Understanding and Characterizing Obfuscated Funds Transfers in Ethereum Smart Contracts

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Sheng, Zhang, Quang, Tan Kia, Wang, Shen, Duan, Shengchen, Li, Kai, Duan, Yue
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866908784039821312
author Sheng, Zhang
Quang, Tan Kia
Wang, Shen
Duan, Shengchen
Li, Kai
Duan, Yue
author_facet Sheng, Zhang
Quang, Tan Kia
Wang, Shen
Duan, Shengchen
Li, Kai
Duan, Yue
contents Scam contracts on Ethereum have rapidly evolved alongside the rise of DeFi and NFT ecosystems, utilizing increasingly complex code obfuscation techniques to avoid early detection. This paper systematically investigates how obfuscation amplifies the financial risks of fraudulent contracts and undermines existing auditing tools. We propose a transfer-centric obfuscation taxonomy, distilling seven key features, and introduce ObfProbe, a framework that performs bytecode-level smart contract analysis to uncover obfuscation techniques and quantify obfuscation complexity via Z-score ranking. In a large-scale study of 1.03 million Ethereum contracts, we isolate over 3 000 highly obfuscated contracts and identify two scam archetypes, three high-risk contract categories, and MEV bots that employ a variety of obfuscation maneuvers such as inline assembly, dead code insertion, and deep function splitting. We further show that obfuscation substantially increases both the scale of financial damage and the time until detection. Finally, we evaluate SourceP, a state-of-the-art Ponzi detection tool, on obfuscated versus non-obfuscated samples and observe its accuracy drop from approximately 80 percent to approximately 12 percent in real-world scenarios. These findings highlight the urgent need for enhanced anti-obfuscation analysis techniques and broader community collaboration to stem the proliferation of scam contracts in the expanding DeFi ecosystem.
format Preprint
id arxiv_https___arxiv_org_abs_2505_11320
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Understanding and Characterizing Obfuscated Funds Transfers in Ethereum Smart Contracts
Sheng, Zhang
Quang, Tan Kia
Wang, Shen
Duan, Shengchen
Li, Kai
Duan, Yue
Cryptography and Security
Scam contracts on Ethereum have rapidly evolved alongside the rise of DeFi and NFT ecosystems, utilizing increasingly complex code obfuscation techniques to avoid early detection. This paper systematically investigates how obfuscation amplifies the financial risks of fraudulent contracts and undermines existing auditing tools. We propose a transfer-centric obfuscation taxonomy, distilling seven key features, and introduce ObfProbe, a framework that performs bytecode-level smart contract analysis to uncover obfuscation techniques and quantify obfuscation complexity via Z-score ranking. In a large-scale study of 1.03 million Ethereum contracts, we isolate over 3 000 highly obfuscated contracts and identify two scam archetypes, three high-risk contract categories, and MEV bots that employ a variety of obfuscation maneuvers such as inline assembly, dead code insertion, and deep function splitting. We further show that obfuscation substantially increases both the scale of financial damage and the time until detection. Finally, we evaluate SourceP, a state-of-the-art Ponzi detection tool, on obfuscated versus non-obfuscated samples and observe its accuracy drop from approximately 80 percent to approximately 12 percent in real-world scenarios. These findings highlight the urgent need for enhanced anti-obfuscation analysis techniques and broader community collaboration to stem the proliferation of scam contracts in the expanding DeFi ecosystem.
title Understanding and Characterizing Obfuscated Funds Transfers in Ethereum Smart Contracts
topic Cryptography and Security
url https://arxiv.org/abs/2505.11320