CHAINTRIX: A multi-pipeline LLM-augmented framework for automated smart-contract security auditing

📅 2026-05-10
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
Smart contract auditing suffers from high costs, low efficiency, and limitations of existing automated tools—such as high false positive rates or hallucinations from large language models (LLMs). To address these challenges, this work proposes an end-to-end auditing framework grounded in a novel Cross-Contract Interaction Model (CCIM) as its structural backbone. The framework integrates a multi-signal engine with a parallel LLM pipeline and employs a staged false positive reduction mechanism, a structured adjudication engine, and deterministic validation via symbolic execution and fuzzing to verify LLM-generated vulnerability claims. Evaluated on the EVMbench benchmark, the approach achieves a 71.7% recall rate for high-severity vulnerabilities and attains 100% recall across 25 audit tasks, outperforming the strongest baseline by 26 percentage points.
📝 Abstract
Smart-contract exploits have caused billions of USD in cumulative losses, yet audits remain expensive and slow. Automated tools have emerged to close this gap, but each class has a characteristic failure mode. Static analyzers report findings that frequently fail manual triage at high rates, while large language models (LLMs) hallucinate findings that contradict the source code. Thus, we propose Chaintrix, an end-to-end auditing framework whose central architectural commitment is that every LLM-generated claim must be discharged against a deterministic structural contract representation. We introduce a Cross-Contract Interaction Model (CCIM) that parses Solidity into a structured map of function-level reads, writes, modifiers and resolved cross-contract calls. CCIM serves as the substrate against which all 12 of Chaintrix's deterministic signal engines and the parallel LLM audit pipelines operate. A staged false-positive-reduction pipeline, terminating in a Structural Verdict Engine (SVE) that applies deterministic structural checks against parsed code, filters the merged finding set, with selected high-confidence findings further validated through symbolic execution and fuzz testing. We evaluate Chaintrix on EVMbench, the smart-contract security benchmark by OpenAI, Paradigm, OtterSec. Chaintrix detects 86 of 120 high-severity vulnerabilities (71.7% recall), with 25 audits scoring 100% recall, placing Chaintrix 26 percentage points above the strongest frontier-model baseline.
Problem

Research questions and friction points this paper is trying to address.

smart contract security
automated auditing
false positives
LLM hallucination
vulnerability detection
Innovation

Methods, ideas, or system contributions that make the work stand out.

LLM-augmented auditing
Cross-Contract Interaction Model
deterministic structural verification
false-positive reduction
smart contract security
🔎 Similar Papers
No similar papers found.
G
Gabriela Dobrita
Bucharest University of Economic Studies, Department of Economic Informatics and Cybernetics, no.6 Piața Romană, Bucharest, 010374, Romania
S
Simona-Vasilica Oprea
Bucharest University of Economic Studies, Department of Economic Informatics and Cybernetics, no.6 Piața Romană, Bucharest, 010374, Romania
A
Adela Bara
Bucharest University of Economic Studies, Department of Economic Informatics and Cybernetics, no.6 Piața Romană, Bucharest, 010374, Romania