。我们希望通过对新兴金融生态系统DeFi首次对现实世界安全事件进行全面分析,从而在今后几年里为分散的加密经济举措提供威胁模型。