What are the Actual Flaws in Important Smart Contracts (and How Can We Find Them)?

11/18/2019
by   Alex Groce, et al.
0

We summarize and systematically categorize results from more than 20 security assessments of Ethereum smart contracts performed by a leading company in blockchain security. These assessments contain over 200 individual defect findings. By limiting our results to contracts for which assessment by paid experts was deemed worthwhile, we avoid the problem of over-reporting problems that primarily appear in low-quality, uninteresting contracts. Because findings are based on expert human analysis aided by high-quality public and internal analysis tools, we expect that the results are generally representative of actual weaknesses in important contracts. These results make it possible to compare impact and frequency of different flaw types, contrast smart contract flaws with non-smart-contract flaws, and estimate the potential of automated flaw-detection approaches.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
09/06/2020

DEFECTCHECKER: Automated Smart Contract Defect Detection by Analyzing EVM Bytecode

Smart contracts are Turing-complete programs running on the blockchain. ...
research
07/16/2020

Inheritance software metrics on smart contracts

Blockchain systems have gained substantial traction recently, partly due...
research
01/10/2013

A Clustering Approach to Solving Large Stochastic Matching Problems

In this work we focus on efficient heuristics for solving a class of sto...
research
06/01/2022

Not so immutable: Upgradeability of Smart Contracts on Ethereum

A smart contract that is deployed to a blockchain system like Ethereum i...
research
09/12/2022

An Investigation of Smart Contract for Collaborative Machine Learning Model Training

Machine learning (ML) has penetrated various fields in the era of big da...
research
02/14/2023

Security Threat Mitigation For Smart Contracts: A Survey

The blockchain technology has been used for recording state transitions ...
research
08/31/2020

A Comprehensive Survey on Smart Contract Construction and Execution: Paradigms, Tools and Systems

Smart contract has been regarded as one of the most promising and appeal...

Please sign up or login with your details

Forgot password? Click here to reset