A Systematic Survey of Smart Contract Fuzzing: Methods, Techniques, and Architectures for Ethereum and Beyond
Blockchain architectures increasingly rely on smart contracts as programmable execution components, yet the security challenges they introduce remain only partially addressed. Fuzz testing has emerged as one of the leading automated techniques for smart contract vulnerability discovery; however, a systematic treatment linking classical fuzzing concepts to the specific architectural constraints of smart contract execution environments has remained elusive. We conduct a large-scale systematic review of 258 publications collected from Scopus and Google Scholar. The review is structured around four research questions covering general fuzzing limitations, EVM execution constraints, cross-contract interaction challenges, and technique transferability. The contributions are fourfold. First, we develop a conceptual taxonomy establishing an explicit correspondence between classical and smart contract fuzzing. Second, we present an architectural taxonomy of representative fuzzers unified under a generalised waypoint architecture that exposes key feedback domains and composition gaps. Third, we provide a categorised technique review spanning coverage-guided, hybrid, and learning-based approaches. Fourth, we offer a reproducibility critique with a structured research roadmap. Coverage-guided greybox fuzzing emerges as the dominant paradigm (51.2% of the 121 SC fuzzer tools); learning-based approaches (machine learning, reinforcement learning, and LLMs) are a small but emerging class, with LLM-guided fuzzing the fastest-emerging subcategory by recency. Feedback-domain composition remains sparse: most surveyed fuzzers combine only a few of the eight identified feedback domains, and none approaches the full set, leaving several high-value multi-domain compositions unexplored. Open challenges include scalable stateful exploration, standardised benchmarks and oracles, and EVM-specific architectural optimisations. The complete categorised corpus, coding, and search strategy are openly available.
Authors
- Luís de la Torre (ORCID: https://orcid.org/0000-0002-9648-9597)
- S. Dormido-Canto (ORCID: https://orcid.org/0000-0001-7652-5338)
- Zehua Wang (ORCID: https://orcid.org/0000-0001-9040-847X)
- Luis Alberto López Alvar (ORCID: https://orcid.org/0009-0009-1980-415X)
Institutions
- University of British Columbia (CA)
- Universidad Nacional de Educación a Distancia (ES)
Publication Details
- Journal
- Applied Sciences
- Published
- 2026-09-14
- DOI
- https://doi.org/10.3390/app16189106
- Primary Topic
- Blockchain Technology Applications and Security
- Type
- article
- Field-Weighted Citation Impact
- 0.00