Gibran Gómez, Kevin van Liebergen, Davide Sanvito, Giuseppe Siracusano ¡ 6 authors
Cryptocurrency abuse reporting services are a valuable data source about abusive blockchain addresses, prevalent types of cryptocurrency abuse, and their financial impact on victims. However, they may suffer data pollution due to their crowd-sourced nature. This work analyzes the extent and impact of data pollution in cryptocurrency abuse reporting services and proposes a novel LLM-based defense to address the pollution. We collect 289K abuse reports submitted over 6 years to two popular services and use them to answer three research questions. RQ1 analyzes the extent and impact of pollution. We show that spam reports will eventually flood unchecked abuse reporting services, with BitcoinAbuse receiving 75% of spam before stopping operations. We build a public dataset of 19,443 abuse reports labeled with 19 popular abuse types and use it to reveal the inaccuracy of user-reported abuse types. We identified 91 (0.1%) benign addresses reported, responsible for 60% of all the received funds. RQ2 examines whether we can automate identifying valid reports and their classification into abuse types. We propose an unsupervised LLM-based classifier that achieves an F1 score of 0.95 when classifying reports, an F1 of 0.89 when classifying out-of-distribution data, and an F1 of 0.99 when identifying spam reports. Our unsupervised LLM-based classifier clearly outperforms two baselines: a supervised classifier and a naive usage of the LLM. Finally, RQ3 demonstrates the usefulness of our LLM-based classifier for quantifying the financial impact of different cryptocurrency abuse types. We show that victim-reported losses heavily underestimate cybercriminal revenue by estimating a 29 times higher revenue from deposit transactions. We identified that investment scams have the highest financial impact and that extortions have lower conversion rates but compensate for them with massive email campaigns.
Smart contracts, self-executing agreements directly encoded in code, are fundamental to blockchain technology, especially in decentralized finance (DeFi) and Web3. However, the rise of Ponzi schemes in smart contracts poses significant risks, leading to substantial financial losses and eroding trust in blockchain systems. Existing detection methods, such as PonziGuard, depend on large amounts of labeled data and struggle to identify unseen Ponzi schemes, limiting their reliability and generalizability. In contrast, we introduce PonziSleuth, the first LLM-driven approach for detecting Ponzi smart contracts, which requires no labeled training data. PonziSleuth utilizes advanced language understanding capabilities of LLMs to analyze smart contract source code through a novel two-step zero-shot chain-of-thought prompting technique. Our extensive evaluation on benchmark datasets and real-world contracts demonstrates that PonziSleuth delivers comparable, and often superior, performance without the extensive data requirements, achieving a balanced detection accuracy of 96.06% with GPT-3.5-turbo, 93.91% with LLAMA3, and 94.27% with Mistral. In real-world detection, PonziSleuth successfully identified 15 new Ponzi schemes from 4,597 contracts verified by Etherscan in March 2024, with a false negative rate of 0% and a false positive rate of 0.29%. These results highlight PonziSleuth's capability to detect diverse and novel Ponzi schemes, marking a significant advancement in leveraging LLMs for enhancing blockchain security and mitigating financial scams.
The web3 applications have recently been growing, especially on the Ethereum platform, starting to become the target of scammers. The web3 scams, imitating the services provided by legitimate platforms, mimic regular activity to deceive users. The current phishing account detection tools utilize graph learning or sampling algorithms to obtain graph features. However, large-scale transaction networks with temporal attributes conform to a power-law distribution, posing challenges in detecting web3 scams. In this paper, we present ScamSweeper, a novel framework to identify web3 scams on Ethereum. Furthermore, we collect a large-scale transaction dataset consisting of web3 scams, phishing, and normal accounts. Our experiments indicate that ScamSweeper exceeds the state-of-the-art in detecting web3 scams.
Ensuring the absence of vulnerabilities or flaws in smart contracts before their deployment is crucial for the smooth progress of subsequent work. Existing detection methods heavily rely on expert rules, resulting in low robustness and accuracy. Therefore, we propose EDSCVD, an enhanced deep learning vulnerability detection model based on dual-channel networks. Firstly, the contract fragments are preprocessed by BERT into the required word embeddings. Next, we utilized adversarial training FGM to the word embeddings to generate perturbations, thereby producing symmetric adversarial samples and enhancing the robustness of the model. Then, the dual-channel model combining BiLSTM and CNN is utilized for feature training to obtain more comprehensive and symmetric information on temporal and local contract features.Finally, the combined output features are passed through a classifier to classify and detect contract vulnerabilities. Experimental results show that our EDSCVD exhibits excellent detection performance in the detection of classical reentrancy vulnerabilities, timestamp dependencies, and integer overflow vulnerabilities.
Web3, also known as the Decentralized Web, is a vision for the next generation of Web applications, supported by blockchain technology, where users have stronger ownership over their data and identity. One of the key components in Web3 is wallets, which hold a userâs public and private keys, manage digital tokens, and sign transaction details. Despite their significance in securely managing digital identities, wallets also introduce vulnerabilities that, if overlooked, can compromise usersâ privacy and security, particularly during data exchange with network endpoints. We investigate how popular wallets like MetaMask can inadvertently expose sensitive information to RPC endpoints, even when no transactions are made. Additionally, we examine the confidentiality risks associated with the registration requirements of major node providers, highlighting how the collection of personal and financial details can further threaten user privacy. We briefly report on ongoing work in analyzing the characteristics of wallets across various blockchain networks to identify key security and privacy features that can be integrated into new wallet designs. This research aims to address the challenges inherent in wallet security and privacy within Web3.
Marco Ortu, Giacomo Ibba, Giuseppe Destefanis, Claudio Conversano ¡ 5 authors
The expansion of smart contracts on the Ethereum blockchain has created a diverse ecosystem of decentralized applications. This growth, however, poses challenges in classifying and securing these contracts. Existing research often separately addresses either classification or vulnerability detection, without a comprehensive analysis of how contract types are related to security risks. Our study addresses this gap by developing a taxonomy of smart contracts and examining the potential vulnerabilities associated with each category. We use the Latent Dirichlet Allocation (LDA) model to analyze a dataset of over 100,040 Ethereum smart contracts, which is notably larger than those used in previous studies. Our analysis categorizes these contracts into eleven groups, with five primary categories: Notary, Token, Game, Financial, and Blockchain interaction. This categorization sheds light on the various functions and applications of smart contracts in today's blockchain environment. In response to the growing need for better security in smart contract development, we also investigate the link between these categories and common vulnerabilities. Our results identify specific vulnerabilities associated with different contract types, providing valuable insights for developers and auditors. This relationship between contract categories and vulnerabilities is a new contribution to the field, as it has not been thoroughly explored in previous research. Our findings offer a detailed taxonomy of smart contracts and practical recommendations for enhancing security. By understanding how contract categories correlate with vulnerabilities, developers can implement more effective security measures, and auditors can better prioritize their reviews. This study advances both academic knowledge of smart contracts and practical strategies for securing decentralized applications on the Ethereum platform.
Peter Howson, Antulio Rosales, Olivier Jutel, Inte Gloerich ¡ 8 authors
This paper explores how so-called âWeb3â blockchain projects are materially and socially constituted. A blockchain is an append-only distributed database. The technology is being hyped as applicable for a whole range of industries, social service provisions, and as a fix for economic disparities in communities left behind by mainstream financial systems. Drawing on case studies from our ongoing research we explain how, despite being virtual, Web3 projects are dependent on clearly defined spaces of production from which they derive their speculative value. We conceptualise this relationship as Crypto/Space, where space and blockchain software are mutually constituted. We consider how Crypto/Spaces are produced in three ways: 1) how project developers are adopting a parasitic relationship with host locations to appropriate energy, infrastructure, and local resources; 2) how projects enable âvirtual land grabsâ where developers are engaging in land acquisitions, and associated displacement of local people, with no real intention to use the land for the declared purpose; and 3) how blockchain technology and speculative finance imaginaries are inspiring new anarcho-capitalist crypto-utopian âExit zonesâ, often in the Global South. Far from being a zero-sum virtual game world, we argue that cryptocurrency projects are parasitic, often requiring predation on poor and otherwise marginalised communities to appropriate resources, onboard new users and enable favourable regulation.
Like any other useful technology, cryptocurrencies are sometimes used for criminal activities. While transactions are recorded on the blockchain, there exists a need for a more rapid and scalable method to detect addresses associated with fraudulent activities. We present RiskSEA, a scalable risk scoring system capable of effectively handling the dynamic nature of large-scale blockchain transaction graphs. The risk scoring system, which we implement for Ethereum, consists of 1. a scalable approach to generating node2vec embedding for entire set of addresses to capture the graph topology 2. transaction-based features to capture the transactional behavioral pattern of an address 3. a classifier model to generate risk score for addresses that combines the node2vec embedding and behavioral features. Efficiently generating node2vec embedding for large scale and dynamically evolving blockchain transaction graphs is challenging, we present two novel approaches for generating node2vec embeddings and effectively scaling it to the entire set of blockchain addresses: 1. node2vec embedding propagation and 2. dynamic node2vec embedding. We present a comprehensive analysis of the proposed approaches. Our experiments show that combining both behavioral and node2vec features boosts the classification performance significantly, and that the dynamic node2vec embeddings perform better than the node2vec propagated embeddings.
⢠Study analyzes victim reports to understand cryptocurrency scam mechanics and prevention strategies. ⢠Seven scam dimensions: techniques, tools, victim profiling, consequences, info harvesting, manipulation, and culture. ⢠The âCrypto-Cognitive Exploitation Modelâ (CCEM) is to explain cryptocurrency scam dynamics. ⢠Findings show cryptocurrency scams evolve, needing ongoing research and countermeasure adaptation. ⢠Key recommendations focus on digital strategies and regulatory frameworks to prevent cryptocurrency scams. The rising prominence of cryptocurrency in global finance has unfortunately rendered it a prime target for scams, leading to significant financial losses. This study employs Cognitive Vulnerability Theory and the Social Engineering Approach to examine the dimensions, consequences, and prevention strategies of cryptocurrency scams. We analyzed data from the U.S. Department of Financial Protection and Innovation (DFPI), focusing on the dimensions of scams within the digital landscape and the efficacy of digital strategies and regulations in mitigating them. Our findings reveal seven critical dimensions of cryptocurrency scams and introduce the âCrypto-Cognitive Exploitation Modelâ (CCEM), which integrates theoretical insights with the unique aspects of these scams. Quantitative analysis indicates that fraudulent trading platform scams are the most prevalent, often intertwined with pig butchering scams, highlighting the complex, multifaceted nature of these fraudulent activities. We demonstrate the practical application of our recommendations, bridging theory and practice in scam mitigation. The study concludes with strategic recommendations for tailored digital approaches and enhanced regulatory mechanisms to combat evolving deceptive practices.
The spread and use of cryptocurrencies (digital currency) in Russia and globally is increasing significantly every year. As the cryptocurrency market has grown, its criminal component has also grown at the same time. The number and degree of public danger of crimes where cryptocurrency acts as an object, aim or means of crime is steadily increasing. Civil and arbitration disputes over cryptocurrencies are also on the rise. Consequently, there is an objective need to effectively protect the interests of victims from criminal offenses, investigate relevant crimes and resolve disputes. Addressing these issues is impossible without the assistance of cryptocurrency specialists. The article formulates a definition of cryptocurrency crime, analyzes the challenges of using cryptocurrencies, ranging from the incomplete regulatory framework of its circulation to the lack of expertise among most practicing lawyers. It investigates and summarizes the conflicting practices in terms of requirements for cryptocurrency specialists, their conditions and procedure of their involvement in various legal proceedings. The prevalence of incompetence and dishonesty among individuals and companies offering services in the crypto market is noted, and appropriate warnings are put forth. The study systematizes and describes typical criminal, investigative and judicial scenarios where the expertise of a cryptocurrency specialist is necessary. It also provides conclusions and recommendations on organizing and strategizing interaction with cryptocurrency specialists in the interests of victims (including organizations), investigative authorities and/or the court. The conclusion summarizes the roles of cryptocurrency research specialists in various stages and legal proceedings (criminal, civil and arbitration) from oral and written consultations, preparation of specialist opinions to participation in investigative actions, court hearings and negotiations between conflicting parties. The research incorporates both general and specific scientific methodologies such as system-structural analysis, formal-logical extrapolation, document analysis, statistical analysis, prognostic and interviewing techniques.
Dongcheng Li, W. Eric Wong, Xiaodan Wang, Sean Pan ¡ 5 authors
This paper introduces a method for detecting vulnerabilities in smart contracts using static analysis and a multi-objective optimization algorithm. We focus on four types of vulnerabilities: reentrancy, call stack overflow, integer overflow, and timestamp dependencies. Initially, smart contracts are compiled into an abstract syntax tree to analyze relationships between contracts and functions, including calls, inheritance, and data flow. These analyses are transformed into static evaluations and intermediate representations that reveal internal relations. Based on these representations, we examine contract's functions, variables, and data dependencies to detect the specified vulnerabilities. To enhance detection accuracy and coverage, we apply a multi-objective optimization algorithm to the static analysis process. This involves assigning initial numeric values to input data and monitoring changes in statement coverage and detection accuracy. Using coverage and accuracy as fitness values, we calculate Pareto front and crowding distance values to select the best individuals for the new parent population, iterating until optimization criteria are met. We validate our approach using an open-source dataset collected from Etherscan, containing 6,693 smart contracts. Experimental results show that our method outperforms state-of-the-art tools in terms of coverage, accuracy, efficiency, and effectiveness in detecting the targeted vulnerabilities.
The objective of this research is to determine the impact of geopolitical developments on Bitcoin's value. It focuses on the events that occurred from October 7, 2023 including the attack on Israel by the militant group Hamas, the tension between Iran and Israel, and the conflict between Palestine and the US. Through a comprehensive event study, we can analyze the returns generated by these events. The results of the study Srevealed that Bitcoin performed well during the adjustment and anticipation periods, which showed that it could be a safe-haven asset. On the other hand, the negative AAR during the event day reflected the market's first reaction. The study also highlighted Bitcoin's dual nature as a speculative asset and a safe-haven asset providing investors with a deeper understanding of the risks that affect the cryptocurrency market.
Zhibo Wang, Liu Guoming, Hongzhen Xu, Shengyu You ¡ 6 authors
Smart contracts play an essential role in the handling and management of digital assets, where vulnerabilities can lead to severe security issues and financial losses. Current detection techniques are largely limited to identifying single vulnerabilities and lack comprehensive identification capabilities for multiple vulnerabilities that may coexist in smart contracts. To address this challenge, we propose a novel multi-label vulnerability detection model that integrates extractive summarization methods with deep learning, referred to as Ext-ttg. The model begins by preprocessing the data using an extractive summarization approach, followed by the deployment of a custom-built deep learning model to detect vulnerabilities in smart contracts. Experimental results demonstrate that our method achieves commendable performance across various metrics, establishing the effectiveness of the proposed approach in the multi-vulnerability detection tasks within smart contracts.
The use of smart contracts in areas such as finance, supply chain management, and the Internet of Things has significantly advanced blockchain technology. However, once deployed on the blockchain, smart contracts cannot be modified or revoked. Any vulnerabilities can lead to severe economic losses and data breaches, making pre-deployment vulnerability detection critically important. Traditional smart contract vulnerability detection methods suffer from low accuracy and limited reusability across different scenarios. To enhance detection capabilities, this paper proposes a smart contract vulnerability detection method based on heterogeneous contract semantic graphs and pre-training techniques. Compared to the conventional graph structures used in existing methods, heterogeneous contract semantic graphs contain richer contract information. By integrating these with pre-trained models, our method exhibits stronger vulnerability capture and generalization capabilities. Experimental results show that this method has improved the accuracy, recall, precision, and F1 value in the detection of four widely existing and harmful smart contract vulnerabilities compared with existing methods, which greatly improves the detection ability of smart contract vulnerabilities.
Ljudi danas sve ÄeĹĄÄe traĹže naÄine kako izaÄi iz svojih rutina i unijeti promjene. Svijet se dugo vremena fokusirao na dionice i obveznice, no one viĹĄe nisu vrlo inovativne i postale su optereÄujuÄe. Prije nekoliko godina pojavilo se neĹĄto ĹĄto je fasciniralo ljude diljem svijeta: kriptovalute. One su radikalno promijenile financijski krajolik. MeÄutim, takoÄer su pokrenule niz pitanja, poput toga kako im financijski pristupiti. Mnoge zemlje joĹĄ uvijek nisu sigurne kako najbolje oporezivati i kategorizirati kriptovalute. U ovom radu se analizira trenutaÄno stanje i uloga kriptovaluta u financijskom sustavu Hrvatske. U radu se pruĹža pregled tehnoloĹĄkih napredaka koji su doprinijeli razvoju i koriĹĄtenju kriptovaluta poput Bitcoina i Ethereuma, kao i njihovoj sve veÄoj prisutnosti u privatnim i poslovnim transakcijama. UnatoÄ nedostatku sveobuhvatne zakonske regulacije, interes pojedinaca i poduzeÄa za kriptovalute raste. U istraĹživanju se takoÄer analizira pravno okruĹženje, prihvaÄenost kriptovaluta meÄu korisnicima te njihov utjecaj na financijsku industriju i cjelokupno gospodarstvo Hrvatske. Studija ispituje potencijalne propise za buduÄi rast ovog sektora te pruĹža uvid u prednosti i izazove koje kriptovalute donose u hrvatski financijski sustav. ZakljuÄno, provedeno je istraĹživanje koje Äe dati opĹĄirniji uvid u stvarno poznavanje kriptovaluta i na koji naÄin bi se one mogle viĹĄe koristit.
Cedrick Agorbia-Atta, Imande Atalor, Rita Korkor Agyei, Richard Nachinaba
This study addresses the critical issue of terrorist financing through cryptocurrency platforms, a growing concern due to digital currencies' pseudonymous nature and global reach. The research explores the strategic role of Artificial Intelligence (AI) and Machine Learning (ML) in identifying, preventing, and disrupting the flow of illicit funds used to finance terrorism. Employing a mixed-methods approach, the study integrates qualitative case studies of documented instances of cryptocurrency-based terrorist financing with quantitative data analysis from significant cryptocurrency exchanges. Advanced AI and ML algorithms, including supervised learning models such as decision trees and neural networks, were applied to detect suspicious transactions indicative of terrorist activities. The findings reveal that AI and ML technologies significantly enhance the ability to identify patterns of terrorist financing within large and complex datasets, with models achieving precision and recall rates exceeding 90%. However, challenges remain, particularly regarding the quality and standardization of data across platforms, algorithmic biases, and the need for continuous updates to counter evolving tactics used by terrorist organizations. The study concludes that AI and ML present powerful tools for enhancing financial security. However, their successful implementation requires overcoming these challenges through collaborative efforts among stakeholders, including financial institutions, regulators, and technology providers. This research contributes to the growing field of economic crime prevention by offering a robust framework for integrating AI-driven solutions into the fight against terrorist financing on cryptocurrency platforms.
We examine cryptocurrency fraud cases prosecuted by Nigeria's Economic and Financial Crimes Commission (EFCC). We considered the lens of the Space Transition Theory (STT) in exploring the dynamics of these digital crimes. Our data analysis reveals common types of fraud, including cryptocurrency investment schemes. The results show an exclusive male demographic (100%), with the majority under 30 years old and only a quarter possessing a degree, providing insights into the socio-demographic characteristics of cryptocurrency fraudsters. Additionally, while most fraudsters (55%) targeted victims in the United States, Bitcoin, leveraging blockchain technology, was the most commonly used method (46%) for cryptocurrency fraud. Our examination of the methods and mediums used for cryptocurrency fraud supports some aspects of STT, while others do not. We advocate for a multifaceted strategy that prioritises stringent regulation, implementation, and heightened scrutiny of digital currency ecosystems in Nigeria and beyond. This study contributes to the broader discourse on cybercrime prevention and enforcement by emphasising the novel methodological approach utilised.
Abstract To address the challenges of internal security policy compliance and dynamic threat response in organizations, we present a novel framework that integrates artificial intelligence (AI), blockchain, and smart contracts. We propose a system that automates the enforcement of security policies, reducing manual effort and potential human error. Utilizing AI, we can analyse cyber threat intelligence rapidly, identify non-compliances and automatically adjust cyber defence mechanisms. Blockchain technology provides an immutable ledger for transparent logging of compliance actions, while smart contracts ensure uniform application of security measures. The frameworkâs effectiveness is demonstrated through simulations, showing improvements in compliance enforcement rates and response times compared to traditional methods. Ultimately, our approach provides for a scalable solution for managing complex security policies, reducing costs and enhancing the efficiency while achieving compliance. Finally, we discuss practical implications and propose future research directions to further refine the system and address implementation challenges.
Ethereum faces growing fraud threats. Current fraud detection methods, whether employing graph neural networks or sequence models, fail to consider the semantic information and similarity patterns within transactions. Moreover, these approaches do not leverage the potential synergistic benefits of combining both types of models. To address these challenges, we propose TLMG4Eth that combines a transaction language model with graph-based methods to capture semantic, similarity, and structural features of transaction data in Ethereum. We first propose a transaction language model that converts numerical transaction data into meaningful transaction sentences, enabling the model to learn explicit transaction semantics. Then, we propose a transaction attribute similarity graph to learn transaction similarity information, enabling us to capture intuitive insights into transaction anomalies. Additionally, we construct an account interaction graph to capture the structural information of the account transaction network. We employ a deep multi-head attention network to fuse transaction semantic and similarity embeddings, and ultimately propose a joint training approach for the multi-head attention network and the account interaction graph to obtain the synergistic benefits of both.
Hany F. Atlam, Ndifon Ekuri, Muhammad Ajmal Azad, Harjinder Singh Lallie
Blockchain technology has gained significant attention in recent years for its potential to revolutionize various sectors, including finance, supply chain management, and digital forensics. While blockchainâs decentralization enhances security, it complicates the identification and tracking of illegal activities, making it challenging to link blockchain addresses to real-world identities. Also, although immutability protects against tampering, it introduces challenges for forensic investigations as it prevents the modification or deletion of evidence, even if it is fraudulent. Hence, this paper provides a systematic literature review and examination of state-of-the-art studies in blockchain forensics to offer a comprehensive understanding of the topic. This paper provides a comprehensive investigation of the fundamental principles of blockchain forensics, exploring various techniques and applications for conducting digital forensic investigations in blockchain. Based on the selected search strategy, 46 articles (out of 672) were chosen for closer examination. The contributions of these articles were discussed and summarized, highlighting their strengths and limitations. This paper examines the selected papers to identify diverse digital forensic frameworks and methodologies used in blockchain forensics, as well as how blockchain-based forensic solutions have enhanced forensic investigations. In addition, this paper discusses the common applications of blockchain-based forensic frameworks and examines the associated legal and regulatory challenges encountered in conducting a forensic investigation within blockchain systems. Open issues and future research directions of blockchain forensics were also discussed. This paper provides significant value for researchers, digital forensic practitioners, and investigators by providing a comprehensive and up-to-date review of existing research and identifying key challenges and opportunities related to blockchain forensics.
This study explores the application of deep learning and machine learning technologies in the field of Anti-Money Laundering (AML) for cryptocurrencies.With the rapid growth of cryptocurrency markets, the associated money laundering activities have increasingly become a focal point for governments and financial institutions worldwide.Traditional AML measures face challenges in the digital realm, particularly in identifying and preventing illicit transactions involving cryptocurrencies.To address this, the study designs various algorithms including Deep Neural Networks (DNN), Random Forest (RF), K-Nearest Neighbors (KNN), and Naive Bayes (NB) to enhance the detection capabilities of suspicious transactions within the Bitcoin Elliptic dataset.Cryptocurrencies involve using cryptographic security measures for financial transactions, yet their anonymity and transnational nature make them susceptible to money laundering activities.By evaluating the performance of different machine learning models on the Bitcoin Elliptic dataset, this research analyzes their effectiveness in identifying illicit transactions.The results indicate that the Random Forest model performs best, achieving an overall accuracy of 95%, effectively distinguishing between most illegal and legal transactions while mitigating overfitting risks.Through these technological approaches, the study aims to enhance AML monitoring capabilities in cryptocurrency markets, providing reliable decision support for financial institutions and regulatory bodies.Future research directions may include exploring more complex deep learning models or ensemble learning methods to further improve classification accuracy across diverse datasets and enable real-time monitoring of emerging money laundering patterns.The integration of these technologies holds promise for strengthening the global AML framework, addressing the increasingly complex challenges posed by digital finance and illicit financial activities (
Ruichao Liang, Jing Chen, Cong Wu, Kun He ¡ 9 authors
Smart contracts, the cornerstone of decentralized applications, have become increasingly prominent in revolutionizing the digital landscape. However, vulnerabilities in smart contracts pose great risks to user assets and undermine overall trust in decentralized systems. Fuzzing, a prominent security testing technique, is extensively explored to detect vulnerabilities. But current smart contract fuzzers fall short of expectations in testing efficiency for two primary reasons. Firstly, smart contracts are stateful programs, and existing approaches, primarily coverage-guided, lack effective feedback from the contract state. Consequently, they struggle to effectively explore the contract state space. Secondly, coverage-guided fuzzers, aiming for comprehensive program coverage, may lead to a wastage of testing resources on benign code areas. This wastage worsens in smart contract testing, as the mix of code and state spaces further complicates comprehensive testing. To address these challenges, we propose Vulseye, a stateful directed graybox fuzzer for smart contracts guided by vulnerabilities. Different from prior works, Vulseyeachieves stateful directed fuzzing by prioritizing testing resources to code areas and contract states that are more prone to vulnerabilities. We introduceCode TargetsandState Targetsinto fuzzing loops as the testing targets of Vulseye. We use static analysis and pattern matching to pinpointCode Targets, and propose a scalable backward analysis algorithm to specifyState Targets. We design a novel fitness metric that leverages feedback from both the contract code space and state space, directing fuzzing toward these targets. With the guidance of code and state targets, Vulseyealleviates the wastage of testing resources on benign code areas and achieves effective stateful fuzzing. In comparison with state-of-the-art fuzzers, Vulseyedemonstrated superior effectiveness and efficiency. Notably, it uncovered 4,845 vulnerabilities in 42,738 real-world smart contracts, outperforming existing approaches by up to$9.7\times $, and identified 11 previously unknown vulnerabilities within the top 50 Ethereum DApps, involving approximately 2,500,000 USD.
Due to its anonymity and decentralization, Bitcoin has long been a haven for various illegal activities. Cyber-criminals generally legalize illicit funds by Bitcoin mixing services. Therefore, it is critical to investigate the mixing services in cryptocurrency anti-money laundering. Existing studies treat different mixing services as a class of suspicious Bitcoin entities. Furthermore, they are limited by relying on expert experience or needing to deal with large-scale networks. So far, multi-class mixing service identification has not been explored yet. It is challenging since mixing services share a similar procedure, presenting no sharp distinctions. However, mixing service identification facilitates the healthy development of Bitcoin, supports financial forensics for cryptocurrency regulation and legislation, and provides technical means for fine-grained blockchain supervision. This paper aims to achieve multi-class Bitcoin Mixing Service Identification with a Graph Classification (BMSI-GC) model. First, BMSI-GC constructs 2-hop ego networks (2-egonets) of mixing services based on their historical transactions. Second, it applies graph2vec, a graph classification model mainly used to calculate the similarity between graphs, to automatically extract address features from the constructed 2-egonets. Finally, it trains a multilayer perceptron classifier to perform classification based on the extracted features. BMSI-GC is flexible without handling the full-size network and handcrafting address features. Moreover, the differences in transaction patterns of mixing services reflected in the 2-egonets provide adequate information for identification. Our experimental study demonstrates that BMSI-GC performs excellently in multi-class Bitcoin mixing service identification, achieving an average identification F1-score of 95.08%.
El-hacen Diallo, Rouwaida Abdallah, Mohammad Dib, Omar Dib
This paper introduces an innovative response to the pressing challenge of rapid and effective incident detection and management in urban settings. The proposed solution is a decentralized incident reporting system (IRS) harnessing blockchain technology and decentralized data storage systems. By empowering residents to report incidents, the proposed IRS enables seamless real-time monitoring and intervention by relevant departments. Built on a blockchain foundation, the proposed solution ensures immutability, transparency, security, and auditability, enhancing data resilience and comprehensive applicability. The proposed system leverages the InterPlanetary File System (IPFS) for the storage of incident proofs to manage the blockchain size effectively. Through the proposed IRS, transparency is upheld, enabling complete auditability of incident details and required interventions by citizens, societal bodies, and governmental bodies. Moreover, an incentive model is introduced to encourage active participation in incident reporting, thereby enhancing the systemâs overall effectiveness and long-term sustainability. The proposed IRS integrates mobile technology to facilitate user engagement and data submission, essential for urban emergency management. Empirical validation using the QuorumâRaft blockchain demonstrates the feasibility of the proposed approach in terms of system throughput, incident reporting delay, blockchain size, and deployment cost. Specifically, the system maintains a latency of under 15 s even at high transaction rates, can handle up to 200 incidents per second, and is cost-effective, with deployment estimates for 16 organizations over five years being under 1.99 million USD. The method involves extensive testing with simulated incidents and user interactions to ensure robustness and scalability, showcasing the systemâs potential for effective emergency management in urban environments.