Attack-Centric by Design: A Program-Structure Taxonomy of Smart Contract Vulnerabilities

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Hedayatnia, Parsa, Tavakkoli, Tina, Amini, Hadi, Allahbakhsh, Mohammad, Amintoosi, Haleh
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866912704204111872
author Hedayatnia, Parsa
Tavakkoli, Tina
Amini, Hadi
Allahbakhsh, Mohammad
Amintoosi, Haleh
author_facet Hedayatnia, Parsa
Tavakkoli, Tina
Amini, Hadi
Allahbakhsh, Mohammad
Amintoosi, Haleh
contents Smart contracts concentrate high value assets and complex logic in small, immutable programs, where even minor bugs can cause major losses. Existing taxonomies and tools remain fragmented, organized around symptoms such as reentrancy rather than structural causes. This paper introduces an attack-centric, program-structure taxonomy that unifies Solidity vulnerabilities into eight root-cause families covering control flow, external calls, state integrity, arithmetic safety, environmental dependencies, access control, input validation, and cross-domain protocol assumptions. Each family is illustrated through concise Solidity examples, exploit mechanics, and mitigations, and linked to the detection signals observable by static, dynamic, and learning-based tools. We further cross-map legacy datasets (SmartBugs, SolidiFI) to this taxonomy to reveal label drift and coverage gaps. The taxonomy provides a consistent vocabulary and practical checklist that enable more interpretable detection, reproducible audits, and structured security education for both researchers and practitioners.
format Preprint
id arxiv_https___arxiv_org_abs_2511_09051
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Attack-Centric by Design: A Program-Structure Taxonomy of Smart Contract Vulnerabilities
Hedayatnia, Parsa
Tavakkoli, Tina
Amini, Hadi
Allahbakhsh, Mohammad
Amintoosi, Haleh
Cryptography and Security
Distributed, Parallel, and Cluster Computing
68N30
D.2.4
Smart contracts concentrate high value assets and complex logic in small, immutable programs, where even minor bugs can cause major losses. Existing taxonomies and tools remain fragmented, organized around symptoms such as reentrancy rather than structural causes. This paper introduces an attack-centric, program-structure taxonomy that unifies Solidity vulnerabilities into eight root-cause families covering control flow, external calls, state integrity, arithmetic safety, environmental dependencies, access control, input validation, and cross-domain protocol assumptions. Each family is illustrated through concise Solidity examples, exploit mechanics, and mitigations, and linked to the detection signals observable by static, dynamic, and learning-based tools. We further cross-map legacy datasets (SmartBugs, SolidiFI) to this taxonomy to reveal label drift and coverage gaps. The taxonomy provides a consistent vocabulary and practical checklist that enable more interpretable detection, reproducible audits, and structured security education for both researchers and practitioners.
title Attack-Centric by Design: A Program-Structure Taxonomy of Smart Contract Vulnerabilities
topic Cryptography and Security
Distributed, Parallel, and Cluster Computing
68N30
D.2.4
url https://arxiv.org/abs/2511.09051