Skip to content
Search
paperAugust 2026Unreviewed

When Verified Source Becomes Attack Input: Defending Smart Contracts Against LLM-Based Vulnerability Scanning

Mingyuan Huang, Zimo Ji, Yifan Mo, Shuai Wang

Abstract

Smart contracts are financial programs deployed on blockchains to manage digital assets. To build trust with users and investors, smart contract projects typically publish their source code on blockchain explorers and verify it against the deployed bytecode, making the on-chain program accessible through a human-readable implementation. However, LLM agents are changing the threat model of this disclosure mechanism. By leveraging publicly disclosed source code, recent agent workflows make it incr

Categories

Cite

@misc{huang2026whena,
  title = {{When Verified Source Becomes Attack Input: Defending Smart Contracts Against LLM-Based Vulnerability Scanning}},
  author = {Mingyuan Huang and Zimo Ji and Yifan Mo and Shuai Wang},
  year = {2026},
  month = aug,
  eprint = {2608.28400},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2608.28400}
}