Odyssey: Hunting Smart Contract Vulnerabilities with Fine-Grained State Modeling and Exploration
Jianzhong Su, Mingxi Ye, Jiachi Chen, Yuhong Nan, Peilin Zheng, Tao Zhang, Zibin Zheng
Abstract
With the rapid development of decentralized applications, many malicious actors exploit smart contract vulnerabilities for launching attacks. Moreover, as smart contracts utilize more state variables to support complex functionalities, some vulnerabilities require specific states to trigger (marked as vulnerable states), bringing new challenges to the vulnerability detection task. Although many smart contract fuzzers have been proposed for this task, they face limitations due to their inability to efficiently explore smart contract states. To address this challenge, we propose a novel fuzzer, Odyssey, with fine-grained state modeling and exploration, which increases the probability of reaching vulnerable states. We improve the efficacy of the fuzzer with two key mechanisms: (1) modeling an essential state space consisting of the variables related to sensitive operations to compress the exploration scope; (2) designing state-aware exploration strategies to identify test seeds that cover new state scope or cause new state transitions, to improve the efficiency of exploration. To evaluate the performance in vulnerability detection, we adopt Odyssey to a labeled benchmark consisting of 130 vulnerable contracts. Odyssey detects at least 70% more vulnerabilities than other fuzzers. Moreover, we evaluate Odyssey on a dataset that consists of 143 DApps (involving 437 contracts) from real-world security incidents. The experimental results demonstrate that state-aware feedback enhances the ability of Odyssey in state exploration by achieving 19% higher state coverage. Meanwhile, Odyssey totally finds 15 exploits of vulnerabilities from real-world attacks, showing its advantage in detecting real-world vulnerabilities.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 12280293-f2ed-4430-ad30-8a52fb7cc902Related papers
- DepFuzz: Efficient Smart Contract Fuzzing with Function Dependence GuidanceChenyang Ma, Wei Song, Jeff HuangOOPSLA 2025 · 3 citations
- Effectively Generating Vulnerable Transaction Sequences in Smart Contracts with Reinforcement Learning-guided FuzzingJianzhong Su, Hong-Ning Dai, Lingjun Zhao, Zibin Zheng et al.ASE 2022 · 59 citations
- SmartShot: Hunt Hidden Vulnerabilities in Smart Contracts using Mutable SnapshotsRuichao Liang, Jing Chen, Ruochen Cao, Kun He et al.FSE 2025 · 2 citations
- EchoFuzz: Empowering Smart Contract Fuzzing with Large Language ModelsJuanen Li, Peng Qian, Guanyan Li, Rui Wang et al.ICSE 2026
- SMARTIAN: Enhancing Smart Contract Fuzzing with Static and Dynamic Data-Flow AnalysesJaeseung Choi, Doyeon Kim, Soomin Kim, Gustavo Grieco et al.ASE 2021 · 164 citations
