RPCSpecter: Detecting Blockchain RPC Bugs through a Specification-Driven, Constraint-Aware Fuzzing Approach
Y H Xiao, Yuhong Nan, Zhijie Zhong, Mingxi Ye, Zibin Zheng · Proceedings of the ACM on software engineering. · 2026
Blockchain Remote Procedure Calls (RPCs) serve as the primary interface for interaction between decentralized applications and blockchain networks. Despite their critical role, existing RPC implementations are prone to bugs that are often challenging to detect using traditional testing methods. In this paper, we introduce RPCSpecter, an automated framework for constraint-aware fuzz testing of blockchain RPC implementations. The core of RPCSpecter is a three-stage process: (1) Constraint Extraction, where implicit semantic dependencies from the documented RPC specifications are parsed and converted into executable constraints, (2) Constraint-Guided Mutation, which generates diverse and semantically valid test inputs based on these constraints, and (3) Bidirectional Assertion, which validates both valid and invalid RPC responses through dynamic checks and self-learning mechanisms. We evaluate RPCSpecter on both Ethereum and Solana, two predominant platforms in the Blockchain ecosystem, covering 6 clients, including Geth, Besu and Agave. The results show that RPCSpecter uncovers a total of 26 previously unknown bugs, including critical errors that are undetectable by existing fuzzers or manual testing, as well as multiple silent semantic inconsistencies. In particular, 4 of them have been acknowledged, and one of the bugs affecting three major Ethereum clients is confirmed as a vulnerability, with a $3,000 bounty award. Additionally, we demonstrate how RPCSpecter's constraint-driven approach significantly improves the efficiency and effectiveness of fuzz testing by systematically guiding mutation to explore boundary conditions and rare edge cases. Our research provides a more robust, scalable, and automated solution for enhancing the reliability and security of blockchain RPC implementations.