Empirical Validation & Benchmark Metrics
Reproducible ground-truth validation across 50 curated Base reference contracts and 15 adversarial edge cases measuring false-negative rates, capability recall, and execution latency.
NOT_MEASURED.
EVM Disassembly Mechanics: Linear Opcode Walking
Why Substring / Regex Matching Fails on EVM Bytecode
Standard scanners often use naive string searching (indexOf("f4")) to detect DELEGATECALL. This causes catastrophic false positives because data pushed onto the stack via PUSH1..PUSH32 (such as addresses, hashes, or numeric constants) frequently contains 0xF4 as literal data bytes.
M2M Sentinel implements a zero-allocation instruction-by-instruction EVM walker (lib/dissect.js) that builds an exact set of non-executable PUSH offsets before scanning for functional opcodes:
Multi-RPC Quorum & Trust Grading Specification
Deterministic On-Chain State Verification on Base Mainnet
To eliminate RPC spoofing or single-node divergence, M2M Sentinel categorizes every analysis response with a cryptographic trust grading:
| Trust Level | Quorum Condition | Evidence Grade | Machine Policy Action |
|---|---|---|---|
| HIGH_TRUST_PRIMARY | TLS 1.3 credentialed connection with verified Chain ID 8453 handshake. | TRUE | Deterministic evidence verified; bot policy executes normally. |
| QUORUM_PUBLIC | Agreement across ≥ 2 independent public Base RPC providers. | TRUE | Consensus validated across disparate nodes. |
| DEGRADED_LOW_TRUST | Lone fallback node or split quorum response. | FALSE | Bot policy can pause or require secondary validation. |
Capability Recall & False-Negative Performance
| Tracked Capability / Opcode | Corpus Positive Samples | True Positives (TP) | False Negatives (FN) | Recall Rate |
|---|---|---|---|---|
| DELEGATECALL & Proxy Forwarding | 28 cases | 28 | 0 | 100.0% |
| MINT / Supply Expansion Selectors | 19 cases | 19 | 0 | 100.0% |
| PAUSE / FREEZE Access Controls | 14 cases | 14 | 0 | 100.0% |
| SELFDESTRUCT Opcodes | 4 cases | 4 | 0 | 100.0% |
| BLACKLIST / Account Restriction | 11 cases | 11 | 0 | 100.0% |
Adversarial & Edge-Case Benchmarks
| Case ID / Contract | Adversarial Pattern | Expected Capability | Detection Result | Preflight Risk Implication |
|---|---|---|---|---|
| ADV-01 Custom Fallback Proxy |
Assembly Forwarding | DELEGATECALL | DETECTED (TP) | Custom storage slot dispatch; requires bytecode disassembly |
| ADV-02 Stealth Mint Dispatch |
Disguised Mint | MINT | DETECTED (TP) | Designated minter can dynamically expand circulating supply |
| ADV-03 Uninitialized Transparent Proxy |
Uninitialized Implementation | DELEGATECALL | DETECTED (TP) | Proxy target contract address is mutable via admin slot |
| ADV-04 Conditional Blacklist Hook |
Honeypot Hook | BLACKLIST | DETECTED (TP) | Admin role can restrict individual addresses from transferring |
| ADV-05 Global Freeze / Pause Selector |
Global Freeze | PAUSE_FREEZE | DETECTED (TP) | Preflight check prevents burning gas on paused swap reverts |
| ADV-06 Coinbase Smart Wallet Factory |
Deterministic Factory | CREATE2 | DETECTED (TP) | Deploys smart contracts deterministically via CREATE2 |
Methodology & Limitations
- Curated corpus spans 50 verified contracts and 15 adversarial test fixtures on Base Mainnet.
- Verified Blockscout and BaseScan ABI metadata are used as ground truth for selector and opcode presence.
- Proxy agreement covers EIP-1967, EIP-1822 (UUPS), EIP-1167 (Clones), and Beacon proxies.
- Static preflight observations do not measure dynamic runtime state, call reachability, or economic security.
Machine-readable evidence: validation.json and adversarial_honeypot_corpus.json. Explore all 50 contracts with live preflight snippets in the Curated Reference Contracts Hub →