Papers1 provider Ā· 1 record
July 5, 2026Ā· Proceedings of the 34th ACM International Conference on the Foundations of Software Engineering
conference-paper
Open access

AllocScope: Towards Automated Vetting of Allocation Manipulation in Smart Contracts

Abstract

Flawed funds allocation logic in DeFi contracts can result in disproportionate token distribution, reflecting fundamental errors in how contracts determine and assign user payouts. These issues extend beyond funds allocation logic and affect token distribution mechanisms. Existing defenses such as static analyzers and runtime detectors fail to capture these behaviors because each operation appears valid in isolation. In this work, we present AllocScope, an auditor-centric static analysis framework that identifies allocation manipulation vulnerabilities by modeling allocation-related fund flow semantics and generating vulnerability findings for auditors. AllocScope constructs a funds allocation graph to track the relationship between user contributions and received payouts, and identifies logic that result in unfair outcomes. Evaluated on over 8,000 real-world contracts, AllocScope achieves zero false negatives. A user study with experienced auditors confirms that its findings are accurate, actionable, and easy to integrate into standard auditing workflows.

Community

0 comments
Use Connect Wallet in the navigation

No discussion yet

Be the first to share a question or observation.