SCBF: Automated detection and patching of smart contract vulnerabilities via Mythril and Open Zeppelin integration

Darvishi, Iman, Esfahani, Alireza and Alsolai, Hadeel (2026) SCBF: Automated detection and patching of smart contract vulnerabilities via Mythril and Open Zeppelin integration. International Journal of Network Security & Its Applications, 18 (3). ISSN 0975-2307

[thumbnail of DarvishiI_SCBF-utomated detection and patching of smart contract vulnerabilities_VoR_PDFA.pdf]
Preview
PDF/A
DarvishiI_SCBF-utomated detection and patching of smart contract vulnerabilities_VoR_PDFA.pdf - Published Version
Available under License Creative Commons Attribution.

Download (986kB) | Preview

Abstract

The Smart Contract Bug Fix (SCBF) framework is an open-source platform for automated detection and remediation of vulnerabilities in Ethereum and decentralised finance smart contracts. SCBF combines symbolic execution through Mythril with OpenZeppelin-based repair strategies to support an end-to-end workflow from vulnerability scanning to patch generation and reporting. The framework organises analysis results using SWC-based classification, applies deterministic patching rules, and exports logs and results through an analytics dashboard. SCBF was evaluated on two public datasets, SmartBugs Curated and Messi-Q. Under the counting scheme adopted in this paper, the framework achieved a fixed rate of 68.5% (170 of 248 Mythril findings) on SmartBugs Curated and a consolidated fix rate of 77.3% (958 of 1,239 findings) on Messi-Q. The results indicate effective handling of several common SWC classes, including tx. origin misuse, arithmetic issues, and re-entrancy related patterns, while also showing lower performance on environment-dependent vulnerabilities. These findings indicate that SCBF supports reproducible and traceable smart contract remediation workflows.

Item Type: Article
Keywords: Automated Patch, Blockchain, Bug Fix, Security, Smart Contracts, Solidity, Symbolic Execution, Vulnerability Remediation
Subjects: Computing > Information security > Cyber security
Computing > Information security
Date Deposited: 15 Sep 2026
Dates:
Date
Publication status
3 May 2026
Accepted
18 May 2026
Published
10 June 2026
Published Online
School, department or research centre: School of Computing and Engineering
Keywords: Automated Patch, Blockchain, Bug Fix, Security, Smart Contracts, Solidity, Symbolic Execution, Vulnerability Remediation
URI: https://repository.uwl.ac.uk/id/eprint/15309

Downloads

Downloads per month over past year

Actions (admin access)

View Item

Menu