DOI: 10.1145/3849091 ISSN: 1049-331X

Mining Invariants to Enhance Fuzzing for Detecting Functional Bugs in Smart Contracts

Xingshuang Lin, Binbin Zhao, Qinge Xie, Na Ruan, Jiliang Li, Shouling Ji

Smart contracts, which are fundamental to DeFi financial systems, are vulnerable to exploitable bugs that can cause substantial monetary losses. A recent study shows that over 80% of these exploitable bugs, primarily functional bugs, evade detection by existing tools. Automatically identifying functional bugs in smart contracts is challenging from multiple perspectives. The primary issue is the significant gap between understanding the high-level logic of the business model and checking the low-level implementations in smart contracts. Furthermore, identifying deeply rooted functional bugs in smart contracts requires the automated generation of effective detection oracles based on various bug features. To address these challenges, we design PromFuzz++, an automated and scalable system for detecting functional bugs in smart contracts. In PromFuzz++, we first propose a dual-agent framework to identify potentially vulnerable functions for further analysis. We then implement a dual-stage coupling approach that generates invariant checkers using logic information extracted from these functions, enhancing bug-oriented fuzzing on target contracts. Our evaluation shows that PromFuzz++ achieves 86.96% recall and a 93.02% F1-score, improving both metrics by at least 50% over state-of-the-art methods. An in-depth analysis of 10 real-world DeFi projects uncovered 30 zero-day bugs, 24 of which have been assigned CVE IDs.