Blockchain interoperability enables independent blockchain systems to communicate and exchange assets across heterogeneous networks. However, the lack of comprehensive security mechanisms remains a critical weakness -- one that attackers have already exploited to cause hundreds of millions of dollars in asset losses. This paper presents a systematic identification and classification of security threats facing interoperable blockchain systems, along with corresponding countermeasures for each. We organize threats into five categories: (1) core blockchain attacks, (2) network attacks, (3) interoperability-specific attacks, (4) social engineering, and (5) code vulnerabilities, with particular attention to smart contract weaknesses. For each identified threat, we analyze its attack surface and propose effective defensive strategies. The resulting taxonomy provides a structured foundation for designing and evaluating secure blockchain interoperability solutions.
翻译:区块链互操作性使独立的区块链系统能够在异构网络间进行通信和资产交换。然而,缺乏全面的安全机制仍是一个关键弱点——攻击者已利用此漏洞造成了数亿美元的资产损失。本文系统性地识别并分类了互操作区块链系统面临的安全威胁,并为每种威胁提出相应的应对措施。我们将威胁分为五类:(1)核心区块链攻击,(2)网络攻击,(3)互操作特有攻击,(4)社会工程学攻击,以及(5)代码漏洞,特别关注智能合约漏洞。针对识别的每种威胁,我们分析其攻击面并提出有效的防御策略。由此形成的分类体系为设计并评估安全的区块链互操作性解决方案提供了结构化基础。