Skip to main content
QUICK REVIEW

[Paper Review] A Survey on the Security of Blockchain Systems

Xiaoqi Li, Peng Jiang|arXiv (Cornell University)|Feb 20, 2018
Blockchain Technology Applications and Security32 references78 citations
TL;DR

This paper provides a systematic survey of security risks, real attacks, and security enhancement techniques across popular blockchain systems from 2009 to May 2017."

ABSTRACT

Since its inception, the blockchain technology has shown promising application prospects. From the initial cryptocurrency to the current smart contract, blockchain has been applied to many fields. Although there are some studies on the security and privacy issues of blockchain, there lacks a systematic examination on the security of blockchain systems. In this paper, we conduct a systematic study on the security threats to blockchain and survey the corresponding real attacks by examining popular blockchain systems. We also review the security enhancement solutions for blockchain, which could be used in the development of various blockchain systems, and suggest some future directions to stir research efforts into this area.

Motivation & Objective

  • Survey the security threats facing blockchain systems (1.0 and 2.0).
  • Survey real-world attacks on popular blockchain platforms and the vulnerabilities exploited.
  • Review practical security enhancements and directions for future research.

Proposed method

  • Classify blockchain security risks into nine categories spanning blockchain operation and smart contract vulnerabilities.
  • Analyze real attacks and case studies to map incidents to specific vulnerabilities.
  • Summarize proposed security improvements and tools from academic literature.

Experimental results

Research questions

  • RQ1What are the major security risks facing blockchain 1.0 and 2.0 systems and their root causes?
  • RQ2What real-world attacks have occurred on popular blockchain systems, and which vulnerabilities did they exploit?
  • RQ3What security enhancements have been proposed to mitigate blockchain risks, and what future directions are suggested?

Key findings

  • Identification of nine risk categories covering consensus, private key security, criminal activity, double spending, privacy leakage, smart contract vulnerabilities, under-optimized contracts, and under-priced operations.
  • Documented attacks and issues including 51% vulnerabilities, private key recovery risks, double spending, and DoS/DoS-like issues through gas mispricing.
  • Evidence of security weaknesses in smart contracts, such as reentrancy and transaction-ordering dependencies, and the need for improved verification tools (e.g., Oyente) and gas optimization techniques.
  • Highlight of real-world cases like ransomware and underground markets using Bitcoin, and analysis of selfish mining as an attack vector.
  • Discussion of vulnerabilities unique to smart contracts (blockchain 2.0) such as criminal smart contracts and immutable bugs.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.