Phantom Events: Demystifying the Issues of Log Forgery in Blockchain

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Liu, Yixuan, Dong, Yuxin, Liu, Ye, Luo, Xiapu, Li, Yi
Formato: Preprint
Publicado: 2025
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866916620309364736
author Liu, Yixuan
Dong, Yuxin
Liu, Ye
Luo, Xiapu
Li, Yi
author_facet Liu, Yixuan
Dong, Yuxin
Liu, Ye
Luo, Xiapu
Li, Yi
contents With the rapid development of blockchain technology, transaction logs play a central role in various applications, including decentralized exchanges, wallets, cross-chain bridges, and other third-party services. However, these logs, particularly those based on smart contract events, are highly susceptible to manipulation and forgery, creating substantial security risks across the ecosystem. To address this issue, we present the first in-depth security analysis of transaction log forgery in EVM-based blockchains, a phenomenon we term Phantom Events. We systematically model five types of attacks and propose a tool designed to detect event forgery vulnerabilities in smart contracts. Our evaluation demonstrates that our approach outperforms existing tools in identifying potential phantom events. Furthermore, we have successfully identified real-world instances for all five types of attacks across multiple decentralized applications. Finally, we call on community developers to take proactive steps to address these critical security vulnerabilities.
format Preprint
id arxiv_https___arxiv_org_abs_2502_13513
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Phantom Events: Demystifying the Issues of Log Forgery in Blockchain
Liu, Yixuan
Dong, Yuxin
Liu, Ye
Luo, Xiapu
Li, Yi
Cryptography and Security
With the rapid development of blockchain technology, transaction logs play a central role in various applications, including decentralized exchanges, wallets, cross-chain bridges, and other third-party services. However, these logs, particularly those based on smart contract events, are highly susceptible to manipulation and forgery, creating substantial security risks across the ecosystem. To address this issue, we present the first in-depth security analysis of transaction log forgery in EVM-based blockchains, a phenomenon we term Phantom Events. We systematically model five types of attacks and propose a tool designed to detect event forgery vulnerabilities in smart contracts. Our evaluation demonstrates that our approach outperforms existing tools in identifying potential phantom events. Furthermore, we have successfully identified real-world instances for all five types of attacks across multiple decentralized applications. Finally, we call on community developers to take proactive steps to address these critical security vulnerabilities.
title Phantom Events: Demystifying the Issues of Log Forgery in Blockchain
topic Cryptography and Security
url https://arxiv.org/abs/2502.13513