블록체인 인프라 회사인 Ensohas는 온체인 실행 중에 거래 시뮬레이션을 조작하면서 실질적으로 다른 결과를 생성할 수 있는 이전에 문서화되지 않은 악성 유동성 풀 범주를 설명하는 새로운 연구를 발표했습니다.
회사는 이러한 풀을 "독성 풀"이라고 부르며 단일 프로토콜에 영향을 미치는 취약점이 아닌 분산형 금융 인프라의 더 광범위한 약점을 노출한다고 주장합니다.
지갑, DEX 수집기 및 라우팅 엔진이 최상의 실행 경로를 결정하기 위해 트랜잭션 시뮬레이션에 점점 더 의존함에 따라, 연구에 따르면 악성 풀은 트랜잭션이 실제로 체인에서 처리될 때 동작을 변경하기 전에 시뮬레이션 중에 매력적인 인용문을 제시하여 이러한 의존도를 활용할 수 있습니다.
Enso에 따르면 독성 풀은 미끄러짐이나 최대 추출 가능 가치(MEV)와 같은 보다 친숙한 거래 위험과 다릅니다. 거래가 제출된 후 사용자를 착취하는 대신 시뮬레이션 프로세스 자체를 속이도록 설계되었습니다.
시뮬레이션된 거래 중에 풀은 가장 경쟁력 있는 실행을 제공하는 것처럼 보이게 하는 가격을 반환합니다. 그러나 일단 거래가 블록에 포함되면 풀은 행동을 변경하여 트레이더가 원래 견적보다 덜 유리한 실행을 받게 되면서도 라우팅 시스템에는 여전히 최적의 경로로 표시됩니다.
회사는 이것이 지갑과 수집자에게 새로운 실행 품질 문제를 야기하며 시뮬레이션 결과가 합법적인 것처럼 보이기 때문에 무의식적으로 사용자를 조작된 유동성으로 계속 유도할 수 있다고 주장합니다.
이 연구는 아카이브 노드 RPC 데이터, 트랜잭션 추적, 스마트 계약 검사 및 독립적 검증을 결합한 약 2개월 간의 포렌식 분석을 기반으로 합니다. Enso는 이번 조사가 Curve와 Oku의 기고자들과의 논의를 통해 이익을 얻었다고 말했습니다.
연구 과정에서 엔지니어들은 서로 다른 분산형 교환 프로토콜에서 작동하지만 유사한 기술을 사용하는 두 개의 활성 독성 풀을 식별했으며, 이는 공격 모델이 단일 생태계에 국한되지 않음을 시사합니다.
문서화된 사례 중 하나는 129, 000개 이상의 성공적인 스왑을 처리하면서 지속적으로 견적 가격보다 더 나쁜 실행을 제공하는 이더리움의 조작된 Curve 유동성 풀과 관련이 있습니다.
Enso에 따르면 불일치로 인해 약 225, 000달러의 과장된 견적이 발생하고 37, 000건 이상의 거래가 실패했으며 취소된 거래에 거의 30, 000달러의 가스 비용이 지출되었습니다.
두 번째 예는 Polygon에 배포된 악성 Uniswap v4 후크에 중점을 둡니다. 연구원들은 후크가 약 99. 1%의 트랜잭션 실패율을 생성하여 트랜잭션을 되돌리기 전에 라우팅 알고리즘을 반복적으로 유인했다고 보고했습니다.
연구원들을 놀라게 한 한 가지 측면은 이더리움 기반 풀이 항상 악의적으로 행동하지 않았다는 것입니다. 대신, 정직한 실행과 조작된 실행을 번갈아 가며 주기적인 시뮬레이션이나 수동 검사로는 패턴을 식별하는 데 불충분했습니다.
또한 조사를 통해 추가 유동성 풀을 지원하기 위해 동일한 운영자가 배포한 여러 오라클 계약이 밝혀졌으며, 이는 유사한 기술이 다른 시장에서도 잠재적으로 복제될 수 있음을 시사합니다.
Enso의 공동 창립자이자 최고 제품 책임자인 Milos Costantini는 "우리의 조사에 따르면 이것이 단순히 또 다른 고립된 스마트 계약 공격이 아니라고 믿게 되었습니다. "라고 말했습니다. "업계에서는 가격 발견을 최적화하는 데 수년을 보냈습니다.
우리의 연구 결과에 따르면 다음 과제는 실행 무결성을 확인하는 것입니다. 실제 실행이 다른 이야기를 전달하는 동안 거래 시뮬레이션을 조작할 수 있다면 사용자가 실제로 받는 것을 확인할 수 있는 더 나은 방법이 필요합니다. ".
Enso는 조사 결과 발표와 함께 회사의 실행 보호 계층인 Enso Shield의 새로운 기능을 발표했습니다.
업데이트된 시스템에는 표준 거래 시뮬레이션을 뛰어넘는 전용 독성 풀 감지 및 실행 검증 도구가 도입되었습니다.
Enso Shield는 시뮬레이션된 견적에만 의존하는 대신 실시간 온체인 조건을 지속적으로 평가하고 시간 경과에 따른 견적 일관성을 모니터링하며 트랜잭션 추적을 사용하여 완료된 실행을 확인하여 기존 시뮬레이션 방법이 간과할 수 있는 불일치를 식별합니다.
Enso는 이번 연구가 분산형 거래 인프라 전체, 특히 시뮬레이션된 거래 결과에 크게 의존하는 지갑, DEX 통합자 및 라우팅 프로토콜의 실행 무결성에 대해 더 광범위한 질문을 제기한다고 믿습니다.
회사는 개별 프로토콜에 책임을 돌리는 대신 유사한 공격 패턴이 얼마나 널리 퍼져 있는지, 그리고 분산 금융 전반에 걸쳐 실행 투명성을 향상시키기 위해 추가 보호 장치가 필요한지 여부를 결정하기 위해 추가적인 업계 연구와 독립적인 검증을 장려하고 있습니다.
원문 제목: Enso Uncovers 'Toxic Pools' That Can Mislead DeFi Transaction Simulations
Blockchain infrastructure companyEnsohas published new research describing a previously undocumented category of malicious liquidity pools capable of manipulating transaction simulations while producing materially different outcomes during on-chain execution.
The company refers to these pools as "toxic pools," arguing that they expose a broader weakness in decentralized finance infrastructure rather than a vulnerability affecting a single protocol.
As wallets, DEX aggregators and routing engines increasingly depend on transaction simulations to determine the best execution path, the research suggests malicious pools can exploit that reliance by presenting attractive quotes during simulations before changing their behavior when transactions are actually processed on-chain.
According to Enso, toxic pools differ from more familiar trading risks such as slippage or maximum extractable value (MEV).
Instead of exploiting users after a trade has been submitted, they are designed to deceive the simulation process itself.
During a simulated transaction, the pools return prices that make them appear to offer the most competitive execution.
Once the transaction is included in a block, however, the pools alter their behavior, causing traders to receive less favorable execution than originally quoted while still appearing to routing systems as the optimal path.
The company argues that this creates a new execution-quality challenge for wallets and aggregators, which may unknowingly continue directing users toward manipulated liquidity because the simulation results appear legitimate.
The research is based on approximately two months of forensic analysis combining archive-node RPC data, transaction tracing, smart contract inspection and independent validation.
Enso said the investigation also benefited from discussions with contributors from Curve and Oku.
During the research, engineers identified two active toxic pools operating on different decentralized exchange protocols but using similar techniques, suggesting the attack model is not limited to a single ecosystem.
One documented case involved a manipulated Curve liquidity pool on Ethereum that processed more than 129,000 successful swaps while consistently delivering worse execution than its quoted prices.
According to Enso, the discrepancy resulted in approximately $225,000 of overstated quotes, more than 37,000 failed transactions and nearly $30,000 in gas costs spent on reverted trades.
A second example focused on a malicious Uniswap v4 hook deployed on Polygon.
The researchers reported that the hook generated a transaction failure rate of roughly 99.
1%, repeatedly attracting routing algorithms before causing transactions to revert.
One aspect that surprised researchers was that the Ethereum-based pool did not behave maliciously all the time.
Instead, it alternated between honest and manipulated execution, making periodic simulations or manual inspections insufficient to identify the pattern.
The investigation also uncovered several oracle contracts deployed by the same operator to support additional liquidity pools, suggesting that similar techniques could potentially be replicated across other markets.
"Our investigation leads us to believe this is not simply another isolated smart contract exploit," said Milos Costantini, co-founder and chief product officer at Enso.
"The industry has spent years optimizing price discovery.
Our findings suggest the next challenge is verifying execution integrity.
If transaction simulations can be manipulated while real execution tells a different story, we need better ways to verify what users actually receive.
".
Alongside the publication of its findings, Enso announced new capabilities for Enso Shield, the company's execution-protection layer.
The updated system introduces dedicated toxic-pool detection and execution verification tools that go beyond standard transaction simulations.
Rather than relying solely on simulated quotes, Enso Shield continuously evaluates live on-chain conditions, monitors quote consistency over time and verifies completed execution using transaction traces to identify discrepancies that conventional simulation methods may overlook.
Enso believes the research raises broader questions about execution integrity across decentralized trading infrastructure, particularly for wallets, DEX aggregators and routing protocols that depend heavily on simulated transaction results.
Rather than attributing responsibility to any individual protocol, the company is encouraging further industry research and independent validation to determine how widespread similar attack patterns may be and whether additional safeguards are needed to improve execution transparency across decentralized finance.