Papers1 provider · 1 record
September 8, 2022· The Auditor's Guide to Blockchain Technology
book-chapter

Smart Contract Vulnerabilities, Attacks and Auditing Considerations

Authors:Maheswar SharmaKeerthana KasthuriParvinder Pal SinghNynisha Akula

Abstract

As its name implies, this chapter focuses on one of the most vulnerable components of blockchain technology, namely, smart contracts. The chapter discusses a total of nine smart contract-related attacks by taking a look at the root causes of such security breaches. These include reentrancy, access control, arithmetic, unchecked return value, DoS, bad randomness, race conditions, short addresses and timestamp dependency attacks. In addition to coding errors and attack discussions, this chapter also discusses seven different smart contract audit methodologies. While – depending on the anticipated use case – not all seven audit methodologies need to be used in the course of smart contracts development, auditors need to have a basic understanding of these audit approaches to be able to recommend a proper mix of smart contract testing and evaluation before the launch of smart contracts. As mentioned, in Chapters 2 and 9 , extreme caution must be exercised during the coding and testing of a smart contract, as smart contract development is akin to firmware development, in the sense that once deployed, a defective smart contract can no longer be fixed by applying a software patch to it. As such, the only workable solution is to kill the smart contract – assuming that such kill switch has been added to its design – and to replace the problematic smart contract with a fully functioning one. Information systems auditors will also find the smart contract audit template a useful tool in planning and conducting smart contract audits.

Community

0 comments
Use Connect Wallet in the navigation

No discussion yet

Be the first to share a question or observation.