POSTER: An Empirical Study of Smart Contract Patching Practices in the Wild

Taeyoung Kim, Gilhee Lee, Hyoungshick Kim

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Smart contract vulnerabilities pose significant financial risks, making their detection and remediation critical before deployment. While numerous vulnerability detection tools exist, limited empirical research examines how smart contract vulnerabilities are patched and maintained in practice. To address this gap, we conducted a comprehensive analysis of patch management practices across smart contract ecosystems. Our study examined 4,345,088 smart contracts and identified 8,727 vulnerable contracts via an automated detection tool and 4,399 through user reports. Smart contract development practices widely acknowledge that vulnerable contracts should be destroyed and redeployed with appropriate fixes. However, we found that only 248 user-reported vulnerable contracts were self-destructed and only 6.85% of them were redeployed following destruction. Furthermore, these redeployed contracts still contained vulnerabilities, indicating ineffective patch implementation. These findings reveal significant shortcomings in current smart contract maintenance practices and highlight the need for improved security patch management protocols.

Original languageEnglish
Title of host publicationACM ASIA CCS 2025 - Proceedings of the 20th ACM ASIA Conference on Computer and Communications Security
PublisherAssociation for Computing Machinery
Pages1803-1805
Number of pages3
ISBN (Electronic)9798400714108
DOIs
StatePublished - 24 Aug 2025
Externally publishedYes
Event20th ACM ASIA Conference on Computer and Communications Security, ASIA CCS 2025 - Hanoi, Viet Nam
Duration: 25 Aug 202529 Aug 2025

Publication series

NameProceedings of the ACM Conference on Computer and Communications Security
ISSN (Print)1543-7221

Conference

Conference20th ACM ASIA Conference on Computer and Communications Security, ASIA CCS 2025
Country/TerritoryViet Nam
CityHanoi
Period25/08/2529/08/25

Keywords

  • Blockchain security
  • Smart contract
  • Vulnerability management

Fingerprint

Dive into the research topics of 'POSTER: An Empirical Study of Smart Contract Patching Practices in the Wild'. Together they form a unique fingerprint.

Cite this