Smart Contract Vulnerabilities, Tools, and Benchmarks: an Updated Systematic Literature Review
arXiv:2412.01719 · doi:10.1016/j.jss.2026.112788
Abstract
Smart contracts are self-executing programs on blockchain platforms like Ethereum, which have revolutionized decentralized finance by enabling trustless transactions and the operation of decentralized applications. Despite their potential, the security of smart contracts remains a critical concern due to their immutability and transparency, which expose them to malicious actors. Numerous solutions for vulnerability detection have been proposed, but it is still unclear which one is the most effective. This paper presents a systematic literature review that explores vulnerabilities in Ethereum smart contracts, focusing on automated detection tools and benchmark evaluation. We reviewed 3,380 studies from five digital libraries and five major software engineering conferences, applying a structured selection process that resulted in 222 high-quality studies. The key results include a hierarchical taxonomy of 192 vulnerabilities grouped into 13 categories, a comprehensive list of 219 detection tools with corresponding functionalities, methods, and code transformation techniques, a mapping between our taxonomy and the list of tools, and a collection of 133 benchmarks used for tool evaluation. We conclude with a discussion about the insights into the current state of Ethereum smart contract security and directions for future research.
References in corpus (12)
- Blockchain-based Digital Twins: Research Trends, Issues, and Future Challenges
- DEFECTCHECKER: Automated Smart Contract Defect Detection by Analyzing EVM Bytecode
- Checking Smart Contracts with Structural Code Embedding
- xFuzz: Machine Learning Guided Cross-Contract Fuzzing
- DAppSCAN: Building Large-Scale Datasets for Smart Contract Weaknesses in DApp Projects
- A security framework for Ethereum smart contracts
- Static Application Security Testing (SAST) Tools for Smart Contracts: How Far Are We?
- SigRec: Automatic Recovery of Function Signatures in Smart Contracts
- OpenSCV: An Open Hierarchical Taxonomy for Smart Contract Vulnerabilities
- SmartAxe: Detecting Cross-Chain Vulnerabilities in Bridge Smart Contracts via Fine-Grained Static Analysis
- Vulpedia: Detecting Vulnerable Ethereum Smart Contracts via Abstracted Vulnerability Signatures
- Unveiling the Landscape of Smart Contract Vulnerabilities: A Detailed Examination and Codification of Vulnerabilities in Prominent Blockchains