Learning from the Past: Real-World Exploit Migration for Smart Contract PoC Generation
Kairan Sun, Zhengzi Xu, Kaixuan Li, Lyuye Zhang, Yebo Feng, Daoyuan Wu, Yang Liu
Abstract
Smart contract vulnerabilities continue to cause significant financial losses, despite the implementation of security measures such as manual audits and bug bounty platforms. A critical component often required by these security measures is the proof-of-concept (PoC) exploit, which validates vulnerability exploitability, assesses impact severity, and guides developers in fixes. Existing tools have explored automated PoC generation with techniques like symbolic execution, fuzzing, and program synthesis. However, these approaches frequently fail to generate PoCs for vulnerabilities exploited in real-world incidents, primarily due to their limitations in handling complex transaction dependencies, navigating vast on-chain state spaces, or requiring extensive manual specifications. Our migration-based approach extracts critical information from documented security incidents and applies it to generate PoCs for similar vulnerable code. This approach leverages proven exploit patterns rather than generating PoCs from scratch. This approach is motivated by two key observations: the prevalence of code reuse in smart contracts (up to 90% at the function level) and the increasing availability of documented PoCs for real-world incidents. Our approach operates in three phases: (1) abstracting essential components (i.e., environment properties, attack logic, and verification checks) from existing PoCs into templates, (2) given a new target contract, selecting suitable templates with adapted values through clone-detection and property-feasibility analysis, and (3) generating and validating PoCs in simulated environments. Our evaluation demonstrates effectiveness and efficiency across multiple scales. Our approach successfully generates valid PoCs for 62 out of 67 manually validated cases without false positives and completes analysis in 3.8 hours compared to 133.2 and 210.5 hours required by existing tools. Large-scale evaluation on 979,512 contracts identifies 256 vulnerable contracts across blockchain networks with 64 cross-chain cases, demonstrating real-world applicability.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 071598be-7433-4309-9690-34f0733a5d68Cited by top-tier papers1
Ask how each one uses itBuilds on17
- teEther: Gnawing at Ethereum to Automatically Exploit Smart ContractsJohannes Krupp, Christian RossowUSENIX Security 2018 · 345 citations
- sFuzz: an efficient adaptive fuzzer for solidity smart contractsTai D. Nguyen, Long H. Pham, Jun Sun, Yun Lin et al.ICSE 2020 · 260 citations
- Smart Contract Vulnerabilities: Vulnerable Does Not Imply ExploitedDaniel Perez, Benjamin LivshitsUSENIX Security 2021 · 150 citations
- Demystifying Exploitable Bugs in Smart ContractsZhuo Zhang, Brian Zhang, Wen Xu, Zhiqiang LinICSE 2023 · 80 citations
- ItyFuzz: Snapshot-Based Fuzzer for Smart ContractChaofan Shou, Shangyin Tan, Koushik SenISSTA 2023 · 76 citations
Related papers
- V2E: Validating Smart Contract Vulnerabilities through Profit-Driven Exploit Generation and ExecutionJingwen Zhang, Yuhong Nan, Kaiwen Ning, Mingxi Ye et al.FSE 2026
- Automated Test Generation For Smart Contracts via On-Chain Test Case Augmentation and MigrationJiashuo Zhang, Jiachi Chen, John Grundy, Jianbo Gao et al.ICSE 2025 · 1 citation
- PoCGen: Generating Proof-of-Concept Exploits for Vulnerabilities in Npm PackagesDeniz Simsek, Aryaz Eghbali, Michael PradelFSE 2026 · 4 citations
- PAGENT: Program Analysis Guided LLM Agent for Proof-of-Concept GenerationAchintya Desai, Md Shafiuzzaman, Wenbo Guo, Tevfik BultanISSTA 2026
- DepFuzz: Efficient Smart Contract Fuzzing with Function Dependence GuidanceChenyang Ma, Wei Song, Jeff HuangOOPSLA 2025 · 3 citations
