SafeMath를 활용한 보안 코딩
산술 연산에서 정수 오버플로 및 언더플로 공격을 방지하기 위해 SafeMath와 같은 라이브러리를 사용하는 방법을 학습합니다.
SafeMath를 활용한 보안 코딩은(는) CoddyKit의 무료 Blockchain Smart Contracts with Solidity 강의입니다. 이것은 4개 중 3번째 강의입니다. 아래에서 전체 강의를 무료로 읽을 수 있으며, 내장 코드 에디터와 24/7 AI 튜터와 함께 브라우저에서 직접 실습할 수 있습니다. 이 강의는 Blockchain Smart Contracts with Solidity 학습 경로의 일부이며, 진행 상황이 웹과 CoddyKit 앱에 동기화됩니다. Blockchain Smart Contracts with Solidity 강의에는 총 4개의 강의가 포함되어 있습니다.
이 강의의 일부는 아직 번역되지 않았으며 영어로 표시됩니다.
The Integer Problem
In Solidity, integer types like uint256 have a fixed size. This means they can only store numbers up to a certain maximum value and down to a minimum (usually 0 for unsigned integers).
When an arithmetic operation exceeds these limits, it can lead to critical vulnerabilities called integer overflows and underflows.
Unchecked Math Dangers
Solidity's default arithmetic operations (+, -, *, /) do not automatically check for overflows or underflows. Instead, the number 'wraps around'.
This behavior can be exploited by attackers, leading to incorrect token balances, unexpected contract state, and financial losses.
Overflow in Action
Consider a uint8 variable, which can hold values from 0 to 255. What happens if we try to add 1 to 255? Run this code and call incrementUnsafely(). You'll see the value reset to 0!
/*
This contract demonstrates an integer overflow.
A uint8 can only hold values from 0 to 255.
Adding 1 to 255 will cause it to wrap around to 0.
*/
// SPDX-License-Identifier: MIT
pragma solidity ^0.8.0;
contract UnsafeCounter {
uint8 public count = 255; // Max value for uint8
// Function to increment the counter unsafely
function incrementUnsafely() public {
count = count + 1;
}
}Underflow Example
Similarly, an underflow occurs when a number goes below its minimum value. For a uint (unsigned integer), the minimum is 0.
If you subtract 1 from 0, it wraps around to the maximum value (255 for uint8, or 2^256 - 1 for uint256).
/*
This contract demonstrates an integer underflow.
A uint8 can only hold values from 0 to 255.
Subtracting 1 from 0 will cause it to wrap around to 255.
*/
// SPDX-License-Identifier: MIT
pragma solidity ^0.8.0;
contract UnderflowDemo {
uint8 public value = 0; // Min value for uint8
// Function to decrement the value unsafely
function decrementUnsafely() public {
value = value - 1;
}
}Introducing SafeMath
To prevent these critical errors, we use libraries like SafeMath. SafeMath provides functions for arithmetic operations (addition, subtraction, multiplication, division) that revert the transaction if an overflow or underflow would occur.
This ensures your contract's state remains consistent and secure, preventing malicious exploits.
Solidity Libraries Explained
A Solidity Library is a special type of contract that contains reusable code. Unlike regular contracts, libraries are stateless (they don't store data directly) and cannot hold Ether.
- They are deployed once and their functions are called via
DELEGATECALL. - This means the library's code runs in the context of the calling contract.
- Libraries are perfect for shared utility functions like SafeMath.
Integrating SafeMath
To use SafeMath, you typically import it from a trusted source like OpenZeppelin. Then, you tell Solidity to apply SafeMath's functions to a specific integer type using the using A for B; directive.
This makes SafeMath's functions available as member functions on type B.
/*
This contract demonstrates how to integrate and use SafeMath.
We're including a simplified mock SafeMath library for demonstration.
*/
// SPDX-License-Identifier: MIT
pragma solidity ^0.8.0;
// A simplified mock SafeMath library for demonstration
library SafeMath {
function add(uint256 a, uint256 b) internal pure returns (uint256) {
uint256 c = a + b;
require(c >= a, "SafeMath: addition overflow");
return c;
}
}
contract MySafeContract {
// Use SafeMath functions for all uint256 variables
using SafeMath for uint256;
uint256 public balance = 100;
function deposit(uint256 amount) public {
// Now you can call .add() directly on balance
balance = balance.add(amount);
}
function getBalance() public view returns (uint256) {
return balance;
}
}Safe Addition in Action
With SafeMath integrated, you use .add() instead of the standard + operator. If the addition would overflow, the transaction will revert, preventing incorrect state changes.
Call safeAdd() with a value like 10. Try calling it with a value that would cause an overflow (e.g., if total was max uint8 and you added 1).
/*
This contract uses SafeMath for secure addition.
If the addition causes an overflow, the transaction will revert.
*/
// SPDX-License-Identifier: MIT
pragma solidity ^0.8.0;
library SafeMath {
function add(uint256 a, uint256 b) internal pure returns (uint256) {
uint256 c = a + b;
require(c >= a, "SafeMath: addition overflow");
return c;
}
}
contract SafeAdder {
using SafeMath for uint256;
uint256 public total = 0;
function safeAdd(uint256 _value) public {
total = total.add(_value); // Uses SafeMath.add
}
}Safe Subtraction in Action
Similarly, use .sub() for subtraction. This prevents underflows, ensuring that a subtraction operation will revert if the result would be negative (below zero for unsigned integers).
Call safeSubtract() with a value like 10. Try calling it with a value larger than balance (e.g., 101) to see it revert.
/*
This contract uses SafeMath for secure subtraction.
If the subtraction causes an underflow, the transaction will revert.
*/
// SPDX-License-Identifier: MIT
pragma solidity ^0.8.0;
library SafeMath {
function sub(uint256 a, uint256 b) internal pure returns (uint256) {
require(b <= a, "SafeMath: subtraction underflow");
uint256 c = a - b;
return c;
}
}
contract SafeSubtractor {
using SafeMath for uint256;
uint256 public balance = 100;
function safeSubtract(uint256 _value) public {
balance = balance.sub(_value); // Uses SafeMath.sub
}
}Multiply, Divide, Modulo
SafeMath also provides .mul(), .div(), and .mod() for multiplication, division, and modulo operations, respectively.
.mul()checks for overflow..div()checks for division by zero and overflow..mod()checks for division by zero.
Always use these safe versions for critical arithmetic in your contracts.
Quick Check on SafeMath
You've learned about the importance of SafeMath. Let's test your understanding.
Recap: Secure Math
You've learned about the critical vulnerabilities of integer overflows and underflows in Solidity and how SafeMath provides a robust solution.
- Always use SafeMath (or similar audited libraries) for arithmetic operations on unsigned integers in your smart contracts.
- This prevents unexpected behavior and protects your contract's integrity.
Keep practicing secure coding! The next lessons will dive deeper into advanced security patterns.
자주 묻는 질문
“SafeMath를 활용한 보안 코딩” 강의는 무료인가요?
네 — “SafeMath를 활용한 보안 코딩” 전체 내용을 이 웹사이트에서 무료로 읽을 수 있습니다. 인터랙티브하게 실습하려면(내장 코드 에디터와 24/7 AI 튜터), CoddyKit PRO로 업그레이드하면 Blockchain Smart Contracts with Solidity 강의 전체를 잠금 해제할 수 있습니다. Blockchain Smart Contracts with Solidity 강의에는 총 4개의 강의가 포함되어 있습니다.
“SafeMath를 활용한 보안 코딩”에서 뭘 배우나요?
산술 연산에서 정수 오버플로 및 언더플로 공격을 방지하기 위해 SafeMath와 같은 라이브러리를 사용하는 방법을 학습합니다. 브라우저에서 직접 실행하는 실습 코드로 Blockchain Smart Contracts with Solidity을(를) 배우며, 24/7 AI 튜터가 강의를 진행하면서 질문에 답변해줍니다.
Blockchain Smart Contracts with Solidity을(를) 시작하는 데 경험이 필요한가요?
사전 경험은 필요하지 않습니다. CoddyKit의 Blockchain Smart Contracts with Solidity은(는) 초급자부터 고급 학습자까지를 위해 구성되어 있으므로, 여기서 시작하거나 처음부터 시작할 수 있으며 자신의 속도대로 진행할 수 있습니다. 이것은 4개 중 3번째 강의입니다.
“SafeMath를 활용한 보안 코딩” 강의는 얼마나 걸리나요?
대부분의 CoddyKit 강의는 약 5~10분이 소요됩니다. 각 강의는 간결하고 인터랙티브하여 꾸준한 진행이 가능하며, 웹과 앱에서 중단한 부분부터 바로 시작할 수 있습니다.
이 Blockchain Smart Contracts with Solidity 강의에서 코드를 작성하고 실행할 수 있나요?
네. 모든 Blockchain Smart Contracts with Solidity 강의에는 내장 코드 에디터가 포함되어 있으므로, 브라우저에서 바로 실제 코드를 작성하고 실행한 후 즉시 AI 피드백을 받을 수 있습니다 — 로컬 설정이 필요 없습니다.
이 강의의 모든 강의
- 일반적인 취약점(재진입 등)
- 접근 제어 패턴
- SafeMath를 활용한 보안 코딩
- 감사, 테스트, 버그 바운티