Six Smart Contract Exploits That Fake 'Firm' Liquidity on On-Chain Order Books
A developer has demonstrated six smart contract techniques that bypass a common on-chain order book security check, EXTCODESIZE, which is used to verify that a resting order cannot be withdrawn. The check confirms code exists at an address but reveals nothing about what that code can actually do, creating a false sense of liquidity firmness. The exploits include hiding a cancel function behind an innocuous method name, using upgradeable proxies, delegating calls to attacker-controlled contracts, and granting external operators cancel rights post-order placement. All six contracts were deployed to a public testnet and their withdrawal escapes executed as real transactions. The findings highlight that EXTCODESIZE alone is an unreliable guarantee of order permanence and can mislead traders into trusting depth that can still be pulled.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in