[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-83123-en":3,"doc-seo-83123-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},83123,1099514067438,"River Wang","https://ap-avatar.wpscdn.com/avatar/100002539ee87300030?x-image-process=image/resize,m_fixed,w_180,h_180&k=1780474512215547542",8,"Research & Report","Blockchain Attacks and Defenses: A Layered and Cross-Domain Survey","Blockchain systems have transformed from simple distributed ledgers into programmable platforms that execute high-value application logic, shifting the attack surface from isolated infrastructure disruption to programmable economic abuse and cross-domain exploits. This survey categorizes blockchain threats and defenses using a four-tier layered architecture (network, cryptographic, consensus, application) and cross-domain trust boundaries. It reviews how blockchain security research evolved over the past decade, especially with DeFi and cross-chain interoperability.","arXiv :2607 .06593v 1 [ cs .CR] 6 Jul 2026  \nBlockchain Attacks and Defenses: A Layered and Cross-Domain Survey  \nJUNJIE HU and NA RUAN, School of Computer Science, Shanghai Jiao Tong University, China  \nBlockchains have evolved from simple distributed ledgers into programmable platforms that process complex application logic and carry significant financial value. All modern Web3 systems share a common goal: providing secure, decentralized, and trustworthy execution in an increasingly interconnected environment. However, this evolution has shifted the attack surface from isolated infrastructure disruptions to programmable economic abuse and cross-domain exploits. In this article, we focus on the research of blockchain attacks and defenses. In particular, we categorize the threat landscape and corresponding mitigation strategies according to both a four-tier layered architecture (network, cryptographic, consensus, and application) and crossdomain trust boundaries. We seek to answer these important questions: How has the research in blockchain security evolved over the past decade, especially with the rise of decentralized finance (DeFi) and cross-chain interoperability? How do local security assumptions fail when protocols are composed, and what are the driving needs for Web3 security research in the future?  \nCCS Concepts: • Security and privacy → Distributed systems security; Economics of security and privacy. Additional Key Words and Phrases: Blockchain security, Web3 security, smart contracts, DeFi, consensus, MEV, cross-chain bridges  \nACM Reference Format:  \nJunjie Hu and Na Ruan. 2026. Blockchain Attacks and Defenses: A Layered and Cross-Domain Survey. 1, 1  \n(July 2026), 35 pages. [https://doi.org/10.1145/nnnnnnn.nnnnnnn](https://doi.org/10.1145/nnnnnnn.nnnnnnn)  \n1 Introduction  \n1.1 Background and Motivation  \nOver the past decade, blockchains have evolved from single-asset ledgers [24] into programmable settlement platforms. Unlike distributed databases focused on replication [177], smart-contract systems execute DeFi and Web3 workflows under open, irreversible, and financially valuable conditions. This coupling changes the threat model: a small implementation bug or economic misconfiguration can immediately become a large loss.  \nThe locus of blockchain security has shifted from infrastructure disruption to programmable economic abuse (Figure 2) . Early attacks targeted P2P networks and consensus bounds; later work focused on smart-contract bytecode flaws. Modern attacks increasingly exploit assumption mismatches—the gap between a protocol’s local guarantee and how other systems consume it. Recent work on PoS incentives, fee rules, MEV, validator deanonymization, and zkEVM soundness shows that these risks now interact within the same adversarial economy [94, 98, 130, 139, 166, 236] .  \nAuthors’ Contact Information: Junjie Hu, [nakamoto@sjtu.edu.cn](nakamoto@sjtu.edu.cn); Na Ruan, [naruan@sjtu.edu.cn](naruan@sjtu.edu.cn), School of Computer  \nScience, Shanghai Jiao Tong University, Shanghai, China.  \nThis research has received support from National Key R&D Program of China (2023YFB2704700), National Natural Science Foundation of China (62472276), and Science and Technology Project of the State Grid Corporation of China (5700- 202321603A-3-2-ZN) .  \nPermission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than the author(s) must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires [prior specific permission and/or a fee. Request permissions from permissions@acm.org](prior specific permission and/or a fee. Request permissions from permissions@acm.org).  \n© 202","cbCaigtzzH43c91S","https://ap.wps.com/l/cbCaigtzzH43c91S","pdf",19534806,2,1,35,"English","en",105,"# Introduction\n## Background and Motivation\n## Limitations of Existing Surveys\n# Layered and Cross-Domain Taxonomy\n## Threat Landscape and Mitigation Strategies\n# Evolution of Blockchain Security Research\n## DeFi, MEV, and Cross-Chain Interoperability","[{\"question\":\"What major change in the blockchain threat model is emphasized in the survey?\",\"answer\":\"Security risks shift from infrastructure disruption to programmable economic abuse, where economic misconfiguration and implementation bugs can trigger large losses across interconnected components.\"},{\"question\":\"How does the survey organize attacks and defenses?\",\"answer\":\"It uses a four-tier layered architecture—network, cryptographic, consensus, and application—combined with cross-domain trust boundaries.\"},{\"question\":\"What gaps does the survey claim exist in earlier blockchain security surveys?\",\"answer\":\"Earlier work is described as outdated in scope, siloed in analysis, and uneven in evidence, often underdeveloping DeFi/oracles/L2 issues and failing to connect network, consensus incentives, MEV, and application logic.\"}]",1784185439,88,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"blockchain-attacks-and-defenses-a-layered-and-cross-domain-survey","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,47,50],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":20},"https://docshare.wps.com/document/","Document",{"item":48,"name":12,"@type":43,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":43,"position":52},"https://docshare.wps.com/document/blockchain-attacks-and-defenses-a-layered-and-cross-domain-survey/83123/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-23","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What major change in the blockchain threat model is emphasized in the survey?","Question",{"text":75,"@type":76},"Security risks shift from infrastructure disruption to programmable economic abuse, where economic misconfiguration and implementation bugs can trigger large losses across interconnected components.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does the survey organize attacks and defenses?",{"text":80,"@type":76},"It uses a four-tier layered architecture—network, cryptographic, consensus, and application—combined with cross-domain trust boundaries.",{"name":82,"@type":73,"acceptedAnswer":83},"What gaps does the survey claim exist in earlier blockchain security surveys?",{"text":84,"@type":76},"Earlier work is described as outdated in scope, siloed in analysis, and uneven in evidence, often underdeveloping DeFi/oracles/L2 issues and failing to connect network, consensus incentives, MEV, and application logic.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]