Targeting the Weakest Link: Social Engineering Attacks in Ethereum Smart Contracts
Nikolay Ivanov, Jianzhi Lou, Ting Chen, Jin Li, Qiben Yan

TL;DR
This paper introduces new social engineering attack methods targeting Ethereum smart contracts, demonstrating their feasibility, potential impact, and the need for improved security measures in smart contract deployment.
Contribution
The work presents two novel classes of social engineering attacks and six zero-day attack patterns, expanding the understanding of human-targeted vulnerabilities in Ethereum smart contracts.
Findings
Identified 1,027 vulnerable smart contracts out of 85,656 analyzed.
Demonstrated attacks can be embedded without altering contract functionality.
Experts agree these attacks pose a significant threat to smart contract security.
Abstract
Ethereum holds multiple billions of U.S. dollars in the form of Ether cryptocurrency and ERC-20 tokens, with millions of deployed smart contracts algorithmically operating these funds. Unsurprisingly, the security of Ethereum smart contracts has been under rigorous scrutiny. In recent years, numerous defense tools have been developed to detect different types of smart contract code vulnerabilities. When opportunities for exploiting code vulnerabilities diminish, the attackers start resorting to social engineering attacks, which aim to influence humans -- often the weakest link in the system. The only known class of social engineering attacks in Ethereum are honeypots, which plant hidden traps for attackers attempting to exploit existing vulnerabilities, thereby targeting only a small population of potential victims. In this work, we explore the possibility and existence of new social…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Code & Models
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsBlockchain Technology Applications and Security · Advanced Malware Detection Techniques · Spam and Phishing Detection
