Ändra sökning
RefereraExporteraLänk till posten
Permanent länk

Direktlänk
Referera
Referensformat
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Annat format
Fler format
Språk
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Annat språk
Fler språk
Utmatningsformat
  • html
  • text
  • asciidoc
  • rtf
Systematic Testing for Input Validation Vulnerabilities in NFT Smart Contracts: A case study
Högskolan Väst, Institutionen för ingenjörsvetenskap.
Högskolan Väst, Institutionen för ingenjörsvetenskap.
2025 (Engelska)Självständigt arbete på avancerad nivå (magisterexamen), 10 poäng / 15 hpStudentuppsats (Examensarbete)
Abstract [en]

This thesis investigates the presence of input validation vulnerabilities in NFT smart contracts that implement the ERC-721 standard on the Ethereum blockchain. Input validation flaws are among the most common sources of smart contract exploits, yet they remain underexplored in the context of non-fungible tokens (NFTs). To address this gap, a custom automated testing framework was developed and applied to a dataset of 2,247 real-world ERC-721 contracts.

The testing suite systematically evaluated each contract’s response to invalid inputs across eight core ERC-721 methods, resulting in the execution of over 190,000 test cases.The results show that while 99.82% of test cases passed, a notable minority (0.18%) revealed compliance issues.

The analysis identified common failure patterns, such as returning incorrect values insteadof reverting on invalid input and falsely reporting support for the standard. These issues havepotential security implications, including denial-of-service risks and semantic inconsistencies.

The study demonstrates that automated testing of deployed contracts is an effective method for identifying robustness issues related to input validation. Beyond detecting individual flaws, the findings underscore the importance of stress-testing smart contracts with edge-case scenarios to uncover hidden vulnerabilities.

The proposed framework offers a reproducible and scalable approach for smart contract auditing and can be extended to other standards such as ERC-20 and ERC-1155.

Ort, förlag, år, upplaga, sidor
2025. , s. 28
Nyckelord [en]
Blockchain, Ethereum, NFT, Input Validation, Testing
Nationell ämneskategori
Datorsystem
Identifikatorer
URN: urn:nbn:se:hv:diva-24158Lokalt ID: EXD600OAI: oai:DiVA.org:hv-24158DiVA, id: diva2:1994511
Ämne / kurs
Datateknik
Utbildningsprogram
Magister i cybersäkerhet 60,0 hp
Handledare
Examinatorer
Tillgänglig från: 2025-09-08 Skapad: 2025-09-03 Senast uppdaterad: 2025-09-30Bibliografiskt granskad

Open Access i DiVA

Fulltext saknas i DiVA

Av organisationen
Institutionen för ingenjörsvetenskap
Datorsystem

Sök vidare utanför DiVA

GoogleGoogle Scholar

urn-nbn

Altmetricpoäng

urn-nbn
Totalt: 89 träffar
RefereraExporteraLänk till posten
Permanent länk

Direktlänk
Referera
Referensformat
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Annat format
Fler format
Språk
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Annat språk
Fler språk
Utmatningsformat
  • html
  • text
  • asciidoc
  • rtf