[2602.01317] TxRay: Agentic Postmortem of Live Blockchain Attacks

[2602.01317] TxRay: Agentic Postmortem of Live Blockchain Attacks

arXiv - AI 4 min read Article

Summary

TxRay is a novel system that automates the postmortem analysis of live blockchain attacks, significantly improving the speed and accuracy of identifying exploit root causes and generating proof of concepts.

Why It Matters

As decentralized finance (DeFi) continues to grow, the frequency and impact of blockchain exploits have escalated. TxRay addresses the critical need for efficient postmortem analysis, enabling faster recovery and enhanced security measures, which is vital for the integrity of financial systems built on blockchain technology.

Key Takeaways

  • TxRay reconstructs blockchain attack lifecycles from limited evidence.
  • The system achieves a 92.11% end-to-end reproduction rate for exploit incidents.
  • TxRay's oracle-validated proofs of concept enhance attack imitation and coverage.
  • The tool significantly reduces postmortem analysis time to under an hour.
  • TxRay addresses the growing need for automated security solutions in the DeFi space.

Computer Science > Cryptography and Security arXiv:2602.01317 (cs) [Submitted on 1 Feb 2026 (v1), last revised 23 Feb 2026 (this version, v5)] Title:TxRay: Agentic Postmortem of Live Blockchain Attacks Authors:Ziyue Wang, Jiangshan Yu, Kaihua Qin, Dawn Song, Arthur Gervais, Liyi Zhou View a PDF of the paper titled TxRay: Agentic Postmortem of Live Blockchain Attacks, by Ziyue Wang and 5 other authors View PDF HTML (experimental) Abstract:Decentralized Finance (DeFi) has turned blockchains into financial infrastructure, allowing anyone to trade, lend, and build protocols without intermediaries, but this openness exposes pools of value controlled by code. Within five years, the DeFi ecosystem has lost over 15.75B USD to reported exploits. Many exploits arise from permissionless opportunities that any participant can trigger using only public state and standard interfaces, which we call Anyone-Can-Take (ACT) opportunities. Despite on-chain transparency, postmortem analysis remains slow and manual: investigations start from limited evidence, sometimes only a single transaction hash, and must reconstruct the exploit lifecycle by recovering related transactions, contract code, and state dependencies. We present TxRay, a Large Language Model (LLM) agentic postmortem system that uses tool calls to reconstruct live ACT attacks from limited evidence. Starting from one or more seed transactions, TxRay recovers the exploit lifecycle, derives an evidence-backed root cause, and generate...

Related Articles

Ai Agents

Considering NeurIPS submission [D]

Wondering if it worth submitting paper I’m working on to NeurIPS. I have formal mathematical proof for convergence of a novel agentic sys...

Reddit - Machine Learning · 1 min ·
Ai Agents

Agent frameworks waste ~350,000+ tokens per session resending static files. 95% reduction benchmarked.

Measured the actual token waste on a local Qwen 3.5 122B setup. The numbers are unreal. Found a compile-time approach that cuts query con...

Reddit - Artificial Intelligence · 1 min ·
OpenClaw gives users yet another reason to be freaked out about security - Ars Technica
Ai Agents

OpenClaw gives users yet another reason to be freaked out about security - Ars Technica

The viral AI agentic tool let attackers silently gain admin unauthenticated access.

Ars Technica - AI · 5 min ·
Robotics

What happens when you let AI agents run a sitcom 24/7 with zero human involvement

Ran an experiment — gave AI agents full control over writing, character creation, and performing a sitcom. Left it running nonstop for ov...

Reddit - Artificial Intelligence · 1 min ·
More in Ai Agents: This Week Guide Trending

No comments

No comments yet. Be the first to comment!

Stay updated with AI News

Get the latest news, tools, and insights delivered to your inbox.

Daily or weekly digest • Unsubscribe anytime