The Dark Side of Upgrades: Uncovering Security Risks in Smart Contract Upgrades
Dingding Wang, Jianting He, Siwei Wu, Yajin Zhou, Lei Wu, Cong Wang

TL;DR
This paper presents a large-scale analysis of smart contract upgrade behaviors, revealing diverse insecurity types and exposing overlooked risks that threaten contract security, along with public awareness gaps and mitigation deficiencies.
Contribution
It introduces the first extensive dataset of upgrade behaviors, develops a comprehensive insecurity taxonomy, and highlights unaddressed security risks and public awareness issues.
Findings
Identified 8 types of upgrade insecurities from 37 real incidents.
Built a dataset of over 83,000 upgraded contracts and 20,902 upgrade chains.
Detected 31,407 issues related to upgrade risks, revealing significant security concerns.
Abstract
Smart contract upgrades are increasingly common due to their flexibility in modifying deployed contracts, such as fixing bugs or adding new functionalities. Meanwhile, upgrades compromise the immutability of contracts, introducing significant security concerns. While existing research has explored the security impacts of contract upgrades, these studies are limited in collection of upgrade behaviors and identification of insecurities. To address these limitations, we conduct a comprehensive study on the insecurities of upgrade behaviors. First, we build a dataset containing 83,085 upgraded contracts and 20,902 upgrade chains. To our knowledge, this is the first large-scale dataset about upgrade behaviors, revealing their diversity and exposing gaps in public disclosure. Next, we develop a taxonomy of insecurities based on 37 real-world security incidents, categorizing eight types of…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsBlockchain Technology Applications and Security · Digital Rights Management and Security · Business Law and Ethics
