A study of inline assembly in solidity smart contracts
Stefanos Chaliasos, Arthur Gervais, Benjamin Livshits
Abstract
The Solidity programming language is the most widely used language for smart contract development. Improving smart contracts' correctness, security, and performance has been the driving force for research in vulnerability detection, program analysis, and compiler techniques for Solidity. Similar to system-level languages such as C, Solidity enables the embedding of low-level code in programs, in the form of inline assembly code. Developers use inline assembly for low-level optimizations, extending the Solidity language through libraries, and using blockchain-specific opcodes only available through inline assembly. Nevertheless, inline assembly fragments are not well understood by an average developer and can introduce security threats as well as affect the optimizations that can be applied to programs by the compiler; it also significantly limits the effectiveness of source code static analyzers that operate on the Solidity level. A better understanding of how inline assembly is used in practice could in turn increase the performance, security, and support for inline assembly in Solidity.
This paper presents a large-scale quantitative study of the use of inline assembly in 6.8𝑀 smart contracts deployed on the Ethereum blockchain. We find that 23% of the analyzed smart contracts contain inline assembly code, and that the use of inline assembly has become more widespread over time. We further performed a manual qualitative analysis for identifying usage patterns of inline assembly in Solidity smart contracts. Our findings are intended to help practitioners understand when they should use inline assembly and guide developers of Solidity tools in prioritizing which parts of inline assembly to implement first. Finally, the insights of this study could be used to enhance the Solidity language, improve the Solidity compiler, and to open up new research directions by driving future researchers to build appropriate methods and techniques for replacing inline assembly in Solidity programs when there is no real necessity to use it.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext abc0396d-b556-4424-a3a2-4506b971250dCited by top-tier papers5
- Speculative Denial-of-Service Attacks In EthereumAviv Yaish, Kaihua Qin, Liyi Zhou, Aviv Zohar et al.USENIX Security 2024 · 38 citations
- Precise Static Identification of Ethereum Storage VariablesSifis Lagouvardos, Yannis Bollanos, Michael Debono, Neville Grech et al.ICSE 2026 · 2 citations
- The Incredible Shrinking Context... in a Decompiler Near YouSifis Lagouvardos, Yannis Bollanos, Neville Grech, Yannis SmaragdakisISSTA 2025 · 1 citation
- Copy-and-Paste? Identifying EVM-Inequivalent Code Smells in Multi-chain Reuse ContractsZexu Wang, Jiachi Chen, Tao Zhang, Yu Zhang et al.ISSTA 2025
- An Empirical Study of WebAssembly Usage in Node.jsMichelle Thalakottur, Maxwell Bernstein, Daniel Lehmann, Michael Pradel et al.ICSE 2026
Builds on8
- Securify: Practical Security Analysis of Smart ContractsPetar Tsankov, Andrei Marian Dan, Dana Drachsler-Cohen, Arthur Gervais et al.CCS 2018 · 1,108 citations
- Empirical review of automated analysis tools on 47, 587 Ethereum smart contractsThomas Durieux, João F. Ferreira, Rui Abreu, Pedro CruzICSE 2020 · 373 citations
- Ethainter: a smart contract security analyzer for composite vulnerabilitiesLexi Brent, Neville Grech, Sifis Lagouvardos, Bernhard Scholz et al.PLDI 2020 · 163 citations
- Inception: System-Wide Security Testing of Real-World Embedded Systems SoftwareNassim Corteggiani, Giovanni Camurati, Aurélien FrancillonUSENIX Security 2018 · 117 citations
- Well-typed programs can go wrong: a study of typing-related bugs in JVM compilersStefanos Chaliasos, Thodoris Sotiropoulos, Georgios-Petros Drosos, Charalambos Mitropoulos et al.OOPSLA 2021 · 31 citations
Related papers
- Towards Understanding the Bugs in Solidity CompilerHaoyang Ma, Wuqi Zhang, Qingchao Shen, Yongqiang Tian et al.ISSTA 2024 · 9 citations
- Demystifying Loops in Smart ContractsBenjamin Mariano, Yanju Chen, Yu Feng, Shuvendu K. Lahiri et al.ASE 2020 · 20 citations
- Revealing Hidden Threats: An Empirical Study of Library Misuse in Smart ContractsMingyuan Huang, Jiachi Chen, Zigui Jiang, Zibin ZhengICSE 2024 · 10 citations
- Clone Detection for Smart Contracts: How Far Are We?Zuobin Wang, Zhiyuan Wan, Yujing Chen, Yun Zhang et al.FSE 2025 · 1 citation
- SmartIFSyn: Automated Information Flow Security Policy Synthesis for Smart ContractsYinghao Wu, Miaomiao Zhang, Fu Song, John W. Baugh Jr.FSE 2026
