Empirical Study of Move Smart Contract Security: Introducing MoveScan for Enhanced Analysis
Shuwei Song, Jiachi Chen, Ting Chen, Xiapu Luo, Teng Li, Wenwu Yang, Leqing Wang, Weijie Zhang, Feng Luo, Zheyuan He, Yi Lu, Pan Li
摘要
Move, a programming language for smart contracts, stands out for its focus on security. However, the practical security efficacy of Move contracts remains an open question. This work conducts the first comprehensive empirical study on the security of Move contracts. Our initial step involves collaborating with a security company to manually audit 652 contracts from 92 Move projects. This process reveals eight types of defects, with half previously unreported. These defects present potential security risks, cause functional flaws, mislead users, or waste computational resources. To further evaluate the prevalence of these defects in real-world Move contracts, we present MoveScan, an automated analysis framework that translates bytecode into an intermediate representation (IR), extracts essential meta-information, and detects all eight defect types. By leveraging MoveScan, we uncover 97,028 defects across all 37,302 deployed contracts in the Aptos and Sui blockchains, indicating a high prevalence of defects. Experimental results demonstrate that the precision of MoveScan reaches 98.85%, with an average project analysis time of merely 5.45 milliseconds. This surpasses previous state-of-the-art tools MoveLint, which exhibits an accuracy of 87.50% with an average project analysis time of 71.72 milliseconds, and Move Prover, which has a recall rate of 6.02% and requires manual intervention. Our research also yields new observations and insights that aid in developing more secure Move contracts.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper8
- Making Smart Contracts SmarterLoi Luu, Duc-Hiep Chu, Hrishi Olickel, Prateek Saxena 等CCS 2016 · 被引用 2,306 次
- sFuzz: an efficient adaptive fuzzer for solidity smart contractsTai D. Nguyen, Long H. Pham, Jun Sun, Yun Lin 等ICSE 2020 · 被引用 260 次
- TokenScope: Automatically Detecting Inconsistent Behaviors of Cryptocurrency Tokens in EthereumTing Chen, Yufei Zhang, Zihao Li, Xiapu Luo 等CCS 2019 · 被引用 140 次
- ItyFuzz: Snapshot-Based Fuzzer for Smart ContractChaofan Shou, Shangyin Tan, Koushik SenISSTA 2023 · 被引用 76 次
- AChecker: Statically Detecting Smart Contract Access Control VulnerabilitiesAsem Ghaleb, Julia Rubin, Karthik PattabiramanICSE 2023 · 被引用 63 次
相关 Paper
- Empirical review of automated analysis tools on 47, 587 Ethereum smart contractsThomas Durieux, João F. Ferreira, Rui Abreu, Pedro CruzICSE 2020 · 被引用 373 次
- Tracking Borrows with Regular ExpressionsTodd Nowacki, Sam Blackshear, John Mitchell, Shaz Qadeer 等OOPSLA 2026
- Let's Move2EVMLorenzo Benetollo, Andreas Lackner, Matteo Maffei, Markus SchererUSENIX Security 2025
- Can advanced type systems be usable? An empirical study of ownership, assets, and typestate in ObsidianMichael J. Coblenz, Jonathan Aldrich, Brad A. Myers, Joshua SunshineOOPSLA 2020 · 被引用 15 次
- Enhancing the Open Network: Definition and Automated Detection of Smart Contract DefectsHao Song, Teng Li, Jiachi Chen, Ting Chen 等ICSE 2025 · 被引用 5 次
