Pith. sign in

REVIEW 7 cited by

Exploring Vulnerabilities and Concerns in Solana Smart Contracts

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2504.07419 v1 pith:B2XUAPUS submitted 2025-04-10 cs.CR

classification cs.CR
keywords securitysolanasmartanalysiscontractstoolssomevulnerabilities
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

The Solana blockchain was created by Anatoly Yakovenko of Solana Labs and was introduced in 2017, employing a novel transaction verification method. However, at the same time, the innovation process introduced some new security issues. The frequent security incidents in smart contracts have not only caused enormous economic losses, but also undermined the credit system based on the blockchain. The security and reliability of smart contracts have become a new focus of research both domestically and abroad. This paper studies the current status of security analysis of Solana by researching Solana smart contract security analysis tools. This paper systematically sorts out the vulnerabilities existing in Solana smart contracts and gives examples of some vulnerabilities, summarizes the principles of security analysis tools, and comprehensively summarizes and details the security analysis tools in Solana smart contracts. The data of Solana smart contract security analysis tools are collected and compared with Ethereum, and the differences are analyzed and some tools are selected for practical testing.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 7 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. A Systematic Classification of Vulnerabilities in MoveEVM Smart Contracts (MWC)

    cs.CR 2025-05 reject novelty 5.0 of 10

    The paper introduces the MoveEVM Weakness Classification (MWC), a 37-code, six-frame taxonomy for Move-EVM hybrid smart contract vulnerabilities, but its empirical validation and internal consistency are lacking.

  2. From Viral to Void: Multi-Dimensional Behavioral and Contractual Analysis for Rug Pull Identification

    cs.CR 2026-08 reject novelty 4.0 of 10

    An MLP with SMOTE and Focal Loss is claimed to detect rug pull tokens with 0.927 accuracy, but the ground truth labels are partly randomly generated.

  3. Fingerprint-Driven Automation: Coupling Reconnaissance with POC Verification

    cs.CR 2026-07 conditional novelty 4.0 of 10

    Deepscan couples web reconnaissance output to vulnerability-verification PoC execution through a fingerprint-matching pipeline and is tested on CTF and Vulhub environments.

  4. Ethereum NFT Smart Contracts: Knowledge-Guided Vulnerability Detection with LLM and Code Slicing

    cs.CR 2026-07 conditional novelty 4.0 of 10

    Code slicing plus a knowledge base raises the LLM's positive-label rate from 73.8% to 97.1% on 450 NFT contracts, an effect not validated against ground truth.

  5. DSA Nonce Vulnerabilities: An Interactive Analysis

    cs.CR 2026-07 conditional novelty 4.0 of 10

    A new interactive Tkinter/PyCryptodome/SageMath tool visualises DSA signing, verification, and nonce-reuse, linear-nonce, and HNP/LLL key-recovery attacks, passing its own functional and performance tests.

  6. An Intelligent-Cloud Edge Multimodal Interaction System for Robots

    cs.RO 2026-07 conditional novelty 4.0 of 10

    A cloud-edge robot system combined a CBAM/DIoU-enhanced YOLO11n gesture detector with LLM/VLM agents, reporting 95–98.9% precision and 82–95% task success on small, validation-based evaluations.

  7. Immutable Digital Recognition via Blockchain

    cs.CR 2025-08 reject novelty 3.0 of 10

    A hybrid blockchain badge system with centralized certification and decentralized issuance is described, but remains a conceptual design with no implementation or validation.

Pith tools