{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T16:31:53Z","timestamp":1783009913544,"version":"3.54.5"},"reference-count":19,"publisher":"Association for Computing Machinery (ACM)","issue":"10","license":[{"start":{"date-parts":[[2020,9,23]],"date-time":"2020-09-23T00:00:00Z","timestamp":1600819200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100011199","name":"European Research Council","doi-asserted-by":"publisher","award":["307334"],"award-info":[{"award-number":["307334"]}],"id":[{"id":"10.13039\/100011199","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Reach High","award":["254\/15\/10"],"award-info":[{"award-number":["254\/15\/10"]}]},{"DOI":"10.13039\/501100000923","name":"Australian Research Council","doi-asserted-by":"crossref","award":["DP180104030"],"award-info":[{"award-number":["DP180104030"]}],"id":[{"id":"10.13039\/501100000923","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Commun. ACM"],"published-print":{"date-parts":[[2020,9,23]]},"abstract":"<jats:p>Ethereum is a distributed blockchain platform, serving as an ecosystem for smart contracts: full-fledged intercommunicating programs that capture the transaction logic of an account. A gas limit caps the execution of an Ethereum smart contract: instructions, when executed, consume gas, and the execution proceeds as long as gas is available.<\/jats:p>\n          <jats:p>Gas-focused vulnerabilities permit an attacker to force key contract functionality to run out of gas---effectively performing a permanent denial-of-service attack on the contract. Such vulnerabilities are among the hardest for programmers to protect against, as out-of-gas behavior may be uncommon in nonattack scenarios and reasoning about these vulnerabilities is nontrivial.<\/jats:p>\n          <jats:p>In this paper, we identify gas-focused vulnerabilities and present MadMax: a static program analysis technique that automatically detects gas-focused vulnerabilities with very high confidence. MadMax combines a smart contract decompiler and semantic queries in Datalog. Our approach captures high-level program modeling concepts (such as \"dynamic data structure storage\" and \"safely resumable loops\") and delivers high precision and scalability. MadMax analyzes the entirety of smart contracts in the Ethereum blockchain in just 10 hours and flags vulnerabilities in contracts with a monetary value in billions of dollars. Manual inspection of a sample of flagged contracts shows that 81% of the sampled warnings do indeed lead to vulnerabilities.<\/jats:p>","DOI":"10.1145\/3416262","type":"journal-article","created":{"date-parts":[[2020,9,23]],"date-time":"2020-09-23T14:26:49Z","timestamp":1600871209000},"page":"87-95","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":45,"title":["MadMax"],"prefix":"10.1145","volume":"63","author":[{"given":"Neville","family":"Grech","sequence":"first","affiliation":[{"name":"University of Athens, Greece"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Michael","family":"Kong","sequence":"additional","affiliation":[{"name":"The University of Sydney, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Anton","family":"Jurisevic","sequence":"additional","affiliation":[{"name":"The University of Sydney, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Lexi","family":"Brent","sequence":"additional","affiliation":[{"name":"The University of Sydney, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Bernhard","family":"Scholz","sequence":"additional","affiliation":[{"name":"The University of Sydney, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yannis","family":"Smaragdakis","sequence":"additional","affiliation":[{"name":"University of Athens, Greece"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2020,9,23]]},"reference":[{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/1640089.1640108"},{"key":"e_1_2_1_3_1","volume-title":"CoRR, 2018","author":"Brent L.","year":"1802","unstructured":"Brent , L. , Jurisevic , A. , Kong , M. , Liu , E. , Gauthier , F. , Gramoli , V. , Holz , R. , Scholz , B. Vandal : A scalable security analysis framework for smart contracts . CoRR, 2018 . abs\/ 1802 .08660 Brent, L., Jurisevic, A., Kong, M., Liu, E., Gauthier, F., Gramoli, V., Holz, R., Scholz, B. Vandal: A scalable security analysis framework for smart contracts. CoRR, 2018. abs\/1802.08660"},{"key":"e_1_2_1_4_1","volume-title":"A next-generation smart contract and decentralized application platform","author":"Buterin V.","year":"2013","unstructured":"Buterin , V. A next-generation smart contract and decentralized application platform , 2013 . https:\/\/github.com\/ethereum\/wiki\/wiki\/White-Paper Buterin, V. A next-generation smart contract and decentralized application platform, 2013. https:\/\/github.com\/ethereum\/wiki\/wiki\/White-Paper"},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/512529.512558"},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2019.00120"},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/3276486"},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4612-0539-5"},{"key":"e_1_2_1_9_1","volume-title":"Programming Language Design and Implementation","author":"Naik M.","year":"2011","unstructured":"Naik , M. Chord : A versatile platform for program analysis . In Programming Language Design and Implementation , 2011 . Tutorial. Naik, M. Chord: A versatile platform for program analysis. In Programming Language Design and Implementation, 2011. Tutorial."},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2009.5070538"},{"key":"e_1_2_1_11_1","volume-title":"Bitcoin: A peer-to-peer electronic cash system","author":"Nakamoto S.","year":"2009","unstructured":"Nakamoto , S. Bitcoin: A peer-to-peer electronic cash system , 2009 . https:\/\/www.bitcoin.org\/bitcoin.pdf Nakamoto, S. Bitcoin: A peer-to-peer electronic cash system, 2009. https:\/\/www.bitcoin.org\/bitcoin.pdf"},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/989393.989421"},{"key":"e_1_2_1_14_1","first-page":"2","volume":"1","author":"Smaragdakis Y.","year":"2015","unstructured":"Smaragdakis , Y. , Balatsouras , G. Pointer analysis. Found. Trends Program. Lang. 1 , 2 ( 2015 ), 1--69. Smaragdakis, Y., Balatsouras, G. Pointer analysis. Found. Trends Program. Lang. 1, 2 (2015), 1--69.","journal-title":"Found. Trends Program. Lang."},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/568547.568561"},{"key":"e_1_2_1_16_1","unstructured":"Various. GovernMental page. http:\/\/governmental.github.io\/GovernMental\/.  Various. GovernMental page. http:\/\/governmental.github.io\/GovernMental\/."},{"key":"e_1_2_1_17_1","unstructured":"Various. Safety-ethereum wiki. https:\/\/github.com\/ethereum\/wiki\/wiki\/Safety. Accessed: 2018-04-15.  Various. Safety-ethereum wiki. https:\/\/github.com\/ethereum\/wiki\/wiki\/Safety. Accessed: 2018-04-15."},{"key":"e_1_2_1_18_1","volume-title":"The solidity contract-oriented programming language","author":"Various","year":"2018","unstructured":"Various . GitHub-ethereum\/solidity : The solidity contract-oriented programming language , 2018 . https:\/\/github.com\/ethereum\/solidity Various. GitHub-ethereum\/solidity: The solidity contract-oriented programming language, 2018. https:\/\/github.com\/ethereum\/solidity"},{"key":"e_1_2_1_19_1","volume-title":"Vandal--A static analysis framework for ethereum bytecode","author":"Various","year":"2018","unstructured":"Various . Vandal--A static analysis framework for ethereum bytecode , 2018 . https:\/\/github.com\/usyd-blockchain\/vandal\/. Various. Vandal--A static analysis framework for ethereum bytecode, 2018. https:\/\/github.com\/usyd-blockchain\/vandal\/."},{"key":"e_1_2_1_20_1","volume-title":"Ethereum griefing wallets: Send w\/throw is dangerous","author":"Vessenes P.","year":"2016","unstructured":"Vessenes , P. Ethereum griefing wallets: Send w\/throw is dangerous , 2016 . http:\/\/vessenes.com\/ethereum-griefing-wallets-send-w-throw-considered-harmful Vessenes, P. Ethereum griefing wallets: Send w\/throw is dangerous, 2016. http:\/\/vessenes.com\/ethereum-griefing-wallets-send-w-throw-considered-harmful"},{"key":"e_1_2_1_21_1","volume-title":"Ethereum: A secure decentralised generalised transaction ledger","author":"Wood G.","year":"2014","unstructured":"Wood , G. Ethereum: A secure decentralised generalised transaction ledger , 2014 . http:\/\/gavwood.com\/Paper.pdf Wood, G. Ethereum: A secure decentralised generalised transaction ledger, 2014. http:\/\/gavwood.com\/Paper.pdf"}],"container-title":["Communications of the ACM"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3416262","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3416262","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T22:01:21Z","timestamp":1750197681000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3416262"}},"subtitle":["analyzing the out-of-gas world of smart contracts"],"short-title":[],"issued":{"date-parts":[[2020,9,23]]},"references-count":19,"journal-issue":{"issue":"10","published-print":{"date-parts":[[2020,9,23]]}},"alternative-id":["10.1145\/3416262"],"URL":"https:\/\/doi.org\/10.1145\/3416262","relation":{},"ISSN":["0001-0782","1557-7317"],"issn-type":[{"value":"0001-0782","type":"print"},{"value":"1557-7317","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,9,23]]},"assertion":[{"value":"2020-09-23","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}