Smart Contract Vulnerability Analysis and Security Audit

Daojing He*, Zhi Deng, Yuxing Zhang, Sammy Chan, Yao Cheng, Nadra Guizani

*Corresponding author for this work

Research output: Journal Publications and ReviewsRGC 21 - Publication in refereed journalpeer-review

96 Citations (Scopus)

Abstract

Ethereum started the blockchain-based smart contract technology that due to its scalability more and more decentralized applications are now based on. On the downside this has led to the exposure of more and more security issues and challenges, which has gained widespread attention in terms of research in the field of Ethereum smart contract vulnerabilities in both academia and industry. This article presents a survey of the Ethereum smart contract's various vulnerabilities and the corresponding defense mechanisms that have been applied to combat them. In particular, we focus on the random number vulnerability in the Fomo3d-like game contracts, as well as that attack and defense methods applied. Finally, we summarize the existing Ethereum smart contract security audit methods and compare several mainstream audit tools from various perspectives.
Original languageEnglish
Pages (from-to)276-282
JournalIEEE Network
Volume34
Issue number5
Online published17 Jul 2020
DOIs
Publication statusPublished - Sept 2020

Research Keywords

  • Contracts
  • Games
  • Bitcoin
  • Computer hacking
  • Industries

Fingerprint

Dive into the research topics of 'Smart Contract Vulnerability Analysis and Security Audit'. Together they form a unique fingerprint.

Cite this