This paper into the critical issue of vulnerability detection in smart contracts, focusing on identifying vulnerabilities, proposing mitigation strategies, and developing techniques for detecting Ponzi schemes within smart contracts. By understanding and addressing these vulnerabilities, we aim to enhance the security and robustness of blockchain-based applications and ecosystems.
Algimantas Venčkauskas, Vacius Jusas, Dominykas Barisas, Boriss Mišņevs
Sharing cyber threat intelligence (CTI) can significantly improve the security of information technology (IT) in organizations. However, stakeholders and practitioners are not keen on sharing CTI data due to the risk of exposing their private data and possibly losing value as an organization on the market. We present a model for CTI data sharing that maintains trust and confidentiality and incentivizes the sharing process. The novelty of the proposed model is that it combines two incentive mechanisms: money and reputation. The reputation incentive is important for ensuring trust in the shared CTI data. The monetary incentive is important for motivating the sharing and consumption of CTI data. The incentives are based on a subscription fee and a reward score for activities performed by a user. User activities are considered in the following three fields: producing CTI data, consuming CTI data, and reviewing CTI data. Each instance of user activity is rewarded with a score, and this score generates some value for reputation. An algorithm is proposed for assigning reward scores and for recording the accumulated reputation of the user. This model is implemented on the Hyperledger Fabric blockchain and the Interplanetary File System for storing data off-chain. The implemented prototype demonstrates the feasibility of the proposed model. The provided simulation shows that the selected values and the proposed algorithm used to calculate the reward scores are in accordance with economic laws.
The coming of cryptocurrencies has, amazingly, changed the face of the financial space. It has opened up opportunities and challenges in the field of money laundering. The deep impact of cryptocurrencies on the practice of money laundering becomes a detailed study. Since digital currencies are embedded with inherent characteristics, such as anonymity, decentralization, and the ease of performing cross-border transfers, criminals have now found new ways to conceal their illicit financial activities. The paper critically reviews how cryptocurrencies are used in money laundering schemes, evaluates the effectiveness of current legal provisions and anti-money laundering measures, and reviews case studies that exemplify real-world applications and challenges to regulatory bodies. Moreover, it offers recommendations on the use of new technologies, like blockchain analytics, toward better detection and prevention of money laundering through cryptocurrency. The paper thus provides a range of useful insights, associated with recommendations for the strengthening of the global regulatory framework in dealing with the increased threat of cryptocurrency money laundering, through a synthesis of the literature review, case analysis, and expert interviews. The paper contributes to this debate by providing insight into the challenges that regulatory authorities face and making recommendations to improve anti-money laundering efforts in the cryptocurrency space. This is done through an in-depth review of recent cases and legislation in this area. The findings were that, though cryptocurrencies pose a great challenge, innovative technology solutions coupled with international cooperation can play a vital role in mitigating the risks associated with cryptocurrency-based money laundering.
Blockchain technology has revolutionised how data is stored, managed, and secured. Its decentralised, transparent, and immutable nature presents unique advantages for data security. This paper delves into the application of blockchain technology in enhancing data security, exploring its fundamental principles, mechanisms, real-world applications, benefits, and challenges. By examining case studies across various industries, this paper aims to demonstrate the transformative potential of blockchain technology in securing data and protecting against cyber threats.
Ardhian Dwiyoenanto, Adi Sulistiyono, Hartiwiningsih Hartiwiningsih
The advance of Information Technology is closely related to and has a direct impact on the development of people’s lives. One of the real technological advancements that plays a major role in creating evolution in the community life order is Internet progress. As time passes, the internet world continues to experience rapid development, such as Metaverse, Non-Fungible Tokens (NFTs), and Cryptocurrency. Meanwhile, the change of regulations and legal products that are not as fast as the advance of the internet and the business world raises their abuse potential as means of Money Laundering Crime. The research method used was normative juridical with analytical descriptive research specifications. Metaverse, NFTs, and Cryptocurrency are relatively new phenomena in this globalization era. The lack of regulation and the high volatility of price characteristics that are strongly influenced by public interest make them potential as means to hide or disguise the origin of assets from criminal acts. So, this research was conducted to analyse the potential use of Metaverse and Non-Fungible Tokens as means of money laundering.
The integration of Blockchain technology and Artificial Intelligence (AI) is revolutionizing data management and business intelligence. Blockchain, with its decentralized, immutable ledger, ensures data integrity and security, while AI enhances data analysis through advanced algorithms and predictive capabilities. This article explores the synergy between these two transformative technologies, examining how their combined strengths can address modern challenges in data security and business operations. The paper begins with an overview of Blockchain and AI, detailing their foundational principles and recent advancements. It then delves into their applications in enhancing data security, highlighting Blockchain's role in providing encryption and immutability and AI's capabilities in threat detection and response. The discussion extends to their impact on business intelligence, showcasing how Blockchain contributes to transparent and verifiable data, while AI drives advanced analytics and decision-making. Real-world case studies illustrate successful implementations of Blockchain and AI integration, demonstrating their potential to revolutionize various industries. The article also addresses technical challenges, privacy concerns, and regulatory issues associated with these technologies. Finally, it outlines future directions for research and innovation, emphasizing the need for continued exploration of their combined potential. By providing a comprehensive analysis of Blockchain and AI's transformative impact, this article aims to offer valuable insights for researchers, practitioners, and policymakers seeking to leverage these technologies for improved data security and business intelligence.
The article examines a new object of forensic economic examination – cryptocurrency. The author provides classic definitions of an object of forensic examination and establish the differences of cryptocurrency from the traditionally understood objects of both forensic examination in general and economic examination in particular. The main difference of cryptocurrency from other currencies and objects of investigation is its virtual nature, lack of affiliation with the material world. Two main points of view on the essence of cryptocurrency are analyzed: as a basis and tool for the development of new effective forms of payments, exchange of goods, and as an object and instrument of criminal activity. A definition of cryptocurrency is given as interpreted by the FATF – Financial Action Task Force. It is identified which issues related to the circulation of cryptocurrency can be attributed to the competence of a forensic expert-economist, and which – to the field of computer forensics. The author also describes the features of cryptocurrency that must be taken into account when considering it as an object of forensic economic examination.
The main purpose of this study is to provide a comprehensive assessment of the importance of cryptocurrencies in terms of money laundering risk and to provide detailed information on money laundering techniques and structures. An analysis of how cryptocurrencies impact local and international money laundering is also being explored to clarify the facts. The article attempts to provide a better understanding of this emerging problem by providing information on the use of digital currency to change the money laundering landscape. To clarify the review, the review is divided into two main parts: The first part will focus on the theoretical framework of the money laundering process, the process complexity of cryptocurrencies and the ecosystems surrounding them. The second part will examine whether virtual currencies are suitable for money laundering, the various features that make virtual currencies ideal for such activities, and the creation of new emerging technologies will also be discussed. This document is designed to provide policymakers, regulators, and law enforcement with useful information and strategic solutions to address the challenges of cryptocurrency money laundering through many of these methods.
Cryptocurrencies, especially privacy coins, conceal the flow of money. Similarly, the dark web obscures the flow of internet traffic, increasing anonymity. In this paper, I provide evidence that secondary market trading activity in privacy coins is linked to dark web traffic, although their pricing remains mostly unaffected. This finding holds after considering various controls and comparing similar privacy and non-privacy coins. However, when disentangling dark web traffic by country of origin, I find that privacy coin prices correlate positively with traffic from China, while trading volume is mainly driven by users from Russia and Iran.
Fernando Richter Vidal, Naghmeh Ivaki, Nuno Laranjeiro
The number of applications supported by blockchain smart contracts has been greatly increasing in recent years, with smart contracts now being used across several domains, such as the music industry, finance, and retail, to name a few. Despite being used in business-critical contexts, the number of security vulnerabilities in smart contracts has also been increasing, with many of them being exploited and resulting in huge financial and reputation losses. This is despite the enormous effort that is being placed into the research and development of vulnerability detection tools and techniques, which have also greatly increased in number and type in the last few years. Motivated by the recent increase in both vulnerabilities and vulnerability detection techniques, this paper reviews the latest research in smart contract vulnerability detection, emphasizing the techniques being used, the vulnerabilities targeted, and the characteristics of the dataset used for evaluating the technique. We mapped the vulnerabilities against two common vulnerability classification schemes (DASP and SWC) and performed a consolidated analysis. We identified the current research trends and gaps in each technique and highlighted future research opportunities in the field. • A categorization of smart contract vulnerability detection techniques. • The identification of smart contract vulnerabilities that are the target of current vulnerability detection tools. • An analysis of the datasets used in smart contract vulnerability research.
Smart contract developers frequently seek solutions to developmental challenges on Q&A platforms such as Stack Overflow (SO). Although community responses often provide viable solutions, the embedded code snippets can also contain hidden vulnerabilities. Integrating such code directly into smart contracts may make them susceptible to malicious attacks. We conducted an online survey and received 74 responses from smart contract developers. The results of this survey indicate that the majority (86.4%) of participants do not sufficiently consider security when reusing SO code snippets. Despite the existence of various tools designed to detect vulnerabilities in smart contracts, these tools are typically developed for analyzing fully-completed smart contracts and thus are ineffective for analyzing typical code snippets as found on SO. We introduce SOChecker, the first tool designed to identify potential vulnerabilities in incomplete SO smart contract code snippets. SOChecker first leverages a fine-tuned Llama2 model for code completion, followed by the application of symbolic execution methods for vulnerability detection. Our experimental results, derived from a dataset comprising 897 code snippets collected from smart contract-related SO posts, demonstrate that SOChecker achieves an F1 score of 68.2%, greatly surpassing GPT-3.5 and GPT-4 (20.9% and 33.2% F1 Scores respectively). Our findings underscore the need to improve the security of code snippets from Q&A websites.
Azreen Shafieqah Asri, Faizatul Fitri Boestamam, Haslizaidi Zakaria, Mohammad Amir Alam Rahim Omar · 6 authors
With the rapid expansion of the Industrial Internet of Things (IIoT), integrating devices, machines, and systems to optimize operations and enable data-driven decision-making, ensuring robust security measures is essential. While blockchain has shown the potential to upgrade traditional authentication methods in IIoT environments, vulnerabilities persist. This paper introduces two innovative methods to enhance blockchain-based authentication in IIoT: first, integrating AI-driven anomaly and threat detection into the blockchain authentication scheme; second, implementing Ethereum smart contracts for enhanced authentication with a two-factor authentication (2FA) system and GFE algorithms. By combining AI for anomaly detection with decentralized smart contracts and blockchain-based 2FA, and leveraging GFE algorithms to enhance blockchain capabilities, the proposed scheme aims to significantly fortify security measures. This integration offers a resilient defense against evolving threats, ensuring transparency, adaptability, and heightened security in IIoT applications.
Mui D. Nguyen, Tuan M. Nguyen, Thang C. Vu, Tien Minh Ta · 6 authors
The paper evaluates potential applications of blockchain technology in enhancing the security and reliability of Wireless Sensor Networks (WSNs). The existing vulnerabilities in WSNs, such as concerns regarding data integrity and security, demand innovative security solutions. Through systematic analysis, this paper provides valuable insights to expand understanding of WSNs security, explaining the feasibility and benefits of deploying blockchain technology. Possible attacks in the networks are classified to point out either risks or potential solusions to protect the networks. By exploring the integration of Blockchain within WSNs, the paper highlights its potential to minimize various security risks. In addition, this work discusses the challenges and considerations associated with implementing Blockchain in WSNs. Overall, this paper contributes on securing WSNs and underscores the role of blockchain technology as a promising way for enhancing security of WSNs.
Junaid Arshad, Muhammad Talha, Bilal Saleem, Zoha Shah · 6 authors
The increasing reliance on computer networks and blockchain technology has led to a growing concern for cybersecurity and privacy. The emergence of zero-day vulnerabilities and unexpected exploits has highlighted the need for innovative solutions to combat these threats. Bug bounty programs have gained popularity as a cost-effective way to crowdsource the task of identifying vulnerabilities, providing a secure and efficient means of enhancing cybersecurity. This paper provides a comprehensive survey of various free and paid bug bounty programs in the computer networks and blockchain industry, evaluating their effectiveness, impact, and credibility. The study explores the structure, incentives, and nature of vulnerabilities uncovered by these programs, as well as their unique value proposition. A comparative analysis is conducted to identify advantages and disadvantages, highlighting the strengths and weaknesses of each program. The paper also examines the role of ethical hackers in bug bounty programs and their contributions to strengthening cybersecurity and privacy. Finally, the study concludes with recommendations for addressing the challenges faced by bug bounty programs and suggests potential future directions to enhance their impact on computer networks and blockchain security.
Decentralized cryptocurrencies, such as bitcoin, use peer-to-peer software protocol, disintermediating the traditional intermediaries that used to be banks and other financial intermediaries, effectuating cross-border transfer. In fact, by removing the requirement for a middleman, the technology has the potential to disrupt current financial transactions that rely on a trusted authority or intermediary operator. Traditional financial regulation, primarily based on the command-and-control approach, is ill-suited to regulating decentralized cryptocurrencies. The present paper aims to investigate the policy option most suitable for regulating decentralized cryptocurrencies. The study employs content analysis method to effectuate the purpose of the study. The paper argues that the combination of both direct and indirect regulatory approaches would be a feasible option for regulating decentralized cryptocurrencies. The absence of centralized authority and the borderless nature of decentralized cryptocurrencies would make them antithetical to centralized direct regulation. Therefore, the findings of the study suggest that regulators should focus on regulating intermediaries bridging the connection between the online world (crypto ecosystem) and the physical world (the point of converting crypto into fiat money). These intermediaries can work as passive actors or surrogate regulators who are indirectly responsible for implementing policy options on behalf of the central authority.
The deliberate fabrication of identity or information to deceive others, the unauthorised use of a credit card, debit card, or ATM, or the use of technology to transmit fraudulent information in an attempt to obtain money or valuables are all considered financial scams. There are many financial scams has been happening across the world, some of the example’s scams which happened in indie among that The Satyam Computers organizations shame was India's greatest corporate scam until 2010. The trailblazer and the heads of non mainstream based reexamining association Satyam PC organization, debased the records, expanded the proposition cost, and took enormous sums from the association a considerable amount of this was placed assets into property. This research paper covers Importance of the study, Objectives of the study, Why people should have an in depth study about Satyam computer and its various legal implication, Why people give valuable opinion and suggestion and also to create an awareness about financial scams and the stake holders, Legal compliance with fraud offense in India, Functions Of forensic accounting and it also explains about Examining financial information, bank statements, invoices, and other accounting records were all part of the forensic audit. and ends with how to prevent financial scams in India. Apparently corporate bookkeeping misrepresentation is a critical issue that is filling in both recurrence and seriousness, as confirmed by the instances of Enron, WorldCom, and Satyam. Research proof has exhibited that a rising number of false exercises have debilitated the respectability of financial reports, added to huge monetary misfortunes, and corrupted financial backers' certainty about the utility and unwavering quality of financial explanations.
The wide application of Ethereum technology has brought technological innovation to traditional industries. As one of Ethereum's core applications, smart contracts utilize diverse contract codes to meet various functional needs and have gained widespread use. However, the non-tamperability of smart contracts, coupled with vulnerabilities caused by natural flaws or human errors, has brought unprecedented challenges to blockchain security. Therefore, in order to ensure the healthy development of blockchain technology and the stability of the blockchain community, it is particularly important to study the vulnerability detection techniques for smart contracts. In this paper, we propose a Dual-view Aware Smart Contract Vulnerability Detection Framework named DVDet. The framework initially converts the source code and bytecode of smart contracts into weighted graphs and control flow sequences, capturing potential risk features from these two perspectives and integrating them for analysis, ultimately achieving effective contract vulnerability detection. Comprehensive experiments on the Ethereum dataset show that our method outperforms others in detecting vulnerabilities.
Purpose The purpose of this paper is to estimate the implications of illicit market use for the value of Bitcoin in an event studies framework. Design/methodology/approach This study uses a data set of 58 state-level marijuana decriminalisation and legalisation bills and referenda in the USA in 2010–2022. Findings Decriminalisation is associated with a strong and consistent positive Bitcoin price response around the event, recreational legalisation induces a more ambiguous reaction and medical legalisation is found to have a negative albeit small impact on Bitcoin value. This suggests decriminalisation enhances shadow economy use value of Bitcoin, whereas recreational and medical legalisation are not consistently reducing illicit drug cryptomarket activity. The effects are robust to various estimation windows, in subsamples, and also when outliers, heavy tails, conditional heteroskedasticity and state size are accounted for. Originality/value New to the literature, the choice of US marijuana bills, specifically as sample events, is based on both theoretical and empirical grounds.
This paper presents a case study of a cryptocurrency scam that utilized coordinated and inauthentic behavior on Twitter. In 2020, 143 accounts sold by an underground merchant were used to orchestrate a fake giveaway. Tweets pointing to a fake blog post lured victims into sending Uniswap tokens (UNI) to designated addresses on the Ethereum blockchain, with the false promise of receiving more tokens in return. Using one of the scammer's addresses and leveraging the transparency and immutability of the Ethereum blockchain, we traced the flow of stolen funds through various addresses, revealing the tactics adopted to obfuscate traceability. The final destination of the funds involved two deposit addresses. The first, managed by a well-known cryptocurrency exchange, was likely associated with the scammer's own account on that platform and saw deposits exceeding $3.5 million. The second address was linked to a popular cryptocurrency swap service. These findings highlight the critical need for more stringent measures to verify the source of funds and prevent illicit activities.
Dr.Abdul Basit Khan, Hira Farman, Saif Hassan, Moomal Seelro · 5 authors
Bitcoin is the most successful cryptocurrency with the highest market capitalization of up to 53%. Due to its pseudonymous mechanism, bitcoin is being utilized in a variety of illicit activities. It is noticed, around US$72 billions of unlawful activities per year involve Bitcoin. In this study, systematic literature review is conducted on the illicit use of bitcoin, and the measures required to counter the illicit activities using Bitcon. In this work, authors have managed to select 45 research articles published during 2018-2022. The synthesis of selected articles revealed that bitcoin is proliferating in darknet markets. It is used to make payments for criminal activities such as drug trafficking, money laundering, human trafficking, pornography, ransomware, and other criminal activities like contract killers, Ponzi schemes, and terrorism financing. By the findings from this study, out of45 research articles 24.4% articles claim that bitcoin has been used in drug trafficking whereas 17.7% believe that people use bitcoin for money laundering. Moreover, Blockchain identity flexibility, dissociative anonymity, and a lack of deterrence encourage users to perform illegal activities. At present, the research community is actively involved in proposing and designing innovative approaches tocounter the illicit use of bitcoin. However, these solutions are unable to stop the misuse of bitcoin.
Analyzing the complex cybersecurity landscape of Uzbekistan’s crypto exchanges, the article emphasizes the importance of developing and implementing cybersecurity policies and regulatory frameworks. The article identifies the most pressing and evolving digital threats and evaluates the effectiveness of advanced mitigation measures. Furthermore, it explores the transformative potential of innovative legal and technological tools, such as blockchain-based identity verification, zero-knowledge proofs, and secure multi-party computation. The article provides an in-depth analysis of the current legislation governing cybersecurity practices within Uzbekistan’s crypto ecosystem and offers insights into future development prospects. To provide a comprehensive analysis of the cybersecurity situation in the cryptocurrency exchange industry, an extensive review of academic publications, industry reports and official documents related to cybersecurity in the cryptocurrency market is used. In addition, the article includes case studies of known cybersecurity incidents related to cryptocurrency exchanges. By analyzing real-life examples, the researchers aim to provide a more detailed understanding of the cybersecurity challenges faced by cryptocurrency exchanges and the effectiveness of various mitigation measures. Ultimately, the article presents practical recommendations for creating a secure, trustworthy, and innovation-driven environment for cryptocurrency users in Uzbekistan.
With the increasing popularity of blockchain, different blockchain platforms coexist in the ecosystem (e.g., Ethereum, BNB, EOSIO, etc.), which prompts the high demand for cross-chain communication. Cross-chain bridge is a specific type of decentralized application for asset exchange across different blockchain platforms. Securing the smart contracts of cross-chain bridges is in urgent need, as there are a number of recent security incidents with heavy financial losses caused by vulnerabilities in bridge smart contracts, as we call them Cross-Chain Vulnerabilities (CCVs). However, automatically identifying CCVs in smart contracts poses several unique challenges. Particularly, it is non-trivial to (1) identify application-specific access control constraints needed for cross-bridge asset exchange, and (2) identify inconsistent cross-chain semantics between the two sides of the bridge. In this paper, we propose SmartAxe, a new framework to identify vulnerabilities in cross-chain bridge smart contracts. Particularly, to locate vulnerable functions that have access control incompleteness, SmartAxe models the heterogeneous implementations of access control and finds necessary security checks in smart contracts through probabilistic pattern inference. Besides, SmartAxe constructs cross-chain control-flow graph (xCFG) and data-flow graph (xDFG), which help to find semantic inconsistency during cross-chain data communication. To evaluate SmartAxe, we collect and label a dataset of 88 CCVs from real-attacks cross-chain bridge contracts. Evaluation results show that SmartAxe achieves a precision of <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" display="inline"> <mml:mn>84.95</mml:mn> <mml:mo>%</mml:mo> </mml:math> and a recall of <mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" display="inline"> <mml:mn>89.77</mml:mn> <mml:mo>%</mml:mo> </mml:math> . In addition, SmartAxe successfully identifies 232 new/unknown CCVs from 129 real-world cross-chain bridge applications (i.e., from 1,703 smart contracts). These identified CCVs affect a total amount of digital assets worth 1,885,250 USD.
Background: Research has been done on the vulnerabilities of Ethereum smart contract detection since the emergence of blockchain technologies. Ethereum is one of the most popular platforms for DApps (decentralized applications) and smart contracts but turns more undoubtedly when their number and popularity grow. Methods: The study evaluates different detection methods including static analysis, dynamic code analysis, symbolic execution, and machine learning. Findings: The performance metrics on key areas, e.g. detection time, true positive rate, false positive rate, and scalability are emphasized in this evaluation analysis. These inferences imply that although Static Analysis can provide fast detection and high accuracy, Machine Learning is better at High scalability. The study also identifies trending flaws often encountered such as re-entrancy attacks and lack of input validation and stresses further the necessity of strong security methods. Besides, you may consider the sensitivity analysis in different network load scenarios as it shows the efficiency of detection technique in changing operational settings. Novelty and applications: Overall, the research brings a reliable development to smart contracts in Ethereum's security industries through analyzing and profiling vulnerability types and performance metrics that inform the development of more stable and efficient security activities for distributed applications.