On-Chain Analysis of Smart Contract Dependency Risks on Ethereum

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Jin, Monica, Liu, Raphina, Monperrus, Martin
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909561116426240
author Jin, Monica
Liu, Raphina
Monperrus, Martin
author_facet Jin, Monica
Liu, Raphina
Monperrus, Martin
contents In this paper, we present the first large-scale empirical study of smart contract dependencies, analyzing over 41 million contracts and 11 billion interactions on Ethereum up to December 2024. Our results yield four key insights: (1) 59% of contract transactions involve multiple contracts (median of 4 per transaction in 2024) indicating potential smart contract dependency risks; (2) the ecosystem exhibits extreme centralization, with just 11 (0.001%) deployers controlling 20.5 million (50%) of alive contracts, with major risks related to factory contracts and deployer privileges; (3) three most depended-upon contracts are mutable, meaning large parts of the ecosystem rely on contracts that can be altered at any time, which is a significant risk, (4) actual smart contract protocol dependencies are significantly more complex than officially documented, undermining Ethereum's transparency ethos, and creating unnecessary attack surface. Our work provides the first large-scale empirical foundation for understanding smart contract dependency risks, offering crucial insights for developers, users, and security researchers in the blockchain space.
format Preprint
id arxiv_https___arxiv_org_abs_2503_19548
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle On-Chain Analysis of Smart Contract Dependency Risks on Ethereum
Jin, Monica
Liu, Raphina
Monperrus, Martin
Software Engineering
Cryptography and Security
In this paper, we present the first large-scale empirical study of smart contract dependencies, analyzing over 41 million contracts and 11 billion interactions on Ethereum up to December 2024. Our results yield four key insights: (1) 59% of contract transactions involve multiple contracts (median of 4 per transaction in 2024) indicating potential smart contract dependency risks; (2) the ecosystem exhibits extreme centralization, with just 11 (0.001%) deployers controlling 20.5 million (50%) of alive contracts, with major risks related to factory contracts and deployer privileges; (3) three most depended-upon contracts are mutable, meaning large parts of the ecosystem rely on contracts that can be altered at any time, which is a significant risk, (4) actual smart contract protocol dependencies are significantly more complex than officially documented, undermining Ethereum's transparency ethos, and creating unnecessary attack surface. Our work provides the first large-scale empirical foundation for understanding smart contract dependency risks, offering crucial insights for developers, users, and security researchers in the blockchain space.
title On-Chain Analysis of Smart Contract Dependency Risks on Ethereum
topic Software Engineering
Cryptography and Security
url https://arxiv.org/abs/2503.19548