Skip to main navigation Skip to search Skip to main content

Smart Contract Vulnerability Analysis and Security Audit

  • Daojing He*
  • , Zhi Deng
  • , Yuxing Zhang
  • , Sammy Chan
  • , Yao Cheng
  • , Nadra Guizani
  • *Corresponding author for this work
  • East China Normal University
  • City University of Hong Kong
  • Agency for Science, Technology and Research, Singapore
  • Purdue University

Research output: Contribution to journalArticlepeer-review

Abstract

Ethereum started the blockchain-based smart contract technology that due to its scalability more and more decentralized applications are now based on. On the downside this has led to the exposure of more and more security issues and challenges, which has gained widespread attention in terms of research in the field of Ethereum smart contract vulnerabilities in both academia and industry. This article presents a survey of the Ethereum smart contract's various vulnerabilities and the corresponding defense mechanisms that have been applied to combat them. In particular, we focus on the random number vulnerability in the Fomo3d-like game contracts, as well as that attack and defense methods applied. Finally, we summarize the existing Ethereum smart contract security audit methods and compare several mainstream audit tools from various perspectives.

Original languageEnglish
Article number9143290
Pages (from-to)276-282
Number of pages7
JournalIEEE Network
Volume34
Issue number5
DOIs
StatePublished - 1 Sep 2020
Externally publishedYes

Fingerprint

Dive into the research topics of 'Smart Contract Vulnerability Analysis and Security Audit'. Together they form a unique fingerprint.

Cite this