How we can front run crypto exploits before they happen - Evgeny Marchenko | Pessimistic Security
ETH Belgrade Community·Sat, Oct 7, 2023, 12:00 AM
Transcript
foreign good morning everyone thank you for coming I know it's like the first talk on the third day so it requires some strength and endurance so yeah uh my name is evgeny and I will tell you how to actually how to identify predict and prevent cryptic exploits that are happening every day so yeah I've joined Security in web 3 like six years ago and I was mostly doing audits all this time but I also participated in security tool development and some other fun stuff and three years ago we formed pessimistic it's a smart contract audition company mostly and we also do some other stuff for example we do research mainly on how to integrate with popular protocols and do it safely and securely and we also work on security tools and Slytherin and supporter are like a couple name couple projects to name okay and because I work in this field I know pretty well that the problem won't go away for example the last year about 4 billion dollars was stolen and like the number of hacks has grown rapidly so it's obvious that audits won't be enough because we cannot scale at the same rate due to manual mention of the work and deal to lack of talent in the field yeah so we need something scalable something we can apply to every contract on every chain and let's look at web 2 for inspiration there we have lots of different tools and like all these shiny pieces like there and luckily there are enough people who know what it means and how to utilize it so companies can secure their products and that's something we lack here in web3 and actually we don't have much right now and that's definitely not enough and for any protocol out there like you can do lots of stuff to help your security security and on this slide I just showing something you could do before the deployment well there are no money at risk and everything is somewhat simpler for you so yeah you can start with having documentation it's very good to understand what you're actually building and to be able to communicate it to your team and maybe other guys around you for example the Auditors they really appreciate this sort of stuff and being able to check your code and see if this particular change breaks anything is also great but like this steps they require your like attention and effort and they don't scale well however as static code analysis is sort of doing pretty well right now and you could use it to to improve security of your code base same comes with spasm it's becoming more and more like available and easy to utilize right now so please use it it will help you and improve your testing skill basically formal verifications is always always there around you but it's like I believe it's not here yet but I hope it will at some moment it will become available to lots of protocols yeah and after deployment the fun part starts so presumably you have some funds at risk so it's I'm very important to continue working on your security and here are some steps essentially like most of them include and require some effort from humans and usually experts so they don't scale either however insurance I expected in like a couple years it will become a norm and it should scale pretty well and More in turn lots of monitoring for all protocols so yeah recently we have several teams that started working on head prevention tools and these projects and in different stages of development some of them are already like sort of in production and you might have heard about them maybe you have tried some of them but yeah the good question is why now or maybe why you can even predict and prevent the heck so my opinion is that recently we finally have enough hex to see some patterns there and try to detect them using this knowledge it was it is something that wasn't available like three years ago two years ago and it's sort of becoming enough right now and the research shows that most hacks happen in several steps common phases are finding preparation actual hack the exploit and money laundering and if we can detect the whole like attack earlier steps of this sequence and intervene then we can save someone's money ideally the heck doesn't happen at all but if we can for example find The Hacker and prevent money laundering and return the funds that's good enough for me and we can look at Euler hack which happened recently so the hacker first used mixer and withdraw some ether to a fresh account and used this method to deploy a smart contract the attack and smart contract and only several minutes later they actually executed the hack and our tool spotter with this actually already deployed for ethereum maintenance and we are testing it and it it detected this hack and it gave us like two minutes for potential reaction unfortunately like we could not do anything besides maybe like posting to Twitter but that's not really a solution here so but we can like theorize and think about how this this hack could be prevented if I don't know maybe the team they could have automated solution prepared for example to pose the whole protocol or maybe only to partially you know post withdrawals limit withdrawal amount for example this will be enough for the attack to fail or maybe liquidity providers could just withdraw their assets and again their money will be safe and like in some cases it will break the attack all as well and there are like slightly more different options we have here basically to delay to prevent the attack maybe to mitigate the damage and like the whole combination of those actions should work and prevent hex but the difficult question is how do we even know that the hack is coming because like you cannot react after all the money are gone so um and the speed is really important because you may be 100 not sure that the heck has just happened but you're already late so we need something fast and static analysis is really good with this because it allows you to get some information about the incoming attack in zero seconds so we have really rely on bytecode analysis here we try to extract some information about the smart contract what it what it can potentially do also we collect some statistical data and see look for up code patterns that are specific to attacks and that's a good starting point next we can enhance these results with Dynamic analysis ideally we'd like to see the exploit transaction before it like this broadcasted with an Ideal World so we can simulate it analyze the traces and its side effects and confirm that it is an attack against particular protocol let's say earlier obviously it's not a thing hackers don't share their ideas and exploits before the actual attack happens but we can for example fuzz any context we based on static code analysis and it will give us insights about how the contract behaves and then we combine this data and feed it into machine learning model uh it's not something immensely complex because we don't have enough data frankly so there are enough attacks to start doing this but not enough to build and you know AI or deep learning on whatever Blackmagic data science might be there we might come there in several years but today we have to stick to like simpler versions and more robust models and but to be honest they work pretty well and then we can enrich our data with blockchain like data that is available right now for example there are many companies that look and monitor illegal and suspicious activity on chain so with their help identifying hex becomes quite simple because hackers they are not stupid they try to avoid kyc and other stuff and usually these systems detect like their sources of money for example pretty good so mixers stolen funds whatever okay now we're on into problem because that's a video I wanted to show you but I cannot so I'll have to improvise here um so as I mentioned earlier spotter is already in testing actually we have built an MVP and because we focus on the speed of this solution and also on easiness of onboarding otherwise people people just don't use tools so all the administrative functions you need to set up a monitoring for your system you can perform them via telegram bot and essentially you just take address of your contract or maybe multiple addresses and with a one line command add them to support via telegram bot it will take a couple seconds to analyze the analyze your contracts and create a custom detector for them and after this [Music] so the detection for your contracts is sort of enabled and you will receive notifications if Sporter detects anything suspicious that tries to communicate to your smart contract and like we've run a bunch of tests and like if you deploy something that interacts with you and seems suspicious like I don't know maybe fans come from wrong place maybe it utilizes flash loans it's probably some complex money lag stuff there so spotted detects on this malicious activity with high risk and they will inform it will inform you immediately and the analysis takes like usually two to five seconds depending on the bytecode size and because Porter looks at the mempool actually 90 percent of smart contracts we finish analyzing it before the smart contracts is even deployed so it works pretty fast and gives you some time to react uh yeah that should be a video sorry for this as I said the MVP is already available and there are several teams that are testing it now we'd love you to join this community and give us feedback on your suggestions we are open to everything and we want to build and improve so all the inputs are very welcome besides for individuals we plan to release adapt version of supporter so you can protect your assets in various protocols because basically we withdraw money to your back to your account if we see any potential risks for this protocol yeah so thank you for listening you can contact me like with a bunch of like methods telegram is the best one I'm the most responsive there or you can just subscribe to our Twitter and look for updates or go to the website and sign up for the attention program there and thank you for your attention I know it's like the first talk of the day so I'm glad you came here and I'm glad to ask you or to answer your questions [Applause] yeah thank you it's yeah very interesting um I have a question so actually you are not front running particular attack so you're training trying to detect malicious smart contract that can actually execute this attack right yeah spotter focus on detection right now like um from trying and per se is not like a solution here because if you react to the heck that is already like running you're trying to work from behind and it's really difficult and won't be like reliable so if we solve the detection part well enough you will have a short but like long enough window of opportunity for any automated reaction you want and you want to build sort of front running will be just like send it in transactions with probably high fees but it's like not a race you're ahead of the hacker you just shouldn't be sloppy there and sporty provides enough time for automated interaction obviously you cannot like assemble your team go to multi-seek maybe create a dial proposal yeah but you can expect like 15 seconds at least and for many attacks it's more like a couple minutes and in rare cases it might be ours which is quite strange to me yeah but what's like direct action after you detected something like wrong I I don't know deployed so you don't likely have a lot of time to analyze this code and like to understand the attack what's happening next uh so with like our approach he will just set up everything via telegram bot and then subscribe to our API and websocket and it will receive sort of alert if we detect anything and like we assume that the simplest solution here is just to use open Zeppelin Defender for actually sending a transaction but in this case you should be prepared because like if your uni soap you don't have any pause or whatever so it requires some steps from contract smart contact development team to adapt for these Solutions foreign I have two questions uh how to do identify the victim protocol and how did you handle the false positives you mean you need the contract to take some actions so identifying the victim a potential victim that's pretty good question uh essentially we can detect Integrations between contracts for example like the simplest example would be just an address hardcoded within the smart contract or within its storage that's a pretty damn good like cue here clue uh and other stuff and yeah for example one contract includes historical and other implements this function this signature is pretty rare so you don't have lots of collisions you can't like rely on balance off and transfer from because they are very popular but some functions are rare and so you can use this as indicator and ideally you've confirmed this Dynamic analysis so some attacks they're just like single function something like start without arguments and you can get find this function with static analysis and confirm with Dynamic analysis so Dynamic analysis also helps with false positives because it gives you strong confirmation of what's going on within this contract otherwise like you have to balance you know like false positives versus false negatives and for example if you're a new protocol like any integration with you is probably an attack and you if you're something like Ave um then you should be very strict because you don't want to pause like unnecessarily but on the other side uh like if you're a large protocol you have enough resources to make Intelligent Decisions based on invaluable information maybe for example I don't know limit withdrawals to five percent of the tvl and it might be enough to break the attack thank you for your efforts of Defending up three actually the question um is about how generic can be uh this approach because say the contract just executed as it is so it cannot be hacked because it just bytecode it executes so the conflict itself just a claim what should be done right so so it's it's like correct in all cases it cannot be incorrect because it's just deployed yes and if so then like how can you differentiate hack versus not hack say in generic way of course I can write some invariants that must be preserved for my smart contract but how that will be different from contract itself because in variance is the contract itself right so it must be the same so it comes back to the question like what is the hack and can it be generalized like can you find the hacks uh without like contacting the protocol Developers for example mm-hmm uh yeah there are like multiple classes of attacks and with different behavior for example some economical attacks they're pretty slow usually and may take minutes or days and slowly drain funds and like our solution doesn't work against this kind of things and because we focus on these large sort of single transaction events which just drain your protocol completely um yeah and for these my category the general description is something for example like a transaction that eventually withdraw like most of tvl from the smart contract and like the cash flow of this transaction like it's one-sided so it's not like a person is burning LP tokens and getting underlying tokens it's more like do some money Lego magic and then receive everything um there's a small like for that cannot be like embedded in the contract itself like why the contract cannot defend itself by invariance like internally because you're trying to to look over smart contract like some umbrella and supervising it and it's like another smart contract over the smart content looks like the contract over the contract like you're like rules that you apply to this like I'm talking about sort of Unchained protection built into the protocol itself okay yeah for some reason I haven't seen it once in six years of doing Audis I've checked like and my team checked hundreds of protocols and I believe it's mostly because it's sort of ineffective and very gas and efficient and currently the narrative wasn't just going this way so and it also requires extra code which delays your release schedule and creates additional attack surface what if you did this wrong yeah and if you didn't account for some edge cases like reasonable edge cases you'll just break user experience at best and Integrations at first for example I don't know you prohibit withdrawals larger than thirty percent of your tvl and then some strategy comes there deploys puts lots of money into your contract and then it's stuck so I don't know people don't do it that's a little shortest answer okay thank you um hi just one more of a simple question do you have any idea what the business model is going to be well yeah that's great question uh So currently we're testing lots of different hypothesis the main we have in mind is just a subscription for the protocols and like b2c solution we mentioned is actually more like B2B to C because of the like um incentives that are there um so yeah that's the main case you can figure out some different stuff for example bug bound sort of bug Bounty looks good here so the team or an individual only pays if we prevent the hack and we can prove that there was a hack oh fun stuff you could try to short the protocol but if you know that it is going to be hacked with sort of did research on this and like actually doesn't work because you cannot short no name protocols and they are the ones that um the most probably to be hacked but it's like sort of combination of all different various methods do we have any more questions okay great thank you okay thank you very much for your attention [Applause]
Automatic transcript — names and jargon may be misspelled.