LOKI: State-Aware Fuzzing Framework for the Implementation of Blockchain Consensus Protocols
Fuchen Ma, Yuanliang Chen, Meng Ren, Yuanhang Zhou, Yu Jiang, Ting Chen, Huizhong Li, Jiaguang Sun
Abstract
—Blockchain consensus protocols are responsible for coordinating the nodes to make agreements on the transaction results. Their implementation bugs, including memory-related and consensus logic vulnerabilities, may pose serious threats. Fuzzing is a promising technique for protocol vulnerability detection. However, existing fuzzers cannot deal with complex consensus states of distributed nodes, thus generating a large number of useless packets, inhibiting their effectiveness in reaching the deep logic of consensus protocols. In this work, we propose LOKI, a blockchain consensus protocol fuzzing framework that detects consensus memory-related and logic bugs. LOKI fetches consensus states in real- time by masquerading as a node. First, LOKI dynamically builds a state model that records the state transition of each node. After that, LOKI adaptively generates the input targets, types, and contents according to the state model. With a bug analyzer, LOKI detects the consensus protocol implementation bugs with well-defined oracles. We implemented and evaluated LOKI on four widely used commercial blockchain systems, including Go-Ethereum, Meta Diem, IBM Fabric, and WeBank FISCO-BCOS. LOKI has detected 20 serious previously unknown vulnerabilities with 9 CVEs assigned. 14 of them are memory-related bugs, and 6 are consensus logic bugs. Compared with state-of-the-art tools such as Peach, Fluffy, and Twins, LOKI improves the branch coverage by an average of 43.21%, 182.05%, and 291.58%.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers15
- Chronos: Finding Timeout Bugs in Practical Distributed Systems by Deep-Priority Fuzzing with Transient DelayYuanliang Chen, Fuchen Ma, Yuanhang Zhou, Ming Gu et al.S&P 2024 · 12 citations
- Phoenix: Detect and Locate Resilience Issues in Blockchain via Context-Sensitive ChaosFuchen Ma, Yuanliang Chen, Yuanhang Zhou, Jingxuan Sun et al.CCS 2023 · 10 citations
- Understanding Ethereum Mempool Security under Asymmetric DoS by Symbolized Stateful FuzzingYibo Wang, Yuzhe Tang, Kai Li, Wanning Ding et al.USENIX Security 2024 · 9 citations
- fAmulet: Finding Finalization Failure Bugs in Polygon zkRollupZihao Li, Xinghao Peng, Zheyuan He, Xiapu Luo et al.CCS 2024 · 5 citations
- BunnyFinder: Finding Incentive Flaws for Ethereum ConsensusRujia Li, Mingfei Zhang, Xueqian Lu, Wenbo Xu et al.NDSS 2026 · 5 citations
Builds on11
- Making Smart Contracts SmarterLoi Luu, Duc-Hiep Chu, Hrishi Olickel, Prateek Saxena et al.CCS 2016 · 2,306 citations
- Securify: Practical Security Analysis of Smart ContractsPetar Tsankov, Andrei Marian Dan, Dana Drachsler-Cohen, Arthur Gervais et al.CCS 2018 · 1,108 citations
- ZEUS: Analyzing Safety of Smart ContractsSukrit Kalra, Seep Goel, Mohan Dhawan, Subodh SharmaNDSS 2018 · 595 citations
- Sereum: Protecting Existing Smart Contracts Against Re-Entrancy AttacksMichael Rodler, Wenting Li, Ghassan O. Karame, Lucas DaviNDSS 2019 · 298 citations
- sFuzz: an efficient adaptive fuzzer for solidity smart contractsTai D. Nguyen, Long H. Pham, Jun Sun, Yun Lin et al.ICSE 2020 · 260 citations
Related papers
- Fuzzing Enterprise-Grade Blockchain Systems: Industrial Practice and SolutionsFuchen Ma, Yuanliang Chen, Zhen Yan, Yuanhang Zhou et al.EuroSys 2026
- Tyr: Finding Consensus Failure Bugs in Blockchain System with Behaviour Divergent ModelYuanliang Chen, Fuchen Ma, Yuanhang Zhou, Yu Jiang et al.S&P 2023
- Fork State-Aware Differential Fuzzing for Blockchain Consensus ImplementationsWonhoi Kim, Hocheol Nam, Muoi Tran, Amin Jalilov et al.ICSE 2025 · 1 citation
- Finding Consensus Bugs in Ethereum via Multi-transaction Differential FuzzingYoungseok Yang, Taesoo Kim, Byung-Gon ChunOSDI 2021 · 57 citations
- Agora: Toward Autonomous Bug Detection in Production-Level Consensus Protocols with LLM AgentsXiang Liu, Sa Song, Zhaowei Zhang, Huiying Lan et al.ICML 2026 · 1 citation
