As the field of Web3 continues its rapid expansion, the security of Web3 authentication, often the gateway to various Web3 applications, becomes increasingly crucial. Despite its widespread use as a login method by numerous Web3 applications, the security risks of Web3 authentication have not received much attention. This paper investigates the vulnerabilities in the Web3 authentication process and proposes a new type of attack. In attacks, attackers trick users into blindly signing messages from target applications by exploiting users' inability to verify the source of messages, thereby achieving unauthorized access to the target application. We have developed Web3AuthChecker, a dynamic detection tool that interacts with Web3 authentication-related APIs to identify vulnerabilities. Our evaluation of real-world Web3 applications shows that a staggering 75.8\% (22/29) of Web3 authentication deployments are at risk of attacks. In response to this alarming situation, we implemented Web3AuthGuard on the open-source wallet MetaMask to alert users of potential attacks. Our evaluation results show that Web3AuthGuard can successfully raise alerts in 80\% of the tested Web3 authentications. We have responsibly reported our findings to vulnerable websites and have been assigned two CVE IDs.
翻译:随着Web3领域持续快速发展,作为各类Web3应用入口的身份验证安全性变得愈发关键。尽管众多Web3应用广泛采用其作为登录方式,但Web3身份验证的安全风险尚未获得足够关注。本文深入探究Web3身份验证流程中的漏洞,并提出一种新型攻击方式。在该攻击中,攻击者利用用户无法验证消息来源的缺陷,诱骗用户盲目签署来自目标应用的消息,从而实现对目标应用的未授权访问。我们开发了动态检测工具Web3AuthChecker,通过交互式调用Web3身份验证相关API来识别漏洞。对真实Web3应用的评估显示,高达75.8%(22/29)的Web3身份验证部署存在被攻击风险。针对这一严峻现状,我们在开源钱包MetaMask中实现了Web3AuthGuard防护机制,以向用户警示潜在攻击。评估结果表明,Web3AuthGuard能够在80%的测试Web3身份验证场景中成功发出警报。我们已向存在漏洞的网站负责任地报告了发现,并获分配两个CVE编号。