Paper 2023/1207

DeFi Auditing: Mechanisms, Effectiveness, and User Perceptions

Ding Feng, University of Macau
Rupert Hitsch, ETH Zurich
Kaihua Qin, Imperial College London
Arthur Gervais, University College London
Roger Wattenhofer, ETH Zurich
Yaxing Yao, Virginia Tech
Ye Wang, University of Macau
Abstract

Decentralized Finance (DeFi), a blockchain-based financial ecosystem, suffers from smart contract vulnerabilities that led to a loss exceeding 3.24 billion USD by April 2022. To address this, blockchain firms audit DeFi applications, a process known as DeFi auditing. Our research aims to comprehend the mechanism and efficacy of DeFi auditing. We discovered its ability to detect vulnerabilities in smart contract logic and interactivity with other DeFi entities, but also noted its limitations in communication, transparency, remedial action implementation, and in preventing certain DeFi attacks. Moreover, our interview study delved into user perceptions of DeFi auditing, unmasking gaps in awareness, usage, and trust, and offering insights to address these issues.

Metadata
Available format(s)
PDF
Category
Applications
Publication info
Preprint.
Keywords
Decentralized financeauditingblockchain
Contact author(s)
mc25944 @ um edu mo
hitsch rupert @ gmail com
kaihua qin @ imperial ac uk
a gervais @ ucl ac uk
wattenhofer @ ethz ch
yaxing @ vt edu
yewang ethz @ gmail com
History
2023-08-10: approved
2023-08-09: received
See all versions
Short URL
https://ia.cr/2023/1207
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2023/1207,
      author = {Ding Feng and Rupert Hitsch and Kaihua Qin and Arthur Gervais and Roger Wattenhofer and Yaxing Yao and Ye Wang},
      title = {DeFi Auditing: Mechanisms, Effectiveness, and User Perceptions},
      howpublished = {Cryptology ePrint Archive, Paper 2023/1207},
      year = {2023},
      note = {\url{https://eprint.iacr.org/2023/1207}},
      url = {https://eprint.iacr.org/2023/1207}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.