Turn the Rudder: A Beacon of Reentrancy Detection for Smart Contracts on Ethereum
Zibin Zheng, Neng Zhang, Jianzhong Su, Zhijie Zhong, Mingxi Ye, Jiachi Chen
Abstract
Smart contracts are programs deployed on a blockchain and are immutable once deployed. Reentrancy, one of the most important vulnerabilities in smart contracts, has caused millions of dollars in financial loss. Many reentrancy detection approaches have been proposed. It is necessary to investigate the performance of these approaches to provide useful guidelines for their application. In this work, we conduct a large-scale empirical study on the capability of five well-known or recent reentrancy detection tools such as Mythril and Sailfish. We collect 230,548 verified smart contracts from Etherscan and use detection tools to analyze 139,424 contracts after deduplication, which results in 21,212 contracts with reentrancy issues. Then, we manually examine the defective functions located by the tools in the contracts. From the examination results, we obtain 34 true positive contracts with reentrancy and 21,178 false positive contracts without reentrancy. We also analyze the causes of the true and false positives. Finally, we evaluate the tools based on the two kinds of contracts. The results show that more than 99.8% of the reentrant contracts detected by the tools are false positives with eight types of causes, and the tools can only detect the reentrancy issues caused by call.value(), 58.8% of which can be revealed by the Ethereum's official IDE, Remix. Furthermore, we collect real-world reentrancy attacks reported in the past two years and find that the tools fail to find any issues in the corresponding contracts. Based on the findings, existing works on reentrancy detection appear to have very limited capability, and researchers should turn the rudder to discover and detect new reentrancy patterns except those related to call.value().
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 116cb09a-ffca-423f-ab4e-01d2bdf7de15Cited by top-tier papers11
- Efficiently Detecting Reentrancy Vulnerabilities in Complex Smart ContractsZexu Wang, Jiachi Chen, Yanlin Wang, Yu Zhang et al.FSE 2024 · 27 citations
- Are We There Yet? Unraveling the State-of-the-Art Smart Contract FuzzersShuohan Wu, Zihao Li, Luyi Yan, Weimin Chen et al.ICSE 2024 · 24 citations
- Uncover the Premeditated Attacks: Detecting Exploitable Reentrancy Vulnerabilities by Identifying Attacker ContractsShuo Yang, Jiachi Chen, Mingyuan Huang, Zibin Zheng et al.ICSE 2024 · 24 citations
- Identifying Smart Contract Security Issues in Code Snippets from Stack OverflowJiachi Chen, Chong Chen, Jiang Hu, John C. Grundy et al.ISSTA 2024 · 9 citations
- Enhancing the Open Network: Definition and Automated Detection of Smart Contract DefectsHao Song, Teng Li, Jiachi Chen, Ting Chen et al.ICSE 2025 · 5 citations
Builds on9
- Making Smart Contracts SmarterLoi Luu, Duc-Hiep Chu, Hrishi Olickel, Prateek Saxena et al.CCS 2016 · 2,306 citations
- Securify: Practical Security Analysis of Smart ContractsPetar Tsankov, Andrei Marian Dan, Dana Drachsler-Cohen, Arthur Gervais et al.CCS 2018 · 1,108 citations
- ZEUS: Analyzing Safety of Smart ContractsSukrit Kalra, Seep Goel, Mohan Dhawan, Subodh SharmaNDSS 2018 · 595 citations
- Empirical review of automated analysis tools on 47, 587 Ethereum smart contractsThomas Durieux, João F. Ferreira, Rui Abreu, Pedro CruzICSE 2020 · 373 citations
- sFuzz: an efficient adaptive fuzzer for solidity smart contractsTai D. Nguyen, Long H. Pham, Jun Sun, Yun Lin et al.ICSE 2020 · 260 citations
Related papers
- Cross-Contract Static Analysis for Detecting Practical Reentrancy Vulnerabilities in Smart ContractsYinxing Xue, Mingliang Ma, Yun Lin, Yulei Sui et al.ASE 2020 · 77 citations
- SAILFISH: Vetting Smart Contract State-Inconsistency Bugs in SecondsPriyanka Bose, Dipanjan Das, Yanju Chen, Yu Feng et al.S&P 2022 · 142 citations
- AdvSCanner: Generating Adversarial Smart Contracts to Exploit Reentrancy Vulnerabilities Using LLM and Static AnalysisYin Wu, Xiaofei Xie, Chenyang Peng, Dijun Liu et al.ASE 2024 · 9 citations
- Silence False Alarms: Identifying Anti-Reentrancy Patterns on Ethereum to Refine Smart Contract Reentrancy DetectionQiyang Song, Heqing Huang, Xiaoqi Jia, Yuanbo Xie et al.NDSS 2025
- Reentrancy Vulnerability Detection and Localization: A Deep Learning Based Two-phase ApproachZhuo Zhang, Yan Lei, Meng Yan, Yue Yu et al.ASE 2022 · 56 citations
