BugMagnifier: TON Transaction Simulator for Revealing Smart Contract Vulnerabilities
Fuente:
arXiv
Saved in:
| Main Authors: | , , , , , , , , |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
| _version_ | 1866911637243428864 |
|---|---|
| author | Yanovich, Yury Kovalevskaya, Victoria Egorov, Maksim Smirnova, Elizaveta Mishuris, Matvey Madhwal, Yash Ziborov, Kirill Gorgadze, Vladimir Sharma, Subodh |
| author_facet | Yanovich, Yury Kovalevskaya, Victoria Egorov, Maksim Smirnova, Elizaveta Mishuris, Matvey Madhwal, Yash Ziborov, Kirill Gorgadze, Vladimir Sharma, Subodh |
| contents | The Open Network (TON) blockchain employs an asynchronous execution model that introduces unique security challenges for smart contracts. A primary concern is race conditions arising from unpredictable message processing order. While previous work established vulnerability patterns through static analysis of audit reports, dynamic detection of temporal dependencies through systematic testing remains an open problem. This study proposes a dynamic evaluation methodology based on controlled message orchestration to systematically expose vulnerabilities in asynchronous smart contracts. By synthesizing precise message queue manipulation with differential state analysis and probabilistic permutation testing, we establish a framework (namely, BugMagnifier) for identifying execution flaws that static methods miss. Experimental evaluation demonstrates BugMagnifier's effectiveness through extensive parametric studies on purpose-built vulnerable contracts and five real-world vulnerability cases reproduced from recent security audits. Results reveal message ratio-dependent detection complexity that aligns with theoretical predictions. This quantitative model enables predictive vulnerability assessment while shifting discovery from manual expert analysis to automated evidence generation. By providing reproducible test scenarios for temporal vulnerabilities, BugMagnifier addresses a critical gap in the TON security tooling, offering practical support for safer smart contract development in asynchronous blockchain environments. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2509_24444 |
| institution | arXiv |
| publishDate | 2025 |
| record_format | arxiv |
| spellingShingle | BugMagnifier: TON Transaction Simulator for Revealing Smart Contract Vulnerabilities Yanovich, Yury Kovalevskaya, Victoria Egorov, Maksim Smirnova, Elizaveta Mishuris, Matvey Madhwal, Yash Ziborov, Kirill Gorgadze, Vladimir Sharma, Subodh Cryptography and Security Distributed, Parallel, and Cluster Computing The Open Network (TON) blockchain employs an asynchronous execution model that introduces unique security challenges for smart contracts. A primary concern is race conditions arising from unpredictable message processing order. While previous work established vulnerability patterns through static analysis of audit reports, dynamic detection of temporal dependencies through systematic testing remains an open problem. This study proposes a dynamic evaluation methodology based on controlled message orchestration to systematically expose vulnerabilities in asynchronous smart contracts. By synthesizing precise message queue manipulation with differential state analysis and probabilistic permutation testing, we establish a framework (namely, BugMagnifier) for identifying execution flaws that static methods miss. Experimental evaluation demonstrates BugMagnifier's effectiveness through extensive parametric studies on purpose-built vulnerable contracts and five real-world vulnerability cases reproduced from recent security audits. Results reveal message ratio-dependent detection complexity that aligns with theoretical predictions. This quantitative model enables predictive vulnerability assessment while shifting discovery from manual expert analysis to automated evidence generation. By providing reproducible test scenarios for temporal vulnerabilities, BugMagnifier addresses a critical gap in the TON security tooling, offering practical support for safer smart contract development in asynchronous blockchain environments. |
| title | BugMagnifier: TON Transaction Simulator for Revealing Smart Contract Vulnerabilities |
| topic | Cryptography and Security Distributed, Parallel, and Cluster Computing |
| url | https://arxiv.org/abs/2509.24444 |