Return
Toward Understanding Functional Bugs in EVM-Based Blockchain Systems
M
Y
J
Z
Y
P
Z
DOI:10.1109/tse.2026.3685454.png)
Abstract
En 中文
Functional bugs within blockchain systems have led to financial losses exceeding millions of dollars. Blockchain systems, such as Ethereum, play a critical role in supporting decentralized applications and managing significant financial assets. Despite the urgent need for enhanced security, relatively few studies have systematically investigated the functional bugs specific to blockchain systems. Unlike in conventional software, functional bugs in blockchain systems are often domain-specific and linked to core blockchain functionalities, necessitating a comprehensive understanding. In this study, we conduct a systematic analysis of functional bugs in Ethereum Virtual Machine (EVM)-based blockchain systems. We focus on the EVM-based architecture, as it is one of the most widely adopted models for blockchain systems. Specifically, we analyze bug-related issues reported in the GitHub repositories of leading blockchain systems, building a dataset of 205 real-world bugs classified into 18 categories. We investigate these collected bugs with respect to their taxonomies, root causes, and detection methods. From this analysis, we summarize eight key findings for enhancing blockchain security. The discovery of seven previously unknown bugs, yielding approximately $12,000 in bug bounties, demonstrates the practical impact of this work. A further investigation of state-of-the-art tools highlights the limitations of existing detection and analysis research.
Keywords:
Blockchain security
system vulnerability
empirical study
Journal
IF:
5.6
Papers:
2.8K
Citations:
1.1W
