Towards Finding Accounting Errors in Smart Contracts
Brian Zhang
摘要
Bugs in smart contracts may have devastating effects as they tend to cause financial loss. According to a recent study, accounting bugs are the most common kind of bugs in smart contracts that are beyond automated tools during pre-deployment auditing. The reason lies in that these bugs are usually in the core business logic and hence contract-specific. They are analogous to functional bugs in traditional software, which are largely beyond automated bug finding tools whose effectiveness hinges on uniform and machine checkable characteristics of bugs. It was also reported that accounting bugs are the second-most difficult to find through manual auditing, due to the need of understanding underlying business models. We observe that a large part of business logic in smart contracts can be modeled by a few primitive operations like those in a bank, such as deposit, withdraw, loan, and pay-off, or by their combinations. The properties of these operations can be clearly defined and checked by an abstract type system that models high-order information such as token units, scaling factors, and financial types. We hence develop a novel type propagation and checking system with the aim of identifying accounting bugs. Our evaluation on a large set of 57 existing accounting bugs in 29 real-world projects shows that 58% of the accounting bugs are type errors. Our system catches 87.9% of these type errors. In addition, applying our technique to auditing a large project in a very recent auditing contest has yielded the identification of 6 zero-day accounting bugs with 4 leading to direct fund loss.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- Detecting Bugs with Substantial Monetary Consequences by LLM and Rule-based ReasoningBrian Zhang, Zhuo ZhangNeurIPS 2024 · 被引用 12 次
- GenDetect: Generalizing Reactive Detection for Resilience Against Imitative DeFi Attack CascadeBowen Cai, Weiheng Bai, Youshui Lu, Haoran Xu 等ICSE 2026
- SymGPT: Auditing Smart Contracts via Combining Symbolic Execution with Large Language ModelsShihao Xia, Mengting He, Shuai Shao, Tingting Yu 等OOPSLA 2026
它引用的顶会 Paper18
- Making Smart Contracts SmarterLoi Luu, Duc-Hiep Chu, Hrishi Olickel, Prateek Saxena 等CCS 2016 · 被引用 2,306 次
- Securify: Practical Security Analysis of Smart ContractsPetar Tsankov, Andrei Marian Dan, Dana Drachsler-Cohen, Arthur Gervais 等CCS 2018 · 被引用 1,108 次
- ZEUS: Analyzing Safety of Smart ContractsSukrit Kalra, Seep Goel, Mohan Dhawan, Subodh SharmaNDSS 2018 · 被引用 595 次
- teEther: Gnawing at Ethereum to Automatically Exploit Smart ContractsJohannes Krupp, Christian RossowUSENIX Security 2018 · 被引用 345 次
- Sereum: Protecting Existing Smart Contracts Against Re-Entrancy AttacksMichael Rodler, Wenting Li, Ghassan O. Karame, Lucas DaviNDSS 2019 · 被引用 298 次
相关 Paper
- SmartInv: Multimodal Learning for Smart Contract Invariant InferenceSally Junsong Wang, Kexin Pei, Junfeng YangS&P 2024 · 被引用 38 次
- PromFuzz: Leveraging LLM-Driven and Bug-Oriented Composite Analysis for Detecting Functional Bugs in Smart ContractsXingshuang Lin, Qinge Xie, Binbin Zhao, Yuan Tian 等ASE 2025 · 被引用 5 次
- Demystifying Exploitable Bugs in Smart ContractsZhuo Zhang, Brian Zhang, Wen Xu, Zhiqiang LinICSE 2023 · 被引用 80 次
- SolType: refinement types for arithmetic overflow in solidityBryan Tan, Benjamin Mariano, Shuvendu K. Lahiri, Isil Dillig 等POPL 2022 · 被引用 29 次
- GPTScan: Detecting Logic Vulnerabilities in Smart Contracts by Combining GPT with Program AnalysisYuqiang Sun, Daoyuan Wu, Yue Xue, Han Liu 等ICSE 2024 · 被引用 131 次
