© AdobeStock/arhendrix

Neuer Compiler härtet Smart Contracts gegen Cyberangriffe ab

Smart Contracts bilden das Fundament vieler Blockchain-Anwendungen, doch die Werkzeuge zur Unterstützung der Entwickler*innen sind bislang noch wenig ausgereift. Die paluno-Arbeitsgruppe für Systemsicherheit hat gemeinsam mit Forschenden der Ruhr-Universität Bochum, NEC Laboratories Europe und Amazon Web Services nun einen neuen Compiler vorgestellt, der die Absicherung von Smart Contracts deutlich vereinfacht.

Der von den Forschenden entwickelte Hardening Contract Compiler (HCC) setzt auf Code Property Graphen (CPG), um Schwachstellen sowie potenzielle Angriffsvektoren im Programmcode von Smart Contracts systematisch zu identifizieren. Um Angriffe effektiv abzuwehren, integriert HCC automatisch Sicherheitspatches direkt im Quellcode – ganz ohne manuellen Analyse- oder Korrekturaufwand auf Seiten der Entwickler*innen.

Besonders hervorzuheben ist die Plattform- und Sprachunabhängigkeit: HCC unterstützt alle gängigen Smart-Contract-Plattformen wie z.B. Ethereum oder Hyperledger Fabric und deren Programmiersprachen. Umfangreiche Evaluationen mit 10.000 echten Smart Contracts und weiteren Sets von unsicheren Smart Contracts aus verwandten Forschungsarbeiten zeigen: HCC hilft Software-Entwickler*innen in der Praxis, schützt zuverlässiger als bisherige Ansätze und verhindert alle überprüften Angriffe. Die Funktionalität der Smart Contracts wird durch die Sicherheitsmaßnahmen nicht beeinträchtigt.

Jens-Rene Giesen aus der Arbeitsgruppe von Prof. Dr. Lucas Davi hat die Arbeit „HCC: A Language-Independent Hardening Contract Compiler for Smart Contracts “ am 23. Juni 2025 auf der 23rd International Conference on Applied Cryptography and Network Security (ACNS 2025) in München vorgestellt. 

Das Paper ist hier verfügbar: https://arxiv.org/abs/2203.00364 

Der Code kann auf Github eingesehen werden: https://github.com/uni-due-syssec/hcc 

Veröffentlichung

Giesen, Jens-Rene; Andreina, Sebastien; Rodler, Michael; Karame, Ghassan; Davi, Lucas: HCC: A Language-Independent Hardening Contract Compiler for Smart Contracts. In: Proc. of 23rd International Conference on Applied Cryptography and Network Security (ACNS). Springer, Munich, Germany 2025 .

Abstract

Developing secure smart contracts remains a challenging task. Existing approaches are either impractical or leave the burden to developers for fixing bugs. In this paper, we propose the first practical smart contract compiler, called HCC, which automatically inserts security hardening checks at the source-code level based on a novel and language-independent code property graph (CPG) notation. The high expressiveness of our developed CPG allows us to mitigate all of the most common smart contract vulnerabilities, namely reentrancy, integer bugs, suicidal smart contracts, improper use of tx.origin, untrusted delegate-calls, and unchecked low-level call bugs. Our large-scale evaluation on 10k real-world contracts and several sets of vulnerable contracts from related work demonstrates that HCC is highly practical, outperforms state-of-the-art contract hardening techniques, and effectively prevents all verified attack transactions without hampering functional correctness.