Christof Ferreira Torres

dblp:169/2279 · DBLP profile ↗
← Back
20ranked-venue papers
12as first author
12since 2021 · last 2025
0000-0001-6992-703XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 16 · 12 first-author · 9 since 2021Computer networks · 3 · 3 since 2021Artificial intelligence and machine learning · 1Software engineering, systems software and programming languages · 1 · 1 since 2021
YearPublicationVenuePosition
2025 On-Chain Risk Signals: Predicting Security Threats in DeFi Projects
abstract
Blockchain has revolutionized finance through decentralization, eliminating the need for traditional intermediaries. However, security concerns remain a major barrier to adoption, as DeFi platforms increasingly face targeted attacks. In this paper, we present the first methodology for automatically assessing and quantifying the risk of fund loss in DeFi projects due to smart contract exploits. By analyzing on-chain behaviors that signal potential malicious interactions, our approach assigns a dynamic risk score to DeFi projects over time. Relying solely on on-chain data ensures resistance to data manipulation and enhances the integrity of the assessment.We evaluated 220 compromised and 200 unaffected DeFi projects on multiple EVM-compatible blockchains – including Ethereum, BSC, Polygon, Arbitrum, Optimism, and Fantom – and conducted a comparative risk assessment on these projects. Our findings reveal statistically significant differences in risk scores before attacks compared to a control group without attacks. We anticipated potential threats to 86% of the projects that were later attacked, one day before the incidents, with a precision of 78%.
Bahareh Parhizkari, Antonio Ken Iannillo, Edward Zulkoski, Christof Ferreira Torres, Radu State
TrustCom4
2024 Rolling in the Shadows: Analyzing the Extraction of MEV Across Layer-2 Rollups
abstract
The emergence of decentralized finance has transformed asset trading on the blockchain, making traditional financial instruments more accessible while also introducing a series of exploitative economic practices known as Maximal Extractable Value (MEV). Concurrently, decentralized finance has embraced rollup-based Layer-2 solutions to facilitate asset trading at reduced transaction costs compared to Layer-1 solutions such as Ethereum. However, rollups lack a public mempool like Ethereum, making the extraction of MEV more challenging.
Christof Ferreira Torres, Albin Mamuti, Ben Weintraub, Cristina Nita-Rotaru, Shweta Shinde
CCS1
2024 Analyzing the Impact of Copying-and-Pasting Vulnerable Solidity Code Snippets from Question-and-Answer Websites
abstract
Ethereum smart contracts are executable programs deployed on a blockchain. Once deployed, they cannot be updated due to their inherent immutability. Moreover, they often manage valuable assets that are worth millions of dollars, making them attractive targets for attackers. The introduction of vulnerabilities in programs due to the reuse of vulnerable code posted on Q&A websites such as Stack Overflow is not a new issue. However, little effort has been made to analyze the extent of this issue on deployed smart contracts.
Konrad Weiss, Christof Ferreira Torres, Florian Wendland
IMC2
2024 Beyond the Public Mempool: Catching DeFi Attacks Before They Happen with Real-Time Smart Contract Analysis
Bahareh Parhizkari, Antonio Ken Iannillo, Christof Ferreira Torres, Sebastian Banescu, Joseph Jiaqi Xu, Radu State
SecureComm (3)3
2023 A Ripple for Change: Analysis of Frontrunning in the XRP Ledger
abstract
Blockchains are disrupting traditional finance by reducing the number of intermediaries and providing transparency. Blockchains, however, come with their own set of prominent issues. One such challenge is frontrunning. Attackers try to influence the transaction order so that their transaction executes before their victims' transaction. While frontrunning is a well-studied topic on Ethereum, it is unknown whether other blockchains are also susceptible to such attacks. One proposed defence strategy against frontrunning attacks is to randomize the transaction execution order. XRP Ledger is the highest-value blockchain to use such a strategy. Furthermore, it runs a Decentralized Exchange, which provides ample frontrunning opportunities. Therefore, in the context of XRP Ledger, we examine whether randomized transaction order provides sufficient protection against frontrunning. Our results show that the mechanism embedded in the XRP Ledger protocol is insufficient to prevent these attacks. We showcase two strategies to perform frontrunning attacks. The first, “naive” strategy, uses randomly generated accounts, whereas the second uses carefully selected accounts to improve the attack's success. Based on our analysis of the XRP Ledgers' historical data, we estimate that attackers could generate up to approx. 1.4M USD profit over two months, provided they succeeded to frontrun every opportunity.
Vytautas Tumas, Beltran Borja Fiz Pontiveros, Christof Ferreira Torres, Radu State
ICBC3
2023 Ethereum's Proposer-Builder Separation: Promises and Realities
abstract
With Ethereum's transition from Proof-of-Work to Proof-of-Stake in September 2022 came another paradigm shift, the Proposer-Builder Separation (PBS) scheme. PBS was introduced to decouple the roles of selecting and ordering transactions in a block (i.e., the builder), from those validating its contents and proposing the block to the network as the new head of the blockchain (i.e., the proposer). In this landscape, proposers are the validators in the Proof-of-Stake consensus protocol, while now relying on specialized block builders for creating blocks with the highest value for the proposer. Additionally, relays act as mediators between builders and proposers. We study PBS adoption and show that the current landscape exhibits significant centralization amongst the builders and relays. Further, we explore whether PBS effectively achieves its intended objectives of enabling hobbyist validators to maximize block profitability and preventing censorship. Our findings reveal that although PBS grants validators the opportunity to access optimized and competitive blocks, it tends to stimulate censorship rather than reduce it. Additionally, we demonstrate that relays do not consistently uphold their commitments and may prove unreliable. Specifically, proposers do not always receive the complete promised value, and the censorship or filtering capabilities pledged by relays exhibit significant gaps.
Lioba Heimbach, Lucianna Kiffer, Christof Ferreira Torres, Roger Wattenhofer
IMC3
2023 Is Your Wallet Snitching On You? An Analysis on the Privacy Implications of Web3
Christof Ferreira Torres, Fiona Willi, Shweta Shinde
USENIX Security Symposium1
2022 A flash(bot) in the pan: measuring maximal extractable value in private pools
abstract
The rise of Ethereum has lead to a flourishing decentralized marketplace that has, unfortunately, fallen victim to frontrunning and Maximal Extractable Value (MEV) activities, where savvy participants game transaction orderings within a block for profit. One popular solution to address such behavior is Flashbots, a private pool with infrastructure and design goals aimed at eliminating the negative externalities associated with MEV. While Flashbots has established laudable goals to address MEV behavior, no evidence has been provided to show that these goals are achieved in practice.
Ben Weintraub, Christof Ferreira Torres, Cristina Nita-Rotaru, Radu State
IMC2
2022 Elysium: Context-Aware Bytecode-Level Patching to Automatically Heal Vulnerable Smart Contracts
abstract
Fixing bugs is easiest by patching source code. However, source code is not always available: only 0.3% of the ∼ 49M smart contracts that are currently deployed on Ethereum have their source code publicly available. Moreover, since contracts may call functions from other contracts, security flaws in closed-source contracts may affect open-source contracts as well. However, current state-of-the-art approaches that operate on closed-source contracts (i.e., EVM bytecode), such as EVMPatch and SmartShield, make use of purely hard-coded templates that leverage fix patching patterns. As a result, they cannot dynamically adapt to the bytecode that is being patched, which severely limits their flexibility and scalability. For instance, when patching integer overflows using hard-coded templates, a particular patch template needs to be employed as the bounds to be checked are different for each integer size (i.e., one template for uint256, another template for uint64, etc.).
Christof Ferreira Torres, Hugo L. Jonker, Radu State
RAID1
2021 ConFuzzius: A Data Dependency-Aware Hybrid Fuzzer for Smart Contracts
abstract
Smart contracts are Turing-complete programs that are executed across a blockchain. Unlike traditional programs, once deployed, they cannot be modified. As smart contracts carry more value, they become more of an exciting target for attackers. Over the last years, they suffered from exploits costing millions of dollars due to simple programming mistakes. As a result, a variety of tools for detecting bugs have been proposed. Most of these tools rely on symbolic execution, which may yield false positives due to over-approximation. Recently, many fuzzers have been proposed to detect bugs in smart contracts. However, these tend to be more effective in finding shallow bugs and less effective in finding bugs that lie deep in the execution, therefore achieving low code coverage and many false negatives. An alternative that has proven to achieve good results in traditional programs is hybrid fuzzing, a combination of symbolic execution and fuzzing. In this work, we study hybrid fuzzing on smart contracts and present ConFuzzius, the first hybrid fuzzer for smart contracts. ConFuzzius uses evolutionary fuzzing to exercise shallow parts of a smart contract and constraint solving to generate inputs that satisfy complex conditions that prevent evolutionary fuzzing from exploring deeper parts. Moreover, ConFuzzius leverages dynamic data dependency analysis to efficiently generate sequences of transactions that are more likely to result in contract states in which bugs may be hidden. We evaluate the effectiveness of ConFuzzius by comparing it with state-of-the-art symbolic execution tools and fuzzers for smart contracts. Our evaluation on a curated dataset of 128 contracts and a dataset of 21K real-world contracts shows that our hybrid approach detects more bugs than state-of-the-art tools (up to 23%) and that it outperforms existing tools in terms of code coverage (up to 69%). We also demonstrate that data dependency analysis can boost bug detection up to 18%.
Christof Ferreira Torres, Antonio Ken Iannillo, Arthur Gervais, Radu State
EuroS&P1
2021 High-Frequency Trading on Decentralized On-Chain Exchanges
abstract
Decentralized exchanges (DEXs) allow parties to participate in financial markets while retaining full custody of their funds. However, the transparency of blockchain-based DEX in combination with the latency for transactions to be processed, makes market-manipulation feasible. For instance, adversaries could perform front-running — the practice of exploiting (typically non-public) information that may change the price of an asset for financial gain.In this work we formalize, analytically exposit and empirically evaluate an augmented variant of front-running: sandwich attacks, which involve front- and back-running victim transactions on a blockchain-based DEX. We quantify the probability of an adversarial trader being able to undertake the attack, based on the relative positioning of a transaction within a blockchain block. We find that a single adversarial trader can earn a daily revenue of over several thousand USD when performing sandwich attacks on one particular DEX — Uniswap, an exchange with over 5M USD daily trading volume by June 2020. In addition to a single-adversary game, we simulate the outcome of sandwich attacks under multiple competing adversaries, to account for the real-world trading environment.
Liyi Zhou, Kaihua Qin, Christof Ferreira Torres, Duc Viet Le 0001, Arthur Gervais
SP3
2021 Frontrunner Jones and the Raiders of the Dark Forest: An Empirical Study of Frontrunning on the Ethereum Blockchain
Christof Ferreira Torres, Ramiro Camino, Radu State
USENIX Security Symposium1
2020 ÆGIS: Shielding Vulnerable Smart Contracts Against Attacks
abstract
In recent years, smart contracts have suffered major exploits, cost- ing millions of dollars. Unlike traditional programs, smart contracts are deployed on a blockchain. As such, they cannot be modified once deployed. Though various tools have been proposed to detect vulnerable smart contracts, the majority fails to protect vulnera- ble contracts that have already been deployed on the blockchain. Only very few solutions have been proposed so far to tackle the issue of post-deployment. However, these solutions suffer from low precision and are not generic enough to prevent any type of attack. In this work, we introduce ÆGIS, a dynamic analysis tool that protects smart contracts from being exploited during runtime. Its capability of detecting new vulnerabilities can easily be extended through so-called attack patterns. These patterns are written in a domain-specific language that is tailored to the execution model of Ethereum smart contracts. The language enables the description of malicious control and data flows. In addition, we propose a novel mechanism to streamline and speed up the process of managing attack patterns. Patterns are voted upon and stored via a smart contract, thus leveraging the benefits of tamper-resistance and transparency provided by the blockchain. We compare ÆGIS to current state-of-the-art tools and demonstrate that our solution achieves higher precision in detecting attacks. Finally, we perform a large-scale analysis on the first 4.5 million blocks of the Ethereum blockchain, thereby confirming the occurrences of well reported and yet unreported attacks in the wild.
Christof Ferreira Torres, Mathis Baden, Robert Norvill, Beltran Borja Fiz Pontiveros, Hugo L. Jonker, Sjouke Mauw
AsiaCCS1
2019 ÆGIS: Smart Shielding of Smart Contracts
abstract
In recent years, smart contracts have suffered major exploits, losing millions of dollars. Unlike traditional programs, smart contracts cannot be updated once deployed. Though various tools were proposed to detect vulnerable smart contracts, they all fail to protect contracts that have already been deployed on the blockchain. Moreover, they focus on vulnerabilities, but do not address scams (e.g., honeypots). In this work, we introduce Æ GIS, a tool that shields smart contracts and users on the blockchain from being exploited. To this end, ÆGIS reverts transactions in real-time based on pattern matching. These patterns encode the detection of malicious transactions that trigger exploits or scams. New patterns are voted upon and stored via a smart contract, thus leveraging the benefits of tamper-resistance and transparency provided by blockchain. By allowing its protection to be updated, the smart contract acts as a smart shield.
Christof Ferreira Torres, Mathis Baden, Robert Norvill, Hugo L. Jonker
CCS1
2019 The Art of The Scam: Demystifying Honeypots in Ethereum Smart Contracts
Christof Ferreira Torres, Mathis Steichen, Radu State
USENIX Security Symposium1
2018 Osiris: Hunting for Integer Bugs in Ethereum Smart Contracts
abstract
The capability of executing so-called smart contracts in a decentralised manner is one of the compelling features of modern blockchains. Smart contracts are fully fledged programs which cannot be changed once deployed to the blockchain. They typically implement the business logic of distributed apps and carry billions of dollars worth of coins. In that respect, it is imperative that smart contracts are correct and have no vulnerabilities or bugs. However, research has identified different classes of vulnerabilities in smart contracts, some of which led to prominent multi-million dollar fraud cases. In this paper we focus on vulnerabilities related to integer bugs, a class of bugs that is particularly difficult to avoid due to some characteristics of the Ethereum Virtual Machine and the Solidity programming language.
Christof Ferreira Torres, Julian Schütte, Radu State
ACSAC1
2018 Investigating Fingerprinters and Fingerprinting-Alike Behaviour of Android Applications
Christof Ferreira Torres, Hugo L. Jonker
ESORICS (2)1
2016 The Fréchet/Manhattan Distance and the Trajectory Anonymisation Problem
Christof Ferreira Torres, Rolando Trujillo-Rasua
DBSec1
2016 Tackling the IFP Problem with the Preference-Based Genetic Algorithm
abstract
In molecular biology, the subject of protein structure prediction is of continued interest, not only to chart the molecular map of living cells, but also to design proteins with new functions. The Inverse Folding Problem (IFP) of finding sequences that fold into a defined structure is in itself an important research problem at the heart of rational protein design. In this work the Preference-Based Genetic Algorithm (PBGA) is employed to find many diversified solutions to the IFP. The PBGA algorithm incorporates a weighted sum model in order to combine fitness and diversity into a single objective function scoring a set of individuals as a whole. By adjusting the sum weights, a direct control of the fitness vs. diversity trade-off in the algorithm population is achieved by means of a selection scheme iteratively removing the least contributing individuals. Experimental results demonstrate the superior performance of the PBGA algorithm compared to other state-of-the-art algorithms both in terms of fitness and diversity.
Sune S. Nielsen, Christof Ferreira Torres, Grégoire Danoy, Pascal Bouvry
GECCO2
2015 FP-Block: Usable Web Privacy by Controlling Browser Fingerprinting
Christof Ferreira Torres, Hugo L. Jonker, Sjouke Mauw
ESORICS (2)1