Detecting Bugs with Substantial Monetary Consequences by LLM and Rule-based Reasoning
Brian Zhang, Zhuo Zhang
Abstract
Financial transactions are increasingly being handled by automated programs called smart contracts . However, one challenge in the adaptation of smart contracts is the presence of vulnerabilities, which can cause significant monetary loss. In 2024, $247.88 M was lost in 20 smart contract exploits. According to a recent study, accounting bugs (i.e., incorrect implementations of domain-specific financial models) are the most prevalent type of vulnerability, and are one of the most difficult to find, requiring substantial human efforts. While Large Language Models (LLMs) have shown promise in identifying these bugs, they often suffer from lack of generalization of vulnerability types, hallucinations, and problems with representing smart contracts in limited token context space. This paper proposes a hybrid system combining LLMs and rule-based reasoning to detect accounting error vulnerabilities in smart contracts. In particular, it utilizes the understanding capabilities of LLMs to annotate the financial meaning of variables in smart contracts, and employs rule-based reasoning to propagate the information throughout a contract’s logic and to validate potential vulnerabilities. To remedy hallucinations, we propose a feedback loop where validation is performed by providing the reasoning trace of vulnerabilities to the LLM for iterative self-reflection. We achieve 75.6% accuracy on the labelling of financial meanings against human annotations. Furthermore, we achieve a recall of 90.5% from running on 23 real-world smart contract projects containing 21 accounting error vulnerabilities. Finally, we apply the automated technique on 8 recent projects, finding 4 known and 2 unknown bugs.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 359a8b2d-8597-4911-a726-edbe5df7c07aCited by top-tier papers3
- SEC-bench: Automated Benchmarking of LLM Agents on Real-World Software Security TasksHwiwon Lee, Ziqi Zhang, Hanxiao Lu, Lingming ZhangNeurIPS 2025 · 86 citations
- InfiMed-ORBIT: Aligning LLMs on Open-Ended Complex Tasks via Rubric-Based Incremental TrainingPengkai Wang, Pengwei Liu, Qi Zuo, Zhijie Sang et al.ICML 2026 · 12 citations
- RepoAudit: An Autonomous LLM-Agent for Repository-Level Code AuditingJinyao Guo, Chengpeng Wang, Xiangzhe Xu, Zian Su et al.ICML 2025
Builds on9
- Using an LLM to Help With Code UnderstandingDaye Nam, Andrew Macvean, Vincent J. Hellendoorn, Bogdan Vasilescu et al.ICSE 2024 · 264 citations
- Large Language Models Are Zero-Shot Fuzzers: Fuzzing Deep-Learning Libraries via Large Language ModelsYinlin Deng, Chunqiu Steven Xia, Haoran Peng, Chenyuan Yang et al.ISSTA 2023 · 253 citations
- SMARTIAN: Enhancing Smart Contract Fuzzing with Static and Dynamic Data-Flow AnalysesJaeseung Choi, Doyeon Kim, Soomin Kim, Gustavo Grieco et al.ASE 2021 · 164 citations
- SAILFISH: Vetting Smart Contract State-Inconsistency Bugs in SecondsPriyanka Bose, Dipanjan Das, Yanju Chen, Yu Feng et al.S&P 2022 · 142 citations
- Demystifying Exploitable Bugs in Smart ContractsZhuo Zhang, Brian Zhang, Wen Xu, Zhiqiang LinICSE 2023 · 80 citations
Related papers
- Towards Finding Accounting Errors in Smart ContractsBrian ZhangICSE 2024 · 8 citations
- GPTScan: Detecting Logic Vulnerabilities in Smart Contracts by Combining GPT with Program AnalysisYuqiang Sun, Daoyuan Wu, Yue Xue, Han Liu et al.ICSE 2024 · 131 citations
- Have We Solved Access Control Vulnerability Detection in Smart Contracts? A Benchmark StudyHan Liu, Daoyuan Wu, Yuqiang Sun, Shuai Wang et al.ASE 2025 · 1 citation
- PromFuzz: Leveraging LLM-Driven and Bug-Oriented Composite Analysis for Detecting Functional Bugs in Smart ContractsXingshuang Lin, Qinge Xie, Binbin Zhao, Yuan Tian et al.ASE 2025 · 5 citations
- Thought Is All You Need: Smart Contract Vulnerability Detection with Thought-Augmented Large Language ModelChaoyuan Peng, Muhui Jiang, Yajin Zhou, Lei WuFSE 2026
