Attack-Centric by Design: A Program-Structure Taxonomy of Smart Contract Vulnerabilities
Fuente:
arXiv
Saved in:
| Main Authors: | , , , , |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
| _version_ | 1866912704204111872 |
|---|---|
| author | Hedayatnia, Parsa Tavakkoli, Tina Amini, Hadi Allahbakhsh, Mohammad Amintoosi, Haleh |
| author_facet | Hedayatnia, Parsa Tavakkoli, Tina Amini, Hadi Allahbakhsh, Mohammad Amintoosi, Haleh |
| contents | Smart contracts concentrate high value assets and complex logic in small, immutable programs, where even minor bugs can cause major losses. Existing taxonomies and tools remain fragmented, organized around symptoms such as reentrancy rather than structural causes. This paper introduces an attack-centric, program-structure taxonomy that unifies Solidity vulnerabilities into eight root-cause families covering control flow, external calls, state integrity, arithmetic safety, environmental dependencies, access control, input validation, and cross-domain protocol assumptions. Each family is illustrated through concise Solidity examples, exploit mechanics, and mitigations, and linked to the detection signals observable by static, dynamic, and learning-based tools. We further cross-map legacy datasets (SmartBugs, SolidiFI) to this taxonomy to reveal label drift and coverage gaps. The taxonomy provides a consistent vocabulary and practical checklist that enable more interpretable detection, reproducible audits, and structured security education for both researchers and practitioners. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2511_09051 |
| institution | arXiv |
| publishDate | 2025 |
| record_format | arxiv |
| spellingShingle | Attack-Centric by Design: A Program-Structure Taxonomy of Smart Contract Vulnerabilities Hedayatnia, Parsa Tavakkoli, Tina Amini, Hadi Allahbakhsh, Mohammad Amintoosi, Haleh Cryptography and Security Distributed, Parallel, and Cluster Computing 68N30 D.2.4 Smart contracts concentrate high value assets and complex logic in small, immutable programs, where even minor bugs can cause major losses. Existing taxonomies and tools remain fragmented, organized around symptoms such as reentrancy rather than structural causes. This paper introduces an attack-centric, program-structure taxonomy that unifies Solidity vulnerabilities into eight root-cause families covering control flow, external calls, state integrity, arithmetic safety, environmental dependencies, access control, input validation, and cross-domain protocol assumptions. Each family is illustrated through concise Solidity examples, exploit mechanics, and mitigations, and linked to the detection signals observable by static, dynamic, and learning-based tools. We further cross-map legacy datasets (SmartBugs, SolidiFI) to this taxonomy to reveal label drift and coverage gaps. The taxonomy provides a consistent vocabulary and practical checklist that enable more interpretable detection, reproducible audits, and structured security education for both researchers and practitioners. |
| title | Attack-Centric by Design: A Program-Structure Taxonomy of Smart Contract Vulnerabilities |
| topic | Cryptography and Security Distributed, Parallel, and Cluster Computing 68N30 D.2.4 |
| url | https://arxiv.org/abs/2511.09051 |