AChecker: Statically Detecting Smart Contract Access Control Vulnerabilities
Asem Ghaleb, Julia Rubin, Karthik Pattabiraman
Abstract
As most smart contracts have a financial nature and handle valuable assets, smart contract developers use access control to protect assets managed by smart contracts from being misused by malicious or unauthorized people. Unfortunately, programming languages used for writing smart contracts, such as Solidity, were not designed with a permission-based security model in mind. Therefore, smart contract developers implement access control checks based on their judgment and in an adhoc manner, which results in several vulnerabilities in smart contracts, called access control vulnerabilities. Further, the in-consistency in implementing access control makes it difficult to reason about whether a contract meets access control needs and is free of access control vulnerabilities. In this work, we propose AChecker - an approach for detecting access control vulnerabilities. Unlike prior work, AChecker does not rely on pre-defined patterns or contract transactions history. Instead, it infers access control implemented in smart contracts via static data-flow analysis. Moreover, the approach performs further symbolic-based analysis to distinguish cases when unauthorized people can obtain control of the contract as intended functionality. We evaluated AChecker on three public datasets of real-world smart contracts, including one which consists of contracts with assigned access control CVEs, and compared its effectiveness with eight analysis tools. The evaluation results showed that AChecker outperforms these tools in terms of both precision and recall. In addition, AChecker flagged vulnerabilities in 21 frequently-used contracts on Ethereum blockchain with 90% precision.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d38d3f35-73ad-43d1-b386-603a7ca5e3b9Cited by top-tier papers20
- GPTScan: Detecting Logic Vulnerabilities in Smart Contracts by Combining GPT with Program AnalysisYuqiang Sun, Daoyuan Wu, Yue Xue, Han Liu et al.ICSE 2024 · 131 citations
- Static Application Security Testing (SAST) Tools for Smart Contracts: How Far Are We?Kaixuan Li, Yue Xue, Sen Chen, Han Liu et al.FSE 2024 · 26 citations
- FlashSyn: Flash Loan Attack Synthesis via Counter Example Driven ApproximationZhiyang Chen, Sidi Mohamed Beillahi, Fan LongICSE 2024 · 21 citations
- Analyzing Quantum Programs with LintQ: A Static Analysis Framework for QiskitMatteo Paltenghi, Michael PradelFSE 2024 · 19 citations
- SmartAxe: Detecting Cross-Chain Vulnerabilities in Bridge Smart Contracts via Fine-Grained Static AnalysisZeqin Liao, Yuhong Nan, Henglong Liang, Sicheng Hao et al.FSE 2024 · 18 citations
Builds on9
- Making Smart Contracts SmarterLoi Luu, Duc-Hiep Chu, Hrishi Olickel, Prateek Saxena et al.CCS 2016 · 2,306 citations
- Securify: Practical Security Analysis of Smart ContractsPetar Tsankov, Andrei Marian Dan, Dana Drachsler-Cohen, Arthur Gervais et al.CCS 2018 · 1,108 citations
- Empirical review of automated analysis tools on 47, 587 Ethereum smart contractsThomas Durieux, João F. Ferreira, Rui Abreu, Pedro CruzICSE 2020 · 373 citations
- teEther: Gnawing at Ethereum to Automatically Exploit Smart ContractsJohannes Krupp, Christian RossowUSENIX Security 2018 · 345 citations
- How effective are smart contract analysis tools? evaluating smart contract static analysis tools using bug injectionAsem Ghaleb, Karthik PattabiramanISSTA 2020 · 183 citations
Related papers
- ACTaint: Agent-Based Taint Analysis for Access Control Vulnerabilities in Smart ContractsHuarui Lin, Zhipeng Gao, Jiachi Chen, Xiang Chen et al.ASE 2025 · 1 citation
- SmartIFSyn: Automated Information Flow Security Policy Synthesis for Smart ContractsYinghao Wu, Miaomiao Zhang, Fu Song, John W. Baugh Jr.FSE 2026
- Automated Inference on Financial Security of Ethereum Smart ContractsWansen Wang, Wenchao Huang, Zhaoyi Meng, Yan Xiong et al.USENIX Security 2023
- Identifying Smart Contract Security Issues in Code Snippets from Stack OverflowJiachi Chen, Chong Chen, Jiang Hu, John C. Grundy et al.ISSTA 2024 · 9 citations
- SmartDagger: a bytecode-based static analysis approach for detecting cross-contract vulnerabilityZeqin Liao, Zibin Zheng, Xiao Chen, Yuhong NanISSTA 2022 · 64 citations
