A conceptual taxonomy establishing an explicit correspondence between classical and smart contract fuzzing is developed and an architectural taxonomy of representative fuzzers unified under a generalised waypoint architecture is presented that exposes key feedback domains and composition gaps.
Abstract
Blockchain architectures increasingly rely on smart contracts as programmable execution components, yet the security challenges they introduce remain only partially addressed. Fuzz testing has emerged as one of the leading automated techniques for smart contract vulnerability discovery; however, a systematic treatment linking classical fuzzing concepts to the specific architectural constraints of smart contract execution environments has remained elusive. We conduct a large-scale systematic review of 258 publications collected from Scopus and Google Scholar. The review is structured around four research questions covering general fuzzing limitations, EVM execution constraints, cross-contract interaction challenges, and technique transferability. The contributions are fourfold. First, we develop a conceptual taxonomy establishing an explicit correspondence between classical and smart contract fuzzing. Second, we present an architectural taxonomy of representative fuzzers unified under a generalised waypoint architecture that exposes key feedback domains and composition gaps. Third, we provide a categorised technique review spanning coverage-guided, hybrid, and learning-based approaches. Fourth, we offer a reproducibility critique with a structured research roadmap. Coverage-guided greybox fuzzing emerges as the dominant paradigm (51.2% of the 121 SC fuzzer tools); learning-based approaches (machine learning, reinforcement learning, and LLMs) are a small but emerging class, with LLM-guided fuzzing the fastest-emerging subcategory by recency. Feedback-domain composition remains sparse: most surveyed fuzzers combine only a few of the eight identified feedback domains, and none approaches the full set, leaving several high-value multi-domain compositions unexplored. Open challenges include scalable stateful exploration, standardised benchmarks and oracles, and EVM-specific architectural optimisations. The complete categorised corpus, coding, and search strategy are openly available.
This paper presents a framework where programmers can use schemas and reusable constructs for a given domain, which domain experts can then use to specify smart contracts in familiar terms and concepts rather than in a specialized programming language.
Yun-Tao Cai, Keerthi Nelaturu, A. Veneris· 0 citations
Blockchain technology has expanded from a system of verifying and recording peer-to-peer cryptocurrency transactions to a general-purpose system that has the capability to execute self-enforcing agreements in a digital form, called a smart contract. Smart Contracts remove the need for a trusted third party by decentral...
Harshraj N. Gadbail, Rajendra M. Rewatkar, Nupur G. Kamdi et al.· 2026 International Conferenc...· 0 citations
Smart contracts are a crucial element in blockchain technology, enabling the decentralisation and automation of digital transactions. However, re-entrancy, access control, integer overflows and logic errors all pose a danger to their security and reliability. Previously available audit solutions rely on a single analy...
Alfiya Sayyad, Tushar H. Ghorpade, Vanita Mane et al.· International journal of com...· 0 citations
This work proposes IntentFuzz: a protocol-aware fuzzer that recovers a bridge's intent structure and deposit/fill function roles directly from unannotated Solidity source, then synthesizes multi-step fuzz sequences using an LLM-based fallback to help build call arguments.
André Augusto, Christof Ferreira Torres, André Vasconcelos et al.· 0 citations
A lightweight method for generating fuzz test cases under bytecode-level static guidance, and results indicate that static guidance, directed seed generation, and vulnerability-specific oracles each contribute to the final performance.
Shiting Yu, Rundong Wei, Xiaoqi Li· 0 citations
Related blog posts
MIT News · Artificial Intelligence· news.mit.eduOct 2, 2026
Martin Trust Center Managing Director Bill Aulet introduces Dear Dreamer, a free platform for middle and high school students who want to learn about entrepreneurship.
Microsoft Research Blog· microsoft.comSep 30, 2026
Extreme space-weather events can damage power systems on Earth and degrade GPS accuracy and satellite operations. A new machine learning system can predict where damage is likely to occur 30-60 minutes before a storm arrives. The post Forecasting space weather risks on power grids appeared first on Microsoft Research.
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.