Research Article

Automated Source Code Vulnerability Assessment in Solidity Contracts via Abstract Interpretation and SMT Solving

52 reads
SciMatic J Cybersec Digit Forensics, 2026, 1 (1), 70-76, doi: , ISSN

Abstract

Smart contracts deployed on the Ethereum Virtual Machine (EVM) govern high-value decentralized finance (DeFi) protocols, rendering them prime targets for malicious exploitation. Despite the proliferation of static analysis tools, existing techniques frequently suffer from high false-positive rates or computational intractability when analyzing complex inter-procedural data flows and arithmetic edge cases. In this paper, we introduce a hybrid verification framework that synergizes abstract interpretation with Satisfiability Modulo Theories (SMT) solving to enable scalable and precise vulnerability detection in Solidity source code. Our approach first employs interval and octagon numerical abstract domains to rapidly compute over-approximated variable bounds, prune provably safe execution paths, and isolate suspicious control-flow subgraphs. Subsequently, path conditions and semantic constraints from these reduced subgraphs are translated into first-order logic formulas encoded in the Bitwuzla and Z3 SMT solvers to verify deep semantic invariants, including reentrancy, integer overflow/underflow under varying compiler semantics, and unhandled external call exceptions. We evaluated our prototype on a benchmark suite of 4,250 verified smart contracts alongside historical exploit datasets. The empirical results demonstrate that our dual-phase method achieves a 94.2% detection precision with an 88.6% recall rate, reducing false-positive rates by 41.3% compared to baseline static analyzers while maintaining an average verification latency of under 4.8 seconds per contract. These findings highlight the viability of combining fast abstract domain approximations with constraint solving for automated security auditing in high-assurance blockchain environments.

Keywords solidity Smart Contract Security Abstract Interpretation SMT Solving Static Analysis
Authors 2

The team behind this paper

2 authors, 2 institutions.

This paper University of Ghana — Ghana University of Ghana 1 author Pontificia Universidad Católica de Chile — Chile Pontificia Universidad … 1 author Prof. Kwesi Mensah — corresponding author KM Prof. Kwesi Mensah ✉ Dr. Sofia Morales-Vega SM Dr. Sofia Morales-Vega

Readership

52 reads over 2 months.

#2 most read in this journal this month
September 2026 October 2026

Blockchain Confirmation

Loading...
If you want to upload this article to SciMatic Hybrid Blockchain, install MetaMask extension to your web browser, create a wallet and buy SCI coins at SciMatic using credit or contact your country coordinator.
One article costs 10 SCI coins to be in the Blockchain. Buy SCI Coins

Bibliographic Information

Prof. Kwesi Mensah, Dr. Sofia Morales-Vega, (2026). Automated Source Code Vulnerability Assessment in Solidity Contracts via Abstract Interpretation and SMT Solving, SciMatic Journal of Cybersecurity and Digital Forensics, 1(1): 70-76
Bibtex Citation
@article{prof._kwesi_mensah2026sjcdf,
author = {Prof. Kwesi Mensah and Dr. Sofia Morales-Vega},
title = {Automated Source Code Vulnerability Assessment in Solidity Contracts via Abstract Interpretation and SMT Solving},
journal = {SciMatic Journal of Cybersecurity and Digital Forensics},
year = {2026},
volume = {1},
number = {1},
pages = {70-76},
doi = {},
url = {https://scimatic.org/show_manuscript/9852}
}
APA Citation
Mensah, P.K., Morales-Vega, D.S., (2026). Automated Source Code Vulnerability Assessment in Solidity Contracts via Abstract Interpretation and SMT Solving. SciMatic Journal of Cybersecurity and Digital Forensics, 1(1), 70-76. https://doi.org/

Author Information

  • To change your profile photo, login to scimatic.org, go to your profile and change the photo.
  • Provide a face photo, and not full body.
  • It is better to remove the background from your photo. Go to Remove Background and then upload to profile
  • If you are unable to login, go to Reset My Password provide your email registered with the article and get new password.
  • In case of any other problem, contact your editor directly or write to us at info @ scimatic.org