Blockchain Security: An Empirical Evaluation of High‐Impact Exploits and Detection Tools
ABSTRACT Blockchain introduced secure, peer‐to‐peer transactions in decentralized environments without reliance on central authorities. However, attackers continue to exploit blockchain projects. Over the past decade, reported blockchain exploit losses have exceeded $24 billion. Although existing research analyzes blockchain vulnerabilities and real‐world incidents, many studies focus on specific vulnerability classes or smart contract issues only. Therefore, we present an empirical study of major blockchain exploits from 2020 to 2025. Based on detailed analysis of these exploits, we introduce a practitioner‐oriented taxonomy that organizes the dominant root causes observed in the analyzed exploits across four domains: Human Risks, Off‐Chain Infrastructure Vulnerabilities, Private Key Compromises, and Smart Contract Vulnerabilities. Across these categories, we present case studies, code illustrations where applicable, and mitigation strategies. Moreover, we evaluate five vulnerability‐detection tools spanning four paradigms, namely static analysis ( Slither , 4naly3er ), symbolic execution ( Mythril ), bounded/formal verification ( SMTChecker ), and LLM‐assisted analysis ( GPTScan ), on a curated test suite of vulnerable and secure contracts. Our results show detection gaps under the evaluated setting: Slither, Mythril, and 4naly3er all scored recall below 40%. SMTChecker and GPTScan were evaluated separately because of their narrower target scopes. SMTChecker detected only arithmetic issues, while GPTScan produced no benchmark‐relevant detections. The study highlights the high average loss associated with smart contract access‐control failures, the need for post‐deployment monitoring beyond one‐time audits, and risks related to Off‐Chain Infrastructure Vulnerabilities. By analyzing exploits and offering mitigations, we provide a structured reference for identifying, prioritizing, and mitigating major blockchain security risks.
Authors
- Hammad Afzal (ORCID: https://orcid.org/0000-0001-9583-5585)
- Abdur Rehman Raza
- Muhammad Ahmad Bilal (ORCID: https://orcid.org/0000-0002-7673-9309)
- Muhammad Jaleed Khan (ORCID: https://orcid.org/0000-0003-4727-4722)
- Shahzaib Tahir (ORCID: https://orcid.org/0000-0003-4737-0191)
- Attiq Ahmad (ORCID: https://orcid.org/0009-0008-4316-7704)
Institutions
- University of Leicester (GB)
- University of Oxford (GB)
- National University of Sciences and Technology (PK)
Publication Details
- Journal
- Security and Privacy
- Published
- 2026-10-09
- DOI
- https://doi.org/10.1002/spy2.70260
- Primary Topic
- Blockchain Technology Applications and Security
- Type
- article
- Field-Weighted Citation Impact
- 0.00