Detecting State Inconsistency Bugs in DApps via On-Chain Transaction Replay and Fuzzing
Mingxi Ye, Yuhong Nan, Zibin Zheng, Dongpeng Wu, Huizhong Li
Abstract
Decentralized applications (DApps) consist of multiple smart contracts running on Blockchain. With the increasing popularity of the DApp ecosystem, vulnerabilities in DApps could bring significant impacts such as financial losses. Identifying vulnerabilities in DApps is by no means trivial, as modern DApps consist of complex interactions across multiple contracts. Previous research suffers from either high false positives or false negatives, due to the lack of precise contextual information which is mandatory for confirming smart contract vulnerabilities when analyzing smart contracts.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 065a1144-2d54-488d-98a4-5a79714b2f12Cited by top-tier papers9
- Nyx: Detecting Exploitable Front-Running Vulnerabilities in Smart ContractsWuqi Zhang, Zhuo Zhang, Qingkai Shi, Lu Liu et al.S&P 2024 · 23 citations
- SlimArchive: A Lightweight Architecture for Ethereum Archive NodesHang Feng, Yufeng Hu, Yinghan Kou, Runhuai Li et al.USENIX ATC 2024 · 11 citations
- Smartreco: Detecting Read-Only Reentrancy via Fine-Grained Cross-DApp AnalysisJingwen Zhang, Zibin Zheng, Yuhong Nan, Mingxi Ye et al.ICSE 2025 · 4 citations
- Demystifying and Detecting Cryptographic Defects in Ethereum Smart ContractsJiashuo Zhang, Yiming Shen, Jiachi Chen, Jianzhong Su et al.ICSE 2025 · 2 citations
- SigScope: Detecting and Understanding Off-Chain Message Signing-related Vulnerabilities in Decentralized ApplicationsSajad Meisami, Hugo Dabadie, Song Li, Yuzhe Tang et al.WWW 2025 · 2 citations
Related papers
- SmartDagger: a bytecode-based static analysis approach for detecting cross-contract vulnerabilityZeqin Liao, Zibin Zheng, Xiao Chen, Yuhong NanISSTA 2022 · 64 citations
- Finding Insecure State Dependency in DApps via Multi-Source Tracing and Semantic EnrichmentJingwen Zhang, Yuhong Nan, Wei Li, Kaiwen Ning et al.ASE 2025 · 1 citation
- EOSAFE: Security Analysis of EOSIO Smart ContractsNingyu He, Ruiyi Zhang, Haoyu Wang, Lei Wu et al.USENIX Security 2021 · 69 citations
- Bad Apples: Understanding the Centralized Security Risks in Decentralized EcosystemsKailun Yan, Jilian Zhang, Xiangyu Liu, Wenrui Diao et al.WWW 2023 · 12 citations
- Confusum Contractum: Confused Deputy Vulnerabilities in Ethereum Smart ContractsFabio Gritti, Nicola Ruaro, Robert McLaughlin, Priyanka Bose et al.USENIX Security 2023
