A Systematic Review of Security Innovations in Decentralized Finance (DeFi) Using Blockchain Technology

Chnar Mohammed Kareem

Abstract


Decentralized Finance (DeFi) represents the new generation of blockchain financial services by developing an open-access financial model without banking or lending institution intermediaries. However, DeFi's open feature threatens its security, making it vulnerable and a target for different attack types. In this systematic review, we present the security of DeFi by selecting fifteen studies from 2020 to 2024 to determine and display the security solutions' effectiveness in identifying the attacks, focusing on various DeFi components such as smart contracts, DEX, AMM, governance, AMM-based DEX, and smart contracts with (DEX, Oracle); detecting different kinds of attacks (e.g., price manipulation, Oracle manipulation, flash loan) using detection tools (e.g., DeFort, CRPWarner, FORAY); we find out that 40% of the selected studies focus on Oracle manipulation attack, 33.33% for price manipulation and flash loan attacks separately, followed by 13.33% for (MEV, rug pull, front-running, Token Leakage, and deep logical bugs), 6.67% for (EEV, reentrancy, sandwich, access control, and state derailment defects). We compare the studies based on the attack type that they detected using four state-of-the-art types of research, such as DeFiScope, FlashSyn, SecPLF, and DeFiGuard; this indicates the concentration of the trend studies is on accuracy and combining AI in DeFi security, or aggregating the existing tools with it, giving an overview of DeFi components' security, underlining the gaps in the attack types that future research can address to build more robust, trustworthy, and secure DeFi systems.


Full Text:

PDF

References


F. Schär, “Decentralized finance: on blockchain-and smart contract-based financial markets,” Federal Reserve Bank of St. Louis Review, vol. 103, no. 2, pp. 153–174, 2021, doi: 10.20955/r.103.153-74.

V. Buterin, “A NEXT GENERATION SMART CONTRACT & DECENTRALIZED APPLICATION PLATFORM.”

Z. Li, B. Xiao, S. Guo, and Y. Yang, “Securing Deployed Smart Contracts and DeFi With Distributed TEE Cluster,” IEEE Transactions on Parallel and Distributed Systems, vol. 34, no. 3, pp. 828–842, Mar. 2023, doi: 10.1109/TPDS.2022.3232548.

A. Almaghrabi and A. Alhogail, “Blockchain-based donations traceability framework,” Journal of King Saud University - Computer and Information Sciences, vol. 34, no. 10, pp. 9442–9454, Nov. 2022, doi: 10.1016/j.jksuci.2022.09.021.

M. Crosby Nachiappan Pradan Pattanayak Sanjeev Verma and V. Kalyanaraman, “BlockChain Technology: Beyond Bitcoin,” 2016.

J. R. Jensen, V. von Wachter, and O. Ross, “An Introduction to Decentralized Finance (DeFi),” Complex Systems Informatics and Modeling Quarterly, vol. 2021, no. 26, pp. 46–54, 2021, doi: 10.7250/csimq.2021-26.03.

J. R. Jensen and O. Ross, “HOW DECENTRALIZED IS THE GOVERNANCE OF BLOCKCHAIN-BASED FINANCE?” [Online]. Available: https://www.balancer.finance

S. Dos Santos, J. Singh, R. K. Thulasiram, S. Kamali, L. Sirico, and L. Loud, “A New Era of Blockchain-Powered Decentralized Finance (DeFi) - A Review,” in Proceedings - 2022 IEEE 46th Annual Computers, Software, and Applications Conference, COMPSAC 2022, Institute of Electrical and Electronics Engineers Inc., 2022, pp. 1286–1292. doi: 10.1109/COMPSAC54236.2022.00203.

M. Saleem and C. Chawla, “Blockchain-Powered Decentralized Finance (DeFi): Transforming Financial Inclusion & Investment Landscapes,” in Proceedings of the 2023 12th International Conference on System Modeling and Advancement in Research Trends, SMART 2023, Institute of Electrical and Electronics Engineers Inc., 2023, pp. 342–346. doi: 10.1109/SMART59791.2023.10428666.

M. H. Jumaa and A. C. Shakir, “Review Study of E-Voting System Based on Smart Contracts Using Blockchain Technology,” Iraqi Journal of Science, vol. 64, no. 4, pp. 2001–2022, 2023, doi: 10.24996/ijs.2023.64.4.36.

O. Ali, M. Ally, P. Clutterbuck, and Y. K. Dwivedi, “The State of Play of Blockchain Technology in the Financial Services Sector: A Systematic Literature Review.”

Y. Long, Y. Gong, W. Huang, J. Cai, N. Xu, and K. ching Li, “Cryptography of Blockchain,” in Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), Springer Science and Business Media Deutschland GmbH, 2023, pp. 340–349. doi: 10.1007/978-3-031-28124-2_32.

Q. Razi, A. Devrani, H. Abhyankar, G. S. S. Chalapathi, V. Hassija, and M. Guizani, “Non-Fungible Tokens (NFTs) - Survey of Current Applications, Evolution, and Future Directions,” IEEE Open Journal of the Communications Society, vol. 5, pp. 2765–2791, 2024, doi: 10.1109/OJCOMS.2023.3343926.

K. Gilani, E. Bertin, J. Hatin, and N. Crespi, “A Survey on Blockchain-based Identity Management and Decentralized Privacy for Personal Data,” 2020.

N. Yadav and V. Sarasvathi, “Venturing crowdfunding using smart contracts in Blockchain,” in Proceedings of the 3rd International Conference on Smart Systems and Inventive Technology, ICSSIT 2020, Institute of Electrical and Electronics Engineers Inc., Aug. 2020, pp. 192–197. doi: 10.1109/ICSSIT48917.2020.9214295.

D. Vujičić, D. Jagodić, and S. Randić, “Blockchain technology, bitcoin, and Ethereum: A brief overview,” in 2018 17th International Symposium on INFOTEH-JAHORINA, INFOTEH 2018 - Proceedings, Institute of Electrical and Electronics Engineers Inc., Apr. 2018, pp. 1–6. doi: 10.1109/INFOTEH.2018.8345547.

Y. M. Wahab et al., “A Framework for Blockchain Based E-Voting System for Iraq,” International Journal of Interactive Mobile Technologies, vol. 16, no. 10, pp. 210–222, 2022, doi: 10.3991/ijim.v16i10.30045.

W. Li, J. Bu, X. Li, H. Peng, Y. Niu, and Y. Zhang, “A survey of DeFi security: Challenges and opportunities,” Nov. 01, 2022, King Saud bin Abdulaziz University. doi: 10.1016/j.jksuci.2022.10.028.

M. Alisawi, A. Al-Dawoodi, Y. Mohammed Wahab, L. Hammood, A. Yaseen Nawaf, and A. Ghazi, “Developing the Real Estate Rental Sector in Third World Countries Using Blockchain Technology,” 2022, pp. 87–109. doi: 10.4018/978-1-7998-9274-8.ch006.

S. Chaliasos et al., “Smart Contract and DeFi Security Tools: Do They Meet the Needs of Practitioners?,” in Proceedings - International Conference on Software Engineering, IEEE Computer Society, Feb. 2024. doi: 10.1145/3597503.3623302.

W. Li, J. Bu, X. Li, and X. Chen, “Security Analysis of DeFi: Vulnerabilities, Attacks and Advances,” May 2022, [Online]. Available: http://arxiv.org/abs/2205.09524

A. H. H. Kabla et al., “Applicability of Intrusion Detection System on Ethereum Attacks: A Comprehensive Review,” IEEE Access, vol. 10, pp. 71632–71655, 2022, doi: 10.1109/ACCESS.2022.3188637.

Y. Liu, D. He, M. S. Obaidat, N. Kumar, M. K. Khan, and K. K. Raymond Choo, “Blockchain-based identity management systems: A review,” Sep. 15, 2020, Academic Press. doi: 10.1016/j.jnca.2020.102731.

J. Swati, P. Nitin, P. Saurabh, D. Parikshit, P. Gitesh, and S. Rahul, “Blockchain based Trusted Secure Philanthropy Platform: Crypto-GoCharity,” in 2022 6th International Conference on Computing, Communication, Control and Automation, ICCUBEA 2022, Institute of Electrical and Electronics Engineers Inc., 2022. doi: 10.1109/ICCUBEA54992.2022.10011026.

Z. Wang, H. Jin, W. Dai, K. K. R. Choo, and D. Zou, “Ethereum smart contract security research: survey and future research opportunities,” Apr. 01, 2021, Higher Education Press Limited Company. doi: 10.1007/s11704-020-9284-9.

A. Trozze, T. Davies, and B. Kleinberg, “Of degens and defrauders: Using open-source investigative tools to investigate decentralized finance frauds and money laundering,” Forensic Science International: Digital Investigation, vol. 46, Sep. 2023, doi: 10.1016/j.fsidi.2023.301575.

J. Collins et al., “Crypto, crime and control in writing from the Global Initiative. Cover: © Da-kuk/iStock via Getty Images Plus Please direct inquiries to: The Global Initiative Against Transnational Organized Crime,” 2022. [Online]. Available: www.globalinitiative.net

T. Barbereau and B. Bodó, “Beyond financial regulation of crypto-asset wallet software: In search of secondary liability,” Computer Law and Security Review, vol. 49, Jul. 2023, doi: 10.1016/j.clsr.2023.105829.

T. Katona, “Decentralized Finance : The Possibilities of a Blockchain ‘Money Lego’ System,” Financial and Economic Review, vol. 20, no. 1, pp. 74–102, 2021, doi: 10.33893/fer.20.1.74102.

M. Salah and S. Gonzalez, “Decentralized Finance (DeFi) on Blockchain: Current Landscape and Future Trends,” 2023.

H. Teng, W. Tian, H. Wang, and Z. Yang, “Applications of the Decentralized Finance (DeFi) on the Ethereum,” in 2022 IEEE Asia-Pacific Conference on Image Processing, Electronics and Computers, IPEC 2022, Institute of Electrical and Electronics Engineers Inc., 2022, pp. 573–578. doi: 10.1109/IPEC54454.2022.9777543.

P. Mell and D. Yaga, “Understanding stablecoin technology and related security considerations,” Sep. 2023. doi: 10.6028/NIST.IR.8408.

M. Lathkar, P. Deshmukh, A. Patil, and P. Shelke, “Increasing Donation Transparency in Disaster Relief: A Blockchain-based Solution,” in 2024 ASU International Conference in Emerging Technologies for Sustainability and Intelligent Systems, ICETSIS 2024, Institute of Electrical and Electronics Engineers Inc., 2024, pp. 1527–1532. doi: 10.1109/ICETSIS61505.2024.10459402.

I. Segeda, V. Kotsiuba, O. Shushura, V. Bokovets, N. Koval, and A. Kalizhanova, “DECENTRALIZED PLATFORM FOR FINANCING CHARITY PROJECTS,” Informatyka, Automatyka, Pomiary w Gospodarce i Ochronie Srodowiska, vol. 14, no. 3, pp. 129–134, 2024, doi: 10.35784/iapgos.6140.

V. Gramlich et al., “Decentralized Finance (DeFi): Foundations, Applications, Potentials, and Challenges,” SSRN Electronic Journal, 2023, doi: 10.2139/ssrn.4535868.

A. A. A. Ahmed, “<strong>The Rise of DeFi: Transforming Traditional Finance with Blockchain Innovation</strong>,” Feb. 13, 2024. doi: 10.20944/preprints202402.0738.v1.

E. Bayraktar, A. Cohen, and A. Nellis, “DEX Specs: A Mean Field Approach to DeFi Currency Exchanges,” Apr. 2024, [Online]. Available: http://arxiv.org/abs/2404.09090

S. Cousaert, J. Xu, and T. Matsui, “SoK: Yield Aggregators in DeFi,” May 2021, doi: 10.1109/ICBC54727.2022.9805523.

T. Surve, A. Tyagi, and G. Kaur, “Article ID: IJARET_14_07_003 Review of The Literature.” [Online]. Available: https://iaeme.com/Home/journal/IJARET48editor@iaeme.com

A. Kumar, N. Sharma, S. Malhotra, S. Devliyal, and B. V. Kumar, “Smart Contract Security: A Review with a Focus on Decentralized Finance,” in 2024 3rd International Conference for Innovation in Technology, INOCON 2024, Institute of Electrical and Electronics Engineers Inc., 2024. doi: 10.1109/INOCON60754.2024.10511387.

Y. Wang, “Automated Market Makers for Decentralized Finance (DeFi),” Sep. 2020, [Online]. Available: http://arxiv.org/abs/2009.01676

J. Xu, K. Paruch, S. Cousaert, and Y. Feng, “SoK: Decentralized Exchanges (DEX) with Automated Market Maker (AMM) Protocols,” ACM Comput Surv, vol. 55, no. 11, Nov. 2023, doi: 10.1145/3570639.

J. Chen et al., “Understanding the Security Risks of Decentralized Exchanges by Uncovering Unfair Trades in the Wild,” Jan. 2024, [Online]. Available: http://arxiv.org/abs/2401.11547

L. Zhou, K. Qin, and A. Gervais, “A2MM: Mitigating Frontrunning, Transaction Reordering and Consensus Instability in Decentralized Exchanges,” Jun. 2021, [Online]. Available: http://arxiv.org/abs/2106.07371

Kaihua. Qin and Fan. Zhang, Proceedings of the 2023 Workshop on Decentralized Finance and Security (DeFi ’23) : November 30, 2023, Copenhagen, Denmark. The Association for Computing Machinery, 2023.

J. Xu, D. Perez, Y. Feng, and B. Livshits, “Auto.gov: Learning-based On-chain Governance for Decentralized Finance (DeFi),” Feb. 2023, [Online]. Available: http://arxiv.org/abs/2302.09551

I. Appel et al., “Decentralized Governance and Digital Asset Prices *.”

A. Patel, “Blockchain Technology and Distributed Systems By The Science Brigade (Publishing) Group 1 Blockchain Technology and Distributed Systems Volume 2 Issue 1 Semi Annual Edition.”

Gailan Ismael Abdullah, “Unraveling the Potential of Decentralized Finance: A Comprehensive Analysis of Opportunities, Risks, and Future Trends,” American Journal of Economics and Business Management, vol. 7, no. 8, pp. 370–387, Aug. 2024, doi: 10.31150/ajebm.v7i8.2891.

S. Borisov, “DeFi-Potential, Advantages and Challenges DEFI-POTENTIAL, ADVANTAGES AND CHALLENGES 2.” [Online]. Available: https://www.researchgate.net/publication/361890666

H. Amler, L. Eckey, S. Faust, M. Kaiser, P. Sandner, and B. Schlosser, “DeFi-ning DeFi: Challenges & Pathway,” Jan. 2021, [Online]. Available: http://arxiv.org/abs/2101.05589

L. Judijanto, I. Ketut Kusuma Wijaya, I. Jayanto, and S. P. Anantadjaya, “THE INFLUENCE OF DECENTRALIZED FINANCE (DEFI) ON GLOBAL FINANCIAL STABILITY: AN EMERGING CHALLENGE PENGARUH KEUANGAN TERDESENTRALISASI (DEFI) TERHADAP STABILITAS KEUANGAN GLOBAL: TANTANGAN YANG MUNCUL.”

M. H. Jumaa and A. C. Shakir, “Iraqi E-Voting System Based on Smart Contract Using Private Blockchain Technology,” Informatica (Slovenia), vol. 46, no. 6, pp. 87–94, 2022, doi: 10.31449/inf.v46i6.4241.




DOI: https://doi.org/10.31449/inf.v49i33.7990

Creative Commons License
This work is licensed under a Creative Commons Attribution 3.0 License.