Blockchain Security: An Empirical Evaluation of High‐Impact Exploits and Detection Tools

ABSTRACT Blockchain introduced secure, peer‐to‐peer transactions in decentralized environments without reliance on central authorities. However, attackers continue to exploit blockchain projects. Over the past decade, reported blockchain exploit losses have exceeded $24 billion. Although existing research analyzes blockchain vulnerabilities and real‐world incidents, many studies focus on specific vulnerability classes or smart contract issues only. Therefore, we present an empirical study of major blockchain exploits from 2020 to 2025. Based on detailed analysis of these exploits, we introduce a practitioner‐oriented taxonomy that organizes the dominant root causes observed in the analyzed exploits across four domains: Human Risks, Off‐Chain Infrastructure Vulnerabilities, Private Key Compromises, and Smart Contract Vulnerabilities. Across these categories, we present case studies, code illustrations where applicable, and mitigation strategies. Moreover, we evaluate five vulnerability‐detection tools spanning four paradigms, namely static analysis ( Slither , 4naly3er ), symbolic execution ( Mythril ), bounded/formal verification ( SMTChecker ), and LLM‐assisted analysis ( GPTScan ), on a curated test suite of vulnerable and secure contracts. Our results show detection gaps under the evaluated setting: Slither, Mythril, and 4naly3er all scored recall below 40%. SMTChecker and GPTScan were evaluated separately because of their narrower target scopes. SMTChecker detected only arithmetic issues, while GPTScan produced no benchmark‐relevant detections. The study highlights the high average loss associated with smart contract access‐control failures, the need for post‐deployment monitoring beyond one‐time audits, and risks related to Off‐Chain Infrastructure Vulnerabilities. By analyzing exploits and offering mitigations, we provide a structured reference for identifying, prioritizing, and mitigating major blockchain security risks.

Authors

Institutions

Publication Details

Journal
Security and Privacy
Published
2026-10-09
DOI
https://doi.org/10.1002/spy2.70260
Primary Topic
Blockchain Technology Applications and Security
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
OCT
article

Blockchain Security: An Empirical Evaluation of High‐Impact Exploits and Detection Tools

Hammad Afzal, Abdur Rehman Raza, Muhammad Ahmad Bilal, Muhammad Jaleed Khan et al.
Security and Privacy
Blockchain Technology Applications and Security
article

Blockchain Security: An Empirical Evaluation of High‐Impact Exploits and Detection Tools

Hammad Afzal, Abdur Rehman Raza, Muhammad Ahmad Bilal, Muhammad Jaleed Khan, Shahzaib Tahir, Attiq Ahmad
article en

Abstract

ABSTRACT Blockchain introduced secure, peer‐to‐peer transactions in decentralized environments without reliance on central authorities. However, attackers continue to exploit blockchain projects. Over the past decade, reported blockchain exploit losses have exceeded $24 billion. Although existing research analyzes blockchain vulnerabilities and real‐world incidents, many studies focus on specific vulnerability classes or smart contract issues only. Therefore, we present an empirical study of major blockchain exploits from 2020 to 2025. Based on detailed analysis of these exploits, we introduce a practitioner‐oriented taxonomy that organizes the dominant root causes observed in the analyzed exploits across four domains: Human Risks, Off‐Chain Infrastructure Vulnerabilities, Private Key Compromises, and Smart Contract Vulnerabilities. Across these categories, we present case studies, code illustrations where applicable, and mitigation strategies. Moreover, we evaluate five vulnerability‐detection tools spanning four paradigms, namely static analysis ( Slither , 4naly3er ), symbolic execution ( Mythril ), bounded/formal verification ( SMTChecker ), and LLM‐assisted analysis ( GPTScan ), on a curated test suite of vulnerable and secure contracts. Our results show detection gaps under the evaluated setting: Slither, Mythril, and 4naly3er all scored recall below 40%. SMTChecker and GPTScan were evaluated separately because of their narrower target scopes. SMTChecker detected only arithmetic issues, while GPTScan produced no benchmark‐relevant detections. The study highlights the high average loss associated with smart contract access‐control failures, the need for post‐deployment monitoring beyond one‐time audits, and risks related to Off‐Chain Infrastructure Vulnerabilities. By analyzing exploits and offering mitigations, we provide a structured reference for identifying, prioritizing, and mitigating major blockchain security risks.

Security and PrivacyVol. 9(6)
University of Leicester (GB), University of Oxford (GB), National University of Sciences and Technology (PK)
Openalex Percentile: Top 6%
Blockchain Technology Applications and Security
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.