The Dark Side of Upgrades: Uncovering Insecurity in Smart Contract Upgrades
摘要
Smart contract upgrades are increasingly adopted to enable bug fixes and feature enhancements in deployed contracts. However, upgrades compromise the immutability of contracts, introducing significant security concerns. Although prior research has begun to explore the security impacts of upgrades, these studies are limited in upgrade patterns and insecurity categories. To address these limitations, we present a comprehensive study on the insecurity of upgrade behaviors. First, we construct a dataset of 83,085 upgraded contracts and 20,902 upgrade chains. To our knowledge, this is the first large-scale dataset about upgrade behaviors, revealing their diversity and exposing critical gaps in public disclosure. Next, we develop a taxonomy of insecurity based on 39 real-world security incidents, providing the first holistic view of upgrade-related insecurity with eight types of upgrade risks. Finally, we survey public awareness of these risks, and find that five types are overlooked. In total, we detect 31,407 upgrade issues, raising significant concerns.