Understanding Security Audits on Blockchain
Abstract
Hacks on blockchains are prevalent nowadays because a wide range of vulnerabilities exists in smart contracts. To deal with the vulnerabilities, security auditing has been emerging and widely adopted for manual code inspection. However, little is known about how manual security auditing impacts the blockchain community. In this work, we investigated security audits on blockchain by answering three research questions covering the type, severity, and resolve status of issues in the audit reports. We in total collected 2,421 security audit reports consisting of the details of 28,782 security issues. We found that manual security auditing has superior merit over static analysis tools in identifying logic-related issues, considering 27.65% of all findings are logical issues. We also found that 87.28% of 2,421 projects have at least one centralization issue that breaks the decentralization primitive of blockchain. Moreover, while 21.17% of issues are of major or critical severity, we surprisingly found that 61.83% of all issues were unresolved or partially resolved. We concluded that while manual security auditing can help identify security vulnerabilities uniquely, project developers need to take serious actions to address and secure their smart contracts.
Community
0 commentsNo discussion yet
Be the first to share a question or observation.