# Honeypots - Hacker traps on the blockchain - Noah Jelich | Hacken

- Channel: [ETH Belgrade Community](https://streameth.org/eth-belgrade-community)
- Date: 2023-10-07
- Duration: 30:24
- Watch: https://streameth.org/watch/yt-sR3bxIIl1sg
- YouTube: https://www.youtube.com/watch?v=sR3bxIIl1sg

## Transcript

hello uh thanks for the generous introduction uh so yeah I'm Noah I'm a lead security auditor at hacken and today I will be telling you about honeypots uh hacker drops on the blockchain a very esoteric very obscure exploit uh that you will probably not encounter unless you are a hacker so uh let's start for for anyone in the audience not really familiar with you know the tech side of blockchain uh I usually have an ethereum crash course where I go over like the easy bits like you know ethereum is a blockchain a bit like Bitcoin but it's special because it's turning complete meaning it can run code and you know the general blockchain definition of uh decentralized com decentralized uh value transfer Network without a trusted entity uh I will usually introduce you to the structure of accounts in ethereum because it's sort of important to understand that everything happens through transactions and there's end user accounts uh which are defined by a private public key pair which have an address defined from the uh that's derived from the public key and the balance as well as smart contracts which have deterministically found addresses a balance but also code usually bytecode or specifically runtime byte code and Storage and end user accounts can interact with smart contracts through transactions and smart contracts can interact with other contracts or accounts through transactions which contain value and data um and of course if you want a code on ethereum you have to pick a language there are several options the most common one most popular one would be solidity which looks a bit like this and you put that really solidity to a compiler you get some byte code and using a transaction once again you put it up on the blockchain what once it is on there it runs on the evm which is touring complete registerless 256-bit virtual machine uh with a gazillion op codes uh which has of course gas costs you're all familiar with that for spam protection and computations in blocks are bounded by the gas limit also some important stuff is that the deployed code is immutable uh though non-native proxy patterns like the open Zeppelin one exist and state is mutable over multiple transactions um and of course wherever there is code there are also exploits in that code so uh since the beginning of this presentation time average of course about four hundred thousand dollars have been stolen by hackers and uh yeah I would really like some of that honestly but you probably also want some of this and you want to get a hack going and you're like okay yeah I can be a hacker so you learn all the hacking stuff right and you you scan all the contracts and you find the Target and you're like look that's a Target I could tag these guys I can even craft a perfect transaction that's going to yield me all the many millions uh and you're like okay yeah I must send this transaction and you just open your metamask wallet because you're a newbie hacker and you're like yeah send and then you're like oh no because front running Bots exist because uh you as a hacker just got uh uh because there's something called the front running bot which pretty much scans this thing called a mempool which is where all your transactions will sit for a while pretty much open to the public until some validator or whoever takes them and actually executes them and if somebody is watching the mempool and uh puts more gas than you did they can get their transaction to execute before yours so that is one way you as a hacker may lose out another way is if what you thought was a vulnerable Target was not a vulnerable Target at all if it said it was a Honeypot a fake exploitable contract the high the pain Herald here and uh that is the topic of today's presentation let's get into honeypots what are they how do they work uh so honeypots compared to you know the general hacker traps in traditional security and blockchain there tend to be a bit more elegant in ways because there tend to be pure code and you know I I like the way security exploits look in blockchain they're usually more elegant and the way they work is they make you the hacker believe that you can gain some funds by sending funds like there's a usually as a hacker you're gonna need to invest a little bit of money like you're gonna need a flash loan to to actually manipulate like uh a decks or something or you're gonna need to put some money to become a member of something to get into a state where you can actually execute a fraudulent transaction so like it's common but in reality it was specifically designed to look like it's vulnerable and really only the owner can retrieve some funds here uh so yeah that's the big idea right so here's an example here's like the most basic School level example of a Honeypot a multiplicate function uh like this so it's uh it's like just this it's a multiplicate function on a contract it's payable which means it can receive funds it's external which means it's called by pretty much anyone and it has just two lines if message dot value so however much you sent is more than equals this dot balance so however much is on this contract address message sender U the transfer will receive this dot balanceplus message.value however much was on the contract plus however much you sent uh do you guys see any problem I mean the PDF format sort of gives me away here because I cannot have the nice animations but uh this dot balance actually already includes message.value so say there was a hundred whatevers on the contract and you're like oh I want to exploit this let's send 101 and fulfill this condition and get all the monies um well you send 101 and this is the balance is already gonna include the message of the value so digital balance is now going to be 201 and this condition is just not going to get executed depending on the optimizer it may even you know be optimized out so this could be two lines of code that you just put in the code anywhere and it will just disappear when compiled uh so it's a pretty pretty cool thing uh and this is just like a little semantics issue that many people may miss out on and it's one of the first like ideas for a Honeypot an impossible conditional branch that is just going to get compiled out there's a lot more of this sort of compiled out case though uh the next one is a bit more complex don't get scared though we have two contracts with inheritance on the left we have the standard ownable you are probably familiar with vaguely how it works and nearly right we have a drone and uh let's let's take a short look at the withdrawal function uh right here so the withdrawal function it's external only owner and it does the address message sender transfer thing so it gives you all the monies right uh and it has its only owner thing that's a modifier and you can see defined on the left here uh it pretty much requires you to be the owner right and how can you become the owner well let's look at the stake function here it's payable external so you give some monies right and it has three lines message value so you send more than larger stake okay seems simple enough and then you become the owner oh that's that's pretty nice uh and the largest stake will then become your message value okay okay let's send let's send them some money you know uh and you send some money and then you try to do the withdrawal thing and nothing happens uh the transaction fails why uh well you you may have noticed there's two owner variables here there's the owner variable on the left and the ownable and there's another owner variable in the Drone and the one on the left is the one used in the modifier that's the only owner here and it is set here in the Constructor and only then so this one is set only once right now in the Constructor and uh it cannot be changed well this other owner that's being used actively here it is set here in the stake function but it is used in nothing so you're fooled by reading this quote quickly to believe that you know you can become the owner this way but really nothing nothing is going to happen because of variable shadowing so the owner variable is shadowed between the two contracts due to inheritance and actually newer research there's another really nice example of something similar with Roland coding in using you know the access control open Zeppelin library and that's a that's a really devious one so uh let's oh yeah and the example you may think okay this sort of silly who would fall for this but uh and this is about one ethereum and progressively higher losses by uh fools and you can see eventually somebody took all the winnings from this Honeypot right and the user that actually deployed a ton of these honey pots I think they earned like probably 30 40K from just deploying this like same Honeypot and catching newer generations of hackers I guess so it's a it's a pretty nice one and right now they have like 6K on their account so they're doing well they're doing well in life uh next one uh this one is sort of the most successful in my in my opinion and it's because and it's also the one that really frustrates me that can make me feel a bit sad for the ux of crypto because uh this one relies on on our trust in tools and eaterscan and in in the fact that it will provide us accurate information about what's going on on blockchain and that it is going to provide that information in a clear and readable way which it does not uh so let's look through this one quickly uh we have two key functions let's look at get gift so this is a good way to set a password by the way uh you don't want to set the password in the contract because all variables all data in the contract is really public you want to get the hash of the password so we have a get gift which takes a hash of the password as input and checks if that hash sorry which takes a password as the input and checks if that password unhashed matches the hash that has been set and then it gives you all the Monies um and we have the set pass function above which you know takes the hash and if the password has not been set and if you send some monies it is gonna allow you to set the password hash and you're reading this and you know at the beginning past has been set is false and you're looking at this and it seems the deployer the graceful God who deployed this contract just to give you some monies um accidentally already put the monies in you know planetarium or something before setting the password they must have been silly or made a mistake and you're like okay okay this looks nice I I could just set the password myself and uh get this money but that's not really how it goes and that's due to this set hidden function I just left here as a placeholder and in short eaterscan is not very good at displaying all transactions and what they actually did so we go to eater scan right and we're looking at all these transactions and we see a deployment here and then we see some attempts at setting the password and at this point during the deployment there is already some funds in there um and these guys that tried to set the password did so because they thought okay the password was not said they couldn't see a transaction setting the password but if you go to internal transactions and then enable advanced mode and then scroll down a bit you can see some internal transactions with very very unclear signatures right that uh that actually did the magic of setting the password by literally just having a contract call this contract that's it there was just a simple routed call and that was all that was needed to hide this from etherscan in a very you know effective way for 99 of the users uh so this is sort of frustrating with the ux because I I mean I I'm sure eaters can could display contract calls or like you know multi-sick calls to these things just as easily as they can end user uh calls and it's really still that hey this is still an issue and B this is an issue at all uh and I hope other transaction viewers uh transaction viewers are taking like a lesson from this and improving their ability to to actually see what's going on on the contract because I mean this is a this is a big gap uh and yeah this this one that really frustrates me so you can see like transaction viewer error ux really uh so why do these things Works uh why do these things work why do honeypots work uh because you probably haven't heard of them because they don't Target you the users and they do not really Target projects they target hackers they target people eager to make some illegal bugs uh and the reason they work is because hacking is a very very crowded Arena um hackers are always actively scanning every new contract uh to find some exploit that they could abuse or researchers to research right and many of them are running tools uh many of them are running the same tools and just Racing for gas you know they don't really have a lot of time think to analyze the code because if they take an extra three minutes somebody else could claim their reward um so some of this is going to be an abuse of a tool right like there may be a bug in a popular hacking automation tool like Tio and uh yeah you just exploit that bug and deploy gazillion honeypots catching all the hackers uh of their balance and the other reason is for like the more analog hackers the complexity of the ethereum system you gotta look through the code you gotta see if something's exploitable here you didn't really have a lot of time and uh and you get stuck on the ux uh so yeah that's that's why they work and uh how can we detect them what can we learn from them really uh and this is like the interesting part because it's a bit of a summary of the learnings about honeypots and the future of honeypots um so there's two main approaches being used uh symbolic solving which is you know the the mitral approach the honey badger approach uh in terms of tools uh where you're just trying to execute a code and find if it resolves to a certain usage pattern within it but this requires an expert and there's like a total of three in the world um and the other one is ml classification which requires a lot of data and processing power and which is based on transaction data and this one can find certain novel honeypots so it's pretty nice because of that uh uh and it can maybe even find some soft true General patterns uh and like the general detection process for this would be you get all the valid smart contracts you get all their data additionally now it's even easier with like uh Google Cloud providing literally a very easily queryable database of all the smart contract byte code because you can just you know SQL select unique and you have all the unique byte code before you needed to write your own index or something and then you symbolically analyze it and then you classify it using ml algorithms however you want and just play around with that optimization and uh what we can find out from that is uh first a ton of smart contracts are duplicates you know two million deployed smart contracts 150 000 unique byte codes right now on ethereum 600 000 unique byte codes no more than that like literally last week and of that only 50 000 are cash flow contracts and of that and that's why they are obscure like 300 honeypots right uh and that you you know that's a lot more deployed honeypots because if one works you're gonna deploy a gazillion times uh but it's it's not that many today there may be like a couple hundred more um and the honeypots uh they vary in terms of type there's a you know balance disorder thing I mentioned as an example there's actually a few of them in the wild that have been successful uh there's the solidity compiler based one so inheritance shadowing uh empty string glitter skipping which is like uh a fun trick uh type deduction which is by the way did you know solidity has a VAR keyword that's just do whatever you want with these types yeah there's a reason nobody uses it and uninitely struct which can catch people offhand even even in proper projects actually these days because uh an initialized trucks tend to uh you know they go to the first storage slot which means they can mess with your memory uh and then there's the ux stuff so hidden State updates hidden transfers and like strawman contracts where you may change where a certain library or pre-compiled points to which can sort of mess with how easy it is to figure out what's actually going on in this code so uh these types uh exist also there are some newer ones there's the role encoding trick which is hey uh you know that joke about going uh going through a like someone's code base and just replacing all the semicolons with uh Greek question marks and they look the same because like visually but there are different Unicode characters yeah imagine if we could make an exploit based on that and that's pretty much it uh with open Zeppelin Access Control in some similar looking characters and then there's an unexecuted call which was like imagine if you didn't put parentheses at the end of a function and it was just reference and you know the compiler removes it anyway uh yeah imagine if that was an exploit like I mean these These are sort of esoteric and creative not really effective but they work they work um and from these uh from these exploits what we learned was okay they're actually fairly successful like 30 percent uh success rate but they will only trap a single victim because eventually you can see that people got messed with on etherscan and uh we're we have confirmed the hypothesis about tool usage and you know we have confirmed how tight the space is how crowded the room is with in terms of hacking because they're all exploited extremely quickly a lot of newbie hackers trying to you know make some make some way uh and uh the hidden State update the ux problem is in the lead unfortunately uh they tend to uh be more popular as price Peaks come around so bull market a lot more of a rush to do everything including to hack people and to get hacked I guess um so it's pretty pretty interesting seasonality uh they're not very profitable in terms of like big exploits but you can make a living like a modest living of honeypots it's not legal though uh thanks to herdalo who's speaking here actually uh for confirming that this would be illegal to do even though I'm targeting hackers so I cannot do this sorry but it would be a modest living um and uh yeah like a gift box the one I mentioned it actually managed to get 12 ethereum and in general you will be earning like 1.7 ethereum per honey pot maybe a bit less now that they're more popular but it's it's a living and uh yeah still ux issues are the biggest uh the biggest gainers if you want to develop your own and they're fairly identifiable right now uh thanks to Honey Badger project and other ones so you can actually do these analysis yourself and recently in like the past two months there has been a lot of Headway in terms of Honey pots research uh and uh you can action now uh join in there's an open source project called smart bugs and it compiles several different tools for analysis including honey badger and it allows you to just you know analyze honeypots all you want all day long it's fairly efficient multi-threaded uh so you can actually run through the entire ethereum uh like found fond of smart contracts in search of honeypots in I would wager about two weeks on my laptop which is a lot better than it was like six months ago when when I just started messing with these things so it's it's Advanced a lot and yeah that's that's pretty much it uh if you really want to find out more there's a link tree link that has popped up several times and there's the smartbox project which is really the center of honeypots research right now where it's a sub part of that that would be it for me and I'm open to questions [Applause] is there any way that honeypots can be fully avoided uh actually uh yes so I mentioned Tio earlier an automated hacking tool and more modern hacking tools they tend to fully Fork the blockchain and simulate any transactions you're going to make and that is pretty much the most foolproof way to run these hacks but once again this can be time intense which when you're in a rush can can mean the difference between uh win and a loss hi you mentioned a devious uh rolling coding trick uh I'm intrigued yeah so in short uh you're all familiar with open Zeppelin Access Control probably which is like the basic Access Control Library uh and it it takes roles as strings and what these guys did they were from Brazil I think uh they had like two characters with uh some umloads or something I don't know weird characters uh and they just had two different roles that looked the same in terms of visually but for different Unicode and they were mixing them in like in the access control a lot to make it really confusing to actually find out what was going on and who could control what and some hacker got stuck in that and it's uh it's like the it's a really nice example I don't know I find comical like I can feel the frustration of the hacker figuring out the transaction failed and then looking at what was actually going on and realizing he got tricked by the you know Greek semicolon equivalent like I I would probably kick a kick a table at that point any other questions okay so let's say that you find an opportunity for an exploit and it's not a Honeypot you mentioned that Mev or you you can get front run right if it's a publicly executable profitable transaction why not just use something like flashbots protect yeah that is an option flashback protect is what we would recommend for any hackers uh trying to avoid being front run while uh while doing their business anyone else yes so given that we have this hype about automatization do you see like any new projects um you know like coming up on stage that can help automatically prevent you from like deploying a hackable contract as a junior solidity developer uh well I mean what we within hack and recommend and what our methodology has mutated towards and I believe we are the only ones doing this right now uh is like a very very strong Reliance on testing and I'm thinking like not just you know have a few tests happy path testing whatever I'm talking 100 test coverage and mutation testing to make sure you have covered all the test cases and this is what I would plug into any CI CD system for you know smart contracts and I think that gives you a very very good guarantee that if you may did something wrong it was because your general idea of what you want to do was wrong like your high level idea and your implementation is going to be fairly good uh and then for for other stuff I mean you know there's there's Slither there's Mitchell there's all the fuzzing tools that you can use but uh you sort of cannot be a junior when you're using those like fuzzing tools are not a thing you just go into and like yeah yeah I can totally use this they're like a thing you get into when you really want to secure a project and uh you're frustrated at how hard it is to find any other exploits and you're like at bug Bounty level not at like pre-audit level um yeah I was thinking specifically of course about chargeability because what I did I took a screenshot of code that you showed and like imported that into charge repeat and he was kind of capable of explaining me what the issue is and how how I can prevent it yeah of course uh that's for a very very popular very School example issue uh but uh recently for example there have been a few hacks due to re-entrancy wait re-entrancy but re-entracy is popular we've known about it for like five years uh how because everybody is aware of like maybe basic single contract like single function reentrancy but you need to keep in mind that you can have re-entracy between multiple functions which is harder to find an allies and more advanced with like several hacks I I think like over 100 million now Global re-entrancy where you have a complex contract system where you have re-entrances between the contract State updates where you where everything is a trusted system but you forgot to account for all the external calls to contracts within your system and you don't have a mutexment in those so like there's always a new exploit it's it's a constantly moving area and this like this year there's no good libraries two months ago I'm literally considering joining the hackathon right now and trying to write the library like there's always a new exploit there's always something on the edge nothing is absolute anything else when yeah no okay uh in that case that would be it for me it has been a pleasure talking to you guys about honeypots and uh yep see you tomorrow at the eat Belgrade panel and probably the DSi panel as well uh uh and yeah enjoy the rest of your day
