{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T16:09:29Z","timestamp":1783008569953,"version":"3.54.5"},"reference-count":42,"publisher":"Association for Computing Machinery (ACM)","issue":"6","funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"crossref","award":["62402001, 62372422, and 62272434"],"award-info":[{"award-number":["62402001, 62372422, and 62272434"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"crossref"}]},{"name":"Anhui Province Natural Science Foundation","award":["2408085MF167"],"award-info":[{"award-number":["2408085MF167"]}]},{"DOI":"10.13039\/501100012226","name":"Fundamental Research Funds for the Central Universities","doi-asserted-by":"crossref","award":["WK2150110024"],"award-info":[{"award-number":["WK2150110024"]}],"id":[{"id":"10.13039\/501100012226","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Softw. Eng. Methodol."],"published-print":{"date-parts":[[2026,6,30]]},"abstract":"<jats:p>WebAssembly (WASM) has emerged as a crucial technology in smart contract development for several blockchain platforms. Unfortunately, since their introduction, WASM smart contracts have been subject to several security incidents caused by contract vulnerabilities, resulting in substantial economic losses. However, existing tools for detecting WASM contract vulnerabilities have accuracy limitations, one of the main reasons being the coarse-grained emulation of the on-chain data APIs. In this article, we introduce WACANA, an analyzer for WASM contracts that accurately detects vulnerabilities through fine-grained emulation of on-chain data APIs. WACANA precisely simulates both the structure of on-chain data tables and their corresponding API functions, and integrates concrete and symbolic execution within a coverage-guided loop to balance accuracy and efficiency. Evaluations on a vulnerability dataset of 2,012 contracts show WACANA outperforming state-of-the-art tools in accuracy. Further validation on 5,602 real-world contracts confirms WACANA\u2019s practical effectiveness.<\/jats:p>","DOI":"10.1145\/3757914","type":"journal-article","created":{"date-parts":[[2025,9,3]],"date-time":"2025-09-03T13:29:55Z","timestamp":1756906195000},"page":"1-22","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["WACANA: A Concolic Analyzer for Detecting On-chain Data Vulnerabilities in WASM Smart Contracts"],"prefix":"10.1145","volume":"35","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-6892-8767","authenticated-orcid":false,"given":"Wansen","family":"Wang","sequence":"first","affiliation":[{"name":"Anhui University, Hefei, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-5358-1943","authenticated-orcid":false,"given":"Caichang","family":"Tu","sequence":"additional","affiliation":[{"name":"University of Science and Technology of China, Hefei, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3788-9643","authenticated-orcid":false,"given":"Zhaoyi","family":"Meng","sequence":"additional","affiliation":[{"name":"Anhui University, Hefei, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2043-2439","authenticated-orcid":false,"given":"Wenchao","family":"Huang","sequence":"additional","affiliation":[{"name":"University of Science and Technology of China, Hefei, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6347-8747","authenticated-orcid":false,"given":"Yan","family":"Xiong","sequence":"additional","affiliation":[{"name":"University of Science and Technology of China, Hefei, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,5,13]]},"reference":[{"key":"e_1_3_2_2_2","unstructured":"Introduction of WebAssembly. 2023. Retrieved from https:\/\/webassembly.org\/"},{"key":"e_1_3_2_3_2","unstructured":"EOSIO Developer Portal. 2021. Retrieved from https:\/\/developers.eos.io\/"},{"key":"e_1_3_2_4_2","unstructured":"NEAR: The Blockchain Built for an Open Web. 2024. Retrieved from https:\/\/near.org\/blockchain"},{"key":"e_1_3_2_5_2","unstructured":"Ethereum Flavored WebAssembly (Ewasm). 2019. Retrieved from https:\/\/github.com\/ewasm\/design"},{"key":"e_1_3_2_6_2","unstructured":"How EOSBET Attacked by aabbccddeefg. 2018. Retrieved from https:\/\/www.reddit.com\/r\/eos\/comments\/9fpcik\/how_eosbet_attacked_by_aabbccddeefg\/?rdt=34529"},{"key":"e_1_3_2_7_2","unstructured":"EOSBet Got Hacked Again; Lost 65000 EOS to Hackers. 2018. Retrieved from https:\/\/latesthackingnews.com\/2018\/10\/19\/eosbet-got-hacked-again-lost-65000-eos-to-hackers\/"},{"key":"e_1_3_2_8_2","unstructured":"EOS vaults.sx Hack. 2021. Retrieved from https:\/\/cmichel.io\/eos-vault-sx-hack\/"},{"key":"e_1_3_2_9_2","unstructured":"SlowMist Hacked Events in EOS Ecosystem. 2023. Retrieved from https:\/\/hacked.slowmist.io\/?c=EOS"},{"key":"e_1_3_2_10_2","unstructured":"Data Persistence in EOSIO. 2021.Retrieved from https:\/\/developers.eos.io\/welcome\/v2.1\/smart-contract-guides\/data-persistence"},{"key":"e_1_3_2_11_2","unstructured":"EOS VM\u2014A Low-Latency High Performance and Extensible WebAssembly Engine. 2019. Retrieved from https:\/\/github.com\/EOSIO\/eos-vm"},{"key":"e_1_3_2_12_2","first-page":"1271","volume-title":"30th USENIX Security Symposium (USENIX Security \u2019 21)","author":"He Ningyu","year":"2021","unstructured":"Ningyu He, Ruiyi Zhang, Haoyu Wang, Lei Wu, Xiapu Luo, Yao Guo, Ting Yu, and Xuxian Jiang. 2021. EOSAFE: Security analysis of EOSIO smart contracts. In 30th USENIX Security Symposium (USENIX Security \u2019 21), 1271\u20131288."},{"key":"e_1_3_2_13_2","doi-asserted-by":"publisher","DOI":"10.1109\/QRS54544.2021.00102"},{"key":"e_1_3_2_14_2","doi-asserted-by":"publisher","DOI":"10.1145\/3533767.3534218"},{"key":"e_1_3_2_15_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2022.3141396"},{"key":"e_1_3_2_16_2","unstructured":"Software Manuals of eosio.cdt v1.8: Database C API. 2022. Retrieved from https:\/\/developers.eos.io\/manuals\/eosio.cdt\/v1.8\/group__database__c__api"},{"key":"e_1_3_2_17_2","first-page":"167","volume-title":"International Symposium on Logic-Based Program Synthesis and Transformation","author":"Vidal Germ\u00e1n","year":"2014","unstructured":"Germ\u00e1n Vidal. 2014. Concolic execution and test case generation in prolog. In International Symposium on Logic-Based Program Synthesis and Transformation. Springer, 167\u2013181."},{"key":"e_1_3_2_18_2","doi-asserted-by":"publisher","DOI":"10.1145\/3383219.3383254"},{"key":"e_1_3_2_19_2","doi-asserted-by":"publisher","DOI":"10.1145\/3377644.3377654"},{"key":"e_1_3_2_20_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2007.41"},{"key":"e_1_3_2_21_2","unstructured":"Software Manuals of eosio.cdt v1.8: ABI Files. 2022. Retrieved from https:\/\/developers.eos.io\/manuals\/eosio.cdt\/latest\/best-practices\/abi\/understanding-abi-files"},{"key":"e_1_3_2_22_2","unstructured":"Software Manuals of eosio.cdt v1.8: Transaction API. 2022. Retrieved from https:\/\/developers.eos.io\/manuals\/eosio.cdt\/v1.8\/group__transaction__c"},{"key":"e_1_3_2_23_2","unstructured":"Dataset of WASAI. 2022. Retrieved from https:\/\/drive.google.com\/file\/d\/1z1rd3o0o6zoYVNcKXpnHWqDLn4EwdcP-\/view?usp=sharing"},{"key":"e_1_3_2_24_2","unstructured":"EOSIO Smart Contract Dataset of WANA. 2021. Retrieved from https:\/\/github.com\/gongbell\/WANA\/tree\/master\/examples\/EOSIO_contracts"},{"key":"e_1_3_2_25_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.ipm.2020.102477"},{"key":"e_1_3_2_26_2","unstructured":"The Source Code of WACANA. 2024. Retrieved from https:\/\/github.com\/secwisf\/WACANA\/tree\/master"},{"key":"e_1_3_2_27_2","unstructured":"The Vulnerability Dataset and the Real-World Dataset of WACANA. 2024. Retrieved from https:\/\/https:\/\/github.com\/secwisf\/WACANA\/tree\/master\/WACANA_dataset"},{"key":"e_1_3_2_28_2","unstructured":"Source Code of WANA a Symbolic Execution Engine for Wasm Bytecode and a Cross-Platform Smart Contract Vulnerability Detector. 2021. Retrieved from https:\/\/github.com\/gongbell\/WANA"},{"key":"e_1_3_2_29_2","unstructured":"Source Code of WASAI the First Concolic Fuzzer in Detecting Vulnerabilities in EOSIO Smart Contracts. 2022. Retrieved from https:\/\/github.com\/WASAIRepo\/WASAI"},{"key":"e_1_3_2_30_2","unstructured":"Ghidra Software Reverse Engineering Framework. 2024. Retrieved from https:\/\/github.com\/NationalSecurityAgency\/ghidra"},{"key":"e_1_3_2_31_2","unstructured":"Cleos a Command Line Tools Used to Interact with the EOSIO. 2024. Retrieved from https:\/\/developers.eos.io\/manuals\/eos\/latest\/cleos\/index"},{"key":"e_1_3_2_32_2","doi-asserted-by":"publisher","DOI":"10.1145\/3182657"},{"key":"e_1_3_2_33_2","doi-asserted-by":"publisher","DOI":"10.1109\/COMPSAC54236.2022.00124"},{"key":"e_1_3_2_34_2","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3563545"},{"key":"e_1_3_2_35_2","unstructured":"Octopus: A Security Analysis Framework for WebAssembly Module and Blockchain Smart Contract. 2020. Retrieved from https:\/\/github.com\/FuzzingLabs\/octopus"},{"key":"e_1_3_2_36_2","unstructured":"Lijin Quan Lei Wu and Haoyu Wang. 2019. EVulHunter: Detecting fake transfer vulnerabilities for EOSIO\u2019s smart contracts at webassembly-level. arXiv:1906.10362. Retrieved from https:\/\/arxiv.org\/abs\/1906.10362"},{"key":"e_1_3_2_37_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2024.24972"},{"key":"e_1_3_2_38_2","doi-asserted-by":"publisher","DOI":"10.1049\/blc2.12029"},{"key":"e_1_3_2_39_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.bcra.2025.100287"},{"key":"e_1_3_2_40_2","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363287"},{"key":"e_1_3_2_41_2","first-page":"217","volume-title":"29th USENIX Security Symposium (USENIX Security \u201920)","author":"Lehmann Daniel","year":"2020","unstructured":"Daniel Lehmann, Johannes Kinder, and Michael Pradel. 2020. Everything old is new again: Binary security of. \\(\\{\\) WebAssembly \\(\\}\\) . In 29th USENIX Security Symposium (USENIX Security \u201920), 217\u2013234."},{"key":"e_1_3_2_42_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00064"},{"key":"e_1_3_2_43_2","doi-asserted-by":"publisher","DOI":"10.1145\/3297858.3304068"}],"container-title":["ACM Transactions on Software Engineering and Methodology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3757914","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,13]],"date-time":"2026-05-13T17:26:20Z","timestamp":1778693180000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3757914"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5,13]]},"references-count":42,"journal-issue":{"issue":"6","published-print":{"date-parts":[[2026,6,30]]}},"alternative-id":["10.1145\/3757914"],"URL":"https:\/\/doi.org\/10.1145\/3757914","relation":{},"ISSN":["1049-331X","1557-7392"],"issn-type":[{"value":"1049-331X","type":"print"},{"value":"1557-7392","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,5,13]]},"assertion":[{"value":"2024-11-21","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-07-29","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-05-13","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}