arXiv · 2608.13191
Smart Contract Invariants Protect Against Cybercriminals
Abstract
Blockchains are among the most adversarial environments in computing. Billions are stolen by cybercriminals who exploit vulnerabilities. This is an open problem and no concept or technique has proven to really make a difference. In this paper, we claim that the classical notion of program invariant is perhaps the most powerful solution to the problem. We devise anoriginal experimental protocol to 1) study how invariants would have protected against past real-world attacks and 2) whether state-of-the-art automated tools can find them. The experimental toolchain is sophisticated. It is based on INVARIANTEVAL, a benchmark of 28 real Ethereum exploits, each paired with a human-authored invariant that blocks the attack. We validate every invariant with PONDEREPLAY, a replay framework that re-executes transactions in order to prove the correctness and soundness of smart contract invariants. We demonstrate that smart contract invariants block all the cybercriminal attacks in INVARIANTEVAL, fully validated by replaying 108,637 historical transactions. Our large-scale experiments clearly demonstrate that smart contract invariants protect against cybercriminals.
Explore related subjects
Keep this discovery
Sofia Bobadilla, Humaira Afrin, Angela Novelli, Martin Monperrus. 2026-08-13. Smart Contract Invariants Protect Against Cybercriminals. https://arxiv.org/abs/2608.13191
Cite the original work for its findings. Save a collection to share your selection of sources.