System update
On Tuesday, August 18th, between 12-1pm, a planned system update of DiVA will take place. During this time, DiVA will not be available.
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Systematic Testing for Input Validation Vulnerabilities in NFT Smart Contracts: A case study
University West, Department of Engineering Science.
University West, Department of Engineering Science.
2025 (English)Independent thesis Advanced level (degree of Master (One Year)), 10 credits / 15 HE creditsStudent thesis
Abstract [en]

This thesis investigates the presence of input validation vulnerabilities in NFT smart contracts that implement the ERC-721 standard on the Ethereum blockchain. Input validation flaws are among the most common sources of smart contract exploits, yet they remain underexplored in the context of non-fungible tokens (NFTs). To address this gap, a custom automated testing framework was developed and applied to a dataset of 2,247 real-world ERC-721 contracts.

The testing suite systematically evaluated each contract’s response to invalid inputs across eight core ERC-721 methods, resulting in the execution of over 190,000 test cases.The results show that while 99.82% of test cases passed, a notable minority (0.18%) revealed compliance issues.

The analysis identified common failure patterns, such as returning incorrect values insteadof reverting on invalid input and falsely reporting support for the standard. These issues havepotential security implications, including denial-of-service risks and semantic inconsistencies.

The study demonstrates that automated testing of deployed contracts is an effective method for identifying robustness issues related to input validation. Beyond detecting individual flaws, the findings underscore the importance of stress-testing smart contracts with edge-case scenarios to uncover hidden vulnerabilities.

The proposed framework offers a reproducible and scalable approach for smart contract auditing and can be extended to other standards such as ERC-20 and ERC-1155.

Place, publisher, year, edition, pages
2025. , p. 28
Keywords [en]
Blockchain, Ethereum, NFT, Input Validation, Testing
National Category
Computer Systems
Identifiers
URN: urn:nbn:se:hv:diva-24158Local ID: EXD600OAI: oai:DiVA.org:hv-24158DiVA, id: diva2:1994511
Subject / course
Computer engineering
Educational program
Master in Cybersecurity
Supervisors
Examiners
Available from: 2025-09-08 Created: 2025-09-03 Last updated: 2025-09-30Bibliographically approved

Open Access in DiVA

No full text in DiVA

By organisation
Department of Engineering Science
Computer Systems

Search outside of DiVA

GoogleGoogle Scholar

urn-nbn

Altmetric score

urn-nbn
Total: 87 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf