A Systematic Survey of Smart Contract Fuzzing: Methods, Techniques, and Architectures for Ethereum and Beyond

Blockchain architectures increasingly rely on smart contracts as programmable execution components, yet the security challenges they introduce remain only partially addressed. Fuzz testing has emerged as one of the leading automated techniques for smart contract vulnerability discovery; however, a systematic treatment linking classical fuzzing concepts to the specific architectural constraints of smart contract execution environments has remained elusive. We conduct a large-scale systematic review of 258 publications collected from Scopus and Google Scholar. The review is structured around four research questions covering general fuzzing limitations, EVM execution constraints, cross-contract interaction challenges, and technique transferability. The contributions are fourfold. First, we develop a conceptual taxonomy establishing an explicit correspondence between classical and smart contract fuzzing. Second, we present an architectural taxonomy of representative fuzzers unified under a generalised waypoint architecture that exposes key feedback domains and composition gaps. Third, we provide a categorised technique review spanning coverage-guided, hybrid, and learning-based approaches. Fourth, we offer a reproducibility critique with a structured research roadmap. Coverage-guided greybox fuzzing emerges as the dominant paradigm (51.2% of the 121 SC fuzzer tools); learning-based approaches (machine learning, reinforcement learning, and LLMs) are a small but emerging class, with LLM-guided fuzzing the fastest-emerging subcategory by recency. Feedback-domain composition remains sparse: most surveyed fuzzers combine only a few of the eight identified feedback domains, and none approaches the full set, leaving several high-value multi-domain compositions unexplored. Open challenges include scalable stateful exploration, standardised benchmarks and oracles, and EVM-specific architectural optimisations. The complete categorised corpus, coding, and search strategy are openly available.

Authors

Institutions

Publication Details

Journal
Applied Sciences
Published
2026-09-14
DOI
https://doi.org/10.3390/app16189106
Primary Topic
Blockchain Technology Applications and Security
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

A Systematic Survey of Smart Contract Fuzzing: Methods, Techniques, and Architectures for Ethereum and Beyond

Luís de la Torre, S. Dormido-Canto, Zehua Wang, Luis Alberto López Alvar
Applied Sciences
Blockchain Technology Applications and Security
article

A Systematic Survey of Smart Contract Fuzzing: Methods, Techniques, and Architectures for Ethereum and Beyond

Luís de la Torre, S. Dormido-Canto, Zehua Wang, Luis Alberto López Alvar
article en

Abstract

Blockchain architectures increasingly rely on smart contracts as programmable execution components, yet the security challenges they introduce remain only partially addressed. Fuzz testing has emerged as one of the leading automated techniques for smart contract vulnerability discovery; however, a systematic treatment linking classical fuzzing concepts to the specific architectural constraints of smart contract execution environments has remained elusive. We conduct a large-scale systematic review of 258 publications collected from Scopus and Google Scholar. The review is structured around four research questions covering general fuzzing limitations, EVM execution constraints, cross-contract interaction challenges, and technique transferability. The contributions are fourfold. First, we develop a conceptual taxonomy establishing an explicit correspondence between classical and smart contract fuzzing. Second, we present an architectural taxonomy of representative fuzzers unified under a generalised waypoint architecture that exposes key feedback domains and composition gaps. Third, we provide a categorised technique review spanning coverage-guided, hybrid, and learning-based approaches. Fourth, we offer a reproducibility critique with a structured research roadmap. Coverage-guided greybox fuzzing emerges as the dominant paradigm (51.2% of the 121 SC fuzzer tools); learning-based approaches (machine learning, reinforcement learning, and LLMs) are a small but emerging class, with LLM-guided fuzzing the fastest-emerging subcategory by recency. Feedback-domain composition remains sparse: most surveyed fuzzers combine only a few of the eight identified feedback domains, and none approaches the full set, leaving several high-value multi-domain compositions unexplored. Open challenges include scalable stateful exploration, standardised benchmarks and oracles, and EVM-specific architectural optimisations. The complete categorised corpus, coding, and search strategy are openly available.

Applied SciencesVol. 16(18)
University of British Columbia (CA), Universidad Nacional de Educación a Distancia (ES)
Partnerships for the goals
Openalex Percentile: Top 4%
Blockchain Technology Applications and Security
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.