Samuel de Oliveira Ribeiro, Dayan Ramos Gomes, Emanuel Ferreira Coutinho, Glauber Dias Gonçalves
Token não fungível ou NFT é um objeto digital insubstituível por qualquer outro objeto, seja do mesmo tipo ou valor, com atributos que provam a sua propriedade a uma pessoa ou organização via redes blockchain. A indústria de artes e mídias digitais vem adotando gradativamente NFTs devido a sua segurança para definir autoria, transferência, royalties desses tokens, entre outros recursos que podem ser programados em contratos inteligentes. Como NFT é uma tecnologia nova com popularidade em ascendência, há oportunidades para desenvolvimento de ferramentas que auxiliem os usuários no consumo desse tipo de token. Neste trabalho, realizamos uma análise e caracterização de coleções de NFTs baseada em dados extraídos do OpenSea, que é a maior plataforma de comercialização de NFTs na atualidade. Utilizamos uma abordagem de classificação não supervisionada para conhecer propriedades estruturais dessas coleções. Isso nos permitiu definir quatro classes de coleções de NFTs que podem ser facilmente compreendidas por usuários para facilitar o comércio e a valoração de seus tokens.
Jiseong Noh, Donghwan Kwon, S.M. Cho, Neo C. K. Yiu
The comparative analysis examined eleven Proof-of-Stake (PoS) consensus-based blockchain networks to assess their openness based on five indicative metrics. These metrics include those of decentralization-related aspects, such as the number of validators and capital concentration, and participation-related aspects, including entry capital requirements and economic network stability. This is to assess and characterize the openness of Proof-of-Stake blockchain networks. The analysis suggested that networks with higher openness included Solana and Avalanche, while BNB Chain, Klaytn, and Polygon measured with lower levels of openness. According to the comparative analysis, Ethereum scored high on network openness in terms of the number of participants and the cost of running the chain, but scored relatively low on capital concentration and staking ratio, which is likely due to the low ratio of staked ether (ETH) to circulating supply and the significant stakes in staking pools like Lido. Permissioned blockchains such as Klaytn and Polygon have limited openness, which suggests the need to take the level of openness into account when transitioning into a permissionless blockchain architecture with a more decentralized setting.
Gislainy Crisostomo Velasco, Noelí Antonia Pimentel Vaz, Sérgio T. Carvalho
The development of smart contracts presents significant challenges compared to traditional software development, such as the immutability of the blockchain. This paper presents a systematic literature review (SLR) that aims to understand the limitations and challenges faced by smart contract developers on the Ethereum Virtual Machine (EVM). Among the main challenges identified are language restrictions, infrastructure limitations, and the lack of sufficient information on interface patterns and implementation specifications. Existing proposals are difficult to understand, with complex formal verifications that require advanced technical knowledge. Additionally, the scarcity of accessible educational resources for training new smart contract developers represents a major challenge to be overcome. In this regard, the SLR seeks to identify opportunities for improvement and innovation in the field, as well as validation and evaluation strategies to make the smart contract development process more efficient and secure.
Gislainy Crisostomo Velasco, Marcos Alves Vieira, Sérgio T. Carvalho
Developers of smart contracts face challenges such as the immutability of contracts and asset storage, which make the activity complex and errorprone. To make contracts safer and more reliable, Model-Driven Engineering (MDE) offers an alternative approach with an emphasis on the High-Level Metamodel for Smart Contract (HLM-SC), which allows for the high-level declaration of elements within a contract. This paper evaluates the HLM-SC using the MQuaRE framework to verify its conceptual validity with 11 external evaluators. The results demonstrated the acceptance of the metamodel. Additionally, this paper presents a guide on how to use HLM-SC to facilitate its adoption by developers. Finally, it demonstrates the application of HLM-SC in a scenario related to the NFT industry.
The wide application of Ethereum smart contracts in the Internet of Things, finance, medical, and other fields is associated with security challenges. Traditional detection methods detect vulnerabilities by stacking hard rules, which are associated with the bottleneck of a high false-positive rate and low detection efficiency. To make up for the shortcomings of traditional methods, existing deep learning methods improve model performance by combining multiple models, resulting in complex structures. From the perspective of optimizing the model feature space, this study proposes a vulnerability detection scheme for Ethereum smart contracts based on metric learning and a bidirectional long short-term memory (BiLSTM) network. First, the source code of the Ethereum contract is preprocessed, and the word vector representation is used to extract features. Secondly, the representation is combined with metric learning and the BiLSTM model to optimize the feature space and realize the cohesion of similar contracts and the discreteness of heterogeneous contracts, improving the detection accuracy. In addition, an attention mechanism is introduced to screen key vulnerability features to enhance detection observability. The proposed method was evaluated on a large-scale dataset containing four types of vulnerabilities: arithmetic vulnerabilities, re-entrancy vulnerabilities, unchecked calls, and inconsistent access controls. The results show that the proposed scheme exhibits excellent detection performance. The accuracy rates reached 88.31%, 93.25%, 91.85%, and 90.59%, respectively.
<p><big>In this study, we examined the efficiency of cryptocurrencies Bitcoin (BTC), Ethereum (ETH), Litecoin (LTC), Ripple (XRP), DASH, EOS, and MONERO from March 1, 2018, to March 1, 2023. We separated the sample into four subperiods for this purpose: a Tranquil period that includes the period from March 1, 2018, to December 31, 2019; a First Wave that includes the year 2020; a Second Wave that includes the year 2021; and a fourth subperiod that includes Russia&#39;s invasion of Ukraine in 2022-2023. The results are mixed, with some cryptocurrencies exhibiting equilibrium and others exhibiting autocorrelation and predictability in their pricing. When the sample is divided into subperiods, most digital currencies have long memories in their returns during the Tranquil period, BTC, LTC, and XRP exhibit efficiency during the First Wave of the pandemic, while BTC, ETH, and MONERO indicate efficiency during the Second Wave. Most assessed digital currencies showed equilibrium by 2022, with the exception of ETH and MONERO, which exhibit long memories, and LTC, which demonstrates anti-persistence. These results hold significance for investors in these alternative markets, as they suggest that some cryptocurrencies may be more predictable and therefore potentially profitable, whereas others may require greater caution and risk management strategies.</big></p>
Phishing is a widespread scam activity on Ethereum, causing huge financial losses to victims. Most existing phishing scam detection methods abstract accounts on Ethereum as nodes and transactions as edges, then use manual statistics of static node features to obtain node embedding and finally identify phishing scams through classification models. However, these methods can not dynamically learn new Ethereum transactions. Since the phishing scams finished in a short time, a method that can detect phishing scams in real-time is needed. In this paper, we propose a streaming phishing scam detection method. To achieve streaming detection and capture the dynamic changes of Ethereum transactions, we first abstract transactions into edge features instead of node features, and then design a broadcast mechanism and a storage module, which integrate historical transaction information and neighbor transaction information to strengthen the node embedding. Finally, the node embedding can be learned from the storage module and the previous node embedding. Experimental results show that our method achieves decent performance on the Ethereum phishing scam detection task.
In recent years, there have been many attempts to introduce blockchain-based identity management solutions, which allow the user to take over control of his/her own identity. In this paper, the authors have reviewed in-depth existing blockchain-based identity management papers and patents published online. Based on that analysis of the literature, a system will be implemented which will come up with the current issues and try to minimize them. Being transparent, immutable, and decentralized in nature, blockchain mechanism is found to be a better technology which can reduce the corruption in the experimental scenario. The objective is to develop a decentralized system which can be used for the verification of the employees in an organization. This is done to stop or reduce the cases of identity theft and data leakage in recent time. This system will be using Ethereum blockchain platform for monitoring the information and smart contract for authentication.
Crowdfunding is a popular method for raising funds for projects, businesses, and social causes.However, traditional crowdfunding platforms are often centralized, opaque, and inefficient.In recent years, Blockchain technology has become a potentially effective remedy to these problems.By leveraging the benefits of blockchain, such as transparency, security, and efficiency, we can create a new paradigm for crowdfunding that is decentralized, transparent, and efficient.In this paper, we explore the use of blockchain in crowdfunding and describe a prototype crowdfunding platform that uses Solidity, Next.js,Node.js,Polygon, Metamask, IPFS, and Infura to provide a secure, efficient, and transparent way for users to create and donate to campaigns on the Ethereum blockchain.The use of smart contracts ensures that the funds are securely and efficiently allocated, while the integration of IPFS and Infura allows for decentralized storage of data and access to the Ethereum network.Our prototype demonstrates the potential of blockchain-based crowdfunding to transform the way we fund projects and causes.
The market for Non-Fungible Tokens (NFT) has grown significantly during the past few years.The idea behind NFT (Non-Fungible Tokens) is derived from the Ethereum token standard, which seeks to distinguish between Tokens with various indications.These NFTs are the type of digital token that may be used to pinpoint a certain characteristic of a digital asset.These NFTs make advantage of cutting-edge blockchain technology.The Non-Fungible Tokens (NFTs), which are tokens with integrated digital assets and proof of work, are the result of extensive study in the blockchain industry.
Decentralization forms an integral part of democracy, arising from the conduction of elections.Modern democracies rely heavily on elections.However, there is a lack of trust building up due to the cases of discrepancies in the process.The "e-voting" system was developed after the 1960s.It overcame a lot of issues existing in the ballot voting system.In present times the significance of E-Voting has grown drastically.It cuts down the cost of hosting an election and increases the number of participants as they are free to cast their vote from any location, without any ballot boxes, or areas for establishing polling booths.There were still obstacles to overcome and deliver results.Even the most developed democracies, such as India and the United States, have error-prone voting processes.Voter fraud, EVM hacking, and polling station theft are the main issues with the current voting system.Reliability along with security and precision must be considered while performing elections.The blockchain with smart-contracts stands out as a leading candidate for developing more reliable, cost-effective, transparent, and user-friendly electronic voting systems.Undoubtedly, the revolutionary blockchain idea is the technology behind the cryptocurrency Bitcoin and its derivatives.Ethereum and its network are among the greatest because of their dependability and wide acceptance.An electronic voting system must be secure and transparent to avoid double voting and maintain privacy.In this study, we have used Ethereum wallet along with Solidity Programming language for developing a smart contact for Ethereum network that works as E-Voting System.
Despite its popularity, the nature of solar energy is highly uncertain and weather dependent, affecting the business viability and investment of solar energy generation, especially for household users. To stabilize the income from solar energy generation, there have been limited traditional options, such as using energy storage to pool excessive solar energy in off-peak periods or financial derivatives from future markets to hedge energy prices. In this paper, we explore a novel idea of "parametric solar energy insurance", by which solar panel owners can insure their solar energy generation based on a verifiable geographically specific index (surface solar irradiation). Parametric solar energy insurance offers opportunities of financial subsidies for insufficient solar energy generation and amortizes the fluctuations of renewable energy generation geographically. Furthermore, we propose to leverage blockchain and remote sensing (satellite imagery) to provide a publicly verifiable platform for solar energy insurance, which not only automates the underwriting and claims of a solar energy insurance policy, but also improves its accountability and transparency. We utilize the state-of-the-art succinct zero-knowledge proofs (zk-SNARK) to realize privacy-preserving blockchain-based solar energy insurance on real-world permissionless blockchain platform Ethereum.
In the era of real-time data, traditional methods often struggle to keep pace with the dynamic nature of streaming environments. In this paper, we proposed a hybrid framework where in (i) stage-I follows a traditional approach where the model is built once and evaluated in a real-time environment, and (ii) stage-II employs an incremental learning approach where the model is continuously retrained as new data arrives, enabling it to adapt and stay up to date. To implement these frameworks, we employed 8 distinct state-of-the-art outlier detection models, including one-class support vector machine (OCSVM), isolation forest adaptive sliding window approach (IForest ASD), exact storm (ES), angle-based outlier detection (ABOD), local outlier factor (LOF), Kitsunes online algorithm (KitNet), and K-nearest neighbour conformal density and distance based (KNN CAD). We evaluated the performance of these models across seven financial and healthcare prediction tasks, including credit card fraud detection, churn prediction, Ethereum fraud detection, heart stroke prediction, and diabetes prediction. The results indicate that our proposed incremental learning framework significantly improves performance, particularly on highly imbalanced datasets. Among all models, the IForest ASD model consistently ranked among the top three best-performing models, demonstrating superior effectiveness across various datasets.
Manufacturing raw materials to get products to consumers in traditional supply chain systems is a manual process with inadequate data and transaction security.In addition, the entire procedure becomes cumbersome as it is time consuming.Overall, undivided processes are inefficient and unreliable for consumers.When blockchain and smart contract technology are integrated with traditional supply chain management system, data security, reliability, time management and transaction process will be greatly improved.Blockchain is a revolutionary decentralized technology that protects data from unauthorized access.Once smart contracts are implemented, the entire supply chain management (SCM) becomes consumer happy.Involvement of intermediaries thus increases the credibility of the plan.The tags used in his traditional SCM process are expensive and offer limited functionality.Therefore, it is difficult for SCM systems to maintain product confidentiality and accountability.It is also a common target for wireless attacks (reply attacks, eavesdropping, etc.).In SCM, the term product confidentiality is very important.This means that only verified persons can access the information.The purpose of this document is to provide an overview of the use of blockchain technology in the supply chain sector.While this technology is often associated with cryptocurrencies, it also shows promise in non-financial applications such as the supply chain, energy and food industries.Blockchain can provide a permanent, shareable and verifiable record of products across the supply chain, improving product traceability, authenticity and legality in a more cost-effective manner.An example of a micro factory proposal using blockchain technology was introduced.
Since the inception of permissionless blockchains with Bitcoin in 2008, it became apparent that their most well-suited use case is related to making the financial system and its advantages available to everyone seamlessly without depending on any trusted intermediaries. Smart contracts across chains provide an ecosystem of decentralized finance (DeFi), where users can interact with lending pools, Automated Market Maker (AMM) exchanges, stablecoins, derivatives, etc. with a cumulative locked value which had exceeded 160B USD. While DeFi comes with high rewards, it also carries plenty of risks. Many financial crimes have occurred over the years making the early detection of malicious activity an issue of high priority. The proposed framework introduces an effective method for extracting a set of features from different chains, including the largest one, Ethereum and it is evaluated over an extensive dataset we gathered with the transactions of the most widely used DeFi protocols (23 in total, including Aave, Compound, Curve, Lido, and Yearn) based on a novel dataset in collaboration with Covalent. Different Machine Learning methods were employed, such as XGBoost and a Neural Network for identifying fraud accounts detection interacting with DeFi and we demonstrate that the introduction of novel DeFi-related features, significantly improves the evaluation results, where Accuracy, Precision, Recall, F1-score and F2-score where utilized.
The rising popularity of e-commerce has led to the widespread adoption of electronic coupons (e-coupons) due to their convenience and portability. However, traditional e-coupon services that rely on centralized servers often face security concerns. Centralization can result in issues like counterfeit e-coupons, difficulties in proving ownership, and the possibility of double-spending on expired e-coupons. In order to address these challenges, we have developed an innovative e-coupon service that harnesses the power of blockchain technology to enhance security. Our approach involves the creation of a dedicated server that facilitates the e-coupon service and interacts seamlessly with the blockchain system. To ensure the integrity of the e-coupon business logic and implementation information, we have developed a smart contract on an Ethereum-based blockchain system. By leveraging this blockchain infrastructure, we can establish a trustable and transparent environment for e-coupon transactions. Through rigorous experimentation and analysis , we have demonstrated that our proposed service significantly bolsters security while incurring only minimal performance impact when compared to existing e-coupon services. By integrating blockchain technology, we provide a robust solution that effectively addresses the concerns surrounding e-coupon security, paving the way for a more reliable and trustworthy e-commerce experience.
Prof. Rupali Jadhav, Sakshi Gawali, Ankita Khutwad
Abstract: This project uses blockchain technology to suggest a workaround for the drawbacks of conventional crowdfunding sites. The suggested platform, "Fund Future," is a decentralised platform for crowdfunding that enables people and organisations to raise money for their projects directly from their supporters. The platform is based on the Ethereum blockchain, which enables smart contracts to carry out the crowdfunding campaign's policies and processes automatically. The platform offers a clear, safe, and effective method of fundraising, making sure that money is delivered properly to the project developers. The project seeks to address the issues that traditional crowdfunding platforms have, like high fees, fraud, and a lack of transparency. With blockchain technology becoming more popular, Fund Future has the potential to completely transform the crowdfunding market.
Most blockchain platforms from Ethereum onwards render smart contracts as stateful reactive objects that update their state and transfer crypto-assets in response to transactions. A drawback of this design is that when users submit a transaction, they cannot predict in which state it will be executed. This exposes them to transaction-ordering attacks, a widespread class of attacks where adversaries with the power to construct blocks of transactions can extract value from smart contracts (the so-called MEV attacks). The UTXO model is an alternative blockchain design that thwarts these attacks by requiring new transactions to spend past ones: since transactions have unique identifiers, reordering attacks are ineffective. Currently, the blockchains following the UTXO model either provide contracts with limited expressiveness (Bitcoin), or require complex run-time environments (Cardano). We present ILLUM , an Intermediate-Level Language for the UTXO Model. ILLUM can express real-world smart contracts, e.g. those found in Decentralized Finance. We define a compiler from ILLUM to a bare-bone UTXO blockchain with loop-free scripts. Our compilation target only requires minimal extensions to Bitcoin Script: in particular, we exploit covenants, a mechanism for preserving scripts along chains of transactions. We prove the security of our compiler: namely, any attack targeting the compiled contract is also observable at the ILLUM level. Hence, the compiler does not introduce new vulnerabilities that were not already present in the source ILLUM contract. We evaluate the practicality of ILLUM as a compilation target for higher-level languages. To this purpose, we implement a compiler from a contract language inspired by Solidity to ILLUM, and we apply it to a benchmark or real-world smart contracts.
<title>Abstract</title> Blockchain Technology has grown exponentially in recent years due to its decentralized, immutable, transparent data storage, transaction sharing, and processing. With the emergence of different blockchain platforms, it is substantial to analyze and evaluate the performance of these platforms in various scenarios. The popularity of the public blockchain, i.e., Bitcoin and Ethereum, has increased manifold. But in distinction to a public blockchain, there is a permissioned and private blockchain that allows restricted involvement of users in the network. To make a well-informed decision regarding the selection of an appropriate platform for utilization, it is crucial to evaluate diverse performance metrics among the numerous available blockchain platforms. In this study, we conducted an assessment of the performance of the Hyperledger Fabric blockchain (HLF), taking into account various metrics such as resource consumption, throughput, success rate, and latency. We have incorporated parameters such as the ordering service, programming language to write chaincode/smart contracts, number of transactions, transactions per second, and organizations to evaluate the system’s performance. Along with our analysis, we also suggested potential areas of research for the future development of blockchain technology.
Traditional Insurance, a popular approach of financial risk management, has suffered from the issues of high operational costs, opaqueness, inefficiency and a lack of trust. Recently, blockchain-enabled "parametric insurance" through authorized data sources (e.g., remote sensing and IoT) aims to overcome these issues by automating the underwriting and claim processes of insurance policies on a blockchain. However, the openness of blockchain platforms raises a concern of user privacy, as the private user data in insurance claims on a blockchain may be exposed to outsiders. In this paper, we propose a privacy-preserving parametric insurance framework based on succinct zero-knowledge proofs (zk-SNARKs), whereby an insuree submits a zero-knowledge proof (without revealing any private data) for the validity of an insurance claim and the authenticity of its data sources to a blockchain for transparent verification. Moreover, we extend the recent zk-SNARKs to support robust privacy protection for multiple heterogeneous data sources and improve its efficiency to cut the incurred gas cost by 80%. As a proof-of-concept, we implemented a working prototype of bushfire parametric insurance on real-world blockchain platform Ethereum, and present extensive empirical evaluations.
Caspar Schwarz-Schilling, Fahad Saleh, Thomas Thiery, Jennifer Pan · 6 authors
We propose a model suggesting that honest-but-rational consensus participants may play timing games, and strategically delay their block proposal to optimize MEV capture, while still ensuring the proposal's timely inclusion in the canonical chain. In this context, ensuring economic fairness among consensus participants is critical to preserving decentralization. We contend that a model grounded in honest-but-rational consensus participation provides a more accurate portrayal of behavior in economically incentivized systems such as blockchain protocols. We empirically investigate timing games on the Ethereum network and demonstrate that while timing games are worth playing, they are not currently being exploited by consensus participants. By quantifying the marginal value of time, we uncover strong evidence pointing towards their future potential, despite the limited exploitation of MEV capture observed at present.
Zibin Zheng, Jianzhong Su, Jiachi Chen, David Lo · 6 authors
The Smart Contract Weakness Classification Registry (SWC Registry) is a widely recognized list of smart contract weaknesses specific to the Ethereum platform. Despite the SWC Registry not being updated with new entries since 2020, the sustained development of smart contract analysis tools for detecting SWC-listed weaknesses highlights their ongoing significance in the field. However, evaluating these tools has proven challenging due to the absence of a large, unbiased, real-world dataset. To address this problem, we aim to build a large-scale SWC weakness dataset from real-world DApp projects. We recruited 22 participants and spent 44 person-months analyzing 1,199 open-source audit reports from 29 security teams. In total, we identified 9,154 weaknesses and developed two distinct datasets, i.e., DAPPSCAN-SOURCE and DAPPSCAN-BYTECODE. The DAPPSCAN-SOURCE dataset comprises 39,904 Solidity files, featuring 1,618 SWC weaknesses sourced from 682 real-world DApp projects. However, the Solidity files in this dataset may not be directly compilable for further analysis. To facilitate automated analysis, we developed a tool capable of automatically identifying dependency relationships within DApp projects and completing missing public libraries. Using this tool, we created DAPPSCAN-BYTECODE dataset, which consists of 6,665 compiled smart contract with 888 SWC weaknesses. Based on DAPPSCAN-BYTECODE, we conducted an empirical study to evaluate the performance of state-of-the-art smart contract weakness detection tools. The evaluation results revealed sub-par performance for these tools in terms of both effectiveness and success detection rate, indicating that future development should prioritize real-world datasets over simplistic toy contracts.
As blockchain technology advances, so has the deployment of smart contracts on blockchain platforms, making it exceedingly challenging for users to explicitly identify application services. Unlike traditional contracts, smart contracts are not written in a natural language, making it difficult to determine their provenance. Automatic classification of smart contracts offers blockchain users keyword-based contract queries and a streamlined effective management of smart contracts. In addition, the advancement in smart contracts is accompanied by security challenges, which are generally caused by domain-specific security breaches in smart contract implementation. The development of secure and reliable smart contracts can be extremely challenging due to domain-specific vulnerabilities and constraints associated with various business logics. Accordingly, contract classification based on the application domain and the transaction context offers greater insight into the syntactic and semantic properties of that class. However, despite initial attempts at classifying Ethereum smart contracts, there has been no research on the identification of smart contracts deployed in transactive energy systems for energy exchange purposes. In this article, in response to the widely recognized prospects of blockchain-enabled smart contracts towards an economical and transparent energy sector, we propose a methodology for the detection and analysis of energy smart contracts. First, smart contracts are parsed by transforming code elements into vectors that encapsulate the semantic and syntactic characteristics of each term. This generates a corpus of annotated text as a balanced, representative collection of terms in energy contracts. The use of a domain corpus builder as an embedding layer to annotate energy smart contracts in conjunction with machine learning models results in a classification accuracy of 98.34%. Subsequently, a source code analysis scheme is applied to identified energy contracts to uncover patterns in code segment distribution, predominant adoption of certain functions, and recurring contracts across the Ethereum network.
Intelligent manufacturing under Industry 4.0 assimilates sophisticated technologies and artificial intelligence for sustainable production and outcomes. Blockchain paradigms are coined with Industry 4.0 for concurrent and well-monitored flawless production. This article introduces Sustainable Production concerned with External Demands (SP-ED). This method is more specific about energy production and the distribution for flawless and outage-less supply. First, the energy demand is identified for internal and external users based on which sustainability is planned. Secondly, Ethereum blockchain monitoring for a similar production and demand satisfaction is coupled with the production system. From two perspectives, the monitoring and condition satisfaction processes are validated using federated learning (FL). The perspectives include demand distribution and production sustainability. In the demand distribution, the condition of meeting the actual requirement is validated. Contrarily, the flaws in internal and external supply due to production are identified in sustainability. The failing conditions in both perspectives are handled using blockchain records. The blockchain records reduce flaws in the new production by modifying the production plan according to the federated learning verifications. Therefore, the sustainability for internal and external demands is met through FL and blockchain integration.