USENIX Security2023Top-tier venue
A Mixed-Methods Study of Security Practices of Smart Contract Developers
Tanusree Sharma, Kyrie Zhixuan Zhou, Andrew Miller, Yang Wang
Abstract
Smart contracts are self-executing programs that run on blockchains (e.g., Ethereum). While security is a key concern for smart contracts, it is unclear how smart contract developers approach security. To help fill this research gap, we conducted a mixed-methods study of smart contract developers, including interviews and a code review task with 29 developers and an online survey with 171 valid respondents. Our findings show various smart contract security perceptions and practices, including the usage of different tools and resources. Overall, the majority of our participants did not consider security as a priority in their smart contract development. In addition, the security vulnerability identification rates in our code review tasks were alarmingly low (often lower than 50%) across different vulnerabilities and regardless of our participants' years of experience in smart contract development. We discuss how future education and tools could better support developers in ensuring smart contract security.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7693612e-24c8-45b9-a96e-6ebfabd553a4Cited by top-tier papers2
- Defying the Odds: Solana's Unexpected Resilience in Spite of the Security Challenges Faced by DevelopersSébastien Andreina, Tobias Cloosters, Lucas Davi, Jens-Rene Giesen et al.CCS 2024 · 4 citations
- Lost in Blockchain Address Misuse: Hidden Cross-Platform Risks and Their Security ImpactZhenzhe Shao, Jiashuo Zhang, Zihao Li, Daoyuan Wu et al.USENIX Security 2026
Builds on9
- Making Smart Contracts SmarterLoi Luu, Duc-Hiep Chu, Hrishi Olickel, Prateek Saxena et al.CCS 2016 · 2,306 citations
- Securify: Practical Security Analysis of Smart ContractsPetar Tsankov, Andrei Marian Dan, Dana Drachsler-Cohen, Arthur Gervais et al.CCS 2018 · 1,108 citations
- Flash Boys 2.0: Frontrunning in Decentralized Exchanges, Miner Extractable Value, and Consensus InstabilityPhilip Daian, Steven Goldfeder, Tyler Kell, Yunqi Li et al.S&P 2020 · 607 citations
- Comparing the Usability of Cryptographic APIsYasemin Acar, Michael Backes, Sascha Fahl, Simson L. Garfinkel et al.S&P 2017 · 261 citations
- Ethainter: a smart contract security analyzer for composite vulnerabilitiesLexi Brent, Neville Grech, Sifis Lagouvardos, Bernhard Scholz et al.PLDI 2020 · 163 citations
Related papers
- Smart Contract Security: a Practitioners' PerspectiveZhiyuan Wan, Xin Xia, David Lo, Jiachi Chen et al.ICSE 2021 · 58 citations
- Large-Scale Study of Vulnerability Scanners for Ethereum Smart ContractsChristoph Sendner, Lukas Petzi, Jasper Stang, Alexandra DmitrienkoS&P 2024 · 19 citations
- Identifying Smart Contract Security Issues in Code Snippets from Stack OverflowJiachi Chen, Chong Chen, Jiang Hu, John C. Grundy et al.ISSTA 2024 · 9 citations
- User Perceptions and Experiences with Smart Home UpdatesJulie M. Haney, Susanne M. FurmanS&P 2023
- Abusing the Ethereum Smart Contract Verification Services for Fun and ProfitPengxiang Ma, Ningyu He, Yuhua Huang, Haoyu Wang et al.NDSS 2024
