Skip to main navigation Skip to search Skip to main content

Uncovering NFT Domain-Specific Defects on Smart Contract Bytecode

  • Zuchao Ma
  • , Muhui Jiang
  • , Xiapu Luo
  • , Haoyu Wang
  • , Yajin Zhou

Research output: Journal article publicationJournal articleAcademic researchpeer-review

Abstract

The peak of monthly trade volume of NFT (non-fungible token) has reached $4.95 billion USD in August 2023, which shows the hot trend and the potential significance of NFT. However, the smart contract responsible for managing NFT may contain defects, which can be exploited by attackers to cause severe damage to victims. We take the first step to systematically analyze three kinds of defects on NFT contracts, namely fragile NFT binding, non-compliant implementation, and implanted backdoor. In particular, we propose Emerium, the first extensible detection framework for capturing these defects by inspecting the bytecode of smart contracts. We conduct extensive experiments to evaluate Emerium, and the experimental results show that it can detect the aforementioned defects with 0.83 and 0.89 F-measure for ERC-721 contracts and ERC-1155 contracts, respectively. Applying Emerium to 87,839 ERC-721 and 9,808 ERC1155 NFT contracts of real world, we uncover 44,863,255 defects of fragile NFT binding, 1,373 defects of non-compliant implementation, and 105 defects of backdoor (also with a new CVE).
Original languageEnglish
Pages (from-to)4877 - 4895
JournalIEEE Transactions on Dependable and Secure Computing
Volume22
Issue number5
DOIs
Publication statusPublished - Sept 2025

Fingerprint

Dive into the research topics of 'Uncovering NFT Domain-Specific Defects on Smart Contract Bytecode'. Together they form a unique fingerprint.

Cite this