Smart Contract Reentrancy Vulnerability Detection Based on Static Analysis
Abstract
Smart contracts are self-executing programs running on blockchain networks. Once deployed, they are immutable, making their security critically important. Reentrancy vulnerability is one of the most notorious security vulnerabilities in smart contracts, which allows attackers to repeatedly invoke target functions before the execution of contract functions is completed, thereby stealing funds or corrupting contract states, resulting in severe economic losses in recent years. Existing detection tools often suffer from insufficient path coverage and oversimplified detection rules. This paper proposes a static analysis approach based on smart contract bytecode that recovers execution paths by constructing a control flow graph (CFG), identifies all potential vulnerability paths using taint analysis, and detects reentrancy vulnerabilities through path matching rules. To validate the approach’s effectiveness, we compare it with mainstream detection tools on an annotated smart contract dataset. Experimental results demonstrate that the approach achieves a precision of 93.2%, outperforming other tools overall. Additionally, through analysis of 2023 real-world smart contracts deployed on Ethereum, 21 contracts are found to contain reentrancy vulnerabilities.
Community
0 commentsNo discussion yet
Be the first to share a question or observation.