MATH - Finding and Fixing Exploits in Algorand
Peter Ince, Xiapu Luo, Jiangshan Yu, Joseph K. Liu, Xiaoning Du · 2023
With the growth in assets managed on-chain comes more attention from hackers. As Algorand uses its own Algorand Virtual Machine (AVM), there is a need for new vulnerability and exploit detection tools, as those built for Ethereum’s EVM are not suitable. This paper presents the MATH static analysis tool with detectors for the math exploit and byte subtraction vulnerability on the Algorand network using only the deployed smart contract base64 code. We use it to analyse 144,006 stateful smart contracts, find and verify three new instances of the math exploit, and evaluate the tools’ runtime and effectiveness.