USENIX Security2021Top-tier venue
EVMPatch: Timely and Automated Patching of Ethereum Smart Contracts
Michael Rodler, Wenting Li, Ghassan O. Karame, Lucas Davi
Abstract
Recent attacks exploiting errors in smart contract code had devastating consequences thereby questioning the benefits of this technology. It is currently highly challenging to fix errors and deploy a patched contract in time. Instant patching is especially important since smart contracts are always online due to the distributed nature of blockchain systems. They also manage considerable amounts of assets, which are at risk and often beyond recovery after an attack. Existing solutions to upgrade smart contracts depend on manual and error-prone processes. This paper presents a framework, called EVMPatch, to instantly and automatically patch faulty smart contracts. EVMPatch features a bytecode rewriting engine for the popular Ethereum blockchain, and transparently/automatically rewrites common off-the-shelf contracts to upgradable contracts. The proof-of-concept implementation of EVMPatch automatically hardens smart contracts that are vulnerable to integer over/underflows and access control errors, but can be easily extended to cover more bug classes. Our extensive evaluation on 14,000 real-world (vulnerable) contracts demonstrate that our approach successfully blocks attack transactions launched on these contracts, while keeping the intended functionality of the contract intact. We perform a study with experienced software developers, showing that EVMPatch is practical, and reduces the time for converting a given Solidity smart contract to an upgradable contract by 97.6 %, while ensuring functional equivalence to the original contract.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext bd3b1632-a237-44cf-a671-e4d756222c3bCited by top-tier papers17
- Impact and User Perception of Sandwich Attacks in the DeFi EcosystemYe Wang, Patrick Zuest, Yaxing Yao, Zhicong Lu et al.CHI 2022 · 52 citations
- WASAI: uncovering vulnerabilities in Wasm smart contractsWeimin Chen, Zihan Sun, Haoyu Wang, Xiapu Luo et al.ISSTA 2022 · 43 citations
- Characterizing Ethereum Upgradable Smart Contracts and Their Security ImplicationsXiaofan Li, Jin Yang, Jiaqi Chen, Yuzhe Tang et al.WWW 2024 · 23 citations
- Fuzz on the Beach: Fuzzing Solana Smart ContractsSven Smolka, Jens-Rene Giesen, Pascal Winkler, Oussama Draissi et al.CCS 2023 · 22 citations
- BunnyFinder: Finding Incentive Flaws for Ethereum ConsensusRujia Li, Mingfei Zhang, Xueqian Lu, Wenbo Xu et al.NDSS 2026 · 5 citations
Builds on9
- Making Smart Contracts SmarterLoi Luu, Duc-Hiep Chu, Hrishi Olickel, Prateek Saxena et al.CCS 2016 · 2,306 citations
- Securify: Practical Security Analysis of Smart ContractsPetar Tsankov, Andrei Marian Dan, Dana Drachsler-Cohen, Arthur Gervais et al.CCS 2018 · 1,108 citations
- ZEUS: Analyzing Safety of Smart ContractsSukrit Kalra, Seep Goel, Mohan Dhawan, Subodh SharmaNDSS 2018 · 595 citations
- teEther: Gnawing at Ethereum to Automatically Exploit Smart ContractsJohannes Krupp, Christian RossowUSENIX Security 2018 · 345 citations
- Sereum: Protecting Existing Smart Contracts Against Re-Entrancy AttacksMichael Rodler, Wenting Li, Ghassan O. Karame, Lucas DaviNDSS 2019 · 298 citations
Related papers
- SmartFix: Fixing Vulnerable Smart Contracts by Accelerating Generate-and-Verify Repair using Statistical ModelsSunbeom So, Hakjoo OhFSE 2023 · 20 citations
- SGUARD: Towards Fixing Vulnerable Smart Contracts AutomaticallyTai D. Nguyen, Long H. Pham, Jun SunS&P 2021 · 69 citations
- EVMbench: Evaluating AI Agents on Smart Contract SecurityJustin Wang, Andreas Bigger, Xiaohai Xu, Justin W. Lin et al.ICML 2026 · 8 citations
- eThor: Practical and Provably Sound Static Analysis of Ethereum Smart ContractsClara Schneidewind, Ilya Grishchenko, Markus Scherer, Matteo MaffeiCCS 2020 · 9 citations
- Your Exploit is Mine: Instantly Synthesizing Counterattack Smart ContractZhuo Zhang, Zhiqiang Lin, Marcelo Morales, Xiangyu Zhang et al.USENIX Security 2023
