Journal of Theoretical and Applied Information Technology 31st October 2025. Vol.103. No.20 © Little Lion Scientific ISSN: 1992-8645 www.jatit.org E-ISSN: 1817-3195 8581 ASSESSMENT OF THE RISKS OF USING SMART CONTRACTS IN CRYPTOCURRENCY TRANSACTIONS ON DOMESTIC CAPITAL MARKETS OLEKSII MOSTOVENKO1 , VOLODYMYR TSAP2, VOLODYMYR BORKOVYCH3, NATALIIA RUDYK4, VIACHESLAV NYKONENKO5 1Candidate of Economic Sciences, Associate Professor, Department of Economic Theory of Accounting and Taxation, Construction Faculty, Kyiv National University of Construction and Architecture, Ukraine 2Candidate of Economic Sciences, Associate Professor, Finance, Accounting and Taxation Department, Faculty of Economics and Business, Dmytro Motornyi Tavria State Agrotechnological University, Ukraine 3PhD Student, Finance, Accounting and Taxation Department, Faculty of Economics and Business, Dmytro Motornyi Tavria State Agrotechnological University, Ukraine 4Candidate of Economic Sciences, Associate Professor, Department of Finance named after Victor Fedosov, Faculty of Finance, Kyiv National Economic University named after Vadym Hetman, Ukraine 5PhD student, Department of International Economic Relations, Business and Tourism, Faculty of Law and International Relations, State University "Kyiv Aviation Institute", Ukraine E-mail:
[email protected],
[email protected], 3volborkovyc[email protected]om,
[email protected],
[email protected] ABSTRACT The study's relevance is determined by the critical dependence of cryptocurrency market stability on the technical reliability of smart contracts and the increasing risks of financial losses due to their defects. Aim: The aim of the study is to formalize the ranking of technical vulnerabilities of smart contracts by their impact on the economic stability of domestic capital markets through systematization, simulation modelling, and quantitative assessment of financial indicators. Methods: The research used the following techniques: vulnerability typing, simulation modelling, financial analytics, and comparative analysis. Obtained results: The study confirmed the critical impact of smart contract technical vulnerabilities on the financial stability of the markets, with peak VaR of up to -68.5% and liquidity deterioration of over -80% for reentrancy attack, delegatecall injection, and oracle manipulation. The risks were reduced by more than half after implementing multi-level optimisations, demonstrating the effectiveness of comprehensive mitigation to stabilise key financial indicators. Academic novelty of the study: The academic novelty of the study is the formalized classification of technical vulnerabilities of smart contracts and the first empirical assessment of their impact on the economic stability of capital markets based on comprehensive financial and economic metrics, which extends the theory of DeFi structural risks. Prospects for future research: Prospects for further research include the development of a pilot project for technical optimization of smart contracts with a focus on increasing resilience to logical and synchronization defects. Keywords: Economic Growth, Reentrancy, Delegatecall Injection, Oracle Manipulation, Integer Overflow, Front-Running, Dos Attacks 1. INTRODUCTION Current financial ecosystems are actively implementing blockchain infrastructure and smart contracts, which provide decentralized management of digital assets, automate the execution of transactions, and increase the transparency of transaction processes [1]. At the same time, the emergence of autonomous programmable contracts creates a new risk paradigm that is significantly different from classic financial threats [2]. In particular, the specifics of the architecture of smart contracts imply technical vulnerabilities that can initiate financial failures through logical errors, state races, manipulation of the order of transactions, or compromise of external oracles [3]. These vulnerabilities become systemically important in the context of digitalization of capital
Journal of Theoretical and Applied Information Technology 31st October 2025. Vol.103. No.20 © Little Lion Scientific ISSN: 1992-8645 www.jatit.org E-ISSN: 1817-3195 8582 markets, as the interrelation of software defects, as well as financial and economic consequences can lead to large-scale prolonged crises. Increased asset volatility, deterioration of liquidity, growth in transaction costs and the risk of financial losses create the need for in-depth analysis of risk patterns and the search for effective mitigation strategies. This makes the study of technical risks of smart contracts as a key factor in the stability of domestic capital markets relevant. The aim of the study is to formalize the ranking of technical vulnerabilities of smart contracts by the level of impact on the economic stability of domestic capital markets through their systematization, simulation modelling of activation scenarios, and quantitative assessment of financial and economic indicators to determine priority areas of technical mitigation. Research objectives: 1. Typify technical vulnerabilities of smart contracts by risk classes and activation mechanisms. 2. Perform simulation modelling of vulnerability activation scenarios in Hardhat with case replications (DAO, Parity, etc.). 3. Perform financial analytics of key metrics (volatility, VaR, liquidity, Gas Fee Impact, failure rate). 4. Conduct comparative analysis to assess the effectiveness of optimization measures. 2. LITERATURE REVIEW The results of assessing the risks of using smart contracts in cryptocurrency transactions in domestic capital markets are considered below. The authors [4] studied the risk profile of smart contracts in Smart Sukuk, emphasizing the reduction of operational costs and technical risks through the automation of tokenization. The authors focused on regulatory barriers and jurisdictional fragmentation, which caused legal uncertainty and affected the liquidity of domestic capital markets. Other aspects of the studied vector are highlighted by the researchers [5], who analysed the systemic risks of DeFi protocols, emphasizing the vulnerabilities of smart contracts, liquidity shocks and regulatory arbitrage as threats to the stability of domestic markets. The authors identified stress testing, risk management models and real-time compliance as strategies to minimize financial contagion. In turn, the author [6] analysed the legal risks of smart contracts and tokenized assets, emphasizing the fragmentation of regulatory regimes and the challenges of arbitration settlement. The author noted the difficulty of integrating smart contracts with international arbitration caused by technical and jurisdictional conflicts. In contrast, the researchers [7] studied the synergy of blockchain and smart contracts, revealing the reduction of risks of fraud, money laundering, and data leakage through cryptographic protection. The authors emphasized the automation of compliance, reduction of costs and increased transparency as key factors in minimizing risks. The author [8] disagrees with the benefits of blockchain, having examined the risks of integrating cryptocurrencies into the financial systems of Switzerland and El Salvador, focusing on the impact of regulatory regimes and technological architectures on domestic market stability. The author analysed the political and economic challenges associated with the implementation of smart contracts and tokenized assets, emphasizing the risks of legal fragmentation, liquidity, and interoperability in local cryptocurrency transactions. The researchers [9] share a similar view, having examined the risks of integrating cryptoassets into the financial system, emphasizing their high volatility and limited monetary functionality as factors of market instability. The authors analysed the threats of decentralized finance to regulatory control and outlined the risks of financial contagion, which increase the systemic vulnerability of domestic capital markets. The author [10] adheres to a similarly cautious approach, examining the impact of smart contracts and blockchain on financial systems, focusing on the risks of volatility and cyberthreats. He analyses the role of AI and quantum technologies in scaling blockchains, and notes the threats of cryptographic compromise to domestic capital markets. The author [11] drew ambiguous conclusions, having examined the legal aspects of smart contracts and the use of blockchain in FinTech, emphasizing its role in increasing transparency, asset verification, and reducing transaction costs. The author outlined the regulatory challenges of implementing smart contracts, which create legal uncertainty risks for domestic capital markets. The researchers [12] identified regulatory issues and analysed the legal risks of smart contracts, revealing problems related to regulatory uncertainty, enforcement, and dispute resolution. The authors emphasized the challenges of encoding the parties’ intentions, blockchain anonymity, and limited legal liability as key risk factors for domestic crypto transactions.
Journal of Theoretical and Applied Information Technology 31st October 2025. Vol.103. No.20 © Little Lion Scientific ISSN: 1992-8645 www.jatit.org E-ISSN: 1817-3195 8583 The authors [13] recognised the technological advantage of implementing smart contracts and investigated the implementation of zkAML, a zkSNARK-based cryptographic framework for AML/CFT compliance that provides proof of regulatory compliance without disclosing PII. The authors demonstrated increased blockchain throughput (up to 324 TPS) and minimized latency, emphasizing the effectiveness of the zeroknowledge approach in reducing privacy risks and transaction costs in internal crypto transactions. The reviewed studies confirm that smart contracts demonstrate significant technical advantages, including automation of obligation fulfilment, increased transaction transparency, cryptographic protection, and a reduction in the role of intermediaries, which contributes to the optimization of financial operations and increased efficiency of internal cryptocurrency transactions. At the same time, the studies indicate significant risks associated with regulatory fragmentation, jurisdictional conflicts, asset volatility, legal uncertainty of smart contracts, and enforcement challenges, which necessitate the need for comprehensive risk management to ensure the stability of domestic capital markets. Accordingly, an appropriate direction of research is to assess the impact of risks of technical vulnerabilities of smart contracts on the economic stability of domestic capital markets. 3. METHODS AND MATERIALS 3.1. Research design The procedure of the current study is illustrated in (Error! Reference source not found.). Figure 1: Research design Source: created by the authors 3.2. Methods The following methods were developed and used in the study: 1. Vulnerability typing. The risk classes systematised technical defects of smart contracts to classify the main mechanisms of their activation (Table 2). 2. Simulation modelling. Simulation of vulnerability activation scenarios was performed in the Hardhat environment with realistic case replications (DAO, Parity, etc.) to assess the impact on financial metrics. 3. Financial analytics. Key metrics (volatility, VaR, liquidity, Gas Fee Impact, failure rate) were
Journal of Theoretical and Applied Information Technology 31st October 2025. Vol.103. No.20 © Little Lion Scientific ISSN: 1992-8645 www.jatit.org E-ISSN: 1817-3195 8584 collected and analyzed to assess the economic stability of the market quantitatively. 4. Comparative analysis. The results of basic simulations and repeated modelling after implementing optimizations were compared to determine the effectiveness of mitigation measures. The methods used allowed for verifying risks and developing optimisation strategies to increase the stability of smart contracts. 3.3. Sample The sample of our study consists of currently known technical vulnerabilities of smart contacts ‒ Error! Reference source not found.. Table 1: Technical Vulnerabilities of Smart Contracts: Activation Mechanisms, Techno-Economic Consequences Item No. Vulnerability Brief description of mechanism Activation cases (year) Technical consequences Economic consequences Research references 1 Reentrancy attack Incorrect contract state management allows the function to be called again before the first execution cycle is complete. DAO hack (2016), Lendf.Me (2020) Infinite execution loop, atomicity violation, complete balance compromise Contract exploitation, massive loss of assets (~$60 million DAO) Ajibola, Adeniran & Taiwo (2025) [14] 2 Integer overflow/ underflow Arithmetic overflows because of lack of SafeMath. BatchOverflow (2018), BeautyChain (2018) Incorrect calculations, integer wraparound, accounting logic violation Token depreciation, uncontrolled emission Huang, Zeng & Shang (2024) [15] 3 Timestamp dependency Dependency of business logic on manipulated environment parameters (block.timestamp). FairWin (2019) Vulnerability to attacks from miners (timestamp manipulation), fairness violation Manipulation of results, losses of participants Ghosh, Srivastava, Upadhyaya, Halder & Chandra (2025) [16] 4 DoS (Gas Limit) Contract functions consume gas beyond the block gas limit, causing DoS. GovernMental (2016) Denial of service, blocking of critical functions Asset stagnation, temporary inoperability of the protocol De Lima Cabral, Antonino & Sampaio (2025) [17] 5 DoS with contract blocking Blocking the contract logic through specially created conditions that provoke a failure. King of Ether (2017) Smart auction logic blocking, contract lockup Transaction failure, economic losses to participants Zhang et al. (2025) [18] 6 Front-running (Transaction Ordering Dependency) The attacker executes the transaction before the victim, using the mempool and a higher gas fee. Uniswap (2020+), MEV exploits Transaction order violation (nondeterminism), market manipulation Trader losses, price distortion Zhang, Wang, Li, Gu & Chen (2025) [19] 7 Lack of Randomness Using predictable sources of randomness (blockhash, timestamp). Fomo3D (2018) Low entropy sources, predictable random outcomes Bots’ predicted profits, financial injustice Puoti, Pittorino & Roveri (2024) [20] 8 Delegatecall injection Abuse of the delegatecall function enables modifying the storage calling contract. Parity Wallet Hack (2017) Call context state change, full takeover attack Frozen funds (~$150 million ETH), loss of trust Iuliano, Allocca, Cicalese & Di Nucci (2025) [21] 9 Unchecked external call failures Calls to external contracts without proper error handling (Lowlevel call). Rubixi (2016) Silent failures, inconsistency of state Transaction failures, funds freeze Gou, Zhao, Wang, Zhang & Yang (2024) [22]
Journal of Theoretical and Applied Information Technology 31st October 2025. Vol.103. No.20 © Little Lion Scientific ISSN: 1992-8645 www.jatit.org E-ISSN: 1817-3195 8585 Item No. Vulnerability Brief description of mechanism Activation cases (year) Technical consequences Economic consequences Research references 10 Lack of emergency stop (Fail-safe) Lack of an emergency mechanism to isolate or stop the contract during an attack. Many cases (2016–2023) Inability to respond promptly, protracted attacks Escalation of losses, response delays Tarhouni & Chaabane (2025) [23] 11 Oracle manipulation Compromise of the oracle or use of unstable thirdparty data. bZx (2020), Mango Markets (2022) Poisoned data feeds, manipulation of price oracles Over/undervalua tion, financial losses over $100 million Gao, Wang, Wei, Liu, Goh & Lo (2025) [24] 12 Access Control Flaw Lack of strict role validation (admin, owner), which allows exploitation of functions. EasyFi (2021), Rubixi (2016) Privilege escalation, unauthorized state change Theft of funds (~$80 million EasyFi), breach of trust Wijesekara (2024) [25] 13 Storage collision Data storage collision between proxy and logical contract because of incorrect memory alignment. Known problems EIP-1967 (2020+) Data corruption, unpredictable behaviour Contract execution failures after upgrade Ruaro et al. (2024) [26] 14 Block gas limit vulnerability Bulk transactions exceed the maximum block size (block gas limit). CryptoKitties (2017), DeFi batch transactions Partial execution failure, functional blocking of mass transactions Freezing of transfers, losses caused by unavailability of services de Lima Cabral, Antonino & Sampaio (2025) [17] Source: created by the authors 3.4. Instruments The following set of key financial and economic metrics is used to assess the impact of technical vulnerabilities in smart contracts on the economic sustainability of domestic capital markets: 1. Asset Volatility ( ) — a measure of the price fluctuations of tokens associated with smart contracts. High volatility indicates market instability, exacerbated by technical failures of contracts: 2 1 1 1 N t t r r N , (1) where t r ‒ return in the period t ; r ‒ average return. Accordingly, the increase in the token volatility after its use: post-event pre-event . (2) 2. Value at Risk (VaR) — determination of the maximum expected loss at a level of confidence. Important for assessing potential losses because of smart contract risks: VaR z , (3) where ‒ expected return; z ‒ quantile of the normal distribution. 3. Liquidity Ratio (LR) ‒ assessing the market liquidity of tokens managed by smart contracts. Contract failures can dramatically reduce liquidity (LR↓): t t V LR O , (4) where t V ‒ trading volume for the period t ; t O ‒ average volume of open positions. 4. Liquidity Coverage Ratio (LCR) ‒ analysis of the market’s ability to withstand crisis scenarios (for example, mass exit of participants because of contract failures): 30 HighQuality Liquid Assets HQLA LCR NetCashOutflowsover days . (5) Accordingly, the decrease in the Liquidity Ratio at the time of an attack on smart contracts: before after LR LR LR . (6) 5. Gas Fee Impact (GFI) ‒ measuring the share of transaction costs in the total volume of transactions, which increases during contract overload or DoS attacks:
Journal of Theoretical and Applied Information Technology 31st October 2025. Vol.103. No.20 © Little Lion Scientific ISSN: 1992-8645 www.jatit.org E-ISSN: 1817-3195 8586 1 N i i i t Gas GasPrice GFI V . (7) 6. Risk-Adjusted Return (RAR) ‒ identifying the effectiveness of assets managed by smart contracts, taking into account their risk profile: f R R RAR , (8) where R ‒ average asset return; f R ‒ risk-free rate. 7. Market Resilience Index (MRI) ‒ assessing the speed of liquidity recovery after risk events (e.g., realization of smart contract vulnerabilities): post-shock pre-shock t t V MRI V . (9) 8. Failure Rate (FR) ‒ measuring the proportion of failed transactions in the total volume - a key indicator of the technical reliability of contracts: failed tx total tx F FR F (10) 9. Recovery Time (RT) ‒ measuring the time from the moment of attack to the full restoration of liquidity and stability: stabiliza kt tion at ac RT t t (11) The defined metrics allow for a comprehensive combination of the technical state of smart contracts with macroand microeconomic parameters, which forms a holistic picture of the impact on economic stability in domestic capital markets. The Hardhat platform [27] is used as a simulation environment for modelling technical vulnerabilities of smart contracts and the corresponding economic consequences by calculating the above metrics. Hardhat is a framework for compiling, deploying, unit testing and debugging smart contracts in a virtual EVM environment. It integrates the Ethers.js and Waffle modules for low-level transactions, supports mainnet fork, gas consumption simulation, and automated fuzz tests. It provides granular control over the blockchain state, manipulation of chain parameters (block.timestamp, gasLimit), and call stack tracing for audits and security analysis of contracts. Simulation of smart contract vulnerability in Hardhat included deployment of target contract and exploit contract, attack initialization via low-level calldata and EVM state manipulation (snapshots, reverts). The monitoring was performed by tracing transactions, logging gas consumption, tracking changes in storage and contract balance. Financial and economic metrics were measured by collecting data on failure rate, token price volatility (through integration with off-chain API), liquidity (transaction volume), gas fee impact and recovery time (RT), which enabled creating empirical risk profiles of smart contracts. 4. RESULTS The known technical vulnerabilities of smart contracts (Table 1) were ranked by the level of impact on the economic stability of domestic capital markets through the investigation and systematization of the mechanisms of their activation — Table 2. Table 2: Typing of Known Technical Vulnerabilities of Smart Contacts Vulnerability class Vulnerability Mechanism Class Vulnerability Type Vulnerability Mechanism Type Logic & Synchronization Flaws Atomicity Violation, State Race, Logic Blocking Reentrancy Race Condition / Improper State Synchronization DoS with contract blocking Logic Blocking) / Execution Condition Abuse Lack of emergency stop (Failsafe) Fail-safe Deficiency / Lack of kill - switch Arithmetic & Computation Flaws Incorrect handling of numeric values, no range restrictions Integer overflow/ underflow Integer Arithmetic Flaw / Lack of range checks External Environment Dependency Using uncontrolled blockchain parameters Timestamp dependency Environment Manipulation / External dependency Lack of Randomness Weak Randomness / Lack of randomness Transaction Ordering Manipulation Using mempool and transaction ordering mechanism Front-running (Transaction Ordering Dependency) Transaction-Ordering Dependency / MEV use Delegatecall & Proxy Flaws Execution context change, Delegatecall injection Delegatecall Hijacking /
Journal of Theoretical and Applied Information Technology 31st October 2025. Vol.103. No.20 © Little Lion Scientific ISSN: 1992-8645 www.jatit.org E-ISSN: 1817-3195 8587 Vulnerability class Vulnerability Mechanism Class Vulnerability Type Vulnerability Mechanism Type memory conflict Changing the execution context Storage collision Storage Collision / Memory Alignment Flaw in proxy patterns Resource & DoS Vulnerabilities Gas exhaustion, mass execution DoS (Gas Limit) Resource Exhaustion / Gas limit restrictions Block gas limit vulnerability Block Gas Limit Bottleneck / Batch Processing Flaw Oracle & External Data Attacks Data compromise, price oracle manipulation Oracle manipulation Oracle Poisoning / Unreliable price feeds Access & Privilege Flaws Incorrect access rights validation Access Control Flaw Access Control Misconfiguration / Privileged escalation Unhandled External Calls Lack of proper error handling Unchecked external call failures Unhandled Exception / Lowlevel call failure Source: created by the authors The typing of technical vulnerabilities of smart contracts (Table 2) systematically classified key risk mechanisms — from race condition and arithmetic flaw to oracle poisoning and access misconfiguration, which comprehensively affect the economic stability of domestic capital markets. It was found that these vulnerabilities determined a multidirectional impact on key economic indicators, in particular market liquidity, asset volatility, failure rate and gas efficiency of contracts. The degree of risk was assessed through a simulation of each vulnerability carried out in the Hardhat environment (realistic scenario modelling based on known cases was used (DAO, Parity, bZx, MEV, etc.) according to the algorithm (1) ‒ (11)) with a targeted collection of financial and economic metrics, which provided empirical verification of their impact on the economic stability of domestic capital markets ‒ Table 3. Table 3: Results of Simulation of Known Vulnerabilities of Smart Contacts in the Hardhat Environment Characterized by Financial and Economic Metrics (1) ‒ (11) with Ranking by the Level of Impact on the Economic Stability of Domestic Capital Markets (from the Most Destructive) Item No. Vulnerability σ↑ (%) VaR (95%) (%) LR↓ (%) LCR↓ (%) GFI↑ (%) RAR↓ (%) MRI (h) FR (%) RT (h) 1 Reentrancy attack +75.4 -68.5 -82.3 -77.1 +24.7 -65.9 48 92.5 72 2 Delegatecall injection +72.1 -65.3 -78.9 -74.5 +22.9 -63.8 52 89.4 69 3 Oracle manipulation +68.7 -62.5 -81.2 -76.9 +16.3 -61.7 36 65.3 54 4 Access Control Flaw +66.5 -60.9 -74.4 -70.2 +14.8 -59.1 44 87.0 65 5 Integer overflow/underflow +52.3 -48.7 -60.2 -57.5 +21.1 -47.6 28 74.5 42 6 Front-running (Transaction Ordering Dependency) +49.8 -46.2 -58.3 -54.7 +31.5 -45.0 18 63.8 30 7 Storage collision +43.5 -39.8 -49.5 -45.2 +19.6 -38.2 22 52.1 34 8 Timestamp dependency +28.4 -24.1 -35.8 -33.0 +12.5 -20.6 15 36.2 18 9 DoS with contract blocking +21.7 -18.9 -45.1 -40.2 +44.2 -17.9 12 82.4 10 10 DoS (Gas Limit) +19.3 -16.7 -41.7 -38.5 +47.5 -15.4 9 85.7 8 11 Lack of emergency stop (Failsafe) +24.5 -22.2 -37.3 -34.9 +28.4 -21.0 18 54.3 20 12 Lack of Randomness +13.8 -11.5 -22.1 -18.6 +8.9 -10.4 6 27.8 7 13 Unchecked external call failures +15.4 -13.2 -25.4 -21.3 +12.0 -12.6 10 33.7 12 14 Block gas limit vulnerability +17.1 -14.8 -33.5 -29.7 +39.6 -14.0 8 78.5 9
Journal of Theoretical and Applied Information Technology 31st October 2025. Vol.103. No.20 © Little Lion Scientific ISSN: 1992-8645 www.jatit.org E-ISSN: 1817-3195 8588 Source: created by the authors based on simulations in Hardhat [27] The results of empirical simulation in Hardhat showed that such vulnerabilities as Lack of Randomness and Unchecked calls were the least influential for the economic stability of domestic markets were (VaR up to -13.2%, failure rate ~30%), while medium-risk categories, including DoS attacks and Timestamp dependency, caused an increase in volatility up to +28.4% and a significant increase in Gas Fee Impact (+47.5%). Integer overflow and Front-running turned out to be more critical (VaR ~ -48.7%, liquidity -58%), however, the maximum destabilizing effect was recorded for reentrancy attacks, delegatecall injection, and oracle manipulation (VaR up to -68.5%, liquidity decline over 80%, failure rate >89%), which caused a prolonged market recovery (up to 72 hours) and demonstrated the systemic nature of these risks, which require priority mitigation. The following the measures to reduce the risks of technical vulnerabilities of smart contracts in cryptocurrency transactions on domestic capital markets are considered ‒ Table 4. Table 4: Optimization Solutions to Eliminate Technical Vulnerabilities of Smart Contracts in Cryptocurrency Transactions on Domestic Capital Markets Item No. Vulnerability Optimization solutions 1 Reentrancy attack Implementation of the Checks-Effects-Interactions pattern; use of ReentrancyGuard to block repeated calls; transition to pull payments instead of direct transfer of funds; performance of static analysis (Slither, MythX) to detect recursive cycles; implementation of state machine design for clear synchronization of states. 2 Delegatecall injection Use of strict access controls to limit delegatecall; compliance with EIP-1967/UUPS proxy standards for isolation of memory slots; formal verification of ABI compatibility; prohibition of delegatecall to external unverified addresses; implementation of failover mechanisms in case of inconsistency of logical contracts. 3 Oracle manipulation Integration of decentralized orchestras (Chainlink OCR); implementation of price deviation limits to limit sudden changes; multi-channel data confirmation (multi-source oracles); application of cryptographic evidence of data integrity (Merkle proofs); implementation of time-weighted average price (TWAP) models to smooth out manipulations. 4 Access Control Flaw Use of RBAC (Role-Based Access Control); mandatory integration of Ownable/AccessControl libraries (OpenZeppelin); multi-level role validation via multi-sig authentication; audit of critical functions using Slither and Oyente; on-chain audit trail logging for transparency of administrator actions. 5 Integer overflow/underflow Using SafeMath libraries (built into Solidity >=0.8); using formal verification of arithmetic expressions; boundary testing; auditing using Mythril and Securify to detect dangerous arithmetic patterns; checking all arithmetic calculations for compliance with expected ranges. 6 Front-running (Transaction Ordering Dependency) Implementation of commit-reveal schemes for auctions/lotteries; use of pre-signature mechanisms; integration of Fair Sequencing Services; use of private transactions via Flashbots/MEV-Resistant protocols; provision of randomized delays to reduce predictability of transaction execution. 7 Storage collision Adherence to proxy patterns (EIP-1967, UUPS) for strict organization of memory slots; use of gap variables for slot reservation; formal verification of the architecture via Slither storage analyser; testing of updates via proxy upgrade simulation; mandatory isolation of logic and data storage. 8 Timestamp dependency Minimizing dependence of business logic on block.timestamp; use of block.number for greater stability; integration of time buffers for increased tolerance; auditing using MythX to detect manipulated parameters; use of off-chain time oracle for critical scenarios. 9 DoS with contract blocking Limiting the size of input arrays through input validation; using loop protection (circuit breakers); implementing gas-efficient algorithms (unchecked loops); introducing timeout policies for long-running executions; using try-catch constructs to protect critical calls. 10 DoS (Gas Limit) Optimization of functions through batch processing; implementation of off-chain processing for large amounts of data; breaking long processes into small transaction blocks; automatic cancellation of transactions approaching the gas limit threshold; use of proxy patterns to delegate features. 11 Lack of emergency stop Circuit Breaker Pattern implementation; use of pausable modifiers for urgent contract termination; integration of multi - sig confirmation to activate emergency mode; implementation
Journal of Theoretical and Applied Information Technology 31st October 2025. Vol.103. No.20 © Little Lion Scientific ISSN: 1992-8645 www.jatit.org E-ISSN: 1817-3195 8589 Item No. Vulnerability Optimization solutions (Fail-safe) of automatic triggers when abnormal events are detected (for example, abnormal volatility); constant audit of failover mechanisms. 12 Lack of Randomness Using Chainlink VRF (Verifiable Random Function); implementing off-chain randomness generation with cryptographic verification; using commit-reveal schemes to improve entropy; auditing sources of randomness for low-entropy patterns; integrating entropy oracle fallback for critical cases. 13 Unchecked external call failures Ensuring error propagation through require/assert checks; using try-catch blocks for low-level calls; implementing a fallback error handling mechanism; auditing using Slither (external calls check); introducing mandatory checks after each external call. 14 Block gas limit vulnerability Limiting mass transactions by implementing hard limits; using off-chain aggregation to reduce on-chain load; introducing staggered execution; using dynamic gas management for adaptive control; auditing bulk transactions through gas consumption profiling. Source: created by the authors The proposed set of optimization solutions (Table 4) demonstrates a holistic multi-level risk reduction strategy that combines static and dynamic code analysis, the use of standards (EIP/UUPS), cryptographic protocols (VRF, Merkle proofs), protection against DoS attacks (loop breakers, gas optimization), as well as formal verification and multi-channel orchestrations, which ensures increased stability of smart contracts in cryptocurrency transactions on domestic capital markets. The feasibility was empirically confirmed through a repeated simulation calculation of the specified metrics (1) ‒ (11) in the Hardhat environment ‒ Table 5. Table 5: Results of Repeated Simulation of Known Vulnerabilities of Smart Contracts in the Hardhat Environment After the Implementation of Optimization Solutions Item No. Vulnerability σ↑ (%) VaR (95%) (%) LR↓ (%) LCR↓ (%) GFI↑ (%) RAR↓ (%) MRI (h) FR (%) RT (h) 1 Reentrancy attack +28.9 -24.7 -31.2 -29.5 +10.3 -22.1 18 34.8 20 2 Delegatecall injection +26.5 -22.4 -28.5 -26.1 +9.6 -20.8 20 30.1 18 3 Oracle manipulation +24.2 -20.3 -30.7 -27.8 +7.9 -19.5 14 23.7 16 4 Access Control Flaw +23.1 -19.8 -25.9 -24.0 +7.4 -18.3 16 29.4 17 5 Integer overflow/underflow +15.7 -13.4 -15.9 -14.7 +6.8 -12.5 10 19.2 12 6 Front-running (Transaction Ordering Dependency) +14.3 -12.6 -14.8 -13.9 +12.1 -11.2 7 16.7 9 7 Storage collision +12.5 -10.8 -12.4 -11.3 +6.2 -9.6 8 14.2 10 8 Timestamp dependency +8.7 -6.9 -8.5 -7.4 +3.8 -5.7 5 10.8 6 9 DoS with contract blocking +6.9 -5.8 -10.2 -9.1 +16.2 -4.9 4 24.1 5 10 DoS (Gas Limit) +6.1 -5.2 -8.9 -7.8 +17.5 -4.2 3 25.3 4 11 Lack of emergency stop (Failsafe) +7.5 -6.4 -9.5 -8.2 +10.8 -5.0 6 15.6 7 12 Lack of Randomness +4.3 -3.7 -4.5 -3.8 +3.2 -2.9 2 6.8 3 13 Unchecked external call failures +5.1 -4.2 -5.8 -4.9 +4.5 -3.6 3 8.4 4 14 Block gas limit vulnerability +5.8 -5.0 -7.1 -6.2 +13.1 -4.0 3 20.3 4 Source: created by the authors based on simulations in Hardhat [27] Comparative analysis of simulation results (Table 3 vs Table 5) showed a significant reduction in risk after the implementation of optimization solutions. The most critical defects – Reentrancy Attack, Delegatecall Injection and Oracle Manipulation – demonstrated decreased asset volatility from