Symbolic value-flow static analysis: deep, precise, complete modeling of Ethereum smart contracts
Yannis Smaragdakis, Neville Grech, Sifis Lagouvardos, Konstantinos Triantafyllou, Ilias Tsatiris
Abstract
We present a static analysis approach that combines concrete values and symbolic expressions. This symbolic value-flow (łsymvalicž) analysis models program behavior with high precision, e.g., full path sensitivity. To achieve deep modeling of program semantics, the analysis relies on a symbiotic relationship between a traditional static analysis fixpoint computation and a symbolic solver: the solver does not merely receive a complex łpath conditionž to solve, but is instead invoked repeatedly (often tens or hundreds of thousands of times), in close cooperation with the flow computation of the analysis.
The result of the symvalic analysis architecture is a static modeling of program behavior that is much more complete than symbolic execution, much more precise than conventional static analysis, and domain-agnostic: no special-purpose definition of anti-patterns is necessary in order to compute violations of safety conditions with high precision.
We apply the analysis to the domain of Ethereum smart contracts. This domain represents a fundamental challenge for program analysis approaches: despite numerous publications, research work has not been effective at uncovering vulnerabilities of high real-world value.
In systematic comparison of symvalic analysis with past tools, we find significantly increased completeness (shown as 83-96% statement coverage and more true error reports) combined with much higher precision, as measured by rate of true positive reports. In terms of real-world impact, since the beginning of 2021, the analysis has resulted in the discovery and disclosure of several critical vulnerabilities, over funds in the many millions of dollars. Six separate bug bounties totaling over $350K have been awarded for these disclosures.
• Software and its engineering → General programming languages; • Security and privacy → Software and application security.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a08c77e8-f3b1-4741-b887-2309db67939dCited by top-tier papers12
- AChecker: Statically Detecting Smart Contract Access Control VulnerabilitiesAsem Ghaleb, Julia Rubin, Karthik PattabiramanICSE 2023 · 63 citations
- eTainter: detecting gas-related vulnerabilities in smart contractsAsem Ghaleb, Julia Rubin, Karthik PattabiramanISSTA 2022 · 57 citations
- Elipmoc: advanced decompilation of Ethereum smart contractsNeville Grech, Sifis Lagouvardos, Ilias Tsatiris, Yannis SmaragdakisOOPSLA 2022 · 40 citations
- Falcon: A Fused Approach to Path-Sensitive Sparse Data Dependence AnalysisPeisen Yao, Jinguo Zhou, Xiao Xiao, Qingkai Shi et al.PLDI 2024 · 11 citations
- Practical Verification of Smart Contracts using Memory SplittingShelly Grossman, John Toman, Alexander Bakst, Sameer Arora et al.OOPSLA 2024 · 7 citations
Builds on15
- Making Smart Contracts SmarterLoi Luu, Duc-Hiep Chu, Hrishi Olickel, Prateek Saxena et al.CCS 2016 · 2,306 citations
- Securify: Practical Security Analysis of Smart ContractsPetar Tsankov, Andrei Marian Dan, Dana Drachsler-Cohen, Arthur Gervais et al.CCS 2018 · 1,108 citations
- Coverage-based Greybox Fuzzing as Markov ChainMarcel Böhme, Van-Thuan Pham, Abhik RoychoudhuryCCS 2016 · 1,026 citations
- Empirical review of automated analysis tools on 47, 587 Ethereum smart contractsThomas Durieux, João F. Ferreira, Rui Abreu, Pedro CruzICSE 2020 · 373 citations
- Learning to Fuzz from Symbolic Execution with Application to Smart ContractsJingxuan He, Mislav Balunovic, Nodar Ambroladze, Petar Tsankov et al.CCS 2019 · 288 citations
Related papers
- ETHBMC: A Bounded Model Checker for Smart ContractsJoel Frank, Cornelius Aschermann, Thorsten HolzUSENIX Security 2020
- Ethainter: a smart contract security analyzer for composite vulnerabilitiesLexi Brent, Neville Grech, Sifis Lagouvardos, Bernhard Scholz et al.PLDI 2020 · 163 citations
- The Incredible Shrinking Context... in a Decompiler Near YouSifis Lagouvardos, Yannis Bollanos, Neville Grech, Yannis SmaragdakisISSTA 2025 · 1 citation
- SmartIFSyn: Automated Information Flow Security Policy Synthesis for Smart ContractsYinghao Wu, Miaomiao Zhang, Fu Song, John W. Baugh Jr.FSE 2026
- SymGPT: Auditing Smart Contracts via Combining Symbolic Execution with Large Language ModelsShihao Xia, Mengting He, Shuai Shao, Tingting Yu et al.OOPSLA 2026
