Background: Smart contracts are revolutionizing the way two or more parties subscribe and apply an agreement. The main reason is that they promise to increase efficiency, transparency, and security. However, their inherent vulnerabilities can lead to automated exploits, resulting in significant resource losses. Among these, reentrancy is one of the most impactful security flaws. Over the past few years, reentrancy vulnerabilities have caused substantial financial damage and threatened the viability of entire blockchain ecosystems. Therefore, investigating whether reentrancy can be effectively mitigated and exploring the methodologies designed to address it is crucial. Methodology: The present paper aims to provide a comprehensive understanding of the impact of reentrancy vulnerabilities in Ethereum smart contracts and to assess the theoretical and practical approaches proposed to counter them. By following the PRISMA framework, we conduct a literature review of academic publications to identify, screen, and analyze relevant studies on detection and mitigation techniques. Results: Our findings indicate that the estimated financial loss due to reentrancy attacks amounted to around 350 million USD by 2023, with increasing frequency and profitability of incidents. Despite advancements in mitigation tools, particularly machine learning, they only partially address vulnerabilities and remain ineffective against zero-day attacks. Contribution: This paper identifies critical challenges in reentrancy detection, including the lack of standardized benchmarks and data on zero-day vulnerabilities. It emphasizes the need for unified datasets and evaluation frameworks to facilitate fair comparisons, improving detection effectiveness. Additionally, it highlights the need for tools addressing all four reentrancy vulnerability types and reporting performance results.

Welcome back: a systematic literature review of smart contract reentrancy and countermeasures

Ghiyami Pour Fatemeh
;
Costa Gabriele;Galletta Letterio
In corso di stampa

Abstract

Background: Smart contracts are revolutionizing the way two or more parties subscribe and apply an agreement. The main reason is that they promise to increase efficiency, transparency, and security. However, their inherent vulnerabilities can lead to automated exploits, resulting in significant resource losses. Among these, reentrancy is one of the most impactful security flaws. Over the past few years, reentrancy vulnerabilities have caused substantial financial damage and threatened the viability of entire blockchain ecosystems. Therefore, investigating whether reentrancy can be effectively mitigated and exploring the methodologies designed to address it is crucial. Methodology: The present paper aims to provide a comprehensive understanding of the impact of reentrancy vulnerabilities in Ethereum smart contracts and to assess the theoretical and practical approaches proposed to counter them. By following the PRISMA framework, we conduct a literature review of academic publications to identify, screen, and analyze relevant studies on detection and mitigation techniques. Results: Our findings indicate that the estimated financial loss due to reentrancy attacks amounted to around 350 million USD by 2023, with increasing frequency and profitability of incidents. Despite advancements in mitigation tools, particularly machine learning, they only partially address vulnerabilities and remain ineffective against zero-day attacks. Contribution: This paper identifies critical challenges in reentrancy detection, including the lack of standardized benchmarks and data on zero-day vulnerabilities. It emphasizes the need for unified datasets and evaluation frameworks to facilitate fair comparisons, improving detection effectiveness. Additionally, it highlights the need for tools addressing all four reentrancy vulnerability types and reporting performance results.
In corso di stampa
Reentrancy, Blockchain security, Smart contract vulnerability, Systematic literature review
File in questo prodotto:
File Dimensione Formato  
1-s2.0-S2096720925000740-main.pdf

accesso aperto

Descrizione: Welcome back: A systematic literature review of smart contract reentrancy and countermeasures
Tipologia: Documento in Post-print
Licenza: Creative commons
Dimensione 7.08 MB
Formato Adobe PDF
7.08 MB Adobe PDF Visualizza/Apri

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/20.500.11771/36239
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus ND
social impact