Dissertation (August 21, 2026): Felipe Mello Fonseca

Student: Felipe Mello Fonseca

Title: Vulnerability Detection in Smart Contracts: A Study Using Automated Tools

Advisors: Diogo Silveira Mendonça and Pedro Henrique Gonzalez

Committee: Diogo Silveira Mendonça (Cefet/RJ), Pedro Henrique Gonzalez (UFRJ), Kele Teixeira Belloze (Cefet/RJ) e José Augusto Miranda Nacif (UFV)

Day/Hours: August 21, 2026 / 8:30 a.m.

Room: https://teams.microsoft.com/meet/290006386263688?p=ICWKLlepYzGWKoe2Ly

Abstract: Blockchain is a technology with applications across multiple domains, including finance, electronic voting, and the Internet of Things. In this context, transactions are frequently mediated by smart contracts — self-executing programs written primarily in Solidity. Because they handle significant cryptocurrency values, these contracts are frequent targets of  attacks, making automated vulnerability detection a relevant technical challenge. This work presents two complementary sets of experiments. In the first, we evaluate the evolution of two widely used static analysis tools Mythril and Slither applied to the SmartBugs Curated dataset under the DASP taxonomy, comparing results against manually validated ground-truth labels. In the second, we assess the performance of Gemini 2.0 Flash on the same vulnerability detection task, comparing it to results previously reported for GPT-4 in the literature. The results show that the latest versions of traditional tools represent concrete progress, particularly in reducing false positives, though limitations remain in specific vulnerability categories. LLMs demonstrated potential as auxiliary mechanisms in preliminary triage, especially given their accessibility, but still require human validation for auditing critical systems. Overall, the experiments reinforce that combining multiple approaches is the most promising path toward increasing the reliability of smart contracts prior to deployment on the blockchain.