Investigating Technical Debt & Post-Deployment Evolution in Ethereum Smart Contracts: A Double-Edged Sword

Amir Mohammad Ebrahimi · QSpace (Queen's University Library) · 2026

Blockchain technology facilitates the creation of decentralized, transparent, and tamper-resistant systems. Ethereum’s immutable smart contracts underpin this trust but severely constrain post-deployment maintenance. This rigidity makes it difficult to address internal quality issues, including both unintentional bugs and deliberate compromises known as Technical Debt (TD). In this immutable context, TD poses unique risks as retroactive fixes are costly or infeasible. This thesis addresses this challenge through three interconnected studies. First, we conduct a large-scale empirical analysis of Self-Admitted Technical Debt (SATD) in over 5.7 million verified smart contracts. Although only 1.5% of contracts contain SATD, they are prevalent in high-value applications handling significant transactions, suggesting an outsized impact on the ecosystem. Crucially, 93.5% are clones, indicating systematic propagation. We develop a domain-specific taxonomy to categorize SATD, highlighting its practical relevance and systemic roots in Ethereum's environment. Second, we analyze the architectural response to immutability: proxy contracts. We hypothesize these are widespread and conduct a large-scale study of over 50 million contracts. Our analysis reveals over 14% employ proxy patterns. We categorize them into Forwarder Proxy Contracts (67.8%), which delegate calls to a fixed logic contract for modularity and cost savings, and Upgradeable Proxy Contracts (32.2%), which enable post-deployment contract evolution. This significant use of UPCs demonstrates a growing reliance on upgradeable architectures. Third, we focus on the heightened risks of UPCs, which introduce implementation complexity and centralization hazards. To address the limitations of existing detection methods, we introduce UPC Sentinel, a robust hybrid static-dynamic analysis tool that operates directly on bytecode. It accurately distinguishes UPCs from FPCs and classifies them into specific implementation variants. Our evaluation shows UPC Sentinel significantly outperforms state-of-the-art source-level detectors, enabling the reconstruction of version histories critical for assessing long-term maintainability. Collectively, this work provides a holistic empirical and technical framework for understanding how Ethereum developers manage the tension between immutability and evolution. Our findings, implications, datasets, and methods empower developers, auditors, and researchers to reason more effectively about smart contract maintainability and evolution, laying a foundation for a more robust and sustainable Ethereum ecosystem.

Read the paper · More papers on PaperTik