Copy-and-Paste? Identifying EVM-Inequivalent Code Smells in Multi-chain Reuse Contracts
Zexu Wang, Jiachi Chen, Tao Zhang, Yu Zhang, Weizhe Zhang, Yuming Feng, Zibin Zheng
摘要
As the development of Solidity contracts on Ethereum, more developers are reusing them on other compatible blockchains. However, developers may overlook the differences between the designs of the blockchain system, such as the Gas Mechanism and Consensus Protocol, leading to the same contracts on different blockchains not being able to achieve consistent execution as on Ethereum. This inconsistency reveals design flaws in reused contracts, exposing code smells that hinder code reusability, and we define this inconsistency as EVM-Inequivalent Code Smells.
In this paper, we conducted the first empirical study to reveal the causes and characteristics of EVM-Inequivalent Code Smells. To ensure the identified smells reflect real developer concerns, we collected and analyzed 1,379 security audit reports and 326 Stack Overflow posts related to reused contracts on EVMcompatible blockchains, such as Binance Smart Chain (BSC) and Polygon. Using the open card sorting method, we defined six types of EVM-Inequivalent Code Smells. For automated detection, we developed a tool named EquivGuard. It employs static taint analysis to identify key paths from different patterns and uses symbolic execution to verify path reachability. Our analysis of 905,948 contracts across six major blockchains shows that EVM-Inequivalent Code Smells are widespread, with an average prevalence of 17.70%. While contracts with code smells do not necessarily lead to financial loss and attacks, their high prevalence and significant asset management underscore the potential threats of reusing these smelly Ethereum contracts. Thus, developers are advised to abandon Copy-and-Paste programming practices and detect EVM-Inequivalent Code Smells before reusing Ethereum contracts.
CCS Concepts: • Software and its engineering → Software testing and debugging.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper7
- Making Smart Contracts SmarterLoi Luu, Duc-Hiep Chu, Hrishi Olickel, Prateek Saxena 等CCS 2016 · 被引用 2,306 次
- Cross-Contract Static Analysis for Detecting Practical Reentrancy Vulnerabilities in Smart ContractsYinxing Xue, Mingliang Ma, Yun Lin, Yulei Sui 等ASE 2020 · 被引用 77 次
- Definition and Detection of Defects in NFT Smart ContractsShuo Yang, Jiachi Chen, Zibin ZhengISSTA 2023 · 被引用 35 次
- Efficiently Detecting Reentrancy Vulnerabilities in Complex Smart ContractsZexu Wang, Jiachi Chen, Yanlin Wang, Yu Zhang 等FSE 2024 · 被引用 27 次
- Demystifying the Composition and Code Reuse in Solidity Smart ContractsKairan Sun, Zhengzi Xu, Chengwei Liu, Kaixuan Li 等FSE 2023 · 被引用 25 次
相关 Paper
- Clone Detection for Smart Contracts: How Far Are We?Zuobin Wang, Zhiyuan Wan, Yujing Chen, Yun Zhang 等FSE 2025 · 被引用 1 次
- Demystifying Invariant Effectiveness for Securing Smart ContractsZhiyang Chen, Ye Liu, Sidi Mohamed Beillahi, Yi Li 等FSE 2024 · 被引用 15 次
- An Empirical Study of Proxy Contracts at the Ethereum Ecosystem ScaleMengya Zhang, Preksha Shukla, Wuqi Zhang, Zhuo Zhang 等ICSE 2025 · 被引用 5 次
- Uncover the Premeditated Attacks: Detecting Exploitable Reentrancy Vulnerabilities by Identifying Attacker ContractsShuo Yang, Jiachi Chen, Mingyuan Huang, Zibin Zheng 等ICSE 2024 · 被引用 24 次
- Detecting Smart Contract State-Inconsistency Bugs via Flow Divergence and Multiplex Symbolic ExecutionYinxi Liu, Wei Meng, Yinqian ZhangFSE 2025 · 被引用 1 次
