Program Analysis for High-Value Smart Contract Vulnerabilities: Techniques and Insights

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Smaragdakis, Yannis, Grech, Neville, Lagouvardos, Sifis, Triantafyllou, Konstantinos, Tsatiris, Ilias, Bollanos, Yannis, Valentine, Tony Rocco
Formato: Preprint
Publicado: 2025
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866909709106151424
author Smaragdakis, Yannis
Grech, Neville
Lagouvardos, Sifis
Triantafyllou, Konstantinos
Tsatiris, Ilias
Bollanos, Yannis
Valentine, Tony Rocco
author_facet Smaragdakis, Yannis
Grech, Neville
Lagouvardos, Sifis
Triantafyllou, Konstantinos
Tsatiris, Ilias
Bollanos, Yannis
Valentine, Tony Rocco
contents A widespread belief in the blockchain security community is that automated techniques are only good for detecting shallow bugs, typically of small value. In this paper, we present the techniques and insights that have led us to repeatable success in automatically discovering high-value smart contract vulnerabilities. Our vulnerability disclosures have yielded 10 bug bounties, for a total of over $3M, over high-profile deployed code, as well as hundreds of bugs detected in pre-deployment or under-audit code. We argue that the elements of this surprising success are a) a very high-completeness static analysis approach that manages to maintain acceptable precision; b) domain knowledge, provided by experts or captured via statistical inference. We present novel techniques for automatically inferring domain knowledge from statistical analysis of a large corpus of deployed contracts, as well as discuss insights on the ideal precision and warning rate of a promising vulnerability detector. In contrast to academic literature in program analysis, which routinely expects false-positive rates below 50% for publishable results, we posit that a useful analysis for high-value real-world vulnerabilities will likely flag very few programs (under 1%) and will do so with a high false-positive rate (e.g., 95%, meaning that only one-of-twenty human inspections will yield an exploitable vulnerability).
format Preprint
id arxiv_https___arxiv_org_abs_2507_20672
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Program Analysis for High-Value Smart Contract Vulnerabilities: Techniques and Insights
Smaragdakis, Yannis
Grech, Neville
Lagouvardos, Sifis
Triantafyllou, Konstantinos
Tsatiris, Ilias
Bollanos, Yannis
Valentine, Tony Rocco
Cryptography and Security
Programming Languages
A widespread belief in the blockchain security community is that automated techniques are only good for detecting shallow bugs, typically of small value. In this paper, we present the techniques and insights that have led us to repeatable success in automatically discovering high-value smart contract vulnerabilities. Our vulnerability disclosures have yielded 10 bug bounties, for a total of over $3M, over high-profile deployed code, as well as hundreds of bugs detected in pre-deployment or under-audit code. We argue that the elements of this surprising success are a) a very high-completeness static analysis approach that manages to maintain acceptable precision; b) domain knowledge, provided by experts or captured via statistical inference. We present novel techniques for automatically inferring domain knowledge from statistical analysis of a large corpus of deployed contracts, as well as discuss insights on the ideal precision and warning rate of a promising vulnerability detector. In contrast to academic literature in program analysis, which routinely expects false-positive rates below 50% for publishable results, we posit that a useful analysis for high-value real-world vulnerabilities will likely flag very few programs (under 1%) and will do so with a high false-positive rate (e.g., 95%, meaning that only one-of-twenty human inspections will yield an exploitable vulnerability).
title Program Analysis for High-Value Smart Contract Vulnerabilities: Techniques and Insights
topic Cryptography and Security
Programming Languages
url https://arxiv.org/abs/2507.20672