As the Ethereum platform continues to mature and gain widespread usage, it is crucial to maintain high standards of smart contract writing practices. While bad practices in smart contracts may not directly lead to security issues, they do elevate the risk of encountering problems. Therefore, to understand and avoid these bad practices, this paper introduces the first systematic study of bad practices in smart contracts, delving into over 35 specific issues. Specifically, we propose a large language models (LLMs)-based framework, SCALM. It combines Step-Back Prompting and Retrieval-Augmented Generation (RAG) to effectively identify and address various bad practices. Our extensive experiments using multiple LLMs and datasets have shown that SCALM outperforms existing tools in detecting bad practices in smart contracts.
The traditional, paper-centric infrastructure public-private partnership (PPP) contracts have experienced record numbers of failures and terminations due to contract compliance issues, lack of trust and transparency, and information distortions. While studies on the adoption of blockchain and smart contracts in PPP are still growing, a quantitative survey of global experts on the application areas and potential benefits of Blockchain-enabled smart contracts (BSC) in the context of PPP is lacking. This study comprehensively examined the potential application areas and benefits of BSC adoption in infrastructure PPP projects to understand their impact on the decision to digitalise PPP and ensure sustainable PPP project performance. The snowball sampling technique and questionnaire were used to gather data from experts across countries. Data analysis was done using means analysis, normalisation value, coefficient of variation , Kendall's coefficient of concordance, Kruskal-Wallis test and partial least square-structural equation modelling (PLS-SEM). The study found high awareness and knowledge of the potential benefits of smart contract adoption in infrastructure PPP projects. The leading benefits of BSC adoption in PPP are (1) decentralisation of payments and other transactions, (2) enhancing supply chain visibility and integration, (3) the autonomy in contract administration, (4) prevent misapplication of contractual provisions, and (5) enhances alternative dispute resolution (ADR). The PLS-SEM revealed that six of the eight hypothetical paths were significant. This study advocated for promoting the digitalisation of infrastructure PPP projects. It could serve as an essential resource to policymakers and industry professionals in their quest to improve PPP project performance and minimise failures.
Federico Badaloni, Sebastian Holler, Chrysoula Oikonomou, Pedro Moreno-Sánchez · 5 authors
A smart contract is an interactive program that governs funds in the realm of a single cryptocurrency. Yet, the many existing cryptocurrencies have spurred the design of cross-chain applications that require interactions with multiple cryp-tocurrencies simultaneously. Currently, cross-chain applications are implemented as use-case-specific cryptographic protocols that serve as overlay to synchronize smart contract executions in the different cryptocurrencies. Hence, their design requires substantial expertise, as well as a security analysis in complex cryptographic frameworks. In this work, we present$BitML^{x}$, the first domain-specific language for cross-chain smart contracts, enabling interactions with several users that hold funds across multiple Bitcoin-like cryptocurrencies. We contribute a compiler to automatically translate a$BitML^{x}$contract into one contract per involved cryp-tocurrency and a user strategy that synchronizes the execution of these contracts. We prove that an honest user, who follows the prescribed strategy when interacting with the several contracts, ends up with at least as many funds as in the corresponding execution of the$BitML^{x}$contract. Last, but not least, we implement the$BitML^{x}$compiler and demonstrate its utility in the design of illustrative examples of cross-chain applications such as multi-chain donations or loans across different cryptocurrencies.
Open access
3 source records
cs.CR
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Cristian Gómez, Francisco Javier Pérez Blanco, David Granada, Juan M. Vara
Abstract Despite the increasing interest in blockchain and smart contracts, their inherent complexity has impeded widespread adoption. In order to mitigate this issue, this work introduces , a model-based framework for the development of smart contracts in Solidity that enables the treatment of contracts as models, opening up new possibilities for their enhancement and maintenance. A key benefit of is its ability to impose a development pattern, which contributes to improved code quality and reduced vulnerabilities. The framework’s effectiveness is evaluated through several case studies, showing how model-driven engineering can mitigate contracts inherent complexity and promote better collaboration between developers and domain experts. As this work will demonstrate, when smart contracts are treated as models, a vast array of possibilities unfolds.
Abstracts The operations of built environment-related sectors are often run on centralized organizational structures. This centralized approach could lead to operational challenges that restrict efficiency, hinder transparency, and misalign with the community’s interests. The emergence of decentralized autonomous organization (DAO) presents a promising avenue for addressing these issues by leveraging blockchain technology and decentralized governance models. This paper presents a review of DAO, examining its existing applications, limitations, and potential use cases in the built environment. Seven categories of DAO applications in the built environment were identified and discussed. The study also explores DAO’s fundamentals, including its governance characteristics, operational mechanism, limitations and technical implementation, and corresponding challenges. Finally, this study highlights three potential areas in the built environment for future DAO use cases. This article serves as an essential reference for future academics, professionals, and policy regulators interested in learning more about the integrations of DAO in the built environment.
We examine which decentralized finance architectures enable meaningful regulation by combining financial and computational theory. We show via deduction that a decentralized and permissionless Turing-complete system cannot provably comply with regulations concerning anti-money laundering, know-your-client obligations, some securities restrictions and forms of exchange control. Any system that claims to follow regulations must choose either a form of permission or a less-than-Turing-complete update facility. Compliant decentralized systems can be constructed only by compromising on the richness of permissible changes. Regulatory authorities must accept new tradeoffs that limit their enforcement powers if they want to approve permissionless platforms formally. Our analysis demonstrates that the fundamental constraints of computation theory have direct implications for financial regulation. By mapping regulatory requirements onto computational models, we characterize which types of automated compliance are achievable and which are provably impossible. This framework allows us to move beyond traditional debates about regulatory effectiveness to establish concrete boundaries for automated enforcement.
Danilo Rafael de Lima Cabral, Pedro Antonino, Augusto Sampaio
The Ethereum blockchain has a \emph{gas system} that associates operations with a cost in gas units. Two central concepts of this system are the \emph{gas limit} assigned by the issuer of a transaction and the \emph{gas used} by a transaction. The former is a budget that must not be exhausted before the completion of the transaction execution; otherwise, the execution fails. Therefore, it seems rather essential to determine the \emph{minimum gas limit} that ensures the execution of a transaction will not abort due to the lack of gas. Despite its practical relevance, this concept has not been properly addressed. In the literature, gas used and minimum gas limit are conflated. This paper proposes a precise notion of minimum gas limit and how it can differ from gas used by a transaction; this is also demonstrated with a quantitative study on real transactions of the Ethereum blockchain. Another significant contribution is the proposition of a fairly precise estimator for each of the two metrics. Again, the confusion between these concepts has led to the creation of estimators only for the gas used by a transaction. We demonstrate that the minimum gas limit for the state of the Ethereum blockchain (after the block) $t$ can serve as a near-perfect estimation for the execution of the transaction at block $t + Δ$, where $Δ\leq 11$; the same holds for estimating gas used. These precise estimators can be very valuable in helping the users predict the gas budget of transactions and developers in optimising their smart contracts; over and underestimating gas used and minimum gas limit can lead to a number of practical issues. Overall, this paper serves as an important reference for blockchain developers and users as to how the gas system really works.
Marlena Broniszewska, Wiktor B. Daszczuk, Denny B. Czejdo
Global digitalization has accelerated, leading to continuous online shopping and services growth. However, the centralized nature of traditional e-commerce platforms raises concerns about data control, privacy, and potential single points of failure. Blockchain technology offers a decentralized alternative that addresses these issues, improving online transactions with enhanced privacy and anonymity for users. This article explores the problem of anonymization in web services by developing an anonymous online auction system using blockchain and zero-knowledge proof (ZKP). We propose a solution that employs ZKP in two stages: first, to verify that a user is eligible to participate in the auction, thereby creating a list of potential bidders; second, to prove that a bid is placed by a user from this list without disclosing their identity. This approach allows participants to engage in auctions anonymously, protecting their interests from competitors and sellers. The system eliminates the need for a trusted third party by leveraging the blockchain immutable ledger for transparency, giving users full control over their data and participation. We present the architecture and implementation details of the system, demonstrating its feasibility and potential to enhance privacy and security in online auctions.
Smart contracts enable autonomous execution between contracting parties without a centralized authority, thereby reducing contract management costs and enhancing the transparency and reliability of contracts. However, the absence of such a certification authority increases the risk of fraud. Rug-pull, a typical form of fraud, involves developers hiding backdoor codes in smart contracts to steal funds under certain conditions, causing significant damage to users. A Rug-pull list warns users of potential fraud, but it only identifies risks after damage has occurred. Additionally, existing backdoor code analysis tools are limited in their ability to detect backdoor codes hidden through modifications to existing patterns or suffer from low accuracy because they rely on comparisons with predefined backdoor codes. Therefore, this paper proposes a balance-tracking-based backdoor code detection model to identify backdoor codes in smart contracts. The proposed model detects backdoor codes by extracting functions from Ethereum bytecodes and inspecting the extracted functions to track balance changes. This approach allows for the detection of balance changes even when backdoor codes are concealed. Experimental results verifying the effectiveness of this model demonstrate 98% accuracy, 0.96 recall, and 0.98 precision. These results are expected to contribute significantly to effectively reducing fraud risks such as Rug-pull.
Good news for researchers in formal verification: smart contracts regularly suffer exploits such as the DAO bug, which lost the equivalent of 60 million USD on Ethereum. This makes a strong case for applying formal methods to guarantee essential properties.<br/><br/>Which properties would we like to prove? Most previous studies focus on contract-specific properties that do not generalize to a wide class of smart contracts. There is currently no commonly agreed upon list of properties to use as a starting point in writing a formal specification.<br/><br/>We propose three properties that we believe are relevant to all smart contracts: Validity, Liquidity, and Fidelity. Focusing on the concrete case of the Cardano platform, we show how these properties stop exploits similar to the DAO bug, as well as preventing other common issues such as the locking of funds and double satisfaction.<br/><br/>We model an account simulation, a multi-signature wallet, and an order book decentralized exchange, as example smart contract specifications using state transition systems in the Agda proof assistant. We formalize the above properties and prove they hold for the models. The models are then separately proven to be functionally equivalent to a validator implementation in Agda, which is translated to Haskell using agda2hs. The Haskell code can then be compiled and put on the Cardano blockchain directly. We use the Cardano Node Emulator to run property-based tests and confirm that our validator works correctly.
This thesis analyzes liquidity provision strategies in decentralized finance (DeFi), focusing on Uniswap V3's automated market maker protocol. The research addresses the challenge of developing effective frameworks for liquidity providers operating in decentralized exchanges, where participants face unique risks including impermanent loss and strategic positioning decisions. Using empirical analysis of on-chain data, the study examines different liquidity provision approaches across various asset pairs and fee tiers to establish quantitative frameworks for strategic decision-making in DeFi markets.
Smart contract technology has witnessed rapid evolution and widespread adoption across diverse industries. However, with the immutable nature of blockchain-deployed contracts, vulnerabilities—especially those embedded in complex business logic—pose severe security risks. Traditional static analysis tools have struggled to accurately capture such vulnerabilities, prompting exploration into novel techniques that integrate large language models (LLMs), static analysis, and property-based testing. Firstly, we proposed a unified evaluation framework called LLM4Vuln, systematically decouples and assesses LLMs’ intrinsic vulnerability reasoning from external aids like knowledge enrichment and context retrieval. Evaluated on 294 code snippets spanning Solidity, Java, and C/C++ over 3,528 scenarios, LLM4Vuln not only elucidated the impacts of various enhancements but also uncovered 14 zero-day vulnerabilities in real-world projects, demonstrating both practical value and potential for significant security improvements. Secondly, building on these insights, we proposed GPTScan, the first tool to integrate GPT with static analysis for smart contract logic vulnerability detection. By decomposing each vulnerability into specific scenarios and properties, GPTScan employs GPT to identify critical code elements and then confirms these findings through static analysis. This hybrid approach achieves high precision on token contracts, maintains acceptable performance on large-scale projects, and delivers an overall recall above 70%, thereby effectively identifying vulnerabilities often overlooked by human auditors. Thirdly, to extend the scope of detectable vulnerabilities, we designed PropertyGPT, a framework leverages retrieval-augmented property generation. By harnessing LLMs’ in-context learning abilities, PropertyGPT generates compilable, context-appropriate, and verifiable properties for formal verification of smart contracts. Experimental results demonstrate an 80% recall relative to ground truth, with the framework successfully detecting multiple CVEs and uncovering several zero-day vulnerabilities, which have resulted in substantial bounty rewards. Fourthly, to address the detection of reentrancy vulnerabilities, we developed ReeSem. ReeSem combines static analysis with semantic understanding through LLMs. Its three-stage detection pipeline—filtering external calls, analyzing affected state variables, and semantically recognizing reentrancy guards—delivers an F1 score of 75.14%, outperforming state-of-the-art baselines significantly. ReeSem’s ability to generate consistent attack paths in real-world scenarios underscores its practical applicability and robustness. Fifthly, complementing the data-driven methods, ZepScope focuses on static analysis by mining constraints directly from official smart contract implementations, specifically, from those provided by OpenZeppelin. Through its MINER and CHECKER components, ZepScope extracts both explicit and implicit security checks and validates their enforcement in real-world contracts. This approach achieves an impressive accuracy of 89.67% across tens of thousands of contracts, offering critical insights into common code practices and potential security pitfalls. Collectively, these contributions, LLM4Vuln, GPTScan, PGPT, ReeSem, and ZepScope, form a comprehensive framework for enhancing vulnerability detection in smart contracts. By synergistically integrating large language models, static analysis, security constraints mining and property-based testing, this work advances the state-of-the-art in secure code auditing and provides valuable methodologies for developers, auditors, and the broader security community.
With complete-information bilateral bargaining in network settings, holdup is eliminated when contracts across the network are agreed atomically (all or none) via a smart contract. Applications include over-the-counter trading, syndicated lending, multi-tranche securitizations, third-party financed purchases, and bookbuilding. Under a novel extensive-form bargaining protocol, any firm can give a “greenlight” to the terms of a contract proposed to that firm, which automatically converts those terms into a binding contract if the terms proposed to all other firms also receive greenlights. In any Perfect Bayesian Equilibrium with Markov strategies, firms immediately agree on socially efficient contracts that equalize expected gains across firms.
Smart contracts frequently fail due to transaction reverts, yet diagnosing the causes of these failures remains challenging. We present an analysis pipeline that automatically extracts and clusters invariants from on-chain reverted transactions, uncovering the underlying conditions that trigger failures. At the core of our approach is ReBERT, a custom embedding model fine-tuned on invariant data, which outperforms existing semantic similarity models in capturing subtle predicate relationships. Our analysis reveals meaningful clusters of failure causes—such as Access Control, Data Flow, and Status Checks—that highlight recurring vulnerabilities in smart contract execution. These findings advance understanding of failure patterns for Ethereum Smart Contracts.
The consensus problem in distributed ledger systems has two distinct dimensions that existing protocols systematically conflate. The first is the Byzantine fault-tolerance question: can a network reach agreement in the presence of arbitrary failures? The second — less formalised but no less fundamental — is the anti-cartel question: can the incentive structure of the consensus mechanism structurally resist the formation of cartels that reconstitute centralised authority under a nominally decentralised banner? Bitcoin's proof-of-work has produced a system where a small number of industrial mining pools control the majority of hash power. BitCell is a proposal that takes the anti-cartel question seriously as an engineering problem rather than an economic folk theorem. BitCell replaces hash-grinding and stake-weighting with cellular automaton tournaments as the computational substrate for block proposal rights. In each round, miners commit to a pattern in a bounded Conway's Game of Life grid, are verifiably randomly paired via a VRF-based pairing mechanism, and compete in a deterministic single-elimination tournament whose outcome depends on strategic pattern design rather than raw computational expenditure or capital size. Victory rights are not transferable and are not enhanced by pooling strategies: a cartel of sub-majority miners cannot coordinate to construct a jointly optimal pattern that dominates unilateral honest play, because the tournament's pairwise structure, hidden identities (via ring signatures), non-shareable rewards, and reputation-gated eligibility remove each of the primary economic motivations that make mining pools attractive. Under a simple Bayesian model of miner incentives, collusive strategies for sub-majority cartels yield strictly lower expected payoffs than unilateral honest participation. Tournament eligibility and reward weighting are governed by an Evidence-Based Subjective Logic (EBSL) reputation layer. All state transitions are proven using succinct zero-knowledge proofs, enabling a ZKVM-backed smart contract layer with native privacy. BitCell makes three primary contributions: (i) a proof-of-computation consensus mechanism whose computational task is verifiable, bounded, non-parallelisable by pooling, and intellectually non-trivial; (ii) a game-theoretic proof that the combination of pairwise tournaments, anonymised pairing, non-transferable victory rights, and reputation gating renders cartel coordination strictly dominated in a Bayesian Nash equilibrium; and (iii) a native ZKVM execution environment for privacy-preserving smart contracts.
Billions of dollars are lost every year in DeFi platforms by transactions exploiting business logic or accounting vulnerabilities. Existing defenses focus on static code analysis, public mempool screening, attacker contract detection, or trusted off-chain monitors, none of which prevents exploits submitted through private relays or malicious contracts that execute within the same block. We present the first decentralized, fully on-chain learning framework that: (i) performs gas-prohibitive computation on Layer-2 to reduce cost, (ii) propagates verified model updates to Layer-1, and (iii) enables gas-bounded, low-latency inference inside smart contracts. A novel Proof-of-Improvement (PoIm) protocol governs the training process and verifies each decentralized micro update as a self-verifying training transaction. Updates are accepted by PoIm only if they demonstrably improve at least one core metric (e.g., accuracy, F1-score, precision, or recall) on a public benchmark without degrading any of the other core metrics, while adversarial proposals get financially penalized through an adaptable test set for evolving threats. We develop quantization and loop-unrolling techniques that enable inference for logistic regression, SVM, MLPs, CNNs, and gated RNNs (with support for formally verified decision tree inference) within the Ethereum block gas limit, while remaining bit-exact to their off-chain counterparts, formally proven in Z3. We curate 298 unique real-world exploits (2020 - 2025) with 402 exploit transactions across eight EVM chains, collectively responsible for $3.74 B in losses. We demonstrate that on-chain ML governed by PoIm detects previously unseen attacks with over 97% attack detection accuracy and 82.0% F1. A single inference, such as one made via an external call, typically incurs zero cost. Fully on-chain inference consumes 57,603 gas (≈ $0.18) for linear models, 143,647 gas (≈ $0.49) for CNN(F2, K1), and 506,397 gas (≈ $1.77) for CNN(F8, K4) on L1 (e.g., Ethereum). Our results show that practical and continually evolving DeFi defenses can be embedded directly in protocol logic without trusted guardians, and our solution achieves highly cost-effective protection while filling a critical gap between vulnerability scanners and real-time transaction screening.
With the rise of smart contracts, decentralized autonomous organizations (DAOs) have emerged in public good auctions, allowing "small" bidders to gather together and enlarge their influence in high-valued auctions. However, models and mechanisms in the existing research literature do not guarantee non-excludability, which is a main property of public goods. As such, some members of the winning DAO may be explicitly prevented from accessing the public good. This side effect leads to regrouping of small bidders within the DAO to have a larger say in the final outcome. In particular, we provide a polynomial-time algorithm to compute the best regrouping of bidders that maximizes the total bidding power of a DAO. We also prove that such a regrouping is less-excludable, better aligning the needs of the entire DAO and the nature of public goods. Next, notice that members of a DAO in public good auctions often have a positive externality among themselves. Thus we introduce a collective factor into the members' utility functions. We further extend the mechanism's allocation for each member to allow for partial access to the public good. Under the new model, we propose a mechanism that is incentive compatible in generic games and achieves higher social welfare as well as less-excludable allocations.