SoftSec-KAIST/Smartian
49.0
Weak · 17 September 2026
4.9k
lines of production code
F#
with Solidity
1
measurement over time
What this system is
Smartian is a grey-box fuzzer for Ethereum smart contracts that combines static and dynamic data-flow analysis with concolic testing to detect security vulnerabilities. It leverages the B2R2 binary analysis framework and Nethermind client to perform context-sensitive abstract interpretation on EVM bytecode, guiding the generation of test cases through def-use chain tracking and path constraint solving. The system supports hybrid fuzzing strategies, integrating random mutations with concolic execution to efficiently explore code paths and identify specific bug patterns such as reentrancy and ether leaks.
Features
Add example contracts and ABI definitions for security analysis
The examples directory now includes a comprehensive set of Solidity contract Application Binary Interfaces (ABI) and bytecode (\.bin\) files, along with a documentation file (\NOTE.md\) that maps specific examples to expected security alarms. These artifacts provide the necessary interface definitions and compiled code for various contract patterns (such as AF, AW, BD, CH, FE, IB, ME, MS, RE, SC, TO, and constructor variants), enabling users to test and validate security analysis tools against these known scenarios.
examples · high confidence
Initial release of Smartian, a grey-box fuzzer for Ethereum smart contracts
This change introduces the Smartian project, a grey-box fuzzer for Ethereum smart contracts that leverages static and dynamic data-flow analyses to enhance fuzzing effectiveness. The repository includes the main F\# application, a solution file for Visual Studio, and a Makefile for building the project. It integrates the Nethermind Ethereum client and the B2R2 binary analysis framework as submodules to support EVM bytecode analysis. The release also provides example contracts and scripts for testing, along with documentation on installation, usage, and citation.
(repo-wide) · high confidence
Introduce Smartian fuzzing agent with core utilities and entry point
This change adds the initial Smartian fuzzing module, providing the main entry point (src/Main/Main.fs) that supports 'fuzz' and 'replay' modes, along with core F\# utilities for address handling, byte manipulation, and configuration (src/Core). It also introduces Solidity smart contracts (src/Agent) used by the agent: AttackerContract for redirecting calls and SFuzzContract (ReentrancyAttacker) for testing reentrancy vulnerabilities.
src/Agent, src/Core, src/Main · high confidence
Introduce Smartian fuzzing engine with concolic and random strategies
Adds the core Smartian fuzzing module (\src/Fuzz\), which implements a hybrid fuzzing loop combining grey-box concolic testing and random fuzzing. The engine initializes seeds from contract ABIs (optionally using DFA analysis), manages resource allocation between strategies based on efficiency, and applies transaction-level and argument-level mutations to explore code paths. It tracks test cases and specific bug types (such as reentrancy, ether leaks, and assertion failures), saving findings to output directories, and supports early termination when all specified target bugs are found.
src/Fuzz · high confidence
Introduce Smartian fuzzing engine with grey-box concolic testing and bug oracles
Smartian now includes a main fuzzing module that performs grey-box concolic testing on Ethereum smart contracts. The tool introduces a new CLI with options to configure static and dynamic data-flow analysis (SDFA/DDFA), detect optional bugs, and utilize external bug oracles. It supports deploying target contracts with initial ether and allows users to specify target bugs for focused detection. The engine integrates with Nethermind for EVM execution and tracks coverage, def-use chains, and specific bug conditions during fuzzing.
Smartian · high confidence
Introduce grey-box concolic fuzzing module for Smartian
Added the core components of the Smartian grey-box concolic fuzzing engine, including branch trace collection, path constraint solving, and seed generation. The new files in src/GreyConcolic implement interval-based path constraints, linear equation and monotonicity solvers, and a main execution loop that evaluates efficiency and spawns new test cases based on branch distance and constraint satisfaction.
src/GreyConcolic · high confidence
Introduce static analysis module for EVM bytecode
A new static analysis module has been added to EVMAnalysis that performs context- and flow-sensitive abstract interpretation on EVM bytecode. This module tracks def-use chains between functions, identifies storage variable usage and definition (including handling of packed variables), and detects specific security patterns such as 'onlyOwner' checks by analyzing sender taint. It also supports generating candidate transaction sequences based on these def-use relationships to guide fuzzing or testing efforts.
EVMAnalysis, EVMAnalysis/src · high confidence
Behavioural changes
B2R2 build artifacts removed from repository
The EVMAnalysis/B2R2-build directory no longer contains pre-built B2R2 binary executables, dependency resolution files (deps.json), or XML documentation (xml). This change removes the locally committed build outputs for B2R2 version 0.4.0, aligning with the shift to importing B2R2 as publishable binary executables rather than distributing raw build artifacts.
EVMAnalysis/B2R2-build · high confidence
Dependencies
Add EVM analysis and Smartian fuzzing modules targeting .NET 8.0
Two new .NET 8.0 projects are introduced: EVMAnalysis, which provides static analysis capabilities for EVM bytecode using the internal B2R2 library and FSharp.Data, and Smartian, a fuzzing tool that integrates with Nethermind components (Dirichlet, EVM, Core, Abi) and utilizes Argu and MathNet.Numerics alongside FSharp.Data.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 49.
Lenses
- Code Health 92
- Architecture 100
- Maturity 44
- Readiness 26
- Security 100
Changes since last survey
- 23 commits — 15 feature/other, 8 fixes
By area
- (root) — 8 commits
- EVMAnalysis/src — 6 commits
- src/Fuzz — 3 commits
- EVMAnalysis/B2R2-build — 2 commits
- src/GreyConcolic — 2 commits
- examples/abi — 1 commit
- examples/replay.sh — 1 commit
Notable commits
- fix: Add an option to terminate early when target bugs are found
- fix: Extend and fix bug oracles
- fix: Fix B2R2 to use internal repository
- fix: Fix code coverage measurement and report
- fix: Fix log messages in seed initialization
- fix: Fix the interface of bug specification and reporting
- fix: Fix the logic for seed initialization
- fix: Use net8.0 and fix build issues
- change: Add Nethermind as submodule
- change: Add README
- change: Add an option to deploy target contract to have initial ether
- change: Add code to print the list of def-use chains (function pairs)
- change: Add example contracts and scripts to test them
- change: Add license
- change: Add main fuzzing module of Smartian
- change: Add static analysis module for EVM bytecode
- change: Import B2R2 as publishable binary executables
- change: Improve the precision of def-use analysis on EVM bytecode
- change: Make --nodfa mode run without analyzing bytecode
- change: Make example testing scripts more friendly to Linux
- …and 3 more
Architecture
- 0 containers · 2 bounded contexts · 1 dependency edges (baseline)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
SoftSec-KAIST/Smartian was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 17 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit eca1ed1d60c88ec5402055a05b59174b7288264c — the exact code this score is about.
- Scored under rubric-2026.09.13 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-d1ef6c0bd534.