{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T10:06:25Z","timestamp":1784369185732,"version":"3.55.0"},"reference-count":52,"publisher":"Association for Computing Machinery (ACM)","issue":"3","license":[{"start":{"date-parts":[[2023,4,26]],"date-time":"2023-04-26T00:00:00Z","timestamp":1682467200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Softw. Eng. Methodol."],"published-print":{"date-parts":[[2023,7,31]]},"abstract":"<jats:p>With the development of decentralized networks, smart contracts, especially those for ERC tokens, are attracting more and more Dapp users to implement their applications. There are some functions in ERC token contracts that only a specific group of accounts could invoke. Among those functions, some even can influence other accounts or the whole system without prior notice or permission. These functions are referred to as contract backdoors. Once exploited by an attacker, they can cause property losses and harm users\u2019 privacy.<\/jats:p>\n          <jats:p>In this work, we propose Pied-Piper, a hybrid analysis method that integrates datalog analysis and directed fuzzing to detect backdoor threats in Ethereum ERC token contracts. First, datalog analysis is applied to abstract the data structures and identification rules related to the threats for preliminary static detection. Then, directed fuzzing is applied to eliminate false positives caused by the static analysis. We first evaluated Pied-Piper on 200 smart contracts, which are injected with different types of backdoors. It reported all problems without false positives, and none of the injected problems was missed. Then, we applied Pied-Piper on 13,484 real token contracts deployed on Ethereum. Pied-Piper reported 189 confirmed problems, four of which have been assigned unique CVE ids while others are still in the review process. Each contract takes 8.03 seconds for datalog analysis on average, and the fuzzing engine can eliminate the false positives within one minute.<\/jats:p>","DOI":"10.1145\/3560264","type":"journal-article","created":{"date-parts":[[2022,8,30]],"date-time":"2022-08-30T07:09:18Z","timestamp":1661843358000},"page":"1-24","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":35,"title":["Pied-Piper: Revealing the Backdoor Threats in Ethereum ERC Token Contracts"],"prefix":"10.1145","volume":"32","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-1360-9814","authenticated-orcid":false,"given":"Fuchen","family":"Ma","sequence":"first","affiliation":[{"name":"Tsinghua University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2639-3941","authenticated-orcid":false,"given":"Meng","family":"Ren","sequence":"additional","affiliation":[{"name":"Tsinghua University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5128-7588","authenticated-orcid":false,"given":"Lerong","family":"Ouyang","sequence":"additional","affiliation":[{"name":"Tsinghua University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2701-4296","authenticated-orcid":false,"given":"Yuanliang","family":"Chen","sequence":"additional","affiliation":[{"name":"Tsinghua University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8927-2632","authenticated-orcid":false,"given":"Juan","family":"Zhu","sequence":"additional","affiliation":[{"name":"Hubei University of Arts and Science, Hubei, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8894-1045","authenticated-orcid":false,"given":"Ting","family":"Chen","sequence":"additional","affiliation":[{"name":"University of Electronic Science and Technology of China, Chengdu, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7482-9992","authenticated-orcid":false,"given":"Yingli","family":"Zheng","sequence":"additional","affiliation":[{"name":"China Central Depository &amp; Clearing Co., Ltd., Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9591-0039","authenticated-orcid":false,"given":"Xiao","family":"Dai","sequence":"additional","affiliation":[{"name":"China Central Depository &amp; Clearing Co., Ltd., Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0955-503X","authenticated-orcid":false,"given":"Yu","family":"Jiang","sequence":"additional","affiliation":[{"name":"Tsinghua University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5884-7939","authenticated-orcid":false,"given":"Jiaguang","family":"Sun","sequence":"additional","affiliation":[{"name":"Tsinghua University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,4,26]]},"reference":[{"key":"e_1_3_2_2_2","volume-title":"IACR Cryptology ePrint Archive","author":"Atzei Nicola","year":"2016","unstructured":"Nicola Atzei, Massimo Bartoletti, and Tiziana Cimoli. 2016. A survey of attacks on Ethereum smart contracts. In IACR Cryptology ePrint Archive."},{"key":"e_1_3_2_3_2","unstructured":"Bancor. 2022. SmartToken. https:\/\/etherscan.io\/address\/0x1f573d6fb3f13d689ff844b4ce37794d79a7ff1c#code. Accessed April 4 2022."},{"key":"e_1_3_2_4_2","unstructured":"Bitcoin. 2022. Bitcoin is an innovative payment network and a new kind of money. https:\/\/bitcoin.org\/en\/. Accessed June 16 2022."},{"key":"e_1_3_2_5_2","article-title":"Vandal: A scalable security analysis framework for smart contracts","volume":"1809","author":"Brent Lexi","year":"2018","unstructured":"Lexi Brent, Anton Jurisevic, Michael Kong, Eric Liu, Fran\u00e7ois Gauthier, Vincent Gramoli, Ralph Holz, and Bernhard Scholz. 2018. Vandal: A scalable security analysis framework for smart contracts. ArXiv abs\/1809.03981 (2018).","journal-title":"ArXiv"},{"key":"e_1_3_2_6_2","first-page":"1967","volume-title":"28th USENIX Security Symposium (USENIX Security 19)","author":"Chen Yuanliang","year":"2019","unstructured":"Yuanliang Chen, Yu Jiang, Fuchen Ma, Jie Liang, Mingzhe Wang, Chijin Zhou, Xun Jiao, and Zhuo Su. 2019. \\(\\lbrace\\) EnFuzz \\(\\rbrace\\) : Ensemble fuzzing with seed synchronization among diverse fuzzers. In 28th USENIX Security Symposium (USENIX Security 19). 1967\u20131983."},{"key":"e_1_3_2_7_2","unstructured":"ConsenSys. 2022. smart-contract-best-practices. https:\/\/github.com\/ConsenSys\/smart-contract-best-practices\/blob\/master\/docs\/known_attacks.md. Accessed April 4 2022."},{"key":"e_1_3_2_8_2","unstructured":"crytic. 2022. echidna. https:\/\/github.com\/crytic\/echidna\/."},{"key":"e_1_3_2_9_2","unstructured":"CVE. 2022. CVE-2018-1000203. http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-1000203. Accessed April 4 2022."},{"key":"e_1_3_2_10_2","unstructured":"CVE. 2022. CVE-2022-16944. https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2022-16944. Accessed April 4 2022."},{"key":"e_1_3_2_11_2","unstructured":"eric.eth. 2022. Just so everyone is aware there is a backdoor in the USDC stablecoin launched by @coinbase today which allows any address to be blacklisted and funds frozen. https:\/\/twitter.com\/econoar\/status\/1054785269843415040. Accessed April 4 2022."},{"key":"e_1_3_2_12_2","unstructured":"Ethereum. 2022. Ethereum is the community-run technology powering the cryptocurrency ether (ETH) and thousands of decentralized applications. https:\/\/ethereum.org\/en\/. Accessed June 16 2022."},{"key":"e_1_3_2_13_2","doi-asserted-by":"crossref","unstructured":"Ethereum. 2022. Ethereum\/Solidity. https:\/\/github.com\/ethereum\/solidity. Accessed April 13 2022.","DOI":"10.1007\/978-1-4842-8045-4_2"},{"key":"e_1_3_2_14_2","unstructured":"Etherscan. 2022. Etherscan. https:\/\/etherscan.io\/. Accessed April 13 2022."},{"key":"e_1_3_2_15_2","article-title":"SmartBugs: A framework to analyze solidity smart contracts","author":"Ferreira Jo\u00e3o F.","year":"2020","unstructured":"Jo\u00e3o F. Ferreira, Pedro Cruz, Thomas Durieux, and Rui Abreu. 2020. SmartBugs: A framework to analyze solidity smart contracts. arXiv preprint arXiv:2007.04771 (2020).","journal-title":"arXiv preprint arXiv:2007.04771"},{"key":"e_1_3_2_16_2","unstructured":"Hard Fork. 2022. PAX stablecoin has backdoor for freezing and seizing cryptocurrency. https:\/\/thenextweb.com\/hardfork\/2018\/09\/20\/stablecoin-backdoor-law-enforcement\/. Accessed April 4 2022."},{"key":"e_1_3_2_17_2","first-page":"116:1\u2013116:27","article-title":"MadMax: Surviving out-of-gas conditions in Ethereum smart contracts","volume":"2","author":"Grech Neville","year":"2018","unstructured":"Neville Grech, Michael Kong, Anton Jurisevic, Lexi Brent, Bernhard Scholz, and Yannis Smaragdakis. 2018. MadMax: Surviving out-of-gas conditions in Ethereum smart contracts. PACMPL 2 (2018), 116:1\u2013116:27.","journal-title":"PACMPL"},{"key":"e_1_3_2_18_2","unstructured":"Gilad Haimov. 2022. How to Create an ERC20 Token the Simple Way. https:\/\/www.toptal.com\/ethereum\/create-erc20-token-tutorial. Accessed April 4 2022."},{"key":"e_1_3_2_19_2","first-page":"531","volume-title":"Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security","author":"He Jingxuan","year":"2022","unstructured":"Jingxuan He, Mislav Balunovi\u0107, Nodar Ambroladze, Petar Tsankov, and Martin Vechev. 2022. Learning to fuzz from symbolic execution with application to smart contracts. In Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security. 531\u2013548."},{"key":"e_1_3_2_20_2","unstructured":"Yoichi Hirai. 2016. Formal verification of deed contract in Ethereum name service. November-2016. [Online]. Available: https:\/\/yoichihirai.com\/deed.pdf (2016)."},{"key":"e_1_3_2_21_2","volume-title":"Graduate Texts in Computer Science","author":"Immerman Neil","year":"1999","unstructured":"Neil Immerman. 1999. Descriptive complexity. In Graduate Texts in Computer Science."},{"key":"e_1_3_2_22_2","unstructured":"Investopedia. 2022. What is ERC-20 and what does it mean for Ethereum. https:\/\/www.investopedia.com\/news\/what-erc20-and-what-does-it-mean-ethereum\/. Accessed April 4 2022."},{"key":"e_1_3_2_23_2","unstructured":"ISE. 2022. Ethercombing: Finding Secrets in Popular Places. https:\/\/www.ise.io\/casestudies\/ethercombing\/. Accessed April 4 2022."},{"key":"e_1_3_2_24_2","first-page":"259","volume-title":"2018 33rd IEEE\/ACM International Conference on Automated Software Engineering (ASE)","author":"Jiang Bo","year":"2018","unstructured":"Bo Jiang, Ye Liu, and WK Chan. 2018. ContractFuzzer: Fuzzing smart contracts for vulnerability detection. In 2018 33rd IEEE\/ACM International Conference on Automated Software Engineering (ASE). IEEE, 259\u2013269."},{"key":"e_1_3_2_25_2","volume-title":"NDSS","author":"Kalra Sukrit","year":"2018","unstructured":"Sukrit Kalra, Seep Goel, Mohan Dhawan, and Subodh Sharma. 2018. ZEUS: Analyzing safety of smart contracts. In NDSS."},{"key":"e_1_3_2_26_2","article-title":"Detecting standard violation errors in smart contracts","volume":"1812","author":"Li Ao","year":"2018","unstructured":"Ao Li and Fan Long. 2018. Detecting standard violation errors in smart contracts. ArXiv abs\/1812.07702 (2018).","journal-title":"ArXiv"},{"key":"e_1_3_2_27_2","doi-asserted-by":"publisher","DOI":"10.1145\/3236024.3275525"},{"key":"e_1_3_2_28_2","first-page":"65","article-title":"ReGuard: Finding reentrancy bugs in smart contracts","author":"Liu Chao","year":"2018","unstructured":"Chao Liu, Han Liu, Zhao Cao, Zhuotong Chen, Bangdao Chen, and A. W. Roscoe. 2018. ReGuard: Finding reentrancy bugs in smart contracts. 2018 IEEE\/ACM 40th International Conference on Software Engineering: Companion (ICSE-Companion) (2018), 65\u201368.","journal-title":"2018 IEEE\/ACM 40th International Conference on Software Engineering: Companion (ICSE-Companion)"},{"key":"e_1_3_2_29_2","first-page":"633","article-title":"Making smart contracts smarter","volume":"2016","author":"Luu Loi","year":"2016","unstructured":"Loi Luu, Duc-Hiep Chu, Hrishi Olickel, Prateek Saxena, and Aquinas Hobor. 2016. Making smart contracts smarter. IACR Cryptology ePrint Archive 2016 (2016), 633.","journal-title":"IACR Cryptology ePrint Archive"},{"key":"e_1_3_2_30_2","article-title":"V-Gas: Generating high gas consumption inputs to avoid out-of-gas vulnerability","author":"Ma Fuchen","year":"2022","unstructured":"Fuchen Ma, Meng Ren, Fu Ying, Wanting Sun, Houbing Song, Heyuan Shi, Yu Jiang, and Huizhong Li. 2022. V-Gas: Generating high gas consumption inputs to avoid out-of-gas vulnerability. ACM Transactions on Internet Technology (TOIT) (2022).","journal-title":"ACM Transactions on Internet Technology (TOIT)"},{"key":"e_1_3_2_31_2","article-title":"Pluto: Exposing vulnerabilities in inter-contract scenarios","author":"Ma Fuchen","year":"2021","unstructured":"Fuchen Ma, Zhenyang Xu, Meng Ren, Zijing Yin, Yuanliang Chen, Lei Qiao, Bin Gu, Huizhong Li, Yu Jiang, and Jiaguang Sun. 2021. Pluto: Exposing vulnerabilities in inter-contract scenarios. IEEE Transactions on Software Engineering (2021).","journal-title":"IEEE Transactions on Software Engineering"},{"key":"e_1_3_2_32_2","volume-title":"PLDI","author":"Madsen Magnus","year":"2016","unstructured":"Magnus Madsen, Ming-Ho Yee, and Ondrej Lhot\u00e1k. 2016. From Datalog to Flix: A declarative language for fixed points on lattices. In PLDI."},{"key":"e_1_3_2_33_2","volume-title":"Financial Cryptography","author":"Mavridou Anastasia","year":"2017","unstructured":"Anastasia Mavridou and Aron Laszka. 2017. Designing secure Ethereum smart contracts: A finite state machine based approach. In Financial Cryptography."},{"key":"e_1_3_2_34_2","doi-asserted-by":"publisher","DOI":"10.4018\/JCIT.2019010102"},{"key":"e_1_3_2_35_2","unstructured":"nDEX. 2022. nDEX token. https:\/\/etherscan.io\/token\/0x1966d718a565566e8e202792658d7b5ff4ece469. Accessed April 4 2022."},{"key":"e_1_3_2_36_2","article-title":"sFuzz: An efficient adaptive fuzzer for solidity smart contracts","volume":"2004","author":"Nguyen T. D.","year":"2020","unstructured":"T. D. Nguyen, L. H. Pham, Jun Sun, Yun Lin, and Q. Minh. 2020. sFuzz: An efficient adaptive fuzzer for solidity smart contracts. ArXiv abs\/2004.08563 (2020).","journal-title":"ArXiv"},{"key":"e_1_3_2_37_2","volume-title":"ACSAC","author":"Nikolic Ivica","year":"2018","unstructured":"Ivica Nikolic, Aashish Kolluri, Ilya Sergey, Prateek Saxena, and Aquinas Hobor. 2018. Finding the greedy, prodigal, and suicidal contracts at scale. In ACSAC."},{"key":"e_1_3_2_38_2","unstructured":"OpenZeppelin. 2022. ERC 20. https:\/\/docs.openzeppelin.com\/contracts\/2.x\/api\/token\/erc20#IERC20-approve-address-uint256-. Accessed June 16 2022."},{"key":"e_1_3_2_39_2","doi-asserted-by":"publisher","DOI":"10.1145\/3468264.3473929"},{"key":"e_1_3_2_40_2","doi-asserted-by":"publisher","DOI":"10.1145\/3460319.3464837"},{"key":"e_1_3_2_41_2","unstructured":"Mauro Sacramento. 2022. Backdoor Flaw Sees Australian Firm Lose $6.6 Million in Cryptocurrency. https:\/\/finance.yahoo.com\/news\/backdoor-flaw-sees-australian-firm-115323212.html. Accessed April 4 2022."},{"key":"e_1_3_2_42_2","unstructured":"Allen Scott. 2022. New Research Finds Backdoor \u2018Centralized Control\u2019 in Many ICOS. https:\/\/bitcoinist.com\/icos-centralized-control-new-study\/. Accessed April 4 2022."},{"key":"e_1_3_2_43_2","unstructured":"Sead. 2022. This New Stablecoin Has a Backdoor for Freezing Funds Too. https:\/\/cryptonews.com\/news\/this-new-stablecoin-has-a-backdoor-for-freezing-funds-too-2908.htm. Accessed April 12 2022."},{"key":"e_1_3_2_44_2","volume-title":"Datalog","author":"Smaragdakis Yannis","year":"2010","unstructured":"Yannis Smaragdakis and Martin Bravenboer. 2010. Using Datalog for fast and easy program analysis. In Datalog."},{"key":"e_1_3_2_45_2","unstructured":"SoarLab. 2022. SoarCoin. https:\/\/etherscan.io\/address\/0xD65960FAcb8E4a2dFcb2C2212cb2e44a02e2a57E#code. Accessed April 4 2022."},{"key":"e_1_3_2_46_2","unstructured":"Souffle. 2022. Souffle. https:\/\/souffle-lang.github.io\/index.html. Accessed April 4 2022."},{"key":"e_1_3_2_47_2","unstructured":"SPAcoin. 2022. SpaCoin. https:\/\/etherscan.io\/address\/0x61402276c74c1def19818213dfab2fdd02361238. Accessed April 4 2022."},{"key":"e_1_3_2_48_2","unstructured":"StackExchange. 2022. What is minting? How is minting prevented after ICO? https:\/\/ethereum.stackexchange.com\/questions\/49867\/what-is-minting-how-is-minting-prevented-after-ico. Accessed April 4 2022."},{"key":"e_1_3_2_49_2","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243780"},{"key":"e_1_3_2_50_2","doi-asserted-by":"publisher","DOI":"10.1145\/3183440.3183494"},{"key":"e_1_3_2_51_2","unstructured":"Udi Wertheimer. 2022. Bancor Unchained: All Your Token Are Belong To Us. https:\/\/medium.com\/unchained-reports\/bancor-unchained-all-your-token-are-belong-to-us-d6bb00871e86. Accessed April 4 2022."},{"key":"e_1_3_2_52_2","unstructured":"CryptoGlobe Staff Writer. 2022. Coinbase\u2019s New Stablecoin (USDC) Could Freeze Funds and Censor Accounts. https:\/\/www.cryptoglobe.com\/latest\/2018\/10\/coinbases-new-stablecoin-usdc-could-freeze-funds-and-censor-accounts\/. Accessed April 4 2022."},{"key":"e_1_3_2_53_2","volume-title":"PLDI","author":"Zhang Xin","year":"2014","unstructured":"Xin Zhang, Ravi Mangal, Radu Grigore, Mayur Naik, and Hongseok Yang. 2014. On abstraction refinement for program analyses in Datalog. In PLDI."}],"container-title":["ACM Transactions on Software Engineering and Methodology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3560264","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3560264","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T19:00:33Z","timestamp":1750186833000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3560264"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,4,26]]},"references-count":52,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2023,7,31]]}},"alternative-id":["10.1145\/3560264"],"URL":"https:\/\/doi.org\/10.1145\/3560264","relation":{},"ISSN":["1049-331X","1557-7392"],"issn-type":[{"value":"1049-331X","type":"print"},{"value":"1557-7392","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,4,26]]},"assertion":[{"value":"2022-04-13","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2022-08-14","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2023-04-26","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}