A research review of AI-based smart contract vulnerability detection
Online published: 2025-08-20
Copyright
The decentralized and immutable feature of blockchain technology has driven the widespread adoption of smart contracts in fields such as finance and supply chain. However, the frequent vulnerabilities in smart contracts and the increasing complexity of attack patterns have made conventional detection approaches struggle to cope, necessitating more efficient detection techniques. To systematically review the research progress of artificial intelligence (AI) technologies in the smart contract vulnerability detection, relevant literature from 2020 to 2025 were surveyed, with the classification of vulnerability detection methods and performance evaluation criteria clarified. The technical principles, typical applications, and comparative advantages and disadvantages of AI methods such as natural language processing, graph neural networks, and large language models were analyzed. Furthermore, the current challenges faced by vulnerability detection methods were discussed, including low data quality, insufficient model interpretability, and limited scalability. Specific future research directions were also proposed, such as constructing diverse and high-quality datasets, developing highly interpretable model architectures, and improving the cross-platform compatibility of detection tools. The findings of this review can provide valuable references for research in the field of smart contract vulnerability detection and promote the deeper practical application of AI technologies.
LUO Yifan , JIANG Siyu , CHEN Weili , ZHANG Jingjing , WANG Changji . A research review of AI-based smart contract vulnerability detection[J]. Journal of Cybersecurity, 2025 , 3(3) : 25 -37 . DOI: 10.20172/j.issn.2097-3136.250302
表 1 智能合约真实攻击案例Table 1 Real-world attack cases of smart contracts |
| 攻击 | 时间 | 损失 | 主要原因 |
| Mt.Gox | 2011年10月 | 84万枚比特币 | 网络协议的缺陷 |
| Bitfloor | 2012年5月 | 2.4万枚比特币 | 钱包备份未加密 |
| Mt.Gox | 2014年 | 75万枚比特币 | 允许用户修改交易ID的漏洞 |
| DAO | 2016年6月 | 5 000万美元 | 存在重入性漏洞 |
| Ethereum network | 2016年 | — | 遭受重入攻击 |
| ParityWallet | 2017年7月 | 3 000万美元 | 访问控制权存在漏洞 |
| Coincheck | 2018年1月 | 5.34亿美元 | 新币种未引入多重签名 |
| Poly Network | 2021年8月 | 6.11亿美元 | 存在跨链桥合约漏洞 |
| Ronin | 2022年3月 | 17.36万以太币 | 桥接升级导致的投票门槛误解 |
| BinanceBNB Bridge | 2022年10月 | 5.69亿美元 | 存在跨链桥漏洞 |
| FTX | 2022年11月 | 4.73亿美元 | fallback/receive控制漏洞 |
| DMM Bitcoin | 2024年5月 | 3.08亿美元 | 植入恶意代码后,交易控制权被篡改 |
| Bybit | 2025年2月 | 14.6亿美元 | 开发设备被入侵且错误签署恶意交易 |
表 2 Smart contract Wakness Classification(SWC)漏洞分类标准Table 2 Smart contract weakness classification standards |
| ID | 漏洞名称 | 描述 |
| SWC-100 | 函数默认可见 | 函数未显式声明可见性,默认可见性为public,可能导致未授权访问。 |
| SWC-101 | 整数溢出和下溢 | 整数运算未检查溢出或下溢,可能导致变量值超出范围,引发意外行为。 |
| SWC-102 | 过时的编译器版本 | 使用低级调用(如call、send、transfer)时未检查返回值,可能导致调用失败,但合约继续执行。 |
| SWC-103 | 浮点数精度 | Solidity 不支持浮点数运算,使用整数模拟可能导致精度丢失或计算错误。 |
| SWC-104 | 未检查的返回值 | 调用外部合约时未检查返回值,可能导致调用失败,但合约继续执行。 |
| SWC-105 | 未保护的以太币提取 | 合约允许任意地址提取以太币,未对调用者进行权限验证。 |
| SWC-106 | 未保护的自毁函数selfdestruct | 合约允许任意地址调用selfdestruct,可能导致资金丢失。 |
| SWC-107 | 重入攻击 | 攻击者通过递归调用合约函数,在状态更新前多次提取资金。 |
| SWC-108 | 状态变量默认可见性 | 状态变量未显式声明可见性,默认可见性为public,可能导致信息泄露。 |
| SWC-109 | 未初始化的存储指针 | 未正确初始化存储指针,可能导致数据被意外覆盖。 |
| SWC-110 | 断言滥用 | 滥用assert进行输入验证,可能导致合约无法正常执行。 |
| SWC-111 | 使用已弃用的函数 | 使用已弃用的Solidity函数或语法,可能导致兼容性问题或安全漏洞。 |
| SWC-112 | 委托调用注入 | 使用delegatecall调用不可信的合约,可能导致状态被恶意修改。 |
| SWC-113 | 拒绝服务 | 外部调用失败导致合约无法继续执行,可能被攻击者利用。 |
| SWC-114 | 交易顺序依赖 | 攻击者通过观察未确认的交易,抢先提交高Gas价格的交易以获取利益。 |
| SWC-115 | 授权通过tx.origin | 使用tx.origin进行授权验证,可能导致钓鱼攻击。 |
| SWC-116 | 时间戳依赖 | 合约逻辑依赖区块时间戳,矿工可能操纵时间戳。 |
| SWC-117 | 签名重放攻击 | 未正确处理签名,导致同一签名被多次使用。 |
| SWC-118 | 错误的构造函数名 | 构造函数名与合约名不一致,导致构造函数变为普通函数。 |
| SWC-119 | 影子状态变量 | 局部变量与状态变量同名,可能导致逻辑错误。 |
| SWC-120 | 弱随机性 | 使用可预测的值(如区块哈希)作为随机数源,可能导致随机性被攻击者预测。 |
| SWC-121 | 缺少事件记录 | 关键操作未触发事件,导致难以追踪合约状态的变化。 |
| SWC-122 | 缺少输入验证 | 未对用户输入进行验证,可能导致合约逻辑被绕过。 |
| SWC-123 | 要求Require滥用 | 滥用Require进行输入验证,可能导致合约无法正常执行。 |
| SWC-124 | 写入任意存储位置 | 智能合约存储须严格授权,攻击者篡改存储可绕过检查,引发安全风险。 |
| SWC-125 | 错误的继承顺序 | 继承顺序错误,可能导致函数覆盖或逻辑错误。 |
| SWC-126 | Gas不足攻击 | Gas不足攻击可以在一个接受数据并在另一个合约的子调用中使用该数据的合约上执行,如果子调用失败,则将整个交易还原或继续执行。 |
| SWC-127 | 函数类型变量任意跳转 | Solidity支持函数类型变量,但滥用汇编指令可能导致任意代码执行,引发安全漏洞。 |
| SWC-128 | 利用区块Gas限制的拒绝服务攻击 | 循环操作消耗过多Gas,可能导致交易失败。 |
| SWC-129 | 拼写错误 | 会发生拼写错误。 |
| SWC-130 | 错误的权限控制 | 权限控制逻辑错误,可能导致未授权访问。 |
| SWC-131 | 未初始化的局部变量 | 局部变量未初始化,可能导致逻辑错误。 |
| SWC-132 | 依赖以太币余额的逻辑 | 如果合约逻辑仅处理特定的以太币余额,则其行为可能会错误。始终可以使用自毁或通过挖矿来强制将以太币发送至合约(不触发其fallback函数)。 |
| SWC-133 | 变长参数导致的哈希冲突 | abi.encodePacked()使用多个可变参数可能导致哈希冲突,存在安全风险。 |
| SWC-134 | 硬编码Gas用量的消息 调用 | 在智能合约中使用低级调用(如call)时,固定了Gas限额。 |
| SWC-135 | 无效果代码 | 未验证外部输入,可能导致恶意代码注入。 |
| SWC-136 | 链上未加密的私人数据 | 未加密的敏感数据存储在链上,可能导致信息泄露。 |
表 3 性能对比Table 3 Performance comparison |
| 方法 | 代表模型/工具 | 精确率 | 召回率 | F1分数 | 准确率 | 检测效率(秒/合约) | 误报率 | 漏报率 | 计算开销 |
| 静态分析工具 | Slither | 0.78 | 0.72 | 0.75 | 0.80 | 0.5~8.0 | 0.20 | 0.15 | 低 |
| 符号执行 | Mythril | 0.73 | 0.68 | 0.70 | 0.75 | 1.0~100.0 | 0.15 | 0.10 | 中 |
| 机器学习方法 | 随机森林 | 0.87 | 0.83 | 0.85 | 0.88 | 2.0~20.0 | 0.10 | 0.08 | 中 |
| 深度学习 | 图神经网络 | 0.93 | 0.91 | 0.92 | 0.94 | 5.0~10.0 | 0.05 | 0.03 | 高 |
| 1 |
CHAUM D. Computer systems established, maintained, and trusted by mutually suspicious groups[D]. Berkeley: University of California, 1982.
|
| 2 |
SHELDON R. A timeline and history of blockchain technology[EB/OL]. (2021-01-01)[2024-03-15]. https://whatis.techtarget.com/feature/A-timeline-and-history-of-blockchain-technology.
|
| 3 |
NAKAMOTO S. Bitcoin: A peer-to-peer electronic cash system[EB/OL]. (2008-10-31)[2024-03-15]. https://bitcoin.org/bitcoin. pdf.
|
| 4 |
NICK S. The idea of smart contracts[EB/OL].(1997-01-01)[2024-03-15]. http://www.fon.hum.uva.nl/rob/Courses/InformationInSpeech/CDROM/Literature/LOTwinters chool2006/szabo.best.vwh.net/idea.html.
|
| 5 |
TIAN Y, ZHANG N, LIN Y H, et al. SmartAuth: User-centered authorization for the Internet of Things[C]. 26th USENIX Security Symposium.USENIX, 2017: 361-378.
|
| 6 |
MEHAR M I, SHIER C L, GIAMBATTISTA A, et al. Understanding a DAO attack[J]. Journal of Cases on Information Technology, 2019, 21 (1): 19- 32.
|
| 7 |
CHU H, ZHANG P, DONG H, et al. A survey on smart contract vulnerabilities: Data sources, detection and repair[J]. Information and Software Technology, 2023, 159, 107221.
|
| 8 |
CHESS B, MCGRAW G. Static analysis for security[J]. IEEE Security and Privacy Magazine. 2004, 2(6): 76-79.
|
| 9 |
SINGH, KUMAR S, SINGH A. Software testing[M]. India: Vandana Publications, 2012.
|
| 10 |
BHARGAVAN K, DELIGNAT-LAVAUD A, FOURNET C, et al. Formal verification of smart contracts[C]//Proceedings of the 2016 ACM Workshop on Programming Languages and Analysis for Security. ACM, 2016: 91-96.
|
| 11 |
MOMENI P, WANG Y, SAMAVI R, et al. Machine llearning model for smart contracts security analysis[C]// 2019 17th International Conference on Privacy, Security and Trust. Fredericton, 2019: 1-6.
|
| 12 |
LUU L. Oyente: An analysis tool for smart contracts[EB/OL]. (2017-7-19)[2021-04-05]. https://loiluu.com/oyente.html.
|
| 13 |
SHARMA N, SHARMA S. A survey of Mythril, a smart contract security analysis tool for EVM bytecode[J]. Indian Journal of Natural Sciences, 2022, 13 (75): 39- 41.
|
| 14 |
FEIST J, GRIECO G, GROCE A, et al. Slither: A static analysis framework for smart contracts[C]//2019 IEEE/ACM 2nd International Workshop on Emerging Trends in Software Engineering for Blockchain. IEEE, 2019: 8-15.
|
| 15 |
TIKHOMIROV S, VOSKRESENSKAYA E, IVANITSKIY I, et al. SmartCheck: Static analysis of Ethereum smart contracts[C]//2018 IEEE/ACM 1st International Workshop on Emerging Trends in Software Engineering for Blockchain (WETSEB). IEEE, 2018: 9-16.
|
| 16 |
LIU Z, JIANG M, ZHANG S, et al. A smart contract vulnerability detection mechanism based on deep learning and expert rules[J]. IEEE Access, 2023, (11): 77990-77999.
|
| 17 |
VIDAL F R, IVAKI N, LARANJEIRO N. Vulnerability detection techniques for smart contracts: A systematic literature review[J]. Journal of Systems and Software, 2024(217): 112160-112193.
|
| 18 |
钱鹏, 刘振广, 何钦铭, 等. 智能合约安全漏洞检测技术研究综述[J]. 软件学报, 2022, 33 (8): 3059- 3085.
QIAN P, LIU Z G, HE Q M, et al. Survey on smart contract vulnerability detection techniques[J]. Journal of Software, 2022, 33 (8): 3059- 3085.
|
| 19 |
邵奇峰, 金澈清, 张召, 等. 区块链技术: 架构及进展[J]. 计算机学报, 2018, 41 (5): 969- 988.
SHAO Q F, JIN C Q, ZHANG Z, et al. Blockchain technology: Architecture and progress[J]. Chinese Journal of Computers, 2018, 41 (5): 969- 988.
|
| 20 |
SANNI B. Role of smart contracts in automating supply chain transactions[EB/OL]. (2024-10-01)[2025-03-01]. https://www.researchgate.net/publication/385209080_Role_of_Smart_Contracts_in_Automating_Supply_Chain_Transactions.
|
| 21 |
ATZEI N, BARTOLETTI M, CIMOLI T. A survey of attacks on Ethereum smart contracts[R]. Luxembourg: IACR, 2016: 1007.
|
| 22 |
LUU L, CHU D H, OLICKEL H, et al. Making smart contracts smarter[C]// Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security. ACM, 2016: 254-269.
|
| 23 |
QIN K, ZHOU L, LIVSHITS B, et al. Attacking the DeFi ecosystem with flash loans for fun and profit[J]. arXiv preprint, arXiv: 2003. 03810, 2021.
|
| 24 |
NIKOLIĆ I, KOLLURI A, SERGEY I, et al. Finding the greedy, prodigal, and suicidal contracts at scale[C]// Proceedings of the 34th Annual Computer Security Applications Conference. ACM, 2018: 653-663.
|
| 25 |
张文博, 陈思敏, 魏立斐, 等. 基于形式化方法的智能合约验证研究综述[J]. 网络与信息安全学报, 2022, 8 (4): 12- 28.
ZHANG W B, CHEN S M, WEI L F, et al. Survey on formal methods-based smart contract verification[J]. Journal of Cyber Security, 2022, 8 (4): 12- 28.
|
| 26 |
杨伊, 李滢, 陈恺. 基于自然语言处理的漏洞检测方法综述[J]. 计算机研究与发展, 2022, 59 (12): 2649- 2666.
YANG Y, LI Y, CHEN K. Survey on natural language processing-based vulnerability detection methods[J]. Journal of Computer Research and Development, 2022, 59 (12): 2649- 2666.
|
| 27 |
TANN W J W, HAN X J, GUPTA S S, et al. Towards safer smart contracts: A sequence learning approach to detecting security threats[J]. arXiv preprint, arXiv:, 1811, 06632, 2018.
|
| 28 |
QIAN P, LIU Z G, HE Q M, et al. Towards automated reentrancy detection for smart contracts based on sequential models[J]. IEEE Access, 2020, 8: 19685-19695.
|
| 29 |
ASHIZAWA N, YAMAMOTO T, TANAKA K, et al. Eth2Vec: Learning contract-wide code representations for vulnerability detection on ethereum smart contracts[C]//Proceedings of the 3rd ACM international symposium on blockchain and secure critical infrastructure. ACM, 2021.
|
| 30 |
NGUYEN H H, NGUYEN N M, XIE C, et al. MANDO-HGT: Het erogeneous graph transformers for smart contract vulnerability detection[C]//2023 IEEE/ACM 20th International Conference on Mining Software Repositories. IEEE, 2023: 334-346.
|
| 31 |
XU Z, LI Y, WANG J, et al. [J]. International Journal of Data Warehousing and Mining, 2023, 19(2): 1-23.
|
| 32 |
FENG Z, GUO D, TANG D, et al. CodeBERT: A pre-trained model for programming and natural languages[J]. arXiv preprint, arXiv:, 2002, 08155, 2020.
|
| 33 |
HANIF H, MAFFEIS S.VulBERTa: Simplified source code pre-training for vulnerability detection[C]//2022 International joint conference on neural networks (IJCNN). IEEE, 2022: 1-8.
|
| 34 |
XING C, CHEN Z, CHEN L, et al. A new scheme of vulnerability analysis in smart contract with machine learning [J]. Wirel Networks, 2024(30): 6325-6334.
|
| 35 |
ZHANG L, WANG J, WANG W, et al. Smart contract vulnerability detection combined with multi-objective detection[J]. Computer Networks, 2022, 217(9): 109289-109290.
|
| 36 |
ZHANG Y, LIU Z G, QIAN P, et al. Smart contract vulnerability detection using graph neural networks[C]//Proceedings of the Twenty-Ninth International Conference on International Joint Conferences on Artificial Intelligence. ACM, 2020: 3283-3290.
|
| 37 |
ZHEN Z, ZHAO X, ZHANG J, et al. DA-GNN: A smart contract vulnerability detection method based on dual attention graph neural network[J]. Computer Networks, 2024, 242, 110238.
|
| 38 |
ZHOU K, CHENG J, LI H, et al. SC-VDM: A light-weight smart contract vulnerability detection model [C]//Proceedings of the International Conference on Data Mining and Big Data. Springer, 2021: 138.
|
| 39 |
HWANG S J, CHOI S H, SHIN J, et al. CodeNet: Codetargeted convolutional neural network archi- tecture for smart contract vulnerability detection[J]. IEEE Access, 2022, 10, 32595-32607.
|
| 40 |
SUN X, TU L, ZHANG J, et al. ASSBert: Active and semi-supervised bert for smart contract vulnerability detection[J]. Journal of Information Security and Applications, 2023, 73: 103423.
|
| 41 |
WEI Z, SUN J, ZHANG Z, et al. FTSmartAudit: A knowledge distillation-enhanced framework for automated smart contract auditing using fine-tuned LLMs[J]. arXiv preprint, arXiv: 2410.13918, 2024.
|
| 42 |
BOI B, ESPOSITO C, LEE S. VulnHunt-GPT: A smart contract vulnerabilities detector based on OpenAI chatGPT[C]//Proceedings of the 39th ACM/SIGAPP Symposium on Applied Computing. ACM, 2024: 1517-1524.
|
| 43 |
WEI Z, SUN J, ZHANG Z, et al. LLM-SmartAudit: Advanced smart contract vulnerability detection[J]. arXiv preprint, arXiv:, 2410, 09381, 2024.
|
| 44 |
YU J. Retrieval augmented generation integrated large language models in smart contract vulnerability detection[J]. arXiv preprint, arXiv:, 2407, 14838, 2024.
|
| 45 |
LIU Z, JIANG M, ZHANG S, et al. A smart contract vulnerability detection mechanism based on deep learning and expert rules[J]. IEEE Access, 2023, 11, 77990- 77999.
|
| 46 |
ZHENG Z, SU J, CHEN J, et al. DAppSCAN: Building large-scale datasets for smart contract weaknesses in DApp projects[J]. IEEE Transactions on Software Engineering, 2024, 50(6): 1360 - 1373.
|
| 47 |
FERREIRA J F, CRUZ P, DURIEUX T, et al. SmartBugs: A framework to analyze solidity smart contracts[C]//Proceedings of the 35th IEEE/ACM international conference on automated software engineering. IEEE, 2020: 1349-1352.
|
| 48 |
GAO Z. When deep learning meets smart contracts[C]//Proceedings of the 35th IEEE/ACM International Conference on Automated Software Engineering. IEEE, 2020: 1400-1402.
|
| 49 |
KUSHWAHA S S, JOSHI S, SINGH D, et al. Ethereum smart contract analysis tools: A systematic review[J]. IEEE Access, 2022, 10, 57037- 57062.
|
| 50 |
王晓丽, 严驰. 生成式AI大模型的风险问题与规制进路: 以GPT-4为例[J]. 北京航空航天大学学报(社会科学版), 2025, 38 (1): 1- 10.
WANG X L, YAN C. Risks and regulatory approaches of generative AI large models: A case study of GPT-4[J]. Journal of Beijing University of Aeronautics and Astronautics (Social Sciences Edition), 2025, 38 (1): 1- 10.
|
| 51 |
PAUDEL D, DE WIT A, BOOGAARD H, et al. Interpretability of deep learning models for crop yield forecasting[J]. Computers and Electronics in Agriculture, 2023, 206, 107663.
|
| 52 |
QIU Y, MA L, PRIYADARSHI R. Deep learning challenges and prospects in wireless sensor network deployment[J]. Archives of Computational Methods in Engineering, 2024, 31(6): 3231-3254.
|
| 53 |
朱涵, 吴胜. 区块链跨链技术及其安全性综述[J]. 计算机应用研究, 2024, 41 (12): 1- 15.
ZHU H, WU S. Blockchain cross-chain technology and its security: A survey[J]. Application Research of Computers, 2024, 41 (12): 1- 15.
|
| 54 |
施敏, 杨海军. 大语言模型数据隐私保护的难点与探索[J]. 大数据研究, 2024, 10 (5): 1- 12.
SHI M, YANG H J. Challenges and explorations in data privacy protection for large language models[J]. Big Data Research, 2024, 10 (5): 1- 12.
|
| 55 |
陈卓, 江辉, 周杨. 一种面向联邦学习对抗攻击的选择性防御策略[J]. 电子与信息学报, 2024, 46 (3): 1119- 1127.
CHEN Z, JIANG H, ZHOU Y. A selective defense strategy against adversarial attacks in federated learning[J]. Journal of Electronics & Information Technology, 2024, 46 (3): 1119- 1127.
|
/
| 〈 |
|
〉 |