August 2026Unreviewed
When Verified Source Becomes Attack Input: Defending Smart Contracts Against LLM-Based Vulnerability Scanning
Mingyuan Huang, Zimo Ji, Yifan Mo, Shuai Wang
Abstract
Smart contracts are financial programs deployed on blockchains to manage digital assets. To build trust with users and investors, smart contract projects typically publish their source code on blockchain explorers and verify it against the deployed bytecode, making the on-chain program accessible through a human-readable implementation. However, LLM agents are changing the threat model of this disclosure mechanism. By leveraging publicly disclosed source code, recent agent workflows make it incr
Categories
Cite
@misc{huang2026whena,
title = {{When Verified Source Becomes Attack Input: Defending Smart Contracts Against LLM-Based Vulnerability Scanning}},
author = {Mingyuan Huang and Zimo Ji and Yifan Mo and Shuai Wang},
year = {2026},
month = aug,
eprint = {2608.28400},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2608.28400}
}