- Research Article
- 10.1145/3765755
Detecting and Analyzing Fine-grained Third-party Library Dependencies in Solidity Smart Contracts
- Sep 04, 2025
- ACM Transactions on Software Engineering and Methodology
- Sicheng Hao + 4 more +4
Solidity is the primary programming language for writing smart contracts. As a lightweight language, Solidity does not have a unified way to manage third-party library (TPL) dependencies. Instead, the copy-and-paste pattern and other dependency managers such as NPM and Git submodules have become alternatives. However, these mechanisms significantly increase the complexity of TPL usage with security concerns. Similar to other programming language ecosystems, incorrect TPL usage can influence the reliability of contracts and even introduce vulnerabilities from outdated versions. Therefore, there is an urgent need to understand and comprehend Solidity TPL dependencies. In this work, we conduct a comprehensive study on TPL dependency usage in Solidity. To achieve this, we first present SPADE, which leverages additional metadata (e.g., package and remapping configurations) to infer fine-grained TPL dependencies with version and contract details in various Solidity projects. With SPADE, we investigate a broad spectrum of 5,242 Solidity repositories to understand the TPL dependencies, including their landscape and version-level usage. Our research reveals a set of interesting and important findings that can be beneficial to the Solidity ecosystem. In particular, TPL dependencies are prevalent in Solidity, but the version management remains inadequate. The propagation of vulnerability is severe, affecting 8.87% of the repositories. Finally, we use on-chain contracts to validate the findings and provide suggestions for future research and development on Solidity TPL dependencies.
Read more