Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

845 papersLast indexed Aug 31, 2026
Search papers

Paper index

845 results · page 14 of 36

Clear filters
Jul 20, 2023·Anais do I Colóquio em Blockchain e Web Descentralizada (CBlockchain 2023)
3 cites
SCMTool: A Graphical Tool for Smart Contract Modeling

Gislainy Crisostomo Velasco, Dionatan Alves Vieira, Marcos Alves Vieira, Sérgio T. Carvalho

The development of smart contracts in the Ethereum Virtual Machine (EVM) can be a complex task, both for experienced and beginner developers. Understanding these contracts can be challenging for both technical and non-technical users, due to the difficulty in comprehending the connection between the elements and resources available, as there is no clear way to visually present the functionalities of a contract and its relationships. In this paper, we introduce the Smart Contract Modeling Tool (SCMTool), a graphical tool based on the Model-Driven Engineering approach, that allows users to specify models that represent the structure of a smart contract in a simpler and more intuitive way. The tool was validated using a use case from the NFT industry.

Open access
FinTech, Crowdfunding, Digital Finance
Auction Theory and Applications
Blockchain Technology Applications and Security
Original source
Jul 13, 2023·Journal of risk and financial management
4 cites
Decoding Decentralized Autonomous Organizations: A Content Analysis Approach to Understanding Scoring Platforms

Christian Ziegler, Syeda Rabab Zehra

This paper evaluates the scoring platforms for decentralized autonomous organization (DAO), examining their methodologies and highlighting their strengths and limitations. Using content analysis, we scrutinize the scoring methodologies of the Prime Rating, DAO Meter, and DeFi Safety platforms, evaluating code, documentation, security, team composition, governance, and regulatory compliance. We analyze the underlying assumptions and data sources relied upon by these platforms, using a content analysis approach. Our investigation furnishes valuable information for stakeholders, aiming to evaluate or enhance DAO scoring methodologies used by scholars and practitioners in the finance and blockchain fields. By contributing to a more rigorous understanding of DAO performance assessment, this paper supports informed decision making and promotes the development of a dependable and efficient scoring system for the decentralized financial ecosystem.

Open access
Blockchain Technology Applications and Security
FinTech, Crowdfunding, Digital Finance
Auction Theory and Applications
Original source
Jul 11, 2023·Zurich Open Repository and Archive (University of Zurich)
17 cites
Time Moves Faster When There is Nothing You Anticipate: The Role of Time in MEV Rewards

Burak Öz, Benjamin Kraner, Nicolò Vallarano, Bingle Stegmann Kruger · 6 authors

This study explores the intricacies of waiting games, a novel dynamic that emerged with Ethereum's transition to a Proof-of-Stake (PoS)-based block proposer selection protocol. Within this PoS framework, validators acquire a distinct monopoly position during their assigned slots, given that block proposal rights are set deterministically, contrasting with Proof-of-Work (PoW) protocols. Consequently, validators have the power to delay block proposals, stepping outside the honest validator specs, optimizing potential returns through MEV payments. Nonetheless, this strategic behaviour introduces the risk of orphaning if attestors fail to observe and vote on the block timely. Our quantitative analysis of this waiting phenomenon and its associated risks reveals an opportunity for enhanced MEV extraction, exceeding standard protocol rewards, and providing sufficient incentives for validators to play the game. Notably, our findings indicate that delayed proposals do not always result in orphaning and orphaned blocks are not consistently proposed later than non-orphaned ones. To further examine consensus stability under varying network conditions, we adopt an agent-based simulation model tailored for PoS-Ethereum, illustrating that consensus disruption will not be observed unless significant delay strategies are adopted. Ultimately, this research offers valuable insights into the advent of waiting games on Ethereum, providing a comprehensive understanding of trade-offs and potential profits for validators within the blockchain ecosystem.

Open access
3 source records
Blockchain Technology Applications and Security
Complex Systems and Time Series Analysis
Auction Theory and Applications
Original source
Jul 10, 2023·Proceedings of the 24th Annual International Conference on Digital Government Research
2 cites
Smart contracts for creating transparent transactions to reduce corruption

Darusalam Darusalam, Marijn Janssen, Jamaliah Said, Normah Omar · 5 authors

Corruption is widely spread and not easy to avoid. Blockchain-based smart contract technology enables the opportunity to develop transactions in such a way that corruption should not be possible. In this paper, we develop and evaluate an arrangement based on blockchain-based smart contracts to avoid and reduce corruption. Smart contracts are used for buying and selling goods, in which the public must agree that the goods arrived and are used to contribute to the creation of societal value. Only then will the supplier be paid. Al transaction data is stored in a blockchain and opened to the public to create transparency. In this way, the price of the good and the sellers can be inspected to avoid price manipulation and nepotism. The smart contract avoids the likelihood that corruption will happen, and it can be spotted if it happens.

Open access
Blockchain Technology Applications and Security
FinTech, Crowdfunding, Digital Finance
Auction Theory and Applications
Original source
Jul 5, 2023·Turkish Journal of Civil Engineering
12 cites
Operational Barriers against the Use of Smart Contracts in Construction Projects

Handan Kunkcu, Kerim Koç, Aslı Pelin Gürgün, Houljakbe Houlteurbe Dagou

As an emerging but embryonic way of contract administration, smart contracts can play a prominent role in managing construction projects in an effective manner. However, there are still some barriers preventing the implementation of them in the life cycles of construction projects. This study investigates operational barriers against the adoption of smart contracts in construction projects and explores the challenges in this process. Operational barriers against smart contract implementation are identified through a comprehensive literature review and a focus group discussion is performed to refine the identified barriers. These barriers are evaluated through fuzzy analytical hierarchy process analysis. Finally, a framework is proposed for the adoption of smart contracts effectively in construction projects. 20 operational barriers were attained based on four main barrier categories: technical, financial, security/technological, and time. The results show that financial and technical aspects establish the most significant categories hindering the adoption of smart contracts, while expensive and clunky drafting and registration process, and cost of upskilling are the most significant barriers. Overall, the proposed framework might be useful for practitioners and project managers, who decide to use smart contracts in managing construction projects. The motive behind understanding critical operational barriers is to assist construction practitioners in automating contract execution processes. This study provides a basis for recommending the necessary strategies for the use of smart contracts in the industry to researchers in the construction management field.

Open access
Blockchain Technology Applications and Security
Auction Theory and Applications
FinTech, Crowdfunding, Digital Finance
Original source
Jul 4, 2023·Sensors
20 cites
Smart Contract Broker: Improving Smart Contract Reusability in a Blockchain Environment

Joonseok Park, Sumin Jeong, Keunhyuk Yeom

In this paper, we propose a smart contract broker to improve the reusability of smart contracts in a blockchain environment. The current blockchain platform lacks a standard approach to sharing and managing smart contracts, which makes it difficult for developers to reuse them and leads to efficiency issues. The proposed smart contract broker uses tags to identify and organize smart contracts, and it provides an environment for comparing and reusing smart contracts. This improves the reusability of smart contracts and efficiency. The proposed smart contract broker can be applied as a reference model that increases the flexibility and reusability of smart contract management in a blockchain environment.

Open access
Blockchain Technology Applications and Security
FinTech, Crowdfunding, Digital Finance
Auction Theory and Applications
Original source
Jul 3, 2023·Distributed Ledger Technologies Research and Practice
5 cites
A Local-First Approach for Green Smart Contracts

Quinten Stokkink, Johan Pouwelse

Shared code in blockchains, known as smart contracts , stands to replace important parts of our digital governance and financial infrastructure. The permissionless execution of smart contracts is tightly coupled to cryptocurrencies and Proof-of-Work blockchains. As a result, smart contracts inherit the environmental impact of Proof-of-Work blockchains, such as its energy consumption, carbon footprint, and electronic waste. The four concepts of relaxed consistency, strong identities, probabilistic consensus, and the use of liabilities instead of assets may change the status quo. This work explores the integration of these concepts to decouple smart contracts from Proof-of-Work blockchains. By means of a local-first approach, which may expose users to inconsistent ephemeral contract states, the architecture of smart contracts can be transformed to become green. Because such contract states may be dropped, we base the interactions between users on liabilities. We propose a novel paradigm for smart contract architectures, named Green Smart Contracts, that is based on a local-first approach. Furthermore, we present and implement a prototype solution for this paradigm. We validate the need for a mechanism to resolve consistency violations by replaying the contract calls of a real smart contract. Our simulation shows that violations occur more often (13% of contract invocations) when using liabilities than when using a traditional blockchain (3% of contract invocations). However, we additionally validate that they can be avoided using a consensus mechanism, and our experiments show that a publish-subscribe messaging pattern uses the fewest messages to do so, though it may not be applicable for use cases that disallow the inherent imbalance in the messaging between peers. Our carbon emission estimation shows that a Green Smart Contract approach lowers carbon emissions by 52.31% when compared with the messaging behavior of a typical peer-to-peer blockchain with 1000 nodes.

Open access
Blockchain Technology Applications and Security
Auction Theory and Applications
Cryptography and Data Security
Original source
Jul 1, 2023·University of North Texas Libraries
0 cites
Paradigm Shift from Vague Legal Contracts to Blockchain-Based Smart Contracts

Kritagya Upadhyay

In this dissertation, we address the problem of vagueness in traditional legal contracts by presenting novel methodologies that aid in the paradigm shift from traditional legal contracts to smart contracts. We discuss key enabling technologies that assist in converting the traditional natural language legal contract, which is full of vague words, phrases, and sentences to the blockchain-based precise smart contract, including metrics evaluation during our conversion experiment. To address the challenge of this contract-transformation process, we propose four novel proof-of-concept approaches that take vagueness and different possible interpretations into significant consideration, where we experiment with popular vendors' existing vague legal contracts. We show through experiments that our proposed methodologies are able to study the degree of vagueness in every interpretation and demonstrate which vendor's translated-smart contract can be more accurate, optimized, and have a lesser degree of vagueness. We also incorporated the method of fuzzy logic inside the blockchain-based smart contract, to successfully model the semantics of linguistic expressions. Our experiments and results show that the smart contract with the higher degrees of truth can be very complex technically but more accurate at the same time. By using fuzzy logic inside a smart contract, it becomes easier to solve the problem of contractual ambiguities as well as expedite the process of claiming compensation when implemented in a blockchain-based smart contract.

Open access
Blockchain Technology Applications and Security
FinTech, Crowdfunding, Digital Finance
Auction Theory and Applications
Original source
Jul 1, 2023·Proceedings/Proceedings of the ... International Conference on Software Engineering and Knowledge Engineering
1 cites
Formalization and Verification of Data Auction Mechanism Based on Smart Contract Using CSP

Yingjia Du, Yuan Fei, Sini Chen, Huibiao Zhu

Nowadays, the utilization of online auction platforms is becoming increasingly prevalent.Online auction provides a common and practical way for global buyers to compete fairly.Nevertheless, the anonymous environment may bring collusion among entities with effects on results.Compared with traditional mechanisms which rely on third-party platforms, the data auction based on smart contract can create a decentralized environment to avoid the occurrence of collusion.Meanwhile, there exists few research on the verification of its reliability and safety which is worth investigating from the perspective of formal methods.In this paper, we apply Process Algebra CSP in modeling the data auction communicating system among five key entities.In addition, we use Process Analysis Toolkit (PAT) to realize the mechanism and verify five crucial properties, including deadlock freedom, data reachability, data correctness, anti-collusion capability and data security.The verification results indicate that the architecture of data auction based on smart contract can satisfy all the above requirements.Especially, the design of asymmetric encryption for the fundamental information ensures the non-occurrence of collusion in the auction.Additionally, the digital signature generated by private key attached to the message guarantees the safety of the interaction.

Open access
Blockchain Technology Applications and Security
Auction Theory and Applications
Privacy-Preserving Technologies in Data
Original source
Jun 29, 2023·arXiv (Cornell University)
0 cites
When Bidders Are DAOs

Maryam Bahrani, Pranav Garimidi, Tim Roughgarden

In a typical decentralized autonomous organization (DAO), people organize themselves into a group that is programmatically managed. DAOs can act as bidders in auctions, with a DAO's bid treated by the auctioneer as if it had been submitted by an individual, without regard to the internal structure of the DAO. We study auctions in which the bidders are DAOs. More precisely, we consider the design of two-level auctions in which the "participants" are groups of bidders rather than individuals. Bidders form DAOs to pool resources, but must then also negotiate the terms by which the DAO's winnings are shared. We model the outcome of a DAO's negotiations by an aggregation function (which aggregates DAO members' bids into a single group bid), and a budget-balanced cost-sharing mechanism (that determines DAO members' access to the DAO's allocation and distributes the total payment demanded from the DAO to its members). We pursue two-level mechanisms that are incentive-compatible (with truthful bidding a dominant strategy for members of each DAO) and approximately welfare-optimal. We prove that, even in the case of a single-item auction, incentive-compatible welfare maximization is not possible: No matter what the outer mechanism and the cost-sharing mechanisms used by DAOs, the welfare of the resulting two-level mechanism can be a $\approx \ln n$ factor less than optimal. We complement this lower bound with a natural two-level mechanism that achieves a matching approximate welfare guarantee. Our upper bound also extends to multi-item auctions where individuals have additive valuations. Finally, we show that our positive results cannot be extended much further: Even in multi-item settings with unit-demand bidders, truthful two-level mechanisms form a highly restricted class and as a consequence cannot guarantee any non-trivial approximation of the maximum social welfare.

Open access
2 source records
Auction Theory and Applications
Experimental Behavioral Economics Studies
Economic Policies and Impacts
Original source
Jun 28, 2023·Data
0 cites
Dataset of Linkability Networks of Ethereum Accounts Involved in NFT Trading of Top 15 NFT Collections

Aleksandar Tošić, Niki Hrovatin, Jernej Vičič

In this paper, we present subgraphs of Ethereum wallets involved in NFT trades of the top 15 ERC721 NFT collections. To obtain the subgraphs, we have extracted the Ethereum transaction graph from a live Ethereum node and filtered out exchanges, mining pools, and smart contracts. For each of the selected collections, we identified the set of accounts involved in NFT trading, which we used to perform a breadth-first search in the Ethereum transaction graph to obtain a subgraph. These subgraphs can offer insight into the linkability of accounts participating in NFT trading on the Ethereum blockchain.

Open access
Blockchain Technology Applications and Security
Digital Platforms and Economics
Auction Theory and Applications
Original source
Jun 26, 2023·Annual Conference of the International Group for Lean Construction
5 cites
A Mechanism for Smart Contracts to Mediate Production Bottlenecks Under Constraints

Gongfan Chen, Chuanni He, Simon M. Hsiang, Min Liu · 5 authors

Central project managers devote massive efforts to monitor, track, coordinate, and take actions to diagnose and prognose governed constraints and remove them to enable a reliable workflow.The blockchain-enabled smart contract can streamline the work process by predefining "intelligent" consensus to facilitate central managers' jobs.However, the inability of smart contracts to handle unexpected events under complicated environments posited challenges in realizing it automatically.This study aimed to develop adaptive mechanism to mediate production bottlenecks caused by constraints.First, the research identified the four main types of constraints and their levels of variability from a prefabricated project.Then, a simulation model was established to quantify the impacts of different constraints and determine the fair payment rules.Lastly, different constraint-bundled scenarios and execution policies were developed and encoded in the smart contracts for automated executions.Smart contracts can assist construction managers to motivate reliable production and minimize waste caused by bottlenecks in the system.

Open access
2 source records
BIM and Construction Integration
Blockchain Technology Applications and Security
Advanced Manufacturing and Logistics Optimization
Original source
Jun 22, 2023·Journal of Organization Design
27 cites
Klima DAO: a crypto answer to carbon markets

Michal Jirásek

Abstract Tackling major societal challenges often requires a significant level of organizational novelty. One such recent example is Klima DAO, a decentralized autonomous organization (DAO) that seeks to transform voluntary markets through the adoption of carbon credits. DAOs rely on self-executing rules and have a high level of decentralization. By leveraging blockchain and related technologies, Klima DAO offers innovative solutions to universal problems of organizing in both its governance and product delivery. Blockchain tools enable Klima DAO to operate uniquely, allowing for rapid scaling while maintaining decentralized governance and promoting transparent carbon credit trading with low transaction fees. As such, Klima DAO may serve as a model for future organizations in search of greater transparency and flatter governance structures.

Open access
Blockchain Technology Applications and Security
FinTech, Crowdfunding, Digital Finance
Auction Theory and Applications
Original source
Jun 19, 2023·Blockchain Research and Applications
39 cites
The ins and outs of decentralized autonomous organizations (DAOs) unraveling the definitions, characteristics, and emerging developments of DAOs

Olivier Rikken, Marijn Janssen, Zenlin Kwee

Despite the increase in the number of blockchain-based Decentralized Autonomous Organizations (DAOs), there is no consensus on what constitutes a DAO. This paper provides an in-depth study of DAOs by analyzing their definitions, characteristics, and emerging developments. Existing definitions in the literature hardly recognize common functionalities and intermingle coded DAOs, DAO deployment platforms, and blockchain DAOs. We developed a comprehensive DAO definition by reviewing the literature and empirically analyzing 1,859 DAOs. The findings show that many DAOs were inactive and that a threshold of 20 tokenholders is a tipping point for DAOs to survive over time and maintain sustained levels of activity. Finally, based on an empirical analysis of 9,845 perceived DAOs, we identified the emerging development of off-chain voting. This emerging development challenges the autonomous nature of DAOs. We recommend further research to investigate the effect of governance structures on their long-term sustainability and viability for both on-chain and off-chain DAOs.

Open access
Blockchain Technology Applications and Security
Auction Theory and Applications
Digital Platforms and Economics
Original source
Jun 9, 2023·arXiv (Cornell University)
2 cites
The Potential of Self-Regulation for Front-Running Prevention on DEXes

Lioba Heimbach, Eric Schertenleib, Roger Wattenhofer

The transaction ordering dependency of the smart contracts building decentralized exchanges (DEXes) allow for predatory trading strategies. In particular, front-running attacks present a constant risk for traders on DEXes. Whereas legal regulation outlaws most front-running practices in traditional finance, such measures are ineffective in preventing front-running on DEXes. While novel market designs hindering front-running may emerge, it remains unclear whether the market's participants, in particular, liquidity providers, would be willing to adopt these new designs. A misalignment of the participant's private incentives and the market's social incentives can hinder the market from adopting an effective prevention mechanism. We present a game-theoretic model to study the behavior of sophisticated traders, retail traders, and liquidity providers in DEXes. Sophisticated traders adjust for front-running attacks, while retail traders do not, likely due to lack of knowledge or irrationality. Our findings show that with less than 1% of order flow from retail traders, traders' and liquidity providers' interests align with the market's social incentives - eliminating front-running attacks. However, the benefit from embracing this novel market is often small and may not suffice to entice them. With retail traders making up a larger proportion (around 10%) of the order flow, liquidity providers tend to stay in pools that do not protect against front-running. This suggests both educating traders and providing additional incentives for liquidity providers are necessary for market self-regulation.

Open access
2 source records
cs.GT
Auction Theory and Applications
Blockchain Technology Applications and Security
Original source
Jun 5, 2023·IEEE Network
26 cites
Insight Into Voting in DAOs: Conceptual Analysis and a Proposal for Evaluation Framework

Yixuan Fan, Lei Zhang, Ruiyu Wang, Muhammad Ali Imran

Driven by the development of blockchain infrastructures and the promotion of Web 3, more than 4000 Decentralized Autonomous Organizations (DAOs) have been developed as online organizations jointly owned and managed by their members who work for the same interests. Voting mechanisms as the democratic administration of DAOs without the involvement of central authority, are crucial to both the development of the DAO community and the protection of individual interests. This paper is one of the first analyses of the critical role of voting mechanisms in DAOs' operation. In the absence of systematic studies of voting mechanisms in DAOs, we propose five tiers of decentralization in DAO voting which marks the critical difference between DAO voting and conventional voting. We also define four dimensions to comprehensively evaluate the performance of DAO voting mechanisms, which identify the demands and characteristics of DAO voting and put forward clear design guidelines for voting mechanisms in DAOs. Finally, we take seven typical voting mechanisms as examples and analyze their performance in our proposed evaluation schemes.

Open access
Auction Theory and Applications
Blockchain Technology Applications and Security
Smart Grid Energy Management
Original source
Jun 3, 2023·EPiC series in computing
2 cites
Overapproximation of Non-Linear Integer Arithmetic for Smart Contract Verification

Petra Hozzová, Jaroslav Bendík, Alexander Nutz, Yoav Rodeh

The need to solve non-linear arithmetic constraints presents a major obstacle to the automatic verification of smart contracts. In this case study we focus on the two overapproximation techniques used by the industry verification tool Certora Prover: overapproximation of non-linear integer arithmetic using linear integer arithmetic and using non-linear real arithmetic. We compare the performance of contemporary SMT solvers on verification conditions produced by the Certora Prover using these two approximations against the natural non-linear integer arithmetic encoding. Our evaluation shows that the use of the overapproximation methods leads to solving a significant number of new problems.

Open access
2 source records
cs.LO
Auction Theory and Applications
Original source
Jun 1, 2023·Wuhan University Journal of Natural Sciences
5 cites
Fine-Tuning Pre-Trained CodeBERT for Code Search in Smart Contract

Huan Jin, Qinying LI

Smart contracts, which automatically execute on decentralized platforms like Ethereum, require high security and low gas consumption. As a result, developers have a strong demand for semantic code search tools that utilize natural language queries to efficiently search for existing code snippets. However, existing code search models face a semantic gap between code and queries, which requires a large amount of training data. In this paper, we propose a fine-tuning approach to bridge the semantic gap in code search and improve the search accuracy. We collect 80 723 different pairs of <comment, code snippet> from Etherscan.io and use these pairs to fine-tune, validate, and test the pre-trained CodeBERT model. Using the fine-tuned model, we develop a code search engine specifically for smart contracts. We evaluate the Recall@ k and Mean Reciprocal Rank (MRR) of the fine-tuned CodeBERT model using different proportions of the fine-tuned data. It is encouraging that even a small amount of fine-tuned data can produce satisfactory results. In addition, we perform a comparative analysis between the fine-tuned CodeBERT model and the two state-of-the-art models. The experimental results show that the fine-tuned CodeBERT model has superior performance in terms of Recall@ k and MRR. These findings highlight the effectiveness of our fine-tuning approach and its potential to significantly improve the code search accuracy.

Open access
FinTech, Crowdfunding, Digital Finance
Blockchain Technology Applications and Security
Auction Theory and Applications
Original source
May 30, 2023·Proceedings of the 27th International Conference on Evaluation and Assessment in Software Engineering
7 cites
Decentralised Autonomous Organisations for Public Procurement

Felix Monteiro, Miguel Correia

Blockchain has been recognised as a technological breakthrough with the ability to support new decentralised security-based solutions in sectors such as information technology and finance. Blockchain allows different communities to create Decentralised Autonomous Organisations (DAOs), which are self-organised democratic organisations controlled by smart contracts. This paper presents a new DAO model for the procurement of services by public organisations, such as government agencies. To demonstrate the advantages of this solution, this work looks specifically at current public procurement systems that resort to third-party contractors that manage these negotiations. Third parties lack the transparency, security, and democratic representation that a DAO can provide. We present the implementation of a DAO as a set of smart contracts executed on Ethereum-compatible permissionless blockchains, supported by a consensus algorithm, replacing third-party contractors.

Open access
Blockchain Technology Applications and Security
Cryptography and Data Security
Auction Theory and Applications
Original source
May 28, 2023·arXiv (Cornell University)
13 cites
Understanding Blockchain Governance: Analyzing Decentralized Voting to Amend DeFi Smart Contracts

Johnnatan Messias, Vabuk Pahari, B. Chandrasekaran, Krishna P. Gummadi · 5 authors

Smart contracts are contractual agreements between participants of a blockchain, who cannot implicitly trust one another. They are software programs that run on top of a blockchain, and we may need to change them from time to time (e.g., to fix bugs or address new use cases). Governance protocols define the means for amending or changing these smart contracts without any centralized authority. They distribute the decision-making power to every user of the smart contract: Users vote on accepting or rejecting every change. In this work, we review and characterize decentralized governance in practice, using Compound and Uniswap -- two widely used governance protocols -- as a case study. We reveal a high concentration of voting power in both Compound and Uniswap: 10 voters hold together 57.86% and 44.72% of the voting power, respectively. Although proposals to change or amend the protocol receive, on average, a substantial number of votes (i.e., 89.39%) in favor within the Compound protocol, they require fewer than three voters to obtain 50% or more votes. We show that voting on Compound proposals can be unfairly expensive for small token holders, and we discover voting coalitions that can further marginalize these users.

Open access
2 source records
Blockchain Technology Applications and Security
Internet Traffic Analysis and Secure E-voting
Auction Theory and Applications
Original source
May 22, 2023·Anais do VI Workshop em Blockchain: Teoria, Tecnologias e Aplicações (WBlockchain 2023)
6 cites
Evaluation of a High-Level Metamodel for Developing Smart Contracts on the Ethereum Virtual Machine

Gislainy Crisostomo Velasco, Marcos Alves Vieira, Sérgio T. Carvalho

Developers of smart contracts face challenges such as the immutability of contracts and asset storage, which make the activity complex and errorprone. To make contracts safer and more reliable, Model-Driven Engineering (MDE) offers an alternative approach with an emphasis on the High-Level Metamodel for Smart Contract (HLM-SC), which allows for the high-level declaration of elements within a contract. This paper evaluates the HLM-SC using the MQuaRE framework to verify its conceptual validity with 11 external evaluators. The results demonstrated the acceptance of the metamodel. Additionally, this paper presents a guide on how to use HLM-SC to facilitate its adoption by developers. Finally, it demonstrates the application of HLM-SC in a scenario related to the NFT industry.

Open access
Blockchain Technology Applications and Security
FinTech, Crowdfunding, Digital Finance
Auction Theory and Applications
Original source
May 15, 2023·IEEE Transactions on Software Engineering
47 cites
DAppSCAN: Building Large-Scale Datasets for Smart Contract Weaknesses in DApp Projects

Zibin Zheng, Jianzhong Su, Jiachi Chen, David Lo · 6 authors

The Smart Contract Weakness Classification Registry (SWC Registry) is a widely recognized list of smart contract weaknesses specific to the Ethereum platform. Despite the SWC Registry not being updated with new entries since 2020, the sustained development of smart contract analysis tools for detecting SWC-listed weaknesses highlights their ongoing significance in the field. However, evaluating these tools has proven challenging due to the absence of a large, unbiased, real-world dataset. To address this problem, we aim to build a large-scale SWC weakness dataset from real-world DApp projects. We recruited 22 participants and spent 44 person-months analyzing 1,199 open-source audit reports from 29 security teams. In total, we identified 9,154 weaknesses and developed two distinct datasets, i.e., DAPPSCAN-SOURCE and DAPPSCAN-BYTECODE. The DAPPSCAN-SOURCE dataset comprises 39,904 Solidity files, featuring 1,618 SWC weaknesses sourced from 682 real-world DApp projects. However, the Solidity files in this dataset may not be directly compilable for further analysis. To facilitate automated analysis, we developed a tool capable of automatically identifying dependency relationships within DApp projects and completing missing public libraries. Using this tool, we created DAPPSCAN-BYTECODE dataset, which consists of 6,665 compiled smart contract with 888 SWC weaknesses. Based on DAPPSCAN-BYTECODE, we conducted an empirical study to evaluate the performance of state-of-the-art smart contract weakness detection tools. The evaluation results revealed sub-par performance for these tools in terms of both effectiveness and success detection rate, indicating that future development should prioritize real-world datasets over simplistic toy contracts.

Open access
3 source records
Big Data and Business Intelligence
Modeling, Simulation, and Optimization
Reservoir Engineering and Simulation Methods
Original source
May 14, 2023·39th IEEE/ACM International Conference on Automated Software Engineering, October 27-November 1, 2024, Sacramento, CA, USA
4 cites
HighGuard: Cross-Chain Business Logic Monitoring of Smart Contracts

Mojtaba Eshghie, Cyrille Artho, Hans Stammler, Wolfgang Ahrendt · 6 authors

Logical flaws in smart contracts are often exploited, leading to significant financial losses. Our tool, HighGuard, detects transactions that violate business logic specifications of smart contracts. HighGuard employs dynamic condition response (DCR) graph models as formal specifications to verify contract execution against these models. It is capable of operating in a cross-chain environment for detecting business logic flaws across different blockchain platforms. We demonstrate HighGuard's effectiveness in identifying deviations from specified behaviors in smart contracts without requiring code instrumentation or incurring additional gas costs. By using precise specifications in the monitor, HighGuard achieves detection without false positives. Our evaluation, involving 54 exploits, confirms HighGuard's effectiveness in detecting business logic vulnerabilities. Our open-source implementation of HighGuard and a screencast of its usage are available at: https://github.com/mojtaba-eshghie/HighGuard https://www.youtube.com/watch?v=sZYVV-slDaY

Open access
3 source records
Blockchain Technology Applications and Security
Auction Theory and Applications
cs.CR
Original source
May 7, 2023·arXiv (Cornell University)
0 cites
Which Games are Unaffected by Absolute Commitments?

Daji Landis, Nikolaj I. Schwartzbach

We identify a subtle security issue that impacts mechanism design in scenarios in which agents can absolutely commit to strategies. Absolute commitments allow the strategy of an agent to depend on the commitments made by the other agents. This changes fundamental game-theoretic assumptions by inducing a meta-game in which agents choose which strategies they commit to. We say that a game that is unaffected by such commitments is Stackelberg resilient and show that computing it is intractible in general, although it can be computed efficiently for two-player games of perfect information. We show the intuitive, but technically non-trivial result, that, if a game is resilient when some number of players have the capacity to make commitments, it is also resilient when these commitments are available to fewer players. We demonstrate the non-triviality of Stackelberg resilience by analyzing two escrow mechanisms from the literature. These mechanisms have the same intended functionality, but we show that only one is Stackelberg resilient. Our model is particularly relevant in Web3 scenarios, where these absolute commitments can be realized by the automated and irrevocable nature of smart contracts. Our work highlights an important issue in ensuring the secure design of Web3. In particular, our work suggests that smart contracts already deployed on major blockchains may be susceptible to these attacks.

Open access
3 source records
cs.GT
Blockchain Technology Applications and Security
Cryptography and Data Security
Original source