Abstract
Decentralized finance (DeFi) and cross-chain interoperability protocols have introduced complex cross-chain smart contract interactions, giving rise to novel security vulnerabilities such as cross-chain race conditions, relay spoofing, and asynchronous state inconsistency. Traditional static analysis and symbolic execution tools struggle with the state explosion problem when analyzing inter-blockchain call graphs, while standalone machine learning models lack formal verification guarantees. In this paper, we present X-ChainGuard, a hybrid vulnerability detection framework that combines Graph Neural Networks (GNNs) with symbolic execution to audit cross-chain smart contracts. X-ChainGuard constructs heterogeneous Cross-Chain Control-Data Flow Graphs (C3-DFGs) that capture inter-contract dependencies and bridge protocol primitives across multiple blockchains. A GNN model pre-filters high-risk call paths and pinpoints suspicious state transitions, significantly pruning the search space. Subsequently, a targeted symbolic execution engine verifies candidate paths, eliminating false positives and generating concrete exploit payloads. We evaluate X-ChainGuard on a curated benchmark dataset of 1,420 cross-chain contract pairs spanning Ethereum, Binance Smart Chain, and Polygon. Experimental results show that X-ChainGuard achieves a detection accuracy of 94.6% and reduces analysis latency by 68.3% compared to baseline symbolic execution techniques, successfully discovering 14 previously unknown vulnerabilities in deployed cross-chain bridge protocols.