Approve Once, Regret Forever: On the Exploitation of Ethereum's Approve-TransferFrom Ecosystem

Authors

Nicola Ruaro, Fabio Gritti, Dongyu Meng, Robert McLaughlin, Ilya Grishchenko, Christopher Kruegel, Giovanni Vigna

Venue

34th USENIX Security Symposium (USENIX Security 25), August 2025

BibTeX

@inproceedings{ruaro25osprey,
  title     = {{Approve Once, Regret Forever: On the Exploitation of Ethereum's Approve-TransferFrom Ecosystem}},
  author    = {Ruaro, Nicola and Gritti, Fabio and Meng, Dongyu and McLaughlin, Robert and Grishchenko, Ilya and Kruegel, Christopher and Vigna, Giovanni},
  booktitle = {34th USENIX Security Symposium (USENIX Security 25)},
  month     = {August},
  year      = {2025},
  pages     = {1281--1298}
}