Mingxi Ye

dblp:331/7925 · DBLP profile ↗
← Back
8ranked-venue papers
4as first author
8since 2021 · last 2026
0009-0004-6708-4074ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 8 · 4 first-author · 8 since 2021
YearPublicationVenuePosition
2026 Toward Understanding Functional Bugs in EVM-Based Blockchain Systems
abstract
Functional bugs within blockchain systems have led to financial losses exceeding millions of dollars. Blockchain systems, such as Ethereum, play a critical role in supporting decentralized applications and managing significant financial assets. Despite the urgent need for enhanced security, relatively few studies have systematically investigated the functional bugs specific to blockchain systems. Unlike in conventional software, functional bugs in blockchain systems are often domain-specific and linked to core blockchain functionalities, necessitating a comprehensive understanding.In this study, we conduct a systematic analysis of functional bugs in Ethereum Virtual Machine (EVM)-based blockchain systems. We focus on the EVM-based architecture, as it is one of the most widely adopted models for blockchain systems. Specifically, we analyze bug-related issues reported in the GitHub repositories of leading blockchain systems, building a dataset of 205 real-world bugs classified into 18 categories. We investigate these collected bugs with respect to their taxonomies, root causes, and detection methods. From this analysis, we summarize eight key findings for enhancing blockchain security. The discovery of seven previously unknown bugs, yielding approximately $12,000 in bug bounties, demonstrates the practical impact of this work. A further investigation of state-of-the-art tools highlights the limitations of existing detection and analysis research.
Mingxi Ye, Yuhong Nan, Jianzhong Su, Yuming Xiao, Peilin Zheng, Zibin Zheng
IEEE Trans. Software Eng.1
2025 Smartreco: Detecting Read-Only Reentrancy via Fine-Grained Cross-DApp Analysis
abstract
Despite the increasing popularity of Decentralized Applications (DApps), they are suffering from various vulnerabilities that can be exploited by adversaries for profits. Among such vulnerabilities, Read-Only Reentrancy (called ROR in this paper), is an emerging type of vulnerability that arises from the complex interactions between DApps. In the recent three years, attack incidents of ROR have already caused around 30M USD losses to the DApp ecosystem. Existing techniques for vulnerability detection in smart contracts can hardly detect Read-Only Reentrancy attacks, due to the lack of tracking and analyzing the complex interactions between multiple DApps. In this paper, we propose SmartReco, a new framework for detecting Read-Only Reentrancy vulnerability in DApps through a novel combination of static and dynamic analysis (i.e., fuzzing) over smart contracts. The key design behind SmartReco is threefold: (1) SmartReco identifies the boundary between different DApps from the heavy-coupled cross-contract interactions. (2) SmartReco performs fine-grained static analysis to locate points of interest (i.e., entry functions) that may lead to ROR. (3) SmartReco utilizes the on-chain transaction data and performs multi-function fuzzing (i.e., the entry function and victim function) across different DApps to verify the existence of ROR. Our evaluation of a manual-labeled dataset with 45 RORs shows that SmartReco achieves a precision of 88.64 % and a recall of 86.67 %. In addition, SmartReco successfully detects 43 new RORs from 123 popular DApps. The total assets affected by such RORs reach around 520,000 USD.
Zibin Zheng, Yuhong Nan, Mingxi Ye, Kaiwen Ning, Yu Zhang 0036, Weizhe Zhang
ICSE4
2025 ASTRO: Detecting Access Control Vulnerabilities in Smart Contracts via Graph Similarity Comparison
abstract
Smart contracts are programs running on blockchains, managing substantial volumes of wealth stored within the blockchain platforms. To safeguard these assets, developers design and implement access control policies. However, incomplete and incorrect access control policies allow malicious attackers to gain unauthorized access and exploit additional assets. Previous tools for detecting access control vulnerabilities in smart contracts rely on predefined patterns, specifications, or mining access control policies from historical transactions. However, these methods are constrained due to their predetermined nature and the diversity and complexity of smart contracts.In this paper, we presentASTRO, a new framework employing code similarity to detect access control vulnerabilities in smart contracts. In contrast to prior approaches that heavily rely on predefined, vulnerable code samples,ASTROdetects whether a target contract has access control vulnerabilities by comparing it against a database of audited contracts. Moreover, to mitigate the impact of language-specific features (e.g., diverse conditional statements and modifiers) and writing style characteristics, we integrate pruning and normalization techniques. We evaluateASTROon a total of 22 smart contracts with assigned access control CVEs and those attacked because of access control vulnerabilities from the past two years. Evaluation results demonstrate that, compared to state-of-the-art tools (i.e., AChecker, SpCon),ASTROsurpasses all tools in recall and achieves an improvement in recall by at least 2.8 times. In addition,ASTROachieves a precision of 78.33% on a dataset consisting of real-wild contracts. Furthermore,ASTROsuccessfully identified 19 exploitable vulnerable contract that can be used to directly gain access to the contract’s permissions and obtain benefits.
Wei Li 0121, Yuhong Nan, Mingxi Ye, Peilin Zheng, Zibin Zheng
IEEE Trans. Software Eng.3
2024 Midas: Mining Profitable Exploits in On-Chain Smart Contracts via Feedback-Driven Fuzzing and Differential Analysis
abstract
In the context of boosting smart contract applications, prioritizing their security becomes paramount. Smart contract exploits often result in notable financial losses. Ensuring their security is by no means trivial. Rather than resulting in program crashes, most attacks in on-chain smart contracts aim to induce financial loss, referred to as profitable exploits. By constructing seemingly innocuous inputs, profitable exploits try to extract extra profit or compromise the interests of others. However, due to the complexity of call chains in on-chain smart contracts and the need for effective oracles for profitable exploits, smart contract fuzzing suffers from low efficiency and low effectiveness in finding profitable exploits. In this paper, we present Midas, a novel feedback-driven fuzzing framework to mine profitable exploits in on-chain smart contracts effectively. Midas consists of two modules: diverse validity fuzzing and profitable transaction identification. The diverse validity fuzzing module applies two waypoints to efficiently generate valid transactions, addressing the complexity of on-chain smart contract call chains. The profitable transaction identification module applies differential analysis to effectively identify profitable exploits, addressing the limitation of ad-hoc oracles. Evaluation of Midas over on-chain smart contracts showed it effectively identified 40 real-world exploits with a precision of 80%, outperforming state-of-the-art tools (i.e., ItyFuzz and Slither) in both efficiency and effectiveness. Particularly, Midas effectively mines five unknown exploits in valuable smart contracts, and two of them have already been confirmed by their DApp developers.
Mingxi Ye, Xingwei Lin, Yuhong Nan, Jiajing Wu, Zibin Zheng
ISSTA1
2024 FunFuzz: A Function-Oriented Fuzzer for Smart Contract Vulnerability Detection with High Effectiveness and Efficiency
abstract
With the increasing popularity of Decentralized Applications (DApps) in blockchain, securing smart contracts has been a long-term, high-priority subject in the domain. Among the various research directions for vulnerability detection, fuzzing has received extensive attention because of its high effectiveness. However, with the increasing complexity of smart contracts, existing fuzzers may waste substantial time exploring locations irrelevant to smart contract vulnerabilities. In this article, we present FunFuzz, a function-oriented fuzzer, which is dedicatedly tailored for detecting smart contract vulnerability with high effectiveness and efficiency. The key observation in our research is that most smart contract vulnerabilities exist in specific functions rather than randomly distributed in all program code like other traditional software. To this end, unlike traditional fuzzers which mainly target code coverage, FunFuzz identifies risky functions while pruning non-risky ones in smart contracts. In this way, it significantly narrows down the exploration scope during the fuzzing process. In addition, FunFuzz employs three unique strategies to direct itself toward effectively discovering vulnerabilities specific to smart contracts (e.g., reentrancy, block dependency, and gasless send). Extensive experiments on 170 real-world contracts demonstrate that FunFuzz outperforms state-of-the-art fuzzers in terms of effectiveness and efficiency.
Mingxi Ye, Yuhong Nan, Hongning Dai, Shuo Yang 0012, Xiapu Luo, Zibin Zheng
ACM Trans. Softw. Eng. Methodol.1
2024 DAppSCAN: Building Large-Scale Datasets for Smart Contract Weaknesses in DApp Projects
abstract
The Smart Contract Weakness Classification Registry (SWC Registry) is a widely recognized list of smart contract weaknesses specific to the Ethereum platform. Despite the SWC Registry not being updated with new entries since 2020, the sustained development of smart contract analysis tools for detecting SWC-listed weaknesses highlights their ongoing significance in the field. However, evaluating these tools has proven challenging due to the absence of a large, unbiased, real-world dataset. To address this problem, we aim to build a large-scale SWC weakness dataset from real-world DApp projects. We recruited 22 participants and spent 44 person-months analyzing 1,199 open-source audit reports from 29 security teams. In total, we identified 9,154 weaknesses and developed two distinct datasets, i.e., DAPPSCAN-SOURCE and DAPPSCAN-BYTECODE. The DAPPSCAN-SOURCE dataset comprises 39,904 Solidity files, featuring 1,618 SWC weaknesses sourced from 682 real-world DApp projects. However, the Solidity files in this dataset may not be directly compilable for further analysis. To facilitate automated analysis, we developed a tool capable of automatically identifying dependency relationships within DApp projects and completing missing public libraries. Using this tool, we created DAPPSCAN-BYTECODE dataset, which consists of 6,665 compiled smart contract with 888 SWC weaknesses. Based on DAPPSCAN-BYTECODE, we conducted an empirical study to evaluate the performance of state-of-the-art smart contract weakness detection tools. The evaluation results revealed sub-par performance for these tools in terms of both effectiveness and success detection rate, indicating that future development should prioritize real-world datasets over simplistic toy contracts.
Zibin Zheng, Jianzhong Su, Jiachi Chen, David Lo 0001, Mingxi Ye
IEEE Trans. Software Eng.6
2023 Turn the Rudder: A Beacon of Reentrancy Detection for Smart Contracts on Ethereum
abstract
Smart contracts are programs deployed on a blockchain and are immutable once deployed. Reentrancy, one of the most important vulnerabilities in smart contracts, has caused millions of dollars in financial loss. Many reentrancy detection approaches have been proposed. It is necessary to investigate the performance of these approaches to provide useful guidelines for their application. In this work, we conduct a large-scale empirical study on the capability of five well-known or recent reentrancy detection tools such as Mythril and Sailfish. We collect 230,548 verified smart contracts from Etherscan and use detection tools to analyze 139,424 contracts after deduplication, which results in 21,212 contracts with reentrancy issues. Then, we manually examine the defective functions located by the tools in the contracts. From the examination results, we obtain 34 true positive contracts with reentrancy and 21,178 false positive contracts without reentrancy. We also analyze the causes of the true and false positives. Finally, we evaluate the tools based on the two kinds of contracts. The results show that more than 99.8% of the reentrant contracts detected by the tools are false positives with eight types of causes, and the tools can only detect the reentrancy issues caused by call.value(), 58.8% of which can be revealed by the Ethereum's official IDE, Remix. Furthermore, we collect real-world reentrancy attacks reported in the past two years and find that the tools fail to find any issues in the corresponding contracts. Based on the findings, existing works on reentrancy detection appear to have very limited capability, and researchers should turn the rudder to discover and detect new reentrancy patterns except those related to call.value().
Zibin Zheng, Neng Zhang 0001, Jianzhong Su, Mingxi Ye, Jiachi Chen
ICSE5
2023 Detecting State Inconsistency Bugs in DApps via On-Chain Transaction Replay and Fuzzing
abstract
Decentralized applications (DApps) consist of multiple smart contracts running on Blockchain. With the increasing popularity of the DApp ecosystem, vulnerabilities in DApps could bring significant impacts such as financial losses. Identifying vulnerabilities in DApps is by no means trivial, as modern DApps consist of complex interactions across multiple contracts. Previous research suffers from either high false positives or false negatives, due to the lack of precise contextual information which is mandatory for confirming smart contract vulnerabilities when analyzing smart contracts.
Mingxi Ye, Yuhong Nan, Zibin Zheng, Dongpeng Wu, Huizhong Li
ISSTA1