Large-Scale Study of Vulnerability Scanners for Ethereum Smart Contracts
Christoph Sendner, Lukas Petzi, Jasper Stang, Alexandra Dmitrienko
Abstract
Ethereum smart contracts, which are autonomous decentralized applications on the blockchain that manage assets often exceeding millions of dollars, have become primary targets for cyberattacks. In 2023 alone, such vulnerabilities led to substantial financial losses exceeding a billion US dollars. To counter these threats, various tools have been developed by academic and commercial entities to detect and mitigate vulnerabilities in smart contracts. Our study investigates the gap between the effectiveness of existing security scanners and the vulnerabilities that still persist in practice. We compiled four distinct datasets for this analysis. The first dataset comprises 77,219 source codes extracted directly from the blockchain, while the second includes over 4 million bytecodes obtained from Ethereum Mainnet and testnets. The other two datasets consist of nearly 14,000 manually annotated smart contracts and 373 smart contracts verified through audits, providing a foundation for a rigorous ground truth analysis on bytecode and source code. Using the unlabeled datasets, we conducted a comprehensive quantitative evaluation of 18 vulnerability scanners, revealing considerable discrepancies in their findings. Our analysis of the ground truth datasets indicated poor performance across all the tools we tested. This study unveils the reasons for poor performance and underscores that the current state of the art for smart contract security falls short in effectively addressing open problems, highlighting that the challenge of effectively detecting vulnerabilities remains a significant and unresolved issue.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Cited by top-tier papers5
- Definition and Detection of Defects in NFT Smart ContractsShuo Yang, Jiachi Chen, Zibin ZhengISSTA 2023 · 35 citations
- FORGE: An LLM-driven Framework for Large-Scale Smart Contract Vulnerability Dataset ConstructionJiachi Chen, Yiming Shen, Jiashuo Zhang, Zihao Li et al.ICSE 2026 · 3 citations
- Definition and Detection of Centralization Defects in Smart ContractsZewei Lin, Jiachi Chen, Jiajing Wu, Weizhe Zhang et al.ICSE 2025 · 2 citations
- When HTTP 402 Meets the Blockchain: Risks on Emerging x402 PaymentsQinying Wang, Yong Yang, Yuan Chen, Shouling Ji et al.USENIX Security 2026
- Revealing the Dark Side of Smart Accounts: An Empirical Study of EIP-7702 Incurred Risks in Blockchain EcosystemMingyuan Huang, Han Liu, Shuo Yang, Daoyuan Wu et al.USENIX Security 2026
Related papers
- Cross-Modality Mutual Learning for Enhancing Smart Contract Vulnerability Detection on BytecodePeng Qian, Zhenguang Liu, Yifang Yin, Qinming HeWWW 2023 · 91 citations
- Empirical review of automated analysis tools on 47, 587 Ethereum smart contractsThomas Durieux, João F. Ferreira, Rui Abreu, Pedro CruzICSE 2020 · 373 citations
- Smart Contract and DeFi Security Tools: Do They Meet the Needs of Practitioners?Stefanos Chaliasos, Marcos Antonios Charalambous, Liyi Zhou, Rafaila Galanopoulou et al.ICSE 2024 · 49 citations
- Empirical evaluation of smart contract testing: what is the best choice?Meng Ren, Zijing Yin, Fuchen Ma, Zhenyang Xu et al.ISSTA 2021 · 83 citations
- Have We Solved Access Control Vulnerability Detection in Smart Contracts? A Benchmark StudyHan Liu, Daoyuan Wu, Yuqiang Sun, Shuai Wang et al.ASE 2025 · 1 citation
