Smart Contract Fuzzing Towards Profitable Vulnerabilities
Ziqiao Kong, Cen Zhang, Maoyi Xie, Ming Hu, Yue Xue, Ye Liu, Haijun Wang, Yang Liu
Abstract
Billions of dollars are transacted through smart contracts, making vulnerabilities a major financial risk. One focus in the security arms race is on profitable vulnerabilities that attackers can exploit. Fuzzing is a key method for identifying these vulnerabilities. However, current solutions face two main limitations: 1. a lack of profit-centric techniques for expediting detection and, 2. insufficient automation in maximizing the profitability of discovered vulnerabilities, leaving the analysis to human experts. To address these gaps, we have developed VERITE, a profit-centric smart contract fuzzing framework that not only effectively detects those profitable vulnerabilities but also maximizes the exploited profits. VERITE has three key features: 1. DeFi action-based mutators for boosting the exploration of transactions with different fund flows; 2. potentially profitable candidates identification criteria, which checks whether the input has caused abnormal fund flow properties during testing; 3. a gradient descent-based profit maximization strategy for these identified candidates. VERITE is fully developed from scratch and evaluated on a dataset consisting of 61 exploited real-world DeFi projects with an average of over 1.1 million dollars loss. The results show that VERITE can automatically extract more than 18 million dollars in total and is significantly better than state-of-the-art fuzzer ItyFuzz in both detection (29/10) and exploitation (134 times more profits gained on average). Remarkably, in 12 targets, it gains more profits than real-world attacking exploits (1.01 to 11.45 times more). VERITE is also applied by auditors in contract auditing, where 6 (5 high severity) zero-day vulnerabilities are found with over $2,500 bounty rewards.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 955e7bdc-59e0-4f4f-b6a7-56292de11c76Cited by top-tier papers3
- Belobog: Move Language Fuzzing Framework for Real-World Smart ContractsZiqiao Kong, Wanxu Xia, Zhengwei Li, Yi Lu et al.ISSTA 2026
- V2E: Validating Smart Contract Vulnerabilities through Profit-Driven Exploit Generation and ExecutionJingwen Zhang, Yuhong Nan, Kaiwen Ning, Mingxi Ye et al.FSE 2026
- Tracing the Shadows: Automatic Tracking and Analysis of Crypto Money Laundering via Transaction Semantic AnalysisHao Wu, Haijun Wang, Shangwang Li, Yin Wu et al.ISSTA 2026
Builds on24
- Securify: Practical Security Analysis of Smart ContractsPetar Tsankov, Andrei Marian Dan, Dana Drachsler-Cohen, Arthur Gervais et al.CCS 2018 · 1,108 citations
- Coverage-based Greybox Fuzzing as Markov ChainMarcel Böhme, Van-Thuan Pham, Abhik RoychoudhuryCCS 2016 · 1,026 citations
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei et al.CCS 2018 · 753 citations
- Angora: Efficient Fuzzing by Principled SearchPeng Chen, Hao ChenS&P 2018 · 616 citations
- Quantifying Blockchain Extractable Value: How dark is the forest?Kaihua Qin, Liyi Zhou, Arthur GervaisS&P 2022 · 336 citations
Related papers
- Midas: Mining Profitable Exploits in On-Chain Smart Contracts via Feedback-Driven Fuzzing and Differential AnalysisMingxi Ye, Xingwei Lin, Yuhong Nan, Jiajing Wu et al.ISSTA 2024 · 5 citations
- EchoFuzz: Empowering Smart Contract Fuzzing with Large Language ModelsJuanen Li, Peng Qian, Guanyan Li, Rui Wang et al.ICSE 2026
- Effectively Generating Vulnerable Transaction Sequences in Smart Contracts with Reinforcement Learning-guided FuzzingJianzhong Su, Hong-Ning Dai, Lingjun Zhao, Zibin Zheng et al.ASE 2022 · 59 citations
- PromFuzz: Leveraging LLM-Driven and Bug-Oriented Composite Analysis for Detecting Functional Bugs in Smart ContractsXingshuang Lin, Qinge Xie, Binbin Zhao, Yuan Tian et al.ASE 2025 · 5 citations
- SMARTIAN: Enhancing Smart Contract Fuzzing with Static and Dynamic Data-Flow AnalysesJaeseung Choi, Doyeon Kim, Soomin Kim, Gustavo Grieco et al.ASE 2021 · 164 citations
