SCAR : Mining and Structuring Smart Contract Security Audit Reports

Dagsetning

Höfundar


Journal Title

Journal ISSN

Volume Title

Útgefandi

Association for Computing Machinery, Inc

Útdráttur

Smart contract security audit reports contain rich information about vulnerabilities and code quality issues in Web3 projects. However, these reports are scattered across different sources and formats, making large-scale analysis difficult. We present SCAR (Smart Contract Audit Repository), an open-source dataset and tool that automatically aggregates these audit reports. SCAR crawls reports from leading security firms (e.g., OpenZeppelin) and community contests (e.g., Code4rena), parses them into a structured JSON schema, and offers a queryable API for accessing the data. Its pipeline includes a crawler, a text-mining module to standardize findings (e.g., vulnerability types, severity, code references), and a web API for retrieving insights. With hundreds of audits covering thousands of issues, SCAR enables empirical studies of smart contract vulnerabilities at scale. The SCAR project repository is available on GitHub, and the screencast demo is available at this link.

Lýsing

Publisher Copyright: © 2026 Copyright held by the owner/author(s).

Efnisorð

audit reports, dataset, decentralized finance, empirical study, security audits, smart contracts, Software

Citation

Qasse, I, Tseng, P Y, Hamdaqa, M & Hjálmtýsson, G 2026, SCAR : Mining and Structuring Smart Contract Security Audit Reports. in S H Tan & F Khomh (eds), FSE Companion 2026 - Proceedings of the 34th ACM International Conference on the Foundations of Software Engineering. FSE Companion 2026 - Proceedings of the 34th ACM International Conference on the Foundations of Software Engineering, Association for Computing Machinery, Inc, pp. 277-281, ACM International Conference on the Foundations of Software Engineering, FSE 2026, Montreal, Canada, 5/07/26. https://doi.org/10.1145/3803437.3806435
conference