Smart Contract Vulnerability Analysis and Security Audit

Research output: Journal Publications and Reviews (RGC: 21, 22, 62)21_Publication in refereed journalpeer-review

23 Scopus Citations
View graph of relations

Author(s)

  • Daojing He
  • Zhi Deng
  • Yuxing Zhang
  • Yao Cheng
  • Nadra Guizani

Related Research Unit(s)

Detail(s)

Original languageEnglish
Pages (from-to)276-282
Journal / PublicationIEEE Network
Volume34
Issue number5
Online published17 Jul 2020
Publication statusPublished - Sep 2020

Abstract

Ethereum started the blockchain-based smart contract technology that due to its scalability more and more decentralized applications are now based on. On the downside this has led to the exposure of more and more security issues and challenges, which has gained widespread attention in terms of research in the field of Ethereum smart contract vulnerabilities in both academia and industry. This article presents a survey of the Ethereum smart contract's various vulnerabilities and the corresponding defense mechanisms that have been applied to combat them. In particular, we focus on the random number vulnerability in the Fomo3d-like game contracts, as well as that attack and defense methods applied. Finally, we summarize the existing Ethereum smart contract security audit methods and compare several mainstream audit tools from various perspectives.

Research Area(s)

  • Contracts, Games, Bitcoin, Computer hacking, Industries

Citation Format(s)

Smart Contract Vulnerability Analysis and Security Audit. / He, Daojing; Deng, Zhi; Zhang, Yuxing et al.

In: IEEE Network, Vol. 34, No. 5, 09.2020, p. 276-282.

Research output: Journal Publications and Reviews (RGC: 21, 22, 62)21_Publication in refereed journalpeer-review