Loading player…

Detecting DoS vulnerabilities caused by gas limits with fuzzing by Sebastian Banescu

DevconYouTube

Fri, Oct 2, 2020, 12:00 AM

During our audits at Quantstamp, we often find functions written in Solidity which are prone to hit out of gas errors because they contain loops over a user defined/influenced value. However, these functions do not run out of gas all the time. It takes a certain input value or a certain contract state to run out of gas. The big question is: how can we identify that state/value? This presentation describes an approach to answering this question by using a smart contract fuzzing approach based on machine learning.