R.M.O.H. Bandara, M.D.T.E. Abeynayake, I.E. Illeperuma, B.A.I. Eranga
Disputes frequently arise in construction projects due to the complexity of the processes and challenging environment, resulting in cost overruns, delays, wastage, and low productivity. Thus, the Construction Industry (CI) is enthusiastic about innovative dispute mitigation measures by incorporating digital technologies. Consequently, Smart Contracts (SCs) have emerged as a pioneering approach to digitise construction contracts and thereby mitigate construction disputes. Accordingly, this research aims to investigate the applications of SCs to mitigate disputes in the Sri Lankan CI. The research aim was approached through an explanatory mixed method. Initially, a questionnaire survey was carried out to collect quantitative data which was followed by qualitative expert interviews. Quantitative data were statistically analysed through Mean Weighted Average (MWA) and Relative Importance Index (RII) whereas qualitative data were analysed through content analysis. The study identified the root causes of construction disputes in the Sri Lankan context as poorly written contracts, poor preparation and approval of drawings, lack of communication and coordination, poor supervision and site management, and contain of contradictory and inaccurate information in the contract documents. The findings highlighted that SCs can significantly reduce construction disputes by replacing ambiguous processes with clear, automated processes. By linking payments to milestones, storing project data transparently, and potentially triggering actions based on safety or quality data, SCs streamline communication, ensure everyone plays by the agreed-upon rules, and thereby minimise disputes. Future researchers are suggested to explore the practical challenges and strategies for implementing SCs in the Sri Lankan CI.
Non-Fungible Tokens (NFTs) have emerged as a significant innovation in the digital economy, particularly in India, where the intersection of art, technology, and finance is evolving rapidly. NFTs are unique digital tokens secured through blockchain technology, representing ownership of digital or physical assets such as art, music, collectibles, and virtual real estate. Their rise in India is marked by increasing participation from creators, investors, and technology platforms.Despite their growing popularity, NFTs operate within a fragmented and ambiguous legal environment. India currently lacks specific legislation dedicated to NFTs, leading to reliance on existing laws such as the Indian Contract Act, 1872; the Information Technology (IT) Act, 2000; intellectual property laws; and provisions in the Finance Act, 2022 concerning virtual digital assets. However, these frameworks offer limited clarity on issues such as copyright ownership, contract enforceability via smart contracts, taxation, and consumer protection.This research paper undertakes a comprehensive examination of the legal standing of NFTs in India. It evaluates the applicability of current legal instruments, identifies regulatory and operational gaps, and explores international best practices. The study also emphasizes the need for a clear, forward-looking legal framework that fosters innovation while ensuring adequate safeguards against fraud, misuse, and environmental concerns. A balanced regulatory approach is essential for India to harness the full potential of NFTs and position itself as a leader in the digital asset economy.
The role of Web3 technologies was examined specifically regarding SmartCharity and their effect on the financing and delivery of public goods in developing countries. The research focused on the case of SmartCharity, its role in making fund distribution more transparent and efficient, and the role of NFTs and smart contracts’ efficacy in changing. For primary data, the cross-sectional study used interviews and questionnaires administered to the critical actors in or close to SmartCharity initiatives; secondary data came from project reports and publicly accessible sources. Quantitative analysis uses statistics to identify trends and correlations in data, whereas qualitative data analysis identifies such trends and patterns. This paper aimed to establish an appreciation of the strengths and weaknesses of Web3 innovation in public good management and make future suggestions for improvement.
Smart contracts are central to a myriad of critical blockchain applications, from financial transactions to supply chain management. However, their adoption is hindered by security vulnerabilities that can result in significant financial losses. Most vulnerability detection tools and methods available nowadays leverage either static analysis methods or machine learning. Unfortunately, as valuable as they are, both approaches suffer from limitations that make them only partially effective. In this survey, we analyze the state of the art in machine-learning vulnerability detection for Ethereum smart contracts, by categorizing existing tools and methodologies, evaluating them, and highlighting their limitations. Our critical assessment unveils issues such as restricted vulnerability coverage and dataset construction flaws, providing us with new metrics to overcome the difficulties that restrain a sound comparison of existing solutions. Driven by our findings, we discuss best practices to enhance the accuracy, scope, and efficiency of vulnerability detection in smart contracts. Our guidelines address the known flaws while at the same time opening new avenues for research and development. By shedding light on current challenges and offering novel directions for improvement, we contribute to the advancement of secure smart contract development and blockchain technology as a whole.
This research paper delves into the intricate world of smart contract derivatives, aiming to unravel the technical intricacies and explore their applications. Smart contract derivatives represent a burgeoning intersection of blockchain technology and financial instruments, providing decentralized and automated solutions for derivative trading. The paper navigates through the complex landscape of smart contract derivatives, addressing both the technical aspects of their implementation and the diverse range of applications they unlock. Through a comprehensive review of existing literature, case studies, and real-world examples, this research aims to provide a holistic understanding of the challenges, opportunities, and implications associated with smart contract derivatives. By comprehensively addressing both the technical intricacies and practical applications of smart contract derivatives, this study contributes valuable insights into the rapidly evolving field of decentralized finance.
Modern blockchains support the execution of application-level code in the form of smart contracts, allowing developers to devise complex Distributed Applications (DApps). Smart contracts are typically written in high-level languages, such as Solidity, and after deployment on the blockchain, their code is executed in a distributed way in response to transactions or calls from other smart contracts. As a common piece of software, smart contracts are susceptible to vulnerabilities, posing security threats to DApps and their users.
Purpose This study aims to identify and analyse critical success factors (CSFs) for the successful implementation of distributed ledger technology (DLT) in the Nigerian construction industry. Design/methodology/approach This study adopts a quantitative approach that uses snowball sampling techniques to identify professionals participating in the study. A structured questionnaire was used to collect data virtually, using Google Forms, resulting in 217 valid responses. The collected data were subjected to rigorous statistical analysis (descriptive and inferential) to identify and prioritise the CSFs and evaluate the participants’ awareness and knowledge of DLT. Findings This study revealed 24 key CSFs that are pivotal in ensuring the effective implementation and adoption of DLT in the Nigerian construction industry. Furthermore, the research highlights a moderate level of awareness, but significantly low knowledge of DLT among industry professionals. Practical implications The findings of this study will benefit professionals, practitioners and policymakers in the Nigerian construction industry by providing insights into the potential of DLT to improve construction operations. Originality/value This study contributes to the literature by identifying the CSFs for implementing DLT in the construction industry and shedding light on the current level of awareness and knowledge within the Nigerian context. The findings offer valuable insights for policymakers, industry practitioners and researchers, providing a solid foundation for informed decision-making and developing effective strategies to enhance DLT adoption in the construction sector.
The advent of blockchain technology and its adoption across various sectors have raised critical discussions about the need for regulatory mechanisms to ensure consumer protection, maintain financial stability, and address privacy concerns without compromising the foundational principles of decentralization and immutability inherent in blockchain platforms. We examine the existing mechanisms for smart contract termination across several major blockchain platforms, including Ethereum, BNB Smart Chain, Cardano, Solana, Hyperledger Fabric, Corda, IOTA, Apotos, and Sui. We assess the compatibility of these mechanisms with the requirements of the EU Data Act, focusing on aspects such as consumer protection, error correction, and regulatory compliance. Our analysis reveals a diverse landscape of approaches, from immutable smart contracts with built-in termination conditions to upgradable smart contracts that allow for post-deployment modifications. We discuss the challenges associated with implementing the so-called smart contract "kill switches," such as the balance between enabling regulatory compliance and preserving the decentralized ethos, the technical feasibility of such mechanisms, and the implications for security and trust in the ecosystem.
Christopher De Baets, Basem Suleiman, Armin Chitizadeh, Imran Razzak
In the growing field of blockchain technology, smart contracts exist as transformative digital agreements that execute transactions autonomously in decentralised networks. However, these contracts face challenges in the form of security vulnerabilities, posing significant financial and operational risks. While traditional methods to detect and mitigate vulnerabilities in smart contracts are limited due to a lack of comprehensiveness and effectiveness, integrating advanced machine learning technologies presents an attractive approach to increasing effective vulnerability countermeasures. We endeavour to fill an important gap in the existing literature by conducting a rigorous systematic review, exploring the intersection between machine learning and smart contracts. Specifically, the study examines the potential of machine learning techniques to improve the detection and mitigation of vulnerabilities in smart contracts. We analysed 88 articles published between 2018 and 2023 from the following databases: IEEE, ACM, ScienceDirect, Scopus, and Google Scholar. The findings reveal that classical machine learning techniques, including KNN, RF, DT, XG-Boost, and SVM, outperform static tools in vulnerability detection. Moreover, multi-model approaches integrating deep learning and classical machine learning show significant improvements in precision and recall, while hybrid models employing various techniques achieve near-perfect performance in vulnerability detection accuracy. By integrating state-of-the-art solutions, this work synthesises current methods, thoroughly investigates research gaps, and suggests directions for future studies. The insights gathered from this study are intended to serve as a seminal reference for academics, industry experts, and bodies interested in leveraging machine learning to enhance smart contract security.
Smart Contract Vulnerability Detection (SCVD) is crucial to guarantee the quality of blockchain-based systems. Graph neural networks have been shown to be effective in learning semantic representations of smart contract code and are commonly adopted by existing deep learning-based SCVD. However, the current methods still have limitations in their utilization of graph sampling or subgraph pooling based on predefined rules for extracting crucial components from structure graphs of smart contract code. These predefined rule-based strategies, typically designed using static rules or heuristics, demonstrate limited adaptability to dynamically adjust extraction strategies according to the structure and content of the graph in heterogeneous topologies of smart contract code. Consequently, these strategies may not possess universal applicability to all smart contracts, potentially leading to false positives or omissions. To address these problems, we propose AFPNet, a novel vulnerability detection model equipped with a feature perception module that has dynamic weights for comprehensive scanning of the entire smart contract code and automatic extraction of crucial code snippets (the $P$ snippets with the largest weights). Subsequently, the relationship perception attention module employs an attention mechanism to learn dependencies among these code snippets and detect smart contract vulnerabilities. The efforts made by AFPNet consistently enable the capture of crucial code snippets and enhance the performance of SCVD optimization. We conduct an evaluation of AFPNet in the several large-scale datasets with vulnerability labels. The experimental results show that our AFPNet significantly outperforms the state-of-the-art approach by 6.38\%-14.02\% in term of F1-score. The results demonstrate the effectiveness of AFPNet in dynamically extracting valuable information and vulnerability detection.
Chunhong Liu, Zihang Sang, Li Duan, Wei Ni · 6 authors
Security vulnerabilities in smart contracts can have serious economic consequences. Existing smart contract vulnerability detection methods rely primarily on strict rules defined by experts, making current research limited to detecting specific known vulnerabilities and difficult to deal with other types of anomalous contracts (i.e., the variants of contracts with potentially known vulnerabilities). The imbalance of a smart contract dataset also affects the effectiveness of deep learning-based methods. This paper proposes a new transfer learning-based, anomalous smart contract generation (TLSCG) method for abnormal contract detection, aimed at effectively detecting known vulnerabilities and other anomalous contracts. This method trains a smart contract operation code sequence generation model and improves the authenticity of generating smart contracts by adding semantic regularization terms to the loss function. Through transfer learning, the generative model can be readily extended to new types of vulnerabilities, obtaining known vulnerabilities and anomalous contract generation models, expanding training data, improving the generalization of detection models, and enabling detection models to detect anomalous contracts. By using a real smart contract dataset for validation, experiments show that the proposed method can effectively improve the generalization of the model in detecting known vulnerabilities. Compared to the latest rule-based vulnerability detection tools, the accuracy of anomalous contract detection is improved by 40% and the F1 score is improved by 24%.
Smart contracts, known for their immutable nature to ensure trust via automated enforcement, have evolved to require upgradeability due to unforeseen vulnerabilities and the need for feature enhancements post-deployment. This contradiction between immutability and the need for modifications has led to the development of upgradeable smart contracts. These contracts are immutable in principle yet upgradable by design, allowing updates without altering the underlying data or state, thus preserving the contract's intent while allowing improvements. This study aims to understand the application and implications of upgradeable smart contracts on the Ethereum blockchain. By introducing a dataset that catalogs the versions and evolutionary trajectories of smart contracts, the research explores key dimensions: the prevalence and adoption patterns of upgrade mechanisms, the likelihood and occurrences of contract upgrades, the nature of modifications post-upgrade, and their impact on user engagement and contract activity. Through empirical analysis, this study identifies upgradeable contracts and examines their upgrade history to uncover trends, preferences, and challenges associated with modifications. The evidence from analyzing over 44 million contracts shows that only 3% have upgradeable characteristics, with only 0.34% undergoing upgrades. This finding underscores a cautious approach by developers towards modifications, possibly due to the complexity of upgrade processes or a preference for maintaining stability. Furthermore, the study shows that upgrades are mainly aimed at feature enhancement and vulnerability mitigation, particularly when the contracts' source codes are accessible. However, the relationship between upgrades and user activity is complex, suggesting that additional factors significantly affect the use of smart contracts beyond their evolution.
The integration of blockchain and smart contracts facilitates efficient and secure data exchange and value transfer. Nevertheless, the reliability of smart contracts has emerged as a critical concern. The vulnerabilities in contracts are intricately linked to their categories, emphasizing the significance of smart contract classification for enhancing code, user, and system security. Formal verification methods offer a robust means to validate the accuracy of contract classification and mitigate vulnerabilities. However, conventional machine learning approaches often lack precision and overlook the impact of account transaction behavior on classification during contract execution. This study introduces an Ethereum smart contract classification methodology based on statistical model detection. Through an examination of five smart contract types and ensuring the logical exclusivity of each, we delineate and formalize the internal logic of each contract type. We establish the contract automata network, devise conversion rules from contract source code to the automata network, and verify class properties using the statistical model detection tool UPPAAL-SMC. Lastly, we showcase the efficacy of our proposed methodology through a practical contract case.
Smart contracts are among the most important applications of blockchain technology and are vulnerable to network attacks, leading to significant financial losses. Thus, smart contract vulnerability detection has become an important research field. Currently, there are problems with limited detection types and low detection efficiency in smart contract vulnerabilities. It is particularly crucial to achieve high detection efficiency and cover a wide range of vulnerability types in smart contract vulnerabilities. This paper builds a dataset named SC-4, which consists of over 3000 data of four common vulnerabilities in smart contracts: Reentrancy, Transaction Order Dependence, Unchecked-Send, and Unhandled-Exceptions. We propose a smart contract vulnerability detection model based on an improved gated recurrent unit (GRU) and random forest (RF) fusion algorithm. The experimental results show that the proposed algorithm can accurately identify four types of smart contract vulnerabilities, and the accuracy can reach 98.47%. The number of vulnerability types detected has also increased compared to that in previous research.
Random numbers play a crucial role in decen-tralized applications (dApps) like decentralized finance (DeFi) and non-fungible tokens (NFTs). However, their generation faces challenges due to blolckchain's deterministic and decentralized nature, risking smart contract security and ecosystem stability. Prior solutions, including Oracles, employing commit-execute schemes, suffer from higher transaction fees, extended processing times, and increased on-chain storage, compromising efficiency. This paper proposes a novel random number provider (RNP) protocol for smart contracts, eliminating dependencies on traditional commit-execute approaches. Furthermore, we systematically identify potential random number-related attacks on smart contracts, particularly Post-reveal Undo Attacks (PUAs), where attackers may reverse contract operations when randomness is unfavorable, and discuss the security requirements. Our protocol addresses these attacks by (1) incorporating distributed random beacons (D RBs) with consensus processes, bridging the semantic gap between DRB and consensus, and (2) thoroughly analyzing and classifying four types of PUA and offering robust mitigations, alongside presenting a security proof. Our experiments show the protocol significantly enhances response times and security for random number queries in smart contracts, slashing request fees by at least 89 % and reducing on-chain data by 76.4% versus current methods. This work advances the integration of DRB protocols and consensus mechanisms, securing and optimizing random number applications in dApps, thus fostering the creation of more dependable, robust systems.
Smart contracts are fundamental to blockchain technology, enabling automated contract execution without intermediaries. Their widespread adoption, particularly on platforms like Ethereum, has led to significant digital asset holdings. However, the immutability of blockchain magnifies the impact of even minor errors during smart contract development, potentially resulting in substantial financial losses. Given the frequency of vulnerabilities in existing contracts, secure smart contract development is essential. This paper conducts a comprehensive review of known vulnerabilities and detection methods to guide a more secure approach to smart contract development and promote safer blockchain ecosystems.
Blockchain technology supports digital currency applications through Ethereum's smart contracts, enabling various functionalities but susceptible to security vulnerabilities. Notably, smart contracts are susceptible to Monetary Exploit Vulnerabilities (MEVs), which result in significant financial losses, evidenced by the billions of dollars lost to hacks in recent years. Traditional fuzzing tools, focused on underlying vulnerabilities such as opcode and stack patterns, fail to address complex, high-level MEVs that involve intricate interactions between contract functions and states. This paper introduces FuzzLaPRO (Fuzz like a PRO), an innovative fuzzing tool designed to understand and simulate smart contract logic to detect MEVs effectively. FuzzLaPRO leverages a Natural Language Processing (NLP) model, trained on a corpus of expert auditing reports and proofs of concept, to generate risk-aware function sequences that target MEVs. Additionally, we address the limitations of existing tools in handling distributed applications (Dapps) by implementing dynamic version discovery and implicit contract bridging. This allows FuzzLaPRO to adapt to various Ethereum Virtual Machine (EVM) versions and interact with implicitly deployed contracts, enhancing its applicability to real-world scenarios. We evaluated FuzzLaPRO on a dataset of 15,132 small and medium-sized smart contracts and 23 Dapps, discovering 79 new vulnerabilities at the smart contract level and 4 at the Dapp level, surpassing state-of-the-art fuzzers in both coverage efficiency and bug discovery rate. This work advances the smart contract security field by introducing a targeted, efficient fuzzing approach and sets a foundation for further innovations in automated security testing tools.
With the soaring popularity of decentralized applications (DApps), smart contract security has become increasingly important. Recently, numerous studies have leveraged artificial intelligence (AI) techniques to enhance efficiency and functional diversity of smart contract security analysis. However, a comprehensive survey of these studies to guide future development is still missing. To fill this gap, we present an innovative and systematic review. First, we establish filtering criteria and define Literature Attributes (LA) to identify 27 representative papers in this field. We then trace their evolution from 2018 and summarize four key research problems. Next, we compare three AI-powered smart contract security analysis tools—DLVA, xFuzz, and GURU—against traditional methods, demonstrating that AI tools still have room for improvement in precision. Finally, we discuss opportunities for improving AI-powered smart contract security analysis.
The paper offers a generalized author’s view on the new phenomenon of the digital world, backed tokenized assets, as a tool for asset accounting in digital accounting systems. This view is new and currently unpopular in the literature since the main aspect of tokenized asset presentation is related to speculation on financial markets, widespread creation of unbacked assets around objects of human life, graphics, etc. The aim of the paper is to determine the essence, generic features and technological basis of the use of tokenized assets for their implementation in the digital and platform-based economy. In accordance with this aim, the author logically presents the material from the general to the specific, analyzing the essential features of 7 main related concepts: distributed ledger, distributed ledger technologies, blockchain technology, tokens and consensus algorithm, tokenized asset, decentralized information platform and blockchain-based ecosystem of services. The author persists in the opinion that a tokenized asset is a type of virtual asset. It is a tool for certifying sufficient and confirmed legal rights: rights of access to products and services, rights to a certain product or service, rights to receive a fixed income or percentage of profits, management rights, rights to purchase a certain asset at a certain price in the future, etc. The paper offers the original definition of a tokenized asset: tokenized asset is a type of virtual asset that exists in a digital data accounting system based on the distributed ledger technology in the form of a record with an identifier of information derived from the original asset. A tokenized asset can be used as a tool for implementing a method of recording, accounting and managing property rights to assets. Moreover, a tokenized asset can be used as a tool for certifying any rights; providing services; recording events; generating, processing and submitting statistical and analytical information; ensuring logistics, etc. Depending on the purpose of creating a specific tokenized asset and, as a result, certain inherent properties envisaged by the creator, this tokenized asset can be classified as a separate type.
Yishun Wang, Xiaoqi Li, Ye, Shipeng, Xie, Lei · 5 authors
Smart contracts with external data are crucial for functionality but pose security and reliability concerns. Statistical and quantitative studies on this interaction are scarce. To address this gap, we analyzed 10,500 smart contracts, retaining 9,356 valid ones after excluding outdated or erroneous ones. We employed code parsing to transform contract code into abstract syntax trees and identified keywords associated with external data dependencies. We conducted a quantitative analysis by comparing these keywords to a reference list. We manually classified the 9,356 valid smart contracts to ascertain their application domains and typical interaction methods with external data. Additionally, we created a database with this data to facilitate research on smart contract dependencies. Moreover, we reviewed over 3,600 security audit reports, manually identifying 249 (approximately 9%) related to external data interactions and categorized their dependencies. We explored the correlation between smart contract complexity and external data dependency to provide insights for their design and auditing processes. These studies aim to enhance the security and reliability of smart contracts and offer practical guidance to developers and auditors.
K Lingaraj, B Harshitha, M Deepika, Madeeha Tanzeem Badal · 5 authors
The Smart Tender Contract Management System utilizes Blockchain technology to support the security and integrity of tender data. Leveraging Blockchain's decentralized architecture and encryption capabilities, the system ensures data remains tamper-proof and resistant to unauthorized access. Each piece of data, along with its hash code, is securely stored in an RTREE structure, enabling continuous verification of transaction integrity. Before adding a new block to the Blockchain, the system rigorously verifies hash codes to ensure data integrity remains intact. Through the creation of contracts within the Blockchain, all transaction details are securely stored, ensuring immutability and encryption throughout the process. This robust approach guarantees data integrity, even in the face of potential server compromises, as verification and retrieval of data can be conducted from multiple functioning nodes within the Blockchain network. By leveraging Blockchain technology, the Smart Tender Contract Management System not only enhances the security and integrity of tender data but also ensures transparency, accountability, and resilience in the tendering process.
Upgradable smart contracts play an important role in the decentralized application ecosystem, to support routine maintenance, security patching, and feature additions. In this paper, we conduct an empirical study on proxy-based upgradable smart contracts to understand the characteristics of contract upgrading. Through our study on 57,118 open source proxy contracts, we found that 583 contracts have ever been upgraded on Ethereum, involving 973 unique implementation contract versions. The results show that developers often intend to improve usability of contracts if upgrading, where functionality addition and update are the most frequent upgrade intentions. We investigated the practical impacts of contract upgrades, e.g., breaking changes causing compatibility issues, storage collisions and initialization risks leading to security vulnerabilities. The results demonstrate that there are 4,334 ABI breaking changes due to the upgrades of 276 proxies, causing real-world broken usages within 584 transactions witnessed by the blockchain; 36 contract upgrades had storage collisions and five proxies with 59 implementation contracts are vulnerable to initialization attacks.
Angela Maria Vargas Ariza, Marleny Corzo Marín, Mayeth Lizeth Duran Duran
Results and contributions: Specific financial assurance procedures adapted to the context of the Metaverse are presented, addressing the particular challenges of virtual assets and smart contracts, where a risk assessment and the appropriate implementation of audit procedures are carried out. Contributing to the adequate preservation of these digital elements to guarantee security and lay the foundation for the future of the digital economy. Purpose: The objective is to describe the financial assurance procedures applicable to virtual assets and smart contracts generated in the metaverse, taking into account their financial, economic, legal and accounting characterization. Gap: The financial, accounting and legal characterization of digital assets in the Metaverse, I contribute to presenting audit procedures in accordance with international financial assurance standards that allow the integrity and reliability of transactions in this rapidly evolving virtual environment. Relevance: It is relevant to accountants and auditors who need to evaluate the integrity and reliability of financial operations in the Metaverse, as well as to any person or entity participating in this environment. Impact: The study will provide a solid foundation to address financial challenges in the metaverse, in the face of adequate procedures to audit and financially support virtual assets, thus contributing to the legality and reliability of operations. Methodology: the methodology is qualitative and descriptive, with a non-experimental transectional design. It begins with a review of the existing standard on financial assurance, virtual assets and smart contracts. It is then characterized by examining the applicable financial principles and regulations, as well as the legal and accounting aspects that influence their management and assurance, and the procedures and their applicability in the context of the Metaverse are evaluated.