Revealing Hidden Threats: An Empirical Study of Library Misuse in Smart Contracts
Mingyuan Huang, Jiachi Chen, Zigui Jiang, Zibin Zheng
Abstract
Smart contracts are Turing-complete programs that execute on the blockchain. Developers can implement complex contracts, such as auctions and lending, on Ethereum using the Solidity programming language. As an object-oriented language, Solidity provides libraries within its syntax to facilitate code reusability and reduce development complexity. Library misuse refers to the incorrect writing or usage of libraries, resulting in unexpected results, such as introducing vulnerabilities during library development or incorporating an unsafe library during contract development. Library misuse could lead to contract defects that cause financial losses. Currently, there is a lack of research on library misuse. To fill this gap, we collected more than 500 audit reports from the official websites of five audit companies and 223,336 real-world smart contracts from Etherscan to measure library popularity and library misuse. Then, we defined eight general patterns for library misuse; three of them occurring during library development and five during library utilization, which covers the entire library lifecycle. To validate the practicality of these patterns, we manually analyzed 1,018 real-world smart contracts and publicized our dataset. We identified 905 misuse cases across 456 contracts, indicating that library misuse is a widespread issue. Three patterns of misuse are found in more than 50 contracts, primarily due to developers lacking security awareness or underestimating negative impacts. Additionally, our research revealed that vulnerable libraries on Ethereum continue to be employed even after they have been deprecated or patched. Our findings can assist contract developers in preventing library misuse and ensuring the safe use of libraries.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 5950f301-3d2b-448b-a01d-6f42be59dcbfCited by top-tier papers3
- Maat: Analyzing and Optimizing Overcharge on Blockchain StorageZheyuan He, Zihao Li, Ao Qiao, Jingwei Li et al.FAST 2025 · 3 citations
- FORGE: An LLM-driven Framework for Large-Scale Smart Contract Vulnerability Dataset ConstructionJiachi Chen, Yiming Shen, Jiashuo Zhang, Zihao Li et al.ICSE 2026 · 3 citations
- Understanding End-User Perception of Transfer Risks in Smart ContractsYustynn Panicker, Ezekiel O. Soremekun, Sudipta Chattopadhyay, Sumei SunCHI 2025 · 2 citations
Related papers
- A study of inline assembly in solidity smart contractsStefanos Chaliasos, Arthur Gervais, Benjamin LivshitsOOPSLA 2022 · 22 citations
- Clone Detection for Smart Contracts: How Far Are We?Zuobin Wang, Zhiyuan Wan, Yujing Chen, Yun Zhang et al.FSE 2025 · 1 citation
- Securify: Practical Security Analysis of Smart ContractsPetar Tsankov, Andrei Marian Dan, Dana Drachsler-Cohen, Arthur Gervais et al.CCS 2018 · 1,108 citations
- Code Cloning in Solidity Smart Contracts: Prevalence, Evolution, and Impact on DevelopmentRan Mo, Haopeng Song, Wei Ding, Chaochao WuICSE 2025 · 1 citation
- Using My Functions Should Follow My Checks: Understanding and Detecting Insecure OpenZeppelin Code in Smart ContractsHan Liu, Daoyuan Wu, Yuqiang Sun, Haijun Wang et al.USENIX Security 2024 · 11 citations
