Fuzzing Enterprise-Grade Blockchain Systems: Industrial Practice and Solutions
Fuchen Ma, Yuanliang Chen, Zhen Yan, Yuanhang Zhou, Yu Jiang, Mingchao Wan
Abstract
Blockchain has been widely adopted across diverse sectors. Yet, enterprise-grade systems remain vulnerable to critical flaws that undermine stability and security. Although academic fuzzing tools such as LOKI and Tyr have shown effectiveness in detecting such issues, their integration into industrial practice remains challenging.
In this paper, we present the industry practice of implementing system-level fuzzing techniques on enterprise-level blockchains. We summarize three main obstacles in industry deployment, namely the hard-to-build state models for fuzzing, the slow convergence of fuzz testing within CI/CD pipelines, and the difficulty of adapting logical bug oracles across diverse blockchain implementations. To address these obstacles, we design Thor, a practical fuzzing framework for industry blockchain systems. Thor uses active and passive packet generation for early stage state-aware testing. To perform efficient fuzzing under strict CI/CD time budgets, Thor adopts a two-tier parallel fuzzing method. And Thor also uses LLM-based oracles to extract logic properties from node logs. Over these years, Thor has discovered 87 bugs in 9 commercial blockchain systems, such as Chainmaker, Go-Ethereum, and WeBank FISCO BCOS.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 8d44574b-48e2-4949-8c25-c7a589a42bd3Builds on13
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei et al.CCS 2018 · 753 citations
- Learning to Fuzz from Symbolic Execution with Application to Smart ContractsJingxuan He, Mislav Balunovic, Nodar Ambroladze, Petar Tsankov et al.CCS 2019 · 288 citations
- sFuzz: an efficient adaptive fuzzer for solidity smart contractsTai D. Nguyen, Long H. Pham, Jun Sun, Yun Lin et al.ICSE 2020 · 260 citations
- Regression Greybox FuzzingXiaogang Zhu, Marcel BöhmeCCS 2021 · 84 citations
- ItyFuzz: Snapshot-Based Fuzzer for Smart ContractChaofan Shou, Shangyin Tan, Koushik SenISSTA 2023 · 76 citations
Related papers
- LOKI: State-Aware Fuzzing Framework for the Implementation of Blockchain Consensus ProtocolsFuchen Ma, Yuanliang Chen, Meng Ren, Yuanhang Zhou et al.NDSS 2023
- Fork State-Aware Differential Fuzzing for Blockchain Consensus ImplementationsWonhoi Kim, Hocheol Nam, Muoi Tran, Amin Jalilov et al.ICSE 2025 · 1 citation
- Tyr: Finding Consensus Failure Bugs in Blockchain System with Behaviour Divergent ModelYuanliang Chen, Fuchen Ma, Yuanhang Zhou, Yu Jiang et al.S&P 2023
- RPCSpecter: Detecting Blockchain RPC Bugs through a Specification-Driven, Constraint-Aware Fuzzing ApproachYuming Xiao, Yuhong Nan, Zhijie Zhong, Mingxi Ye et al.ISSTA 2026
- Finding Consensus Bugs in Ethereum via Multi-transaction Differential FuzzingYoungseok Yang, Taesoo Kim, Byung-Gon ChunOSDI 2021 · 57 citations
