ExploitGen: automated smart contract vulnerability verification via taxonomy specialized multi-agent detection and proof-of-concept exploit generation
Aysheh Aminnezhad · Espace ÉTS (ETS) · 2026
Smart contracts underpin decentralized finance (DeFi), where software vulnerabilities cause irreversible financial losses. Existing automated auditing approaches face a detection–verification gap: static analyzers and single-agent large language model (LLM) systems exhibit low recall, whereas unverified multi-agent architectures achieve high recall at the cost of prohibitive false-positive rates that overwhelm human auditors and negate the efficiency benefits of automation. This thesis presents ExploitGen, a LangGraph orchestrated multi-agent pipeline that closes this gap by coupling taxonomy-specialized detection with executable verification. Eight detection agents, each scoped to a single OpenSCV category, first maximize recall. Each candidate then passes through a verification sequence: static graph extraction, falsification-first validation, semantic characterization, Structured Chain-of-Thought (SCoT) attack planning, proof-of-concept (PoC) synthesis, and counterfactual confirmation. A vulnerability is confirmed only when its generated Foundry PoC passes on the vulnerable contract and fails on a signature-preserving patched counterpart, establishing exploitability causally rather than by syntactic resemblance. Evaluated on the SB Curated benchmark against 139 ground truth vulnerabilities, ExploitGen verifies 86 counterfactually confirmed exploits at a confirmation yield of 0.741 and an F1-score of 0.675. Against a single-attempt configuration of the same pipeline, unconfirmed candidates fall by 23.1% while confirmed exploits rise from 73 to 86. Against the detection-only paradigm, which uses unscoped parallel detection, unconfirmed findings fall from 342 to 30. A controlled ablation shows that SCoT planning improves reentrancy F1 by 0.200 but degrades access-control performance, establishing that component selection must be adapted to the vulnerability class. The augmented dataset of 139 patched contracts is released to support reproducibility.