CrossGuard : Runtime‐Adaptive LLM Fuzzing for Cross‐Contract Vulnerabilities Detection

Ghazi Mergani Ahmead Ali, Hongsong Chen, Zhongru Wang, Chunlai Du · Concurrency and Computation Practice and Experience · 2025

ABSTRACT Smart contract transactions are increasingly interspersed with cross‐contract calls, creating intricate vulnerabilities that current tools frequently neglect. Cross‐contract vulnerabilities, stemming from interactions among many contracts, are notably difficult to identify, as existing methodologies are restricted to the analysis of only two contracts simultaneously. The growing number of transaction sequences and the larger area to search due to multiple contracts working together make it very hard to find these vulnerabilities. Traditional fuzzing methods are good at finding simple errors within a single contract, but they struggle to detect problems that come from complex interactions between multiple contracts, such as how they call each other and depend on each other's states. This work presents CrossGuard, a fuzz testing‐based approach aimed at effectively identifying cross‐contract vulnerabilities by addressing the shortcomings of conventional tools. Instead of using random transaction sequences like earlier fuzzers, CrossGuard uses smart fuzzing that learns from large language models (LLMs) to better explore important paths. We evaluate CrossGuard against top tools like CrossFuzz and xFuzz using 500 cross‐contracts that have vulnerabilities such as reentrancy, integer overflow, and block dependency. CrossGuard consistently achieves higher coverage and excels at detecting reentrancy and block dependency vulnerabilities. However, its performance on integer overflow detection is currently lower than that of CrossFuzz; this contrast underscores both the potential and the current limitations of LLM‐guided fuzzing. Natural language reasoning is highly effective for path‐sensitive, stateful vulnerabilities, but less precise for numeric edge cases where mutational fuzzing remains strong.

Read the paper · More papers on PaperTik