EchoFuzz: Empowering Smart Contract Fuzzing with Large Language Models
Juanen Li, Peng Qian, Guanyan Li, Rui Wang, Peixin Wang, Zhiqing Tang, Fuchen Ma, Yuanliang Chen, Lun Zhang
Abstract
Smart contracts, serving as the cornerstone of decentralized applications, autonomously manage trillion-dollar digital assets, making them attractive targets for attacks. Fuzzing has emerged as a promising technique for detecting vulnerabilities in smart contracts, yet existing methods face two main challenges. (1) The logical gap in state transitions and combinatorial redundancy hinders effective tradeoffs between bug detection efficiency and state space exploration cost, leading to critical execution paths to be overlooked.
(2) Rule-based sequence mutation strategies suffer from path redundancy and inadequate guidance from contract logic, resulting in performance bottlenecks that stall the exploration of in-depth vulnerability-oriented paths.
To tackle these challenges, we propose EchoFuzz, an LLM-guided fuzzing framework introducing Vulnerable Function Call Sequences (VFCS) -minimal, behavior-preserving execution paths that expose bugs through key state transitions. EchoFuzz consists of two key procedures. First, we develop a chain-guided LLM approach, that combines static analysis with logical understanding to generate contract-specific VFCS candidates that eliminate combinatorial redundancy. Second, we adopt an iterative fuzzing strategy that uses LLMs with real-time feedback to adaptively steer fuzzer toward uncovered branches. Experiments show EchoFuzz outperforms stateof-the-art methods, achieving 29% higher branch coverage and detecting 62% more vulnerabilities. It also found 37 previously unknown vulnerabilities in real contracts, showing strong practicality.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 8a55c2b7-6703-4993-a2f8-97b502d62871Builds on11
- Hawk: The Blockchain Model of Cryptography and Privacy-Preserving Smart ContractsAhmed E. Kosba, Andrew Miller, Elaine Shi, Zikai Wen et al.S&P 2016 · 2,201 citations
- Learning to Fuzz from Symbolic Execution with Application to Smart ContractsJingxuan He, Mislav Balunovic, Nodar Ambroladze, Petar Tsankov et al.CCS 2019 · 288 citations
- sFuzz: an efficient adaptive fuzzer for solidity smart contractsTai D. Nguyen, Long H. Pham, Jun Sun, Yun Lin et al.ICSE 2020 · 260 citations
- Large Language Models Are Zero-Shot Fuzzers: Fuzzing Deep-Learning Libraries via Large Language ModelsYinlin Deng, Chunqiu Steven Xia, Haoran Peng, Chenyuan Yang et al.ISSTA 2023 · 253 citations
- Large Language Models Can Self-ImproveJiaxin Huang, Shixiang Gu, Le Hou, Yuexin Wu et al.EMNLP 2023 · 184 citations
Related papers
- Effectively Generating Vulnerable Transaction Sequences in Smart Contracts with Reinforcement Learning-guided FuzzingJianzhong Su, Hong-Ning Dai, Lingjun Zhao, Zibin Zheng et al.ASE 2022 · 59 citations
- Adaptive Mutation Scheduling with Deep Reinforcement Learning for Smart Contract FuzzingQianqian Pang, Xin Yin, Tingting Bi, Lingfeng Bao et al.FSE 2026
- DepFuzz: Efficient Smart Contract Fuzzing with Function Dependence GuidanceChenyang Ma, Wei Song, Jeff HuangOOPSLA 2025 · 3 citations
- MuFuzz: Sequence-Aware Mutation and Seed Mask Guidance for Blockchain Smart Contract FuzzingPeng Qian, Hanjie Wu, Zeren Du, Turan Vural et al.ICDE 2024 · 22 citations
- Odyssey: Hunting Smart Contract Vulnerabilities with Fine-Grained State Modeling and ExplorationJianzhong Su, Mingxi Ye, Jiachi Chen, Yuhong Nan et al.FSE 2026
