Have We Solved Access Control Vulnerability Detection in Smart Contracts? A Benchmark Study
Han Liu, Daoyuan Wu, Yuqiang Sun, Shuai Wang, Yang Liu
Abstract
Access control (AC) vulnerabilities are among the most critical security threats to smart contracts. Despite extensive research, they remain widespread and damaging in the Ethereum ecosystem. To understand and advance the current state-of-the-art (SOTA) in AC vulnerability detection, we first curate a diverse dataset of 180 real-world AC vulnerabilities from CVE entries, DeFiHackLabs incidents, and Code4rena audit reports. Using this dataset, we conduct a systematic benchmark study along three dimensions. First, we develop a cause-based taxonomy and analyze the prevalence and evolution of AC vulnerabilities. Second, we evaluate six SOTA tools, including two from industry and four from academia, revealing low recall (3% to 8%) and significant blind spots. To understand these failures, we examine 1.2 million deployed contracts and uncover practical gaps in AC protection mechanisms overlooked by existing tools. Finally, we assess the potential of large language models (LLMs) for AC vulnerability detection and show that LLMs detect 53-75% of vulnerabilities, outperforming traditional tools but facing challenges such as hallucinations and scalability. Our findings highlight the need for hybrid approaches that combine static analysis with LLM-based semantic reasoning to address the complexity of modern AC vulnerabilities.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 2ad8dd72-0eeb-4bdd-801f-5a0930f5487dBuilds on16
- Chain-of-Thought Prompting Elicits Reasoning in Large Language ModelsJason Wei, Xuezhi Wang, Dale Schuurmans, Maarten Bosma et al.NeurIPS 2022 · 22,562 citations
- Making Smart Contracts SmarterLoi Luu, Duc-Hiep Chu, Hrishi Olickel, Prateek Saxena et al.CCS 2016 · 2,306 citations
- Securify: Practical Security Analysis of Smart ContractsPetar Tsankov, Andrei Marian Dan, Dana Drachsler-Cohen, Arthur Gervais et al.CCS 2018 · 1,108 citations
- Empirical review of automated analysis tools on 47, 587 Ethereum smart contractsThomas Durieux, João F. Ferreira, Rui Abreu, Pedro CruzICSE 2020 · 373 citations
- How effective are smart contract analysis tools? evaluating smart contract static analysis tools using bug injectionAsem Ghaleb, Karthik PattabiramanISSTA 2020 · 183 citations
Related papers
- GPTScan: Detecting Logic Vulnerabilities in Smart Contracts by Combining GPT with Program AnalysisYuqiang Sun, Daoyuan Wu, Yue Xue, Han Liu et al.ICSE 2024 · 131 citations
- ACTaint: Agent-Based Taint Analysis for Access Control Vulnerabilities in Smart ContractsHuarui Lin, Zhipeng Gao, Jiachi Chen, Xiang Chen et al.ASE 2025 · 1 citation
- Detecting Bugs with Substantial Monetary Consequences by LLM and Rule-based ReasoningBrian Zhang, Zhuo ZhangNeurIPS 2024 · 12 citations
- Thought Is All You Need: Smart Contract Vulnerability Detection with Thought-Augmented Large Language ModelChaoyuan Peng, Muhui Jiang, Yajin Zhou, Lei WuFSE 2026
- Beyond Static Pattern Matching? Rethinking Automatic Cryptographic API Misuse Detection in the Era of LLMsYifan Xia, Zichen Xie, Peiyu Liu, Kangjie Lu et al.ISSTA 2025 · 2 citations
