Solidity Vulnerability Scanner
Abstract
The Ethereum smart contract language Solidity has caused a breakthrough in the field of blockchain technology with the introduction of logic in contract-form via these smart contracts. Since these contracts are immutable, there is a serious requirement to audit and test these contracts multiple times before they are deployed. There are several cases of financial and reputation damage due to unaudited smart contracts as seen in the cases of the Axie Infinity hack or Wormhole bridge hack which resulted in hundreds of millions of dollar losses. For a developer just getting into web3 development, these hacks might intimidate and drive them away from learning due to the fear of incurring such losses themselves or due to not understanding the reason for hacks. This tool allows a developer to simply paste their contract into a textbox and obtain a list of the contract-based vulnerabilities found via parsing and pattern searching. Mitigation techniques are also suggested line by line to aid the developer in securing the contract. The key difference between this tool and existing technologies is that it is compact and very precise in identifying known contract-based vulnerabilities. Providing developers with a quick and simple interface was the rationale behind the motivation. Tools like parsers and regular expression libraries were used to look for keyword detection methodology. The tool is to be used supplementarily and not as the sole identifier of vulnerabilities since there are multiple layers to web3 security and this tool only identifies smart contract-based vulnerabilities, not off-chain ones. Future additions to this tool may include example vulnerable code snippets and also explanations for the reason they are not safe for deployment as well as mitigations which can be used by any user who is interested in learning web3 security and how hacks happen.
Community
0 commentsNo discussion yet
Be the first to share a question or observation.