Definition and Detection of Defects in NFT Smart Contracts
Shuo Yang, Jiachi Chen, Zibin Zheng
Abstract
In recent years, security incidents stemming from centralization defects in smart contracts have led to substantial financial losses. A centralization defect refers to any error, flaw, or fault in a smart contract's design or development stage that introduces a single point of failure. Such defects allow a specific account or user to disrupt the normal operations of smart contracts, potentially causing malfunctions or even complete project shutdowns. Despite the significance of this issue, most current smart contract analyses overlook centralization defects, focusing primarily on other types of defects. To address this gap, our paper introduces six types of centralization defects in smart contracts by manually analyzing 597 Stack Exchange posts and 117 audit reports. For each defect, we provide a detailed description and code examples to illustrate its characteristics and potential impacts. Additionally, we introduce a tool named CDRipper (Centralization Defects Ripper) designed to identify the defined centralization defects. Specifically, CDRipper constructs a permission dependency graph (PDG) and extracts the permission dependencies of functions from the source code of smart contracts. It then detects the sensitive operations in functions and identifies centralization defects based on predefined patterns. We conduct a large-scale experiment using CDRipper on 244,424 real-world smart contracts and evaluate the results based on a manually labeled dataset. Our findings reveal that 82,446 contracts contain at least one of the six centralization defects, with our tool achieving an overall precision of 93.7%.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3feae891-b299-4df1-a3d1-1637e4a0e50aCited by top-tier papers14
- Uncover the Premeditated Attacks: Detecting Exploitable Reentrancy Vulnerabilities by Identifying Attacker ContractsShuo Yang, Jiachi Chen, Mingyuan Huang, Zibin Zheng et al.ICSE 2024 · 24 citations
- Identifying Smart Contract Security Issues in Code Snippets from Stack OverflowJiachi Chen, Chong Chen, Jiang Hu, John C. Grundy et al.ISSTA 2024 · 9 citations
- When Contracts Meets Crypto: Exploring Developers' Struggles with Ethereum Cryptographic APIsJiashuo Zhang, Jiachi Chen, Zhiyuan Wan, Ting Chen et al.ICSE 2024 · 9 citations
- Hyperion: Unveiling DApp Inconsistencies Using LLM and Dataflow-Guided Symbolic ExecutionShuo Yang, Xingwei Lin, Jiachi Chen, Qingyuan Zhong et al.ICSE 2025 · 6 citations
- Enhancing the Open Network: Definition and Automated Detection of Smart Contract DefectsHao Song, Teng Li, Jiachi Chen, Ting Chen et al.ICSE 2025 · 5 citations
Builds on9
- Making Smart Contracts SmarterLoi Luu, Duc-Hiep Chu, Hrishi Olickel, Prateek Saxena et al.CCS 2016 · 2,306 citations
- Securify: Practical Security Analysis of Smart ContractsPetar Tsankov, Andrei Marian Dan, Dana Drachsler-Cohen, Arthur Gervais et al.CCS 2018 · 1,108 citations
- ZEUS: Analyzing Safety of Smart ContractsSukrit Kalra, Seep Goel, Mohan Dhawan, Subodh SharmaNDSS 2018 · 595 citations
- Ethainter: a smart contract security analyzer for composite vulnerabilitiesLexi Brent, Neville Grech, Sifis Lagouvardos, Bernhard Scholz et al.PLDI 2020 · 163 citations
- Finding permission bugs in smart contracts with role miningYe Liu, Yi Li, Shang-Wei Lin, Cyrille ArthoISSTA 2022 · 54 citations
Related papers
- Definition and Detection of Centralization Defects in Smart ContractsZewei Lin, Jiachi Chen, Jiajing Wu, Weizhe Zhang et al.ICSE 2025 · 2 citations
- Demystifying and Detecting Cryptographic Defects in Ethereum Smart ContractsJiashuo Zhang, Yiming Shen, Jiachi Chen, Jianzhong Su et al.ICSE 2025 · 2 citations
- SSR: Safeguarding Staking Rewards by Defining and Detecting Logical Defects in DeFi StakingZewei Lin, Jiachi Chen, Jingwen Zhang, Zexu Wang et al.ASE 2025 · 1 citation
- Towards Finding Accounting Errors in Smart ContractsBrian ZhangICSE 2024 · 8 citations
- PrettySmart: Detecting Permission Re-delegation Vulnerability for Token Behaviors in Smart ContractsZhijie Zhong, Zibin Zheng, Hong-Ning Dai, Qing Xue et al.ICSE 2024 · 12 citations
