Journal of Computer Technology & Applications Original Research
An Automated Smart Contract Repair Framework for Reentrancy, Integer Overflow, and Denial- of-Service Vulnerabilities
Abstract
This paper introduces a novel static analysis framework designed to bridge a long-standing gap in Ethereum smart contract security: the disconnect between vulnerability detection and automated remediation. Although widely adopted tools such as Slither and Oyente are highly effective at identifying security weaknesses, they stop short of providing actionable fixes. As a result, developers manually patch vulnerabilities, a process that is not only time-consuming but also susceptible to human error and inconsistent implementation. Our proposed solution directly addresses this limitation by integrating vulnerability detection with lightweight, automated repair mechanisms. The framework employs a regex-based static analyzer that prioritizes efficiency and practicality over heavyweight program analysis techniques. It introduces three core innovations. First, it automatically injects noReentrant modifiers into vulnerable functions, effectively preventing reentrancy attacks without altering business logic. Second, it performs context-aware wrapping of arithmetic operations inside unchecked{} blocks, reducing the risk of integer overflow and underflow issues while maintaining Solidity compiler compatibility. Third, it systematically annotates loops containing external calls to highlight potential denial-of-service (DoS) risks, improving code readability and auditability. To evaluate effectiveness, the tool was tested on three purpose-built vulnerable contracts: ReentrancyDemo.sol, IntegerBugDemo.sol, and DoSDemo.sol. The results show 100% detection accuracy with zero false positives. In addition, the analyzer outperforms Oyente’s symbolic execution approach by a factor of three to five in execution speed, while achieving precision comparable to Slither. By avoiding abstract syntax tree construction and leveraging a modular, regex-driven design, the framework consistently analyzes 200–300 line contracts in under one second, making it both scalable and developer-friendly.
Keywords
References (19)
- Atzei N, Bartoletti M, Cimoli T. A Survey of Attacks on Ethereum Smart Contracts (SoK). Lecture Notes in Computer Science. 2017:164-186. doi:10.1007/978-3-662-54455-6_8
- Luu L, Chu DH, Olickel H, Saxena P, Hobor A. Making Smart Contracts Smarter. Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security. 2016:254-269. doi:10.1145/2976749.2978309
- Tsankov P, Dan A, Drachsler-Cohen D, Gervais A, Bünzli F, Vechev M. Securify. Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security. 2018:67-82. doi:10.1145/3243734.3243780
- Feist J, Grieco G, Groce A. (2019). Slither: Static analyzer for Solidity and Vyper. [Online] GitHub. Available from: https://github.com/crytic/slither
- Kolluri A, Nikolic I, Sergey I, Hobor A, Saxena P. Exploiting the laws of order in smart contracts. Proceedings of the 28th ACM SIGSOFT International Symposium on Software Testing and Analysis. 2019:363-373. doi:10.1145/3293882.3330560
- GitHub. (2026). GitHub - protofire/solhint: Solhint is an open-source project to provide a linting utility for Solidity code. [online] GitHub. Available from: https://github.com/protofire/solhint
- Solidity Authors. (2025). Security considerations. [online]. Solidity. Available from: https://docs.soliditylang.org/en/latest/security-considerations.html
- Jaffar J, Murali V, Navas JA, Santosa AE. TRACER: A Symbolic Execution Tool for Verification. Lecture Notes in Computer Science. 2012:758-766. doi:10.1007/978-3-642-31424-7_61
- Griggs B. Node Cookbook: Discover Solutions, Techniques, and Best Practices for Server-Side Web Development with Node.js 14. Birmingham (UK): Packt Publishing; 2020.
- Antonio Pierro G, Tonelli R. PASO: A Web-Based Parser for Solidity Language Analysis. 2020 IEEE International Workshop on Blockchain Oriented Software Engineering (IWBOSE). 2020:16-21. doi:10.1109/iwbose50093.2020.9050263
- Boi B, Esposito C, Lee S. Smart Contract Vulnerability Detection: The Role of Large Language Model (LLM). ACM SIGAPP Applied Computing Review. 2024;24(2):19-29. doi:10.1145/3687251.3687253
- Grech N, Kong M, Jurisevic A, Brent L, Scholz B, Smaragdakis Y. MadMax. Communications of the ACM. 2020;63(10):87-95. doi:10.1145/3416262
- Rameder H, di Angelo M, Salzer G. Review of Automated Vulnerability Analysis of Smart Contracts on Ethereum. Frontiers in Blockchain. 2022;5. doi:10.3389/fbloc.2022.814977
- Sharma N, Sharma S. A survey of Mythril, a smart contract security analysis tool for EVM bytecode. Indian J Nat Sci. 2022;13(75):51003–51010.
- Badruddoja S, Dantu R, He Y, Upadhayay K, Thompson M. Making Smart Contracts Smarter. 2021 IEEE International Conference on Blockchain and Cryptocurrency (ICBC). 2021:1-3. doi:10.1109/icbc51069.2021.9461148
- He Y, Fan J, Wu H. A Systematic Review and Performance Evaluation of Open-Source Tools for Smart Contract Vulnerability Detection. Computers, Materials & Continua. 2024;80(1):995-1032. doi:10.32604/cmc.2024.052887
- Mitropoulos C, Kechagia M, Maschas C, Ioannidis S, Sarro F, Mitropoulos D. Broken Agreement: The Evolution of Solidity Error Handling. Proceedings of the 18th ACM/IEEE International Symposium on Empirical Software Engineering and Measurement. 2024:257-268. doi:10.1145/3674805.3686686
- Zhou H, Milani Fard A, Makanju A. The State of Ethereum Smart Contracts Security: Vulnerabilities, Countermeasures, and Tool Support. Journal of Cybersecurity and Privacy. 2022;2(2):358-378. doi:10.3390/jcp2020019
- Huang R, Shen Q, Wang Y, Wu Y, Wu Z, Luo X, et al. ReenRepair: Automatic and semantic equivalent repair of reentrancy in smart contracts. Journal of Systems and Software. 2024;216:112107. doi:10.1016/j.jss.2024.112107