Smart contract vulnerabilities, tools, and benchmarks: An updated systematic literature review

Gerardo Iuliano & Dario Di Nucci

Journal of Systems and Software2026https://doi.org/10.1016/j.jss.2026.112788preprint
AJG 2
Weight
0.44

What the paper says

Smart contracts are self-executing programs on blockchain platforms like Ethereum, which have revolutionized decentralized finance by enabling trustless transactions and the operation of decentralized applications. Despite their potential, the security of smart contracts remains a critical concern due to their immutability and transparency, which expose them to malicious actors. Numerous solutions for vulnerability detection have been proposed, but it is still unclear which one is the most effective. This paper presents a systematic literature review that explores vulnerabilities in Ethereum smart contracts, focusing on automated detection tools and benchmark evaluation. We reviewed 3,380 studies from five digital libraries and five major software engineering conferences, applying a structured selection process that resulted in 222 high-quality studies. The key results include a hierarchical taxonomy of 192 vulnerabilities grouped into 13 categories, a comprehensive list of 219 detection tools with corresponding functionalities, methods, and code transformation techniques, a mapping between our taxonomy and the list of tools, and a collection of 133 benchmarks used for tool evaluation. We conclude with a discussion about the insights into the current state of Ethereum smart contract security and directions for future research.

3 citations

Open paper page →

Cite this paper

https://doi.org/https://doi.org/10.1016/j.jss.2026.112788

Or copy a formatted citation

@article{gerardo2026,
  title        = {{Smart contract vulnerabilities, tools, and benchmarks: An updated systematic literature review}},
  author       = {Gerardo Iuliano & Dario Di Nucci},
  journal      = {Journal of Systems and Software},
  year         = {2026},
  doi          = {https://doi.org/https://doi.org/10.1016/j.jss.2026.112788},
}

Paste directly into BibTeX, Zotero, or your reference manager.

Flag this paper

Smart contract vulnerabilities, tools, and benchmarks: An updated systematic literature review

Flags are reviewed by the Arbiter methodology team within 5 business days.


Evidence weight

0.44

Balanced mode · F 0.40 / M 0.15 / V 0.05 / R 0.40

F · citation impact0.32 × 0.4 = 0.13
M · momentum0.57 × 0.15 = 0.09
V · venue signal0.50 × 0.05 = 0.03
R · text relevance †0.50 × 0.4 = 0.20

† Text relevance is estimated at 0.50 on the detail page — for your query’s actual relevance score, open this paper from a search result.