SCAR: Mining and Structuring Smart Contract Security Audit Reports
This program is tentative and subject to change.
Smart contract security audit reports contain rich information about vulnerabilities and code quality issues in Web3 projects. However, these reports are scattered across different sources and formats, making large-scale analysis difficult. We present SCAR (Smart Contract Audit Repository), an open-source dataset and tool that automatically aggregates these audit reports. SCAR crawls reports from leading security firms (e.g., OpenZeppelin) and community contests (e.g., Code4rena), parses them into a structured JSON schema, and offers a queryable API for accessing the data. Its pipeline includes a crawler, a text-mining module to standardize findings (e.g., vulnerability types, severity, code references), and a web API for retrieving insights. With hundreds of audits covering thousands of issues, SCAR enables empirical studies of smart contract vulnerabilities at scale.
This program is tentative and subject to change.
Tue 7 JulDisplayed time zone: Eastern Time (US & Canada) change
14:00 - 15:10 | |||
14:00 10mTalk | SCAR: Mining and Structuring Smart Contract Security Audit Reports Tool Demonstrations Ilham Qasse Reykjavik University, Po-Yu Tseng National Taiwan University, Mohammad Hamdaqa Polytechnique Montreal, Gísli Hjálmtýsson Reykjavik University | ||
14:10 20mTalk | Verifying Smart Contract Security Against Re-entrancy Attacks through Relational Value Analysis Research Papers | ||
14:30 20mTalk | SmartCoder-R1: Towards Secure and Explainable Smart Contract Generation with Security-Aware Group Relative Policy Optimization Research Papers Lei Yu Institute of Software, Chinese Academy of Sciences, University of Chinese Academy of Sciences, China, Jingyuan Zhang Institute of Software, Chinese Academy of Sciences, University of Chinese Academy of Sciences, China, Xin Wang Institute of Software, Chinese Academy of Sciences, University of Chinese Academy of Sciences, Li Yang Institute of Software, Chinese Academy of Sciences, Fengjun Zhang Institute of Software, Chinese Academy of Sciences, China, Jiajia Ma Institute of Software, Chinese Academy of Sciences, China | ||
14:50 20mTalk | V2E: Validating Smart Contract Vulnerabilities through Profit-driven Exploit Generation and Execution Research Papers Jingwen Zhang School of Software Engineering, Sun Yat sen University, Yuhong Nan Sun Yat-sen University, Kaiwen Ning Sun Yat-sen University, Mingxi Ye Sun Yat-sen University, Wei Li School of Software Engineering, Sun Yat sen University, Yuming Xiao School of Software Engineering, Sun Yat sen University, Yuming Feng Peng Cheng Laboratory, Weizhe Zhang Harbin Institute of Technology, Zibin Zheng Sun Yat-sen University | ||