New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

A cat-and-mouse game: how to frontrun a transaction in the future? by Qi Su | Devcon SEA

DevconTue, Oct 7, 2025, 12:00 AM

This talk will describe the attack-defense game in the MEV world. First it will briefly discuss MEV transactions and how it can protect projects from hackers. Then it will delve into attack-defense games between MEV bots. Finally it will discuss our latest observations and direction in this cat-and-mouse game. Speaker(s): Qi Su Skill level: Intermediate Track: Security Keywords: Security, Fuzzing, MEV, program, analysis Follow us: https://twitter.com/efdevcon, https://twitter.com/ethereum, https://warpcast.com/devcon Learn more about devcon: https://www.devcon.org/ Learn more about ethereum: https://ethereum.org/ Visit the https://archive.devcon.org/ to gain access to the entire library of Devcon talks with the ease of filtering, playlists, personalized suggestions, decentralized access on Swarm, IPFS and more. Devcon is the Ethereum conference for developers, researchers, thinkers, and makers. Devcon SEA was held in Bangkok, Thailand on Nov 12 - Nov 15, 2024. Devcon is organized and presented by the Ethereum Foundation. To find out more, please visit https://ethereum.foundation/

Transcript

[Music] [Music] production like as possible instead all right thank you okay thank you Kim thank you so much now we are going to have have our last Talk of the day from chisu he's a security engineer from fosland he's going to show us attack and defense game in the me world let's welcome him hello everyone um my name is shei and I'm a security engineer at Fen and uh for the for the past year we have been digging into the M well so we have some uh insights to share to bring some new methodologies into this world and uh the topic is how to F run transaction in the future so in 2023 we have seen a lot of fundr Runners has rescued millions of dollars in the hacking incidents for example like C they rescued uh 5.4 million and also bloack and also in the kyos SW incident they rescue 5.7 million and return those funds to the protocols these are like white hat hackers but we are seeing a decline declining trend for this uh in 2024 and there are main some some reasons for that so before that let me go over around about the background of MV and for rning so this is how a transaction's life cycle so on the top you can see when the user want to send the transaction he want to send it to the Builder first then the validator then the validator will propose a block and commit it to the chain but if there is a front runner uh when the user sends the transaction to the Builder the fund Runner will see this transaction and uh he when he detects this transaction is profitable he'll replace the beneficiary to himself and then add a little bit more gas on to that so the Builder will place his transaction in front of the normal transaction so the um users transaction will be reverted so the front runner will gain profit from this so then the role of private M came they say we will keep transaction private uh and this is beneficiary for most parties first Arbitrage are fair like MV boss day one to balance the pools they find the a better swap path when and also user they don't need to suffer from um sandwiches and also the side effect of this is that hackers transactions they are protected by the pr and pool as well uh for example in the previous examples uh those phone Runners are not able to phone run with a private transaction and is f running that and we found the uh answer to this question is no not not on the Block Level let me explain that so we have seen a lot of patterns like this it's called a two-phase style attack so first uh if if a hacker want to hack something he will first deploy a assistant contract and do some preparation and finally he'll send another transaction to trigger the vulnerable function of the victim so to exploit it um all a map bot or a fundr runner needs to do is to extract all the functions of a contract uh by using the function signatures and call every function and if it happens to be the trigger function uh aont runner will be able to like font run this transaction that that has not never been sent to the Builder before and so it becomes a uh catam Mouse game between the MV Bots and hackers and there are like hackers they are they thought of some like better strategies to protect their contracts for example here we have a address verification Bas it's easy to bypass all it B need to do is to add some hints and also if it has a authentication uh like here you you have a hash of some address uh if it's compared it's compared to a fixed hash but all a bot needs to do is to change that equal sign to a not equal sign and also then hackers thought of some more sophisticated uh methods for example they hide the parameter to uh to the vulnerable function directly in the parameter in the function and we found that the goal is really to find the input that to trigger a profitable path in the contract because it's already in this contract and fuzzing is a good tool to do that so what is fuzzing it's basically generate a random input this random is not really random uh and then it execute the program observe and analyze the execution collect interesting information and if it's a profitable path we will exit otherwise will repeat using the collected information and there are different purposes for fuzzing in web 2 you might corrupting corrupting some memory in web three audio space it might be breaking some invariance and here we are really to find a um profitable path so the effects really depends on the input generation here are some heris uh functions uh or generation methods we uh want to offer you and um important thing is about theistic functions uh these are the that makes the fuzzing different and there are some pros and cons to buing for example it's fast accurate and easy to build a prototype and also for the accounts uh it can be timec consuming uh especially in some chains that have a very low block time interval and what we want to um promote is that I think we should bring more web to methodologies into web three for example we haven't seen stat analysis something like that and we're bringing fuzing also adding added some T analysis and symbolic execution into our

Automatic transcript — names and jargon may be misspelled.