The Effectiveness of Echidna in Detecting Reentrancy in Ethereum Smart Contracts Using Bug Injection
Downloads
Smart contract vulnerabilities, particularly reentrancy, have caused hundreds of millions of dollars in losses across the Ethereum ecosystem. While static analysis tools dominate current auditing practice, empirical evaluations have consistently demonstrated their high false negative and false positive rates for reentrancy detection. Dynamic analysis, exemplified by property-based fuzzing with Echidna, offers an alternative by evaluating contracts through actual execution. However, systematic empirical evaluation of dynamic tools under controlled ground-truth conditions remains limited. This study adapts the bug injection methodology, previously applied only to static analysis evaluation, to assess Echidna's effectiveness in detecting reentrancy. A dataset of 50 Solidity contracts was instrumented with oracle properties and injected with two reentrancy variants, single-function and cross-function, producing 100 ground-truth contract variants. Three fuzzing configurations of increasing intensity were evaluated across three metrics: detection rate, activation rate, and average detection time. Results show that Echidna achieved 100% activation but detected only 20% to 42% of injected bugs depending on the configuration and variant. Nearly all detections occurred within the first 25 seconds of each campaign, with no benefit from extended timeouts. These findings reveal a fundamental gap between bug reachability and exploitability confirmation under standard fuzzing conditions.
A. Alkhalifah, A. Ng, P. A. Watters, and A. S. M. Kayes, "A Mechanism to Detect and Prevent Ethereum Blockchain Smart Contract Reentrancy Attacks," Front. Comput. Sci., vol. 3, pp. 1–15, Feb. 2021,doi: https://doi.org/10.3389/fcomp.2021.598780.
S. S. Kushwaha, S. Joshi, D. Singh, M. Kaur, and H. N. Lee, "Systematic Review of Security Vulnerabilities in Ethereum Blockchain Smart Contract," IEEE Access, vol. 10, pp. 6605–6621, 2022, doi: https://doi.org/10.1109/ACCESS.2021.3140091.
L. Marchesi, L. Pompianu, and R. Tonelli, "Security checklists for Ethereum smart contract development: patterns and best practices," Blockchain: Res. Appl., p. 100367, 2025, doi: https://doi.org/10.1016/j.bcra.2025.100367.
Qasse, I. M. Ali, N. Ahmed, and M. Hamdaqa, "The Myth of Immutability: A Multivocal Review on Smart Contract Upgradeability," arXiv:2504.02719, 2025. [Online]. Available: https://arxiv.org/abs/2504.02719
AliceHsu, "2024 DeFi Smart Contract Hack Incident Review," Cymetrics Tech Blog, 2024. [Online]. Available: https://tech-blog.cymetrics.io/en/posts/alice/2024_defi_hack/
J. V. Behanan and Shashank, "OWASP Smart Contract Top 10," OWASP, 2025. [Online]. Available: https://owasp.org/www-project-smart-contract-top-10/
S. Burnet and K. Kinder, "Decentralized Finance (DeFi) Market Statistics 2025: TVL, Token Caps & User Adoption Revealed," CoinLaw, 2025. [Online]. Available: https://coinlaw.io/decentralized-finance-market-statistics/
S. Cholakov, "2024 Exploits Recap: Top 10 Most Exploited DeFi Vulnerabilities and How to Prevent Them," THREE SIGMA, 2025. [Online]. Available: https://threesigma.xyz/blog/exploit/2024-defi-exploits-top-vulnerabilities
A. Ghaleb and K. Pattabiraman, "How Effective are Smart Contract Analysis Tools? Evaluating Smart Contract Static Analysis Tools Using Bug Injection," in Proc. 29th ACM SIGSOFT Int. Symp. Software Testing and Analysis (ISSTA), 2020, pp. 415–427, doi: https://doi.org/10.1145/3395363.3397385.
J. Feist, G. Grieco, and A. Groce, "Slither: A Static Analysis Framework for Smart Contracts," in Proc. 2nd Int. Workshop Emerging Trends in Software Engineering for Blockchain (WETSEB), 2019, pp. 8–15, doi: https://doi.org/10.1109/WETSEB.2019.00008.
Q. Huang, Y. Ju, Y. Jiang, and Y. Shang, "Analysis and Identification of False Positives in Reentrancy Vulnerabilities Based on Anti-Patterns," SSRN, 2024. [Online]. Available: https://ssrn.com/abstract=5024533
L. Benetollo, S. Guesmi, C. Piazza, D. Ressi, S. Rossi, and A. Spanò, "Modeling Reentrancy in Smart Contracts through Noninterference," in Proc. Seventh Distributed Ledger Technology Workshop (DLT 2025), 2025. [Online]. Available: https://ceur-ws.org/Vol-4105/paper11.pdf
S. Yang, J. Chen, M. Huang, Z. Zheng, and Y. Huang, "Uncover the Premeditated Attacks: Detecting Exploitable Reentrancy Vulnerabilities by Identifying Attacker Contracts," in Proc. IEEE/ACM 46th Int. Conf. Software Engineering (ICSE), 2024, pp. 1573–1584, doi: https://doi.org/10.1145/3597503.3639153.
Wang, Z., Chen, J., Zheng, Z., Zheng, P., Zhang, Y., & Zhang, W. (2020). Unity is Strength : Enhancing Precision in Reentrancy Vulnerability Detection of Smart Contract Analysis Tools. IEEE Transactions on Software Engineering, 1–12. https://doi.org/10.48550/arXiv.2402.09094.
F. R. Vidal, N. Ivaki, and N. Laranjeiro, "Detection techniques for smart contracts: A systematic literature review," J. Syst. Softw., vol. 217, p. 112160, Jul. 2024, doi: https://doi.org/10.1016/j.jss.2024.112160.
Y. Xue and Y. Lin, "Cross-Contract Static Analysis for Detecting Practical Reentrancy Vulnerabilities in Smart Contracts," in Proc. IEEE Int. Conf. Automated Software Engineering (ASE), 2020, doi: 10.1109/ASE.2020.00029.
G. Grieco, W. Song, A. Cygan, and A. Groce, "Echidna: Effective, Usable, and Fast Fuzzing for Smart Contracts," in Proc. 29th ACM SIGSOFT Int. Symp. Software Testing and Analysis (ISSTA), 2020, pp. 20–23, doi: https://doi.org/10.1145/3395363.3404366.
M. Ren, Z. Yin, F. Ma, Z. Xu, Y. Jiang, and C. Sun, "Empirical Evaluation of Smart Contract Testing: What Is the Best Choice?" in Proc. 30th ACM SIGSOFT Int. Symp. Software Testing and Analysis (ISSTA), 2021, pp. 566–579,
Doi: https://doi.org/10.1145/3460319.3464837.
N. F. Samreen and M. H. Alalfi, "Reentrancy Vulnerability Identification in Ethereum Smart Contracts," in Proc. Int. Workshop Blockchain Oriented Software Engineering (IWBOSE), 2020,
Doi:https://doi.org/10.1109/IWBOSE50093.2020.9050260.
N. Deshpande and D. Rana, "Demystifying Reentrancy Attacks on Smart Contracts: Understanding Types and Mitigations," NFSU – J. Cyber Security and Digital Forensics, pp. 66–77, 2024. [Online]. Available: https://jcsdf.nfsu.ac.in/articles?id=54
The Solidity Authors, "Security Considerations," Solidity Documentation, 2023. [Online]. Available: https://docs.soliditylang.org/en/v0.8.24/security-considerations.html
Q. Song, H. Huang, X. Jia, Y. Xie, and J. Cao, "Silence False Alarms: Identifying Anti-Reentrancy Patterns on Ethereum to Refine Smart Contract Reentrancy Detection," in Proc. Network and Distributed System Security (NDSS) Symp., Feb. 2025.
K. Li et al., "Static Application Security Testing (SAST) Tools for Smart Contracts: How Far Are We?" Proc. ACM Softw. Eng., vol. 1, pp. 1–24, Jul. 2024, doi: https://doi.org/10.1145/3660772.
P. E. Black, A. Delaitre, D. Cupif, G. Haben, A.-K. Loembe, V. Okun, and Y. Prono, "SATE VI Report: Bug Injection and Collection," U.S. Department of Commerce, NIST SP 500-341, 2023, doi: https://doi.org/10.6028/NIST.SP.500-341.
F. Salzano et al., "An Empirical Analysis of Vulnerability Detection Tools for Solidity Smart Contracts Using Line Level Manually Annotated Vulnerabilities," arXiv:2505.15756, 2025, doi: https://doi.org/10.48550/arXiv.2505.15756.
H. Wang, Y. Liu, Y. Li, S. Lin, C. Artho, L. Ma, and Y. Liu, "Oracle-Supported Dynamic Exploit Generation for Smart Contracts," IEEE Trans. Dependable Secure Comput., 2022, doi: https://doi.org/10.1109/TDSC.2020.3037332.
Imran Pollob, “smart-contract-vulnerability-dataset”. https://github.com/imranpollob/smart-contract-vulnerability-dataset/
