Run gh-30059118265-1
- Date (UTC):
2026-07-24 01:30:15Z - Benchmark:
a0a57a3e0b5b533094f20079e9a9b7ef - Timeout:
4h - Target:
scfuzzbench/aave-v4-scfuzzbench@edd6c82721 - Benchmark type:
property - Instances:
2×c6a.4xlargeper fuzzer - Harness:
scfuzzbench/scfuzzbench@00775ce0bd
Trial run
Warning — trial run. This benchmark was executed with fewer than 10 instances per fuzzer and/or a time budget shorter than 24h. Results from trial runs are meant for debugging purposes and are not valid for extracting conclusions across different fuzzers.
Charts











Report
Fuzzer Benchmark Report (from bug-count CSV)
- Time budget: 4.00h
Warning — trial run. This benchmark was executed with fewer than 10 instances per fuzzer and/or a time budget shorter than 24h. Results from trial runs are meant for debugging purposes and are not valid for extracting conclusions across different fuzzers.
Executive summary
This report is derived solely from cumulative bugs-found over time across repeated runs per fuzzer. It emphasizes robust, distribution-based metrics (median/IQR, success rates, time-to-k) and shape-based behavior (plateau time, late discovery share) instead of single-run time-to-first-bug.
Bugs found at fixed time budgets (median [IQR])
| Fuzzer | Runs | 1h | 4h |
|---|---|---|---|
| recon-fuzzer | 2 | 12 [11,12] | 12 [11,12] |
| echidna | 2 | 10 [9,10] | 10 [10,10] |
| medusa | 2 | 6 [5,6] | 7 [6,8] |
| foundry | 2 | 6 [6,7] | 6 [6,7] |
Overall metrics
| Fuzzer | AUC (norm) | Plateau time | Late discovery share | Final median | Final IQR |
|---|---|---|---|---|---|
| recon-fuzzer | 0.908 | 0.80h | 0.000 | 12 | 0.50 |
| echidna | 0.768 | 1.30h | 0.000 | 10 | 1.00 |
| medusa | 0.477 | 3.50h | 0.071 | 7 | 1.00 |
| foundry | 0.526 | 0.30h | 0.000 | 6 | 0.50 |
Milestones: time-to-k and success rates
| Fuzzer | time-to-1 (p50) | time-to-3 (p50) | time-to-5 (p50) | reach-1 rate | reach-3 rate | reach-5 rate |
|---|---|---|---|---|---|---|
| recon-fuzzer | 0.00h | 0.10h | 0.10h | 100.0% | 100.0% | 100.0% |
| echidna | 0.10h | 0.10h | 0.10h | 100.0% | 100.0% | 100.0% |
| medusa | 0.00h | 0.10h | 0.70h | 100.0% | 100.0% | 100.0% |
| foundry | 0.00h | 0.10h | 0.10h | 100.0% | 100.0% | 100.0% |
Throughput metrics (if supported by log format)
Values are run-level rates aggregated per fuzzer; n/a indicates the parser could not recover that metric from logs.
| Fuzzer | Runs | Tx/s runs | Tx/s p50 [p25,p75] | Gas/s runs | Gas/s p50 [p25,p75] |
|---|---|---|---|---|---|
| recon-fuzzer | 2 | 2 | 30092.26 [29865.29,30319.22] | 2 | 4311456929.00 [4292418785.00,4330495073.00] |
| echidna | 2 | 2 | 1681.04 [1678.31,1683.77] | 2 | 16184719816.00 [15275081743.50,17094357888.50] |
| medusa | 2 | 2 | 1214.00 [1205.50,1222.50] | 2 | 140092861.50 [140017351.25,140168371.75] |
| foundry | 2 | 2 | 8730.08 [7265.51,10194.66] | 2 | 7081539689.95 [6703134535.82,7459944844.09] |
Progress metrics from logs (fuzzer-specific proxies)
Sequence-rate and corpus values are parsed from native progress output and are useful for within-tool trend context.
| Fuzzer | Runs | Seq/s runs | Seq/s p50 [p25,p75] | Corpus runs | Corpus p50 [p25,p75] |
|---|---|---|---|---|---|
| recon-fuzzer | 2 | 0 | n/a | 2 | 93.50 [92.75,94.25] |
| echidna | 2 | 0 | n/a | 2 | 101.50 [99.75,103.25] |
| medusa | 2 | 2 | 12.00 [12.00,12.00] | 2 | 230.50 [229.25,231.75] |
| foundry | 2 | 0 | n/a | 2 | 0.00 [0.00,0.00] |
Function selector sanity checks
Counts are occurrences in unique saved corpus sequences, not runtime execution frequencies The complete per-instance distribution is in selector_distribution.csv; selector_summary.json preserves statuses and provenance.
- Expected-set status: available (23 selector(s))
- Expected-set provenance: peer-consensus heuristic: observed in every available corpus for at least two independent evidence families (Echidna and Recon count as one related typed-corpus family); not benchmark ground truth
| Fuzzer | Status | Instances with telemetry | Saved-corpus calls | Unique selectors |
|---|---|---|---|---|
| echidna | available | 2/2 | 20246 | 44 |
| foundry | unavailable | 0/2 | 0 | 0 |
| medusa | available | 2/2 | 22182 | 66 |
| recon-fuzzer | available | 2/2 | 18616 | 32 |
Most common saved-corpus selectors
| Fuzzer | Selector | Function | Calls | Share |
|---|---|---|---|---|
| echidna | 0x20bea9dd | iHub_mintFeeShares_ASSERTION_MINT_FEE_SHARES_PPS_CHANGE(uint256) | 871 | 4.30% |
| echidna | 0x5c9d5cb7 | iSpoke_supply_ASSERTION_SUPPLY_DOS(uint256,uint256) | 815 | 4.03% |
| echidna | 0x5d55852e | iSpoke_addDynamicReserveConfig(uint256,(uint16,uint32,uint16)) | 809 | 4.00% |
| echidna | 0xbb1b32f0 | invariant_totalBorrowedLessThanSupplied_v1() | 783 | 3.87% |
| echidna | 0xca2664f9 | iSpoke_setUsingAsCollateral(uint256,bool) | 733 | 3.62% |
| echidna | 0x6801b82e | switchActor(uint256) | 721 | 3.56% |
| echidna | 0x77494a8e | invariant_hubAddedSharesMatchesSpokeSum() | 679 | 3.35% |
| echidna | 0x25a00713 | invariant_shouldNotBecomeLiquidatable() | 675 | 3.33% |
| echidna | 0x5b00e9f0 | iSpoke_updateUserRiskPremium() | 675 | 3.33% |
| echidna | 0x27dd847c | iSpoke_liquidationCall_ASSERTION_LIQUIDATION_CALL_DOS(uint256,uint256,uint256,uint256,bool) | 671 | 3.31% |
| medusa | 0xb722c6ed | iHub_updateAssetConfig(uint256,(address,uint16,address,address),(uint16,uint32,uint32,uint32)) | 1215 | 5.48% |
| medusa | 0x5d55852e | iSpoke_addDynamicReserveConfig(uint256,(uint16,uint32,uint16)) | 1075 | 4.85% |
| medusa | 0xf24a44c9 | assert_canary_ASSERTION_CANARY(uint256) | 1052 | 4.74% |
| medusa | 0x5c9d5cb7 | iSpoke_supply_ASSERTION_SUPPLY_DOS(uint256,uint256) | 1020 | 4.60% |
| medusa | 0xca2664f9 | iSpoke_setUsingAsCollateral(uint256,bool) | 1015 | 4.58% |
| medusa | 0x4b430dd2 | iSpoke_updateDynamicReserveConfig(uint256,uint24,(uint16,uint32,uint16)) | 1010 | 4.55% |
| medusa | 0x1be3427b | switch_spoke(uint256) | 982 | 4.43% |
| medusa | 0xdfbe4d80 | iSpoke_repay_ASSERTION_REPAY_DOS(uint256,uint256) | 974 | 4.39% |
| medusa | 0x20bea9dd | iHub_mintFeeShares_ASSERTION_MINT_FEE_SHARES_PPS_CHANGE(uint256) | 969 | 4.37% |
| medusa | 0xf9f2ec54 | iSpoke_borrow(uint256,uint256) | 961 | 4.33% |
| recon-fuzzer | 0xca2664f9 | iSpoke_setUsingAsCollateral(uint256,bool) | 747 | 4.01% |
| recon-fuzzer | 0x8aa3bc37 | switch_oracle(uint256) | 689 | 3.70% |
| recon-fuzzer | 0x6801b82e | switchActor(uint256) | 687 | 3.69% |
| recon-fuzzer | 0x27dd847c | iSpoke_liquidationCall_ASSERTION_LIQUIDATION_CALL_DOS(uint256,uint256,uint256,uint256,bool) | 670 | 3.60% |
| recon-fuzzer | 0x25a00713 | invariant_shouldNotBecomeLiquidatable() | 665 | 3.57% |
| recon-fuzzer | 0xf9f2ec54 | iSpoke_borrow(uint256,uint256) | 665 | 3.57% |
| recon-fuzzer | 0x77494a8e | invariant_hubAddedSharesMatchesSpokeSum() | 645 | 3.46% |
| recon-fuzzer | 0xd3fabfac | iSpoke_withdraw_ASSERTION_WITHDRAW_DOS(uint256,uint256) | 642 | 3.45% |
| recon-fuzzer | 0x4896f9c3 | iHub_updateSpokeConfig(uint256,uint256,(uint40,uint40,uint24,bool,bool)) | 639 | 3.43% |
| recon-fuzzer | 0x44a0611b | iHub_setInterestRateData(uint256,(uint16,uint32,uint32,uint32)) | 633 | 3.40% |
Selector diagnostic findings
- INFO: i-034cb6720a6436703-recon-v0.4.18: peer-heuristic gap (diagnostic, not ground truth): absent 1 selector(s): 0xb0464fdc
- INFO: i-0ed8d9bccde77b824-recon-v0.4.18: peer-heuristic gap (diagnostic, not ground truth): absent 1 selector(s): 0xb0464fdc
Selector telemetry limitations
- i-01db3533f5c6c560f-foundry-git-02c05d9: Foundry selector distribution is unavailable because no persisted corpus was present; failure-event selectors are intentionally not used as a distribution
- i-0467b881cc0070621-foundry-git-02c05d9: Foundry selector distribution is unavailable because no persisted corpus was present; failure-event selectors are intentionally not used as a distribution
Statistical comparison (Mann-Whitney U and Vargha-Delaney A12)
Pairwise Mann-Whitney U tests and Vargha-Delaney A12 effect sizes on end-of-budget bug counts. The tests are two-sided, with Bonferroni correction applied for 6 comparison(s). Significance level: alpha = 0.05.
Warnings:
- One or more fuzzers have fewer than 5 runs. Statistical power may be limited.
| Fuzzer A | Fuzzer B | Median A | Median B | U statistic | A12 (A over B) | Effect magnitude | p-value | p (corrected) | Significant |
|---|---|---|---|---|---|---|---|---|---|
| recon-fuzzer | echidna | 11.5 | 10 | 3.5 | 0.875 | large | 0.4142 | 1.0000 | no |
| recon-fuzzer | medusa | 11.5 | 7 | 4.0 | 1.000 | large | 0.3333 | 1.0000 | no |
| recon-fuzzer | foundry | 11.5 | 6.5 | 4.0 | 1.000 | large | 0.3333 | 1.0000 | no |
| echidna | medusa | 10 | 7 | 4.0 | 1.000 | large | 0.3333 | 1.0000 | no |
| echidna | foundry | 10 | 6.5 | 4.0 | 1.000 | large | 0.3333 | 1.0000 | no |
| medusa | foundry | 7 | 6.5 | 2.5 | 0.625 | small | 1.0000 | 1.0000 | no |
No pairwise comparison reached significance after Bonferroni correction.
Note: A12 is the probability that a randomly selected Fuzzer A run has a higher final bug count than a randomly selected Fuzzer B run, counting ties as half. Values above 0.5 favor A, values below 0.5 favor B, and 0.5 means equal tendency. Magnitude thresholds by distance from 0.5 are negligible (<0.06), small (<0.14), medium (<0.21), and large (>=0.21). Small sample sizes (fewer than 5 runs) reduce statistical power. A12 and its magnitude label are descriptive; the thresholds are rules of thumb. Neither the effect size nor statistical significance establishes practical importance, causation, or performance beyond the observed runs.
Shape-based interpretation (rules of thumb)
- Fast-start / early-plateau: high early checkpoint median + early plateau time + low late discovery share.
- Steady: moderate AUC, later plateau, consistent improvements across checkpoints, moderate variance.
- Slow-burn / late-surge: low early checkpoints but high late discovery share and later plateau time; often higher final median.
Limitations
- Core count-based charts use normalized event identities stored under the legacy
bugs_foundcolumn. They do not count crash inputs, but they are not confirmed root-cause bug counts. - Use
known_bug_report.md,known_bug_summary.csv, andknown_bug_findings.csvfor evidence-backed known-bug hit rates; usebroken_invariants.md/broken_invariants.csvfor raw invariant identities. - Severity, exploitability, and root-cause uniqueness cannot be measured directly without richer per-bug metadata.
- Harness design still affects results; mitigate by keeping harness identical across fuzzers and reporting many runs.
Broken invariants
- Budget filter: 4.00h
- Events considered: 70 / 70
- Unique invariants: 12
Warning — trial run. This benchmark was executed with fewer than 10 instances per fuzzer and/or a time budget shorter than 24h. Results from trial runs are meant for debugging purposes and are not valid for extracting conclusions across different fuzzers.
Per-fuzzer totals
| Fuzzer | Invariants |
|---|---|
| echidna | 11 |
| foundry | 7 |
| medusa | 9 |
| recon-fuzzer | 12 |
High-level overlap
- Shared by all active fuzzers: 6
- Exclusive to
echidna: 0 - Exclusive to
foundry: 0 - Exclusive to
medusa: 0 - Exclusive to
recon-fuzzer: 1
Grouped invariants
Exclusive to echidna (0)
None.
Exclusive to foundry (0)
None.
Exclusive to medusa (0)
None.
Exclusive to recon-fuzzer (1)
iSpoke_supply
Shared by all active fuzzers (6)
assert_canaryiHub_mintFeeSharesinvariant_canaryinvariant_shouldNotBecomeLiquidatableinvariant_totalBorrowedLessThanSupplied_v0invariant_totalBorrowedLessThanSupplied_v1
Top shared subsets (top 3 by size):
echidna, medusa, recon-fuzzer (3)
iSpoke_liquidationCalliSpoke_repayiSpoke_withdraw
echidna, foundry, recon-fuzzer (1)
invariant_totalBorrowedLessThanSupplied_v2
echidna, recon-fuzzer (1)
invariant_supplySharePriceAndDrawnIndexMonotonic
Ground-truth known-bug mapping
Ground-truth mapping was not applied.
- Reason: run commit edd6c82721512540c8c90e7a36a4a8e19fd7bdf3 is not the evidence-pinned catalog revision 459b020058f4a65d18eb1481083b75c766340124
- Catalog:
benchmarks/known_bugs.json
No event was classified as a known bug. Raw event analysis remains available, but it must not be interpreted as a confirmed bug count.
Runner resource usage
- Budget filter: 4.00h
- Instances with metrics: 8
- Total samples: 22394
Per-fuzzer medians (across instances)
| Fuzzer | Instances | CPU active avg (%) | CPU active peak (%) | Memory used avg (GiB) | Memory used peak (GiB) | Memory used avg (%) | Memory used peak (%) |
|---|---|---|---|---|---|---|---|
| echidna | 2 | 94.99 | 97.65 | 19.16 | 19.76 | 62.53 | 64.47 |
| foundry | 2 | 99.15 | 100.00 | 1.05 | 3.79 | 3.41 | 12.35 |
| medusa | 2 | 98.10 | 99.64 | 1.55 | 3.76 | 5.07 | 12.27 |
| recon-fuzzer | 2 | 98.27 | 100.00 | 4.17 | 6.20 | 13.61 | 20.23 |
Instance stats
| Instance | Fuzzer | Samples | Duration (h) | CPU active avg (%) | CPU active peak (%) | Memory avg (GiB) | Memory peak (GiB) | Memory avg (%) | Memory peak (%) |
|---|---|---|---|---|---|---|---|---|---|
| i-01c1f3bff75608e5e-echidna-v2.3.2 | echidna | 2783 | 4.00 | 94.71 | 97.43 | 19.26 | 19.97 | 62.84 | 65.15 |
| i-024af362fccb49540-echidna-v2.3.2 | echidna | 2783 | 4.00 | 95.26 | 97.86 | 19.07 | 19.55 | 62.22 | 63.78 |
| i-01db3533f5c6c560f-foundry-git-02c05d9 | foundry | 2809 | 4.00 | 99.14 | 100.00 | 1.05 | 3.86 | 3.42 | 12.61 |
| i-0467b881cc0070621-foundry-git-02c05d9 | foundry | 2809 | 4.00 | 99.16 | 100.00 | 1.04 | 3.71 | 3.41 | 12.09 |
| i-05df0296ef97b51ba-medusa-v1.5.1 | medusa | 2807 | 4.00 | 98.10 | 99.63 | 1.55 | 3.75 | 5.07 | 12.23 |
| i-0ebbecf47656b1194-medusa-v1.5.1 | medusa | 2808 | 4.00 | 98.11 | 99.65 | 1.55 | 3.77 | 5.07 | 12.32 |
| i-034cb6720a6436703-recon-v0.4.18 | recon-fuzzer | 2798 | 4.00 | 98.27 | 100.00 | 4.17 | 6.26 | 13.62 | 20.42 |
| i-0ed8d9bccde77b824-recon-v0.4.18 | recon-fuzzer | 2797 | 4.00 | 98.27 | 100.00 | 4.17 | 6.14 | 13.59 | 20.04 |
Manifest
- scfuzzbench_commit:
00775ce0bd3a33b7bf8e9ff213e2e7c235163220 - target_repo_url: https://github.com/scfuzzbench/aave-v4-scfuzzbench
- target_commit:
edd6c82721512540c8c90e7a36a4a8e19fd7bdf3 - benchmark_type:
property - instance_type:
c6a.4xlarge - instances_per_fuzzer:
2 - timeout_hours:
4 - aws_region:
us-east-1 - ubuntu_ami_id:
ami-052355af2a014bd2c - foundry_version:
1.7.2-dev - foundry_git_repo:
https://github.com/foundry-rs/foundry - foundry_git_ref:
02c05d970d2801da0aef8b82486ce84b01ede36d - foundry_source_patch:
scfuzzbench-throughput-progress-v1@sha256:2ee9e69b77c8007c78c816eb9ca791684aa5ecede0651b63f86cdd2e055eb17e - echidna_version:
2.3.2 - medusa_version:
1.5.1 - recon_version:
0.4.18 - fuzzer_keys:
echidna, foundry, medusa, recon-fuzzer
Artifacts
Manifest (index): https://scfuzzbench-logs-185f44d6.s3.us-east-1.amazonaws.com/runs/gh-30059118265-1/a0a57a3e0b5b533094f20079e9a9b7ef/manifest.json
Report prefix: https://scfuzzbench-logs-185f44d6.s3.us-east-1.amazonaws.com/analysis/a0a57a3e0b5b533094f20079e9a9b7ef/gh-30059118265-1/
Broken invariants (Markdown): https://scfuzzbench-logs-185f44d6.s3.us-east-1.amazonaws.com/analysis/a0a57a3e0b5b533094f20079e9a9b7ef/gh-30059118265-1/broken_invariants.md
Broken invariants (CSV): https://scfuzzbench-logs-185f44d6.s3.us-east-1.amazonaws.com/analysis/a0a57a3e0b5b533094f20079e9a9b7ef/gh-30059118265-1/broken_invariants.csv
Ground-truth known bugs (Markdown): https://scfuzzbench-logs-185f44d6.s3.us-east-1.amazonaws.com/analysis/a0a57a3e0b5b533094f20079e9a9b7ef/gh-30059118265-1/known_bug_report.md
Ground-truth summary (CSV): https://scfuzzbench-logs-185f44d6.s3.us-east-1.amazonaws.com/analysis/a0a57a3e0b5b533094f20079e9a9b7ef/gh-30059118265-1/known_bug_summary.csv
Ground-truth findings (CSV): https://scfuzzbench-logs-185f44d6.s3.us-east-1.amazonaws.com/analysis/a0a57a3e0b5b533094f20079e9a9b7ef/gh-30059118265-1/known_bug_findings.csv
Throughput summary (CSV): https://scfuzzbench-logs-185f44d6.s3.us-east-1.amazonaws.com/analysis/a0a57a3e0b5b533094f20079e9a9b7ef/gh-30059118265-1/throughput_summary.csv
Progress metrics summary (CSV): https://scfuzzbench-logs-185f44d6.s3.us-east-1.amazonaws.com/analysis/a0a57a3e0b5b533094f20079e9a9b7ef/gh-30059118265-1/progress_metrics_summary.csv
Function selector distribution (CSV): https://scfuzzbench-logs-185f44d6.s3.us-east-1.amazonaws.com/analysis/a0a57a3e0b5b533094f20079e9a9b7ef/gh-30059118265-1/selector_distribution.csv
Function selector summary and health (JSON): https://scfuzzbench-logs-185f44d6.s3.us-east-1.amazonaws.com/analysis/a0a57a3e0b5b533094f20079e9a9b7ef/gh-30059118265-1/selector_summary.json
Runner resource usage (Markdown): https://scfuzzbench-logs-185f44d6.s3.us-east-1.amazonaws.com/analysis/a0a57a3e0b5b533094f20079e9a9b7ef/gh-30059118265-1/runner_resource_usage.md
Runner resource summary (CSV): https://scfuzzbench-logs-185f44d6.s3.us-east-1.amazonaws.com/analysis/a0a57a3e0b5b533094f20079e9a9b7ef/gh-30059118265-1/runner_resource_summary.csv
Runner resource timeseries (CSV): https://scfuzzbench-logs-185f44d6.s3.us-east-1.amazonaws.com/analysis/a0a57a3e0b5b533094f20079e9a9b7ef/gh-30059118265-1/runner_resource_timeseries.csv
Analysis bundle: https://scfuzzbench-logs-185f44d6.s3.us-east-1.amazonaws.com/analysis/a0a57a3e0b5b533094f20079e9a9b7ef/gh-30059118265-1/bundles/analysis.zip
Raw logs prefix: https://scfuzzbench-logs-185f44d6.s3.us-east-1.amazonaws.com/logs/gh-30059118265-1/a0a57a3e0b5b533094f20079e9a9b7ef/
Raw corpus prefix: https://scfuzzbench-logs-185f44d6.s3.us-east-1.amazonaws.com/corpus/gh-30059118265-1/a0a57a3e0b5b533094f20079e9a9b7ef/
