Decentralized Finance Under Attack
File(s)
Author(s)
Zhou, Liyi
Type
Thesis
Abstract
Since 2019, Decentralized Finance (DeFi) has emerged as a technology that leverages distributed
systems, particularly blockchains, to facilitate financial transactions without centralized interme-
diaries. While DeFi offers the potential for increased transparency, accessibility, and innovation
in financial services, it also introduces novel security challenges that must be addressed to ensure
the safety and integrity of these systems.
Our contributions, conducted primarily from 2019 through 2023, were among the earliest sys-
tematic explorations of emerging DeFi security risks through investigating real-world incidents,
academic research, and state-of-the-art tools. Specifically, we identify new security challenges
arising from three fundamental features of DeFi: (i) transparency; (ii) composability; and (iii)
predictable execution outcome (due to deterministic code).
This thesis begins by leveraging system transparency and predictable execution to provide a for-
mal analysis of sandwich attacks. Our analysis demonstrates their effectiveness on real-world DeFi
protocols while highlighting the need for countermeasures. Building on protocol composability,
we develop tools for automatically composing DeFi protocols to generate profitable trading strate-
gies, illustrating both the potential for automated revenue generation and raising concerns about
impacts on blockchain consensus. Through a systematic review of DeFi incidents, we identify
promising approaches for threat identification and neutralization, including methods for tracing
attack funds and exploiting “rescue time frames” to protect vulnerable protocols. Our analysis
further reveals significant open challenges, particularly the absence of robust detection mecha-
nisms and the inherent difficulty of developing protocol-level defenses, problems fundamentally
rooted in the combinatorial complexity of DeFi composability.
These findings have influenced the evolution of DeFi security practices and continue to shape the
field’s development. While DeFi has matured considerably since our initial research, the fun-
damental security challenges stemming from system transparency, protocol composability, and
deterministic execution remain intrinsic to the technology. Our work demonstrates that address-
ing these challenges requires ongoing innovation in security measures and highlights the critical
importance of continued research collaboration between academia and industry to ensure DeFi’s
sustainable growth and long-term viability.
systems, particularly blockchains, to facilitate financial transactions without centralized interme-
diaries. While DeFi offers the potential for increased transparency, accessibility, and innovation
in financial services, it also introduces novel security challenges that must be addressed to ensure
the safety and integrity of these systems.
Our contributions, conducted primarily from 2019 through 2023, were among the earliest sys-
tematic explorations of emerging DeFi security risks through investigating real-world incidents,
academic research, and state-of-the-art tools. Specifically, we identify new security challenges
arising from three fundamental features of DeFi: (i) transparency; (ii) composability; and (iii)
predictable execution outcome (due to deterministic code).
This thesis begins by leveraging system transparency and predictable execution to provide a for-
mal analysis of sandwich attacks. Our analysis demonstrates their effectiveness on real-world DeFi
protocols while highlighting the need for countermeasures. Building on protocol composability,
we develop tools for automatically composing DeFi protocols to generate profitable trading strate-
gies, illustrating both the potential for automated revenue generation and raising concerns about
impacts on blockchain consensus. Through a systematic review of DeFi incidents, we identify
promising approaches for threat identification and neutralization, including methods for tracing
attack funds and exploiting “rescue time frames” to protect vulnerable protocols. Our analysis
further reveals significant open challenges, particularly the absence of robust detection mecha-
nisms and the inherent difficulty of developing protocol-level defenses, problems fundamentally
rooted in the combinatorial complexity of DeFi composability.
These findings have influenced the evolution of DeFi security practices and continue to shape the
field’s development. While DeFi has matured considerably since our initial research, the fun-
damental security challenges stemming from system transparency, protocol composability, and
deterministic execution remain intrinsic to the technology. Our work demonstrates that address-
ing these challenges requires ongoing innovation in security measures and highlights the critical
importance of continued research collaboration between academia and industry to ensure DeFi’s
sustainable growth and long-term viability.
Version
Open Access
Date Issued
2025-01-18
Date Awarded
01/02/2025
Citation
2025
Advisor
Cully, Antoine
Publisher Department
Department of Computing
Publisher Institution
Imperial College London
Qualification Level
Doctoral
Qualification Name
Doctor of Philosophy (PhD)
