Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

1 papersLast indexed Aug 31, 2026
Search papers

Paper index

1 results · page 1 of 1

Clear filters
Aug 21, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
From Invariants to Exploitability Traces: A Practitioner Framework for Auditing State-Dependent Vulnerabilities in DeFi

Adesh Kolte

Decentralized finance failures frequently arise not from a single obviously unsafe function, but from valid operations composed into an invalid state transition. Static analyzers and vulnerability checklists remain valuable, yet they often stop before answering the question that determines real risk: can an adversary control the preconditions, sequence, capital, ordering, and external dependencies required to turn a defect into impact? This working paper presents the Invariant-to-Exploit (I2E) framework, a practitioner-oriented method for connecting architecture assumptions to executable invariants, stateful counterexamples, exploitability evidence, and remediation regression tests. I2E consists of six linked activities: system scoping, invariant-ledger construction, adversarial controllability analysis, stateful sequence generation, exploitability tracing, and fix validation. The framework is applied retrospectively to three publicly documented incidents: KyberSwap Elastic, Euler, and the Curve sDOLA LlamaLend market. These analyses do not claim prospective vulnerability discovery; instead, they demonstrate the test signals that reviewers can derive from public root-cause information. The principal contribution is a reproducible audit worksheet that preserves the chain from protocol assumption to broken property, realistic exploitability, observable impact, and regression-tested remediation. The method is designed to remain usable by independent security researchers who cannot publish confidential client evidence. A benchmark design is proposed for future controlled comparison against checklist-only security review.

Open access
2 source records
Security and Verification in Computing
Information and Cyber Security
Web Application Security Vulnerabilities
Original source