Connect with us

Crypto

Researchers uncover vulnerabilities leading to predatory trading in popular Ethereum cryptocurrency rollups

Published

on

Researchers uncover vulnerabilities leading to predatory trading in popular Ethereum cryptocurrency rollups
Ben Weintraub and his co-authors conducted a large-scale analysis of exploitative trading activities on Ethereum and across popular rollups. Credit: Matthew Modoono/Northeastern University

Ethereum, a decentralized online platform that allows users to conduct financial transactions in Ether cryptocurrency, prides itself on the system’s high security.

But new findings from Northeastern University’s computer scientists and researchers at ETH Zurich, a public research university in Switzerland, show that it might not be so bulletproof, and its users might be susceptible to some market participants’ predatory practices.

“There are direct monetary incentives,” says Ben Weintraub, a Northeastern doctoral student in the Khoury College of Computer Sciences. “So in my view, it’s better if researchers find and publicize it first before people mistakenly lose money.”

Weintraub presented the paper on the findings at the Association for Computing Machinery’s annual Conference on Computer and Communications Security (ACM CCS 2024) held Oct. 14–18 in Salt Lake City. The study is available on the arXiv preprint server.

Advertisement

He and his co-authors conducted a large-scale analysis of exploitative trading activities on Ethereum itself and across so-called rollups, or off-the-platform services that allow faster processing of higher volumes of transactions.

The researchers found evidence that certain actors can manipulate the market on rollups, which was previously thought to be impossible.

“It was known to be possible on regular Ethereum, but it was thought to be impossible on rollups and we showed that it is not impossible,” Weintraub says.

The paper presents three novel types of attacks in which predatory traders could have made about $2 million in profits in the last three years by manipulating transactions within Ethereum trading networks.

Advertisement

Ethereum is a network of independent computers across the world that follows the Ethereum protocol—a set of rules on how the computers in the global network can interact with each other. It uses blockchain technology, pioneered by Bitcoin.

A blockchain is a database of transactions that is shared across computers in a network. Once a new block, or a new set of transactions, is added to the blockchain, that data can no longer be removed by anybody, primarily due to cryptographic techniques that highlight any attempts at tampering.

Anyone can create an Ethereum account from anywhere, at any time. No central authority such as a government or a company has control over Ethereum, which means no individual can change the rules or restrict users’ access. Any Ethereum protocol changes require approval from more than half of the network.

Unlike Bitcoin, which is solely a payment system with a name-sake cryptocurrency, Ethereum allows users to build applications, communities and organizations on its platform.

The Ethereum network, however, has a scalability problem—as the number of people using it has grown, the blockchain has reached certain throughput limitations that further inflated the costs for conducting transactions on the platform.

Advertisement

One solution are the rollups, such as Arbitrum, Optimism and zkSync—which were analyzed by Weintraub—that aim to improve Ethereum’s speed by taking batches of transactions and calculations off Ethereum. This reduced the processing cost of a transaction to roughly 1 cent, Weintraub says.

Some actors make profits trading cryptocurrencies by trying to achieve maximal extractable value, he says, by manipulating the order of transactions that are pending inclusion on the blockchain. The research provides exclusive insights into the volume of maximal extractable value transactions on rollups, costs associated with them, profits made by such exploitative traders, competition between them and response time to such activities across Ethereum and the rollups.

Some methods that malicious actors use are common to financial markets, like arbitrage, when a user buys something on one exchange and quickly sells it for profit on another exchange.

“It’s generally thought to be a good thing because it keeps different exchanges balanced in terms of price,” Weintraub says. “But there are also types [of maximal extractable value] that are not good. One that’s fairly well-known in research is called sandwiching.”

In sandwiching, when a speculator sees someone is about to buy an asset, they buy it first, driving up the price. The speculator then quickly sells it at the higher price.

Advertisement

Sandwiching is considered a “bad,” manipulative trading strategy affecting the price that other traders get. On Ethereum, block producers—people or groups who get paid when their hardware is randomly selected to verify a block’s transactions—can try to maximize the amount of profit they make by manipulating how transactions are ordered or included in a block before it is added to the blockchain.

“The reason we call this an attack is because it is purely damaging to that victim, who now has to pay a little bit more for their transaction,” Weintraub says. “The system broadly does not benefit at all. There’s just the one who profits—the ‘sandwicher.’”

While the researchers didn’t find traditional sandwich attacks on popular rollups, they identified three potential strategies for them when transactions move between Ethereum and rollups with a time delay.

“This just came from analyzing the protocol and looking at the exact flow of transactions—when they get sent, when the rollup seems to respond to them or when they end up on the blockchain,” Weintraub says.

Advertisement

“We tested our attacks on [Ethereum’s] test-net, a network of ‘fake’ money that is used by developers to test their applications,” he says. “And, essentially, we stole all of the money from only ourselves.”

Weintraub is currently in contact with major rollups’ developers to see what can be done about the possibility of the attacks. Two types of these novel attacks can be prevented, Weintraub says, while it is unclear how to protect users from the third type.

“Our view is that it’s better to just get this information out there so people, at least, are aware of the risks,” he says.

More information:
Christof Ferreira Torres et al, Rolling in the Shadows: Analyzing the Extraction of MEV Across Layer-2 Rollups, arXiv (2024). DOI: 10.48550/arxiv.2405.00138

Journal information:
arXiv
Advertisement

Provided by
Northeastern University

This story is republished courtesy of Northeastern Global News news.northeastern.edu.

Advertisement

Citation:
Researchers uncover vulnerabilities leading to predatory trading in popular Ethereum cryptocurrency rollups (2024, November 11)
retrieved 11 November 2024
from https://techxplore.com/news/2024-11-uncover-vulnerabilities-predatory-popular-ethereum.html

This document is subject to copyright. Apart from any fair dealing for the purpose of private study or research, no
part may be reproduced without the written permission. The content is provided for information purposes only.

Advertisement

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Crypto

Cryptocurrency Company Tether Bids For Italian Soccer Club Juventus

Published

on

Cryptocurrency Company Tether Bids For Italian Soccer Club Juventus
Stablecoin issuer Tether said Friday it has submitted an all-cash offer to buy Italian soccer juggernaut Juventus from the Agnelli family, a novel bid by a cryptocurrency company to acquire a blue-chip global soccer club from one of Europe’s most storied dynasties.

Tether is the largest stablecoin issuer with $186 billion of its USDT tokens in circulation. The company previously took an

Continue Reading

Crypto

Gemini Titan Enters US Prediction Markets With Yes-or-No Event Contracts

Published

on

Gemini Titan Enters US Prediction Markets With Yes-or-No Event Contracts
Gemini Titan now holds a U.S. license to offer prediction markets, setting up a fierce push for trader liquidity as the platform challenges rivals, draws in new market flow, and builds toward a broader lineup of future derivatives products.
Continue Reading

Crypto

Crypto mogul Do Kwon sentenced to 15 years in prison over $40B ‘epic fraud’

Published

on

Crypto mogul Do Kwon sentenced to 15 years in prison over B ‘epic fraud’

Do Kwon, the South Korean cryptocurrency entrepreneur behind two digital currencies that lost an estimated $40 billion in 2022, was sentenced on Thursday to 15 years in prison for for what a judge called an “epic fraud.”

U.S. District Judge Paul A. Engelmayer, who handed down the sentence, sharply rebuked Kwon for repeatedly lying to everyday investors who trusted him with their life savings.

“This was a fraud on an epic, generational scale. In the history of federal prosecutions, there are few frauds that have caused as much harm as you have, Mr. Kwon,” Engelmayer said during a hearing in Manhattan federal court.

Crypto Mogul Do Kwon, shown in 2023, was sentenced in New York federal court on Thursday to 15 years in prison for fraud and conspiracy. REUTERS

Kwon, 34, who co-founded Singapore-based Terraform Labs and developed the TerraUSD and Luna currencies, previously pleaded guilty and admitted to misleading investors about a coin that was supposed to maintain a steady price during periods of crypto market volatility.

He is one of several cryptocurrency moguls to face federal charges after a slump in digital token prices in 2022 prompted the collapse of a number of companies.

Advertisement

Dressed in yellow prison garb, Kwon addressed the court and apologized to his victims, including the hundreds who submitted letters to the court describing the harm they had suffered.

“All of their stories were harrowing and reminded me again of the great losses that I’ve caused. I want to tell these victims that I am sorry,” Kwon said.

Ayyildiz Attila, one of the hundreds of victims who submitted letters to the court, said he lost between $400,000 and $500,000 in the collapse.

Kwon in custody in Montenegro in 2024. AP

“My savings, my future, and the results of years of sacrifice disappeared. I struggled to keep up with payments and responsibilities, and everything I had worked forwas erased,” Attila said.

Kwon’s lawyer Sean Hecker said in an email after the sentencing that Kwon spoke from the heart, expressed genuine remorse and will continue his efforts to make amends.

Advertisement

US Attorney Jay Clayton in Manhattan said in a statement following the hearing that Kwon devised elaborate schemes to inflate the value of his cryptocurrencies and fled accountability when his crimes caught up to him.

Prosecutors had asked for a sentence of at least 12 years in prison, saying the crash of Kwon’s Terra cryptocurrency caused billions of dollars in losses and triggered a cascade of crises in the crypto market.

Kwon’s lawyers had asked that he be sentenced to no more than five years so he can return to South Korea to face criminal charges.

Kwon was accused of misleading investors in 2021 about TerraUSD, a so-called stablecoin designed to maintain a value of $1. REUTERS

Prosecutors charged Kwon in January with nine criminal counts for securities fraud, wire fraud, commodities fraud and money laundering conspiracy.

Kwon was accused of misleading investors in 2021 about TerraUSD, a so-called stablecoin designed to maintain a value of $1. Prosecutors alleged that when TerraUSD slipped below its $1 peg in May 2021, Kwon told investors a computer algorithm known as “Terra Protocol” had restored the coin’s value.

Advertisement

Instead, Kwon arranged for a high-frequency trading firm to secretly buy millions of dollars of the token to artificially prop up its price, according to charging documents.

Kwon pleaded guilty in August to two counts, conspiracy to defraud and wire fraud, and apologized in court for his conduct.

“I made false and misleading statements about why it regained its peg by failing to disclose a trading firm’s role in restoring that peg,” Kwon said at the time. “What I did was wrong.”

Kwon agreed in 2024 to pay $80 million as a civil fine and be banned from crypto transactions as part of a $4.55 billion settlement he and Terraform reached with the Securities and Exchange Commission.

He also faces charges in South Korea. As part of his plea deal, prosecutors will not oppose Kwon’s potential application to be transferred abroad after serving half his US sentence.

Advertisement
Continue Reading
Advertisement

Trending