Federico Cernera, Massimo La Morgia, Alessandro Mei, Alberto Maria Mongardini · 5 authors
In the world of cryptocurrencies, public listing of a new token often generates significant hype, in many cases causing its price to skyrocket in a few seconds. In this scenario, timing is crucial to determine the success or failure of an investment opportunity. In this work, we present an in-depth analysis of sniper bots, automated tools designed to buy tokens as soon as they are listed on the market. We leverage GitHub open-source repositories of sniper bots to analyze their features and how they are implemented. Then, we build a dataset of Ethereum and BNB Smart Chain (BSC) liquidity pools to identify addresses that serially take advantage of sniper bots. Our findings reveal 14,029 sniping operations on Ethereum and 1,395,042 in BSC that bought tokens for a total of $10,144,808 dollars and $18,720,447, respectively. We find that Ethereum operations have a higher success rate but require a larger investment. Finally, we analyze token smart contracts to identify mechanisms that can hinder sniper bots.
We investigate the connectedness of automated market makers (AMM) that play a pivotal role in liquidity and ease of operations in the decentralized exchange (DEX). By applying the TVP-VAR model, our findings show higher level of connectivity during periods of turmoil (such as Delta, Omicron variants of SARS-Covid, and the Russia Ukraine conflict). Furthermore, risk transmission/reception is found to be independent of the platform on which they typically run (Ethereum based AMMs were both emitters as well as receivers). Pancake (a Binance based AMM) and Perpetual Protocol (Ethereum based AMM) emerged as moderate to high receivers of risk transmission, whereas all of the other AMMs, including Ethereum, were found to be risk emitters at varying degrees. We argue that AMMs typically depend on the underlying smart contracts. If the contract is flexible, AMMs can vary (either receiver or emitter), otherwise AMMs behave in tandem.
The International Journal of Computer Engineering in Research Trends (IJCERT) is a peer-reviewed, open access journal that publishes high-quality research papers, reviews, short communications, and notes in the field of computer science engineering and its research trends. The journal covers a wide range of topics in computer science and engineering, including: Welcome to the International Journal of Computer Engineering in Research Trends (IJCERT), is a peer-reviewed, open access journal dedicated to publishing innovative research papers, reviews, short communications, and notes in the field of computer science engineering and related disciplines. IJCERT encourages conceptual, state-of-the-art, research, standard, implementation, experimental, application, and industrial case study discussions in various areas, including: computer architecture, computer networks, software engineering, information security, artificial intelligence, machine learning, data science, robotics, cyber-physical systems, the internet of things, and other areas of computer science engineering and Its Applications.
Blockchain explorers are important tools for quick look-ups of on-chain activities. However, as centralized data providers, their reliability remains under-studied. As a case study, we investigate Beaconcha.in , a leading explorer serving Ethereum’s proof-of-stake (PoS) update. According to the explorer, we find that more than 75% of slashable Byzantine actions were not slashed. Since Ethereum relies on the “stake-and-slash" mechanism to align incentives, this finding would at its face value cause concern over Ethereum’s security. However, further investigation reveals that all the apparent unslashed incidents were erroneously recorded due to the explorer’s mishandling of consensus edge cases. Besides the usual message of using caution with centralized information providers, our findings also call for attention to improving the monitoring of blockchain systems that support high-value applications.
Teknolojinin gelişmesiyle birlikte kripto para borsaları insanların daha fazla gelir elde etmek amacıyla kullandığı borsalardan biri olmuştur. Borsalarda alım-satım işlemleri yapılırken teknik ve temel analiz yöntemleri kullanılmaktadır. Teknik analiz, geçmiş verilerden yola çıkarak gelecekteki fiyat hareketlerini tahmin etme işlemidir. Teknik analiz yapılırken çok büyük verilerle karşılaşılınca verilerin analizi zorlaşmakta ve teknik analiz sonucu elde edilecek verilerin hatalı olma ihtimali artmaktadır. Bu durum sonucunda büyük verileri doğru analiz edemeyen yatırımcıların büyük zararlara uğrama ihtimali artmaktadır. Kripto para tahmini hem yatırımcılara doğru karar almak için hem de bilimsel alanda uygulamalara açık olduğu için değerlidir. Bu sebeple bu çalışmada, kripto para hareketliliği en yüksek olan kripto paralar arasından 3 adet kripto para seçilerek fiyat tahmini çalışması yapılmıştır. Seçilen kripto paralar; Bitcoin, Ethereum ve Cardano’dur. Verilerin büyük olması sebebiyle ve karar etkenlerinin analizi açısından Yapay Sinir Ağları ve Regresyon Analizi yöntemleri ile bu kripto paraların açılış, kapanış, gün içindeki en küçük ve en büyük değerleri kullanılarak bir sonraki günün kapanış değeri tahmin edilmiştir. Sonrasında tahmini değerlerle gerçek değerler arasında karşılaştırma yapılmıştır. Çalışma sonucunda Yapay Sinir Ağları ile yapılan tahmin çalışmasının Regresyon Analizi ile yapılan tahmin çalışmasından daha başarılı performans sergilediği gözlemlenmiştir.
The aim of this paper is to investigate the effect of a novel method called linear law-based feature space transformation (LLT) on the accuracy of intraday price movement prediction of cryptocurrencies. To do this, the 1-minute interval price data of Bitcoin, Ethereum, Binance Coin, and Ripple between 1 January 2019 and 22 October 2022 were collected from the Binance cryptocurrency exchange. Then, 14-hour nonoverlapping time windows were applied to sample the price data. The classification was based on the first 12 hours, and the two classes were determined based on whether the closing price rose or fell after the next 2 hours. These price data were first transformed with the LLT, then they were classified by traditional machine learning algorithms with 10-fold cross-validation. Based on the results, LLT greatly increased the accuracy for all cryptocurrencies, which emphasizes the potential of the LLT algorithm in predicting price movements.
The growing potential and high volatility of the cryptocurrency market attract a lot of interest from both businesses and investors. Even though the prices fluctuate, predicting with time serious models such as ARMA and ARIMA would still provide a useful reference for analyzing the market. Recent studies on machine learning methods including RNNs have made new progress in forecasting digital currencies. This study focuses on one of the traditional models ARMA to predict the time serious dataset from 2021-2022 of cryptocurrencies including Bitcoin, Ethereum and Ripple. To be specific, AIC and ADF tests are used to choose the optimal model and suitable dataset. According to the analysis, the ARMA model would be affected by the volatility of Bitcoin. However, the predictions are not precise enough but still a valuable reference for certain businesses and individual investors. More state-of-art machine learning models can be utilized in future study to enhance the performance. Overall, these results shed light on guiding further exploration of crypto currency price prediction.
As the world is advancing into a more digitalized version of itself, people's needs and luxuries are evolving with it.People are gravitating towards online shopping rather than visiting shops physically.In e-commerce, most of the interactions between the buyer and seller occur through an online medium.So, it is essential to have a secure form of interaction between them.This project aims to make a secure interaction between the buyer and seller.The owner who owns the product and the buyer who sells the product both have the unique encrypted id, which will contain the whole transaction detail.The owner who owns the product that can add the product to the blockchain and the buyer who wants to buy has to use his/her encrypted buyer id which is shown on the website to buy the product.When the transaction has been performed using an Ethereum currency the transaction hash is generated which is secure (encrypted) such that if anyone tries to decrypt it is not possible.This project involves the use of smart contracts where it refreshes the encrypted ids on the last transaction and no second transaction id from the same buyer is the same as the first transaction.
From gold standard currencies to fiat money secured by government credit, to today's cryptocurrencies, the basic form of money and mankind's perception of its value has shifted dramatically. This paper will demonstrate the value and risk assessment of the two cryptocurrencies with the highest market share, i.e., Bitcoin and Ethereum. Although the current technology of cryptocurrencies is not perfect, it will improve over time and their value will increase due to the high demand for them. This aim of the study to give first-time investors an understanding of the valuation and risks of cryptocurrencies, rather than treating them as simple financial assets for investment. According to the analysis, the value and risk of Bitcoin depend deeply on many characteristics that were initially built into it. It also has an impact on the value of other virtual currencies at the same time. On the other hand, Ether is a much more open platform, so its value and risk depend more on the various applications and contracts built into a blockchain than Bitcoin. These results shed the light on guiding the further exploration of solving the safety problem of cryptocurrencies from different perspectives.
R. A. Zamare, Pramey Deshmukh, Chinmay Gulhane, Mohd Meeran Iqbal · 6 authors
The use of E-Voting systems has become popular in these recent years due to the ability of Blockchain environment to provide a more efficient and convenient voting process. Earlier, the security and integrity of e-voting systems has been very concerning, as they are vulnerable to cyber-attacks and manipulation. On the contrary, Blockchain technology provides a decentralized and distributed platform that can ensure the integrity and immutability of data. This research paper proposes an e-voting system based on blockchain technology. The proposed system aims to provide a secure, transparent, and tamper-proof voting process. The system utilizes smart contracts, which automates the voting processes and ensures the accuracy of the results. The system also provides transparency and accuracy, allowing voters to verify their vote and ensuring that the results are accurate and trustworthy. The proposed system will be tested and evaluated to determine its effectiveness and feasibility. The evaluation will focus on the security, scalability, and usability of the system. The security evaluation will test the system's ability to prevent attacks and ensure the confidentiality of the votes. The scalability evaluation will test the system's ability to handle a large number of voters and transactions. The usability evaluation will test the ease of use and accessibility of the system for all types of voters
Open access
Blockchain Technology Applications and Security
Internet Traffic Analysis and Secure E-voting
Advanced Steganography and Watermarking Techniques
The blockchain-powered decentralized applications and systems have been widely deployed in recent years. The decentralization feature promises users anonymity, security, and non-censorship, which is especially welcomed in the areas of decentralized finance and digital assets. From the perspective of most common users, a decentralized ecosystem means every service follows the principle of decentralization. However, we find that the services in a decentralized ecosystem still may contain centralized components or scenarios, like third-party SDKs and privileged operations, which violate the promise of decentralization and may cause a series of centralized security risks. In this work, we systematically study the centralized security risks existing in decentralized ecosystems. Specifically, we identify seven centralized security risks in the deployment of two typical decentralized services – crypto wallets and DApps, such as anonymity loss and overpowered owner. Also, to measure these risks in the wild, we designed an automated detection tool called Naga and carried out large-scale experiments. Based on the measurement of 28 Ethereum crypto wallets (Android version) and 110,506 on-chain smart contracts, the result shows that the centralized security risks are widespread. Up to 96.4% of wallets and 83.5% of contracts exist at least one security risk, including 260 well-known tokens with a total market cap of over $98 billion.
In the present digital era, Personal Data Privacy is considered one of the fundamental rights in many countries, and regulation demands strict compliance with privacy laws. Patient Health Records in electronic form are highly personal and must be handled with due care and sensitivity to ensure the individual's privacy by giving full control to the patient by employing a self-sovereign model and, at the same time, protected from attacks by hackers. While blockchain technology, with its distributed ledger and immutability, promises to take care of the basic privacy and security requirements of personal digital data, there are several areas where improvements are needed in order to make this technology a robust, practical system. This paper proposes a system which introduces the privacy protection mechanisms to be applied to a blockchain-based patient records system for full privacy protection. The data is shared between different stakeholders in an encrypted format with a session key operational for a predetermined amount of time. The session keys are managed by private certificate authorization with quantum resistance NTRU algorithm. A comparative analysis of various asymmetric key cryptography algorithms indicates that Enhanced NTRU is superior in performance and provides the best security. The encrypted Electronic Health Record (EHR) is stored using Interplanetary File System (IPFS) protocol, and its hashes are recorded on the Ethereum blockchain test network. IPFS solves the issue of storing a large amount of data on the blockchain, and encryption solves the data transparency with Public Key Infrastructure (PKI) to resolve the authentication of the stakeholders. The proposed system's response time, latency, resource utilization and efficiency have been assessed experimentally for various transactions. The proposed system ensures patient confidentiality while sharing health records, making it future-proof.
Pedro Vílchez, Saulo Jacques, Fèlix Freitag, Roc Meseguer
Environmental monitoring is a growing application of the Internet of Things. The low cost of the sensor nodes, LoRa connectivity, and increased awareness of environmental issues have motivated many citizens to participate in open IoT monitoring applications. However, the value of these applications for decision makers is limited since the data from the IoT sensors do not have sufficient guarantees to be trusted. In this paper, we introduce a new concept that attributes value to both IoT data and devices, such as sensor nodes and gateways, and leverage distributed ledger technology to enable a data trust system. A first design decision was to assign Ethereum addresses with their associated public and private key pairs to all actors. This allows the authentication of data senders and hence the accounting for the contribution of each participant. Secondly, we introduce an auditor to validate the received IoT data. The results of these audits increase the trust in the quality of the data. We present the architectural components that we designed to enhance trust in open IoT monitoring applications and present an operational prototype to show the feasibility of the implementation. By achieving both trust in the data and accounting of contributions for giving rewards, open participatory IoT monitoring applications can become both valuable and sustainable. Then, trusted open monitoring may complement commercial solutions as a technical and economic alternative for addressing the increasing environmental monitoring needs of our society.
Yu Gai, Liyi Zhou, Kaihua Qin, Dawn Song · 5 authors
This paper presents a dynamic, real-time approach to detecting anomalous blockchain transactions. The proposed tool, BlockGPT, generates tracing representations of blockchain activity and trains from scratch a large language model to act as a real-time Intrusion Detection System. Unlike traditional methods, BlockGPT is designed to offer an unrestricted search space and does not rely on predefined rules or patterns, enabling it to detect a broader range of anomalies. We demonstrate the effectiveness of BlockGPT through its use as an anomaly detection tool for Ethereum transactions. In our experiments, it effectively identifies abnormal transactions among a dataset of 68M transactions and has a batched throughput of 2284 transactions per second on average. Our results show that, BlockGPT identifies abnormal transactions by ranking 49 out of 124 attacks among the top-3 most abnormal transactions interacting with their victim contracts. This work makes contributions to the field of blockchain transaction analysis by introducing a custom data encoding compatible with the transformer architecture, a domain-specific tokenization technique, and a tree encoding method specifically crafted for the Ethereum Virtual Machine (EVM) trace representation.
In this paper, we have presented the design and implementation of a blockchain-based approach for ensuring reliable supply chain management for commodities transported through smart containers. To administer interactions between the sender and receiver, our developed system makes use of the Ethereum blockchain’s smart contract features. Smart containers equipped with Internet of Things (IoT)-enabled sensors are used to monitor shipping conditions to check predefined shipping requirements. Smart contracts on Ethereum are used to automate payments, validate receivers, and give refunds in the case of violation of predefined requirements. We have also implemented our designed front-end decentralized WebApp and wallet that allows the sender and receiver to communicate with Ethereum smart contracts.
The Internet of Things (IoT) technology has grown rapidly and continuously. The IoT ecosystem comprises an increasing number of smart devices that can sense, act, process, store, and communicate via the Internet. Data within such communication technology is continuously exposed to be hacked or attacked. Therefore, there should be methods to protect the issue of data authentication and increase the security of such large-scale networks. In this article, a method of using a Blockchain network is proposed. The proposed system uses the Ethereum blockchain and benefits from several critical technologies, including distributed consensus, smart contracts, digital signatures, and cryptographic hashes. The whitelist and blacklist are the two lists that are suggested. The approved users who have obtained their private keys are included on the whitelist. The blacklist, on the other hand, is intended to stop illegal users who are flagged as spammers or attacks. According to findings, the Blockchain can drastically save expenses and boost the security of IoT networks
Recent years have witnessed explosive growth in blockchain smart contract applications. As smart contracts become increasingly popular and carry trillion dollars worth of digital assets, they become more of an appealing target for attackers, who have exploited vulnerabilities in smart contracts to cause catastrophic economic losses. Notwithstanding a proliferation of work that has been developed to detect an impressive list of vulnerabilities, the bad randomness vulnerability is overlooked by many existing tools. In this paper, we make the first attempt to provide a systematic analysis of random numbers in Ethereum smart contracts, by investigating the principles behind pseudo-random number generation and organizing them into a taxonomy. We also lucubrate various attacks against bad random numbers and group them into four categories. Furthermore, we present RNVulDet - a tool that incorporates taint analysis techniques to automatically identify bad randomness vulnerabilities and detect corresponding attack transactions. To extensively verify the effectiveness of RNVulDet, we construct three new datasets: i) 34 well-known contracts that are reported to possess bad randomness vulnerabilities, ii) 214 popular contracts that have been rigorously audited before launch and are regarded as free of bad randomness vulnerabilities, and iii) a dataset consisting of 47,668 smart contracts and 49,951 suspicious transactions. We compare RNVulDet with three state-of-the-art smart contract vulnerability detectors, and our tool significantly outperforms them. Meanwhile, RNVulDet spends 2.98s per contract on average, in most cases orders-of-magnitude faster than other tools. RNVulDet successfully reveals 44,264 attack transactions. Our implementation and datasets are released, hoping to inspire others.
Smart contracts are small programs on the blockchain that often handle valuable assets. Vulnerabilities in smart contracts can be costly, as time has shown over and over again. Countermeasures are high in demand and include best practice recommendations as well as tools supporting development, program verification, and post-deployment analysis. Many tools focus on detecting the absence or presence of a subset of the known vulnerabilities, delivering results of varying quality. Most comparative tool evaluations resort to selecting a handful of tools and testing them against each other. In the best case, the evaluation is based on a smallish ground truth. For Ethereum, there are commendable efforts by several author groups to manually classify contracts. However, a comprehensive ground truth is still lacking. In this work, we construct a ground truth based on publicly available benchmark sets for Ethereum smart contracts with manually checked ground truth data. We develop a method to unify these sets. Additionally, we devise strategies for matching entries that pertain to the same contract, such that we can determine overlaps and disagreements between the sets and consolidate the disagreements. Finally, we assess the quality of the included ground truth sets. Our work reduces inconsistencies, redundancies, and incompleteness while increasing the number of data points and heterogeneity.
Izdehar M. Aldyaflah, Wenbing Zhao, Himanshu Upadhyay, Leonel Lagos
In this paper, we present a secure datastore based on an Ethereum smart contract. Our research is guided by three research questions. First, we will explore to what extend a smart-contract-based datastore should resemble a traditional database system. Second, we will investigate how to store the data in a smart-contract-based datastore for maximum flexibility while minimizing the gas consumption. Third, we seek answers regarding whether or not a smart-contract-based datastore should incorporate complex processing such as data encryption and data analytic algorithms. The proposed smart-contract-based datastore aims to strike a good balance between several constraints: (1) smart contracts are publicly visible, which may create a confidentiality concern for the data stored in the datastore; (2) unlike traditional database systems, the Ethereum smart contract programming language (i.e., Solidity) offers very limited data structures for data management; (3) all operations that mutate the blockchain state would incur financial costs and the developers for smart contracts must make sure sufficient gas is provisioned for every smart contract call, and ideally, the gas consumption should be minimized. Our investigation shows that although it is essential for a smart-contract-based datastore to offer some basic data query functionality, it is impractical to offer query flexibility that resembles that of a traditional database system. Furthermore, we propose that data should be structured as tag-value pairs, where the tag serves as a non-unique key that describes the nature of the value. We also conclude that complex processing should not be allowed in the smart contract due to the financial burden and security concerns. The tag-based secure datastore designed this way also defines its applicative perimeter, i.e., only applications that align with our strategy would find the proposed datastore a good fit. Those that would rather incur higher financial cost for more data query flexibility and/or less user burden on data pre- and post-processing would find the proposed database too restrictive.
Sarah Azouvi, Guy Goren, Lioba Heimbach, Alexander Hicks
In 2021 Ethereum adjusted the transaction pricing mechanism by implementing EIP-1559, which introduces the base fee - a network fee that is burned and dynamically adjusts to the network demand. The authors of the Ethereum Improvement Proposal (EIP) noted that a miner with more than 50% of the mining power could be incentivized to deviate from the honest mining strategy. Instead, such a miner could propose a series of empty blocks to artificially lower demand and increase her future rewards. In this paper, we generalize this attack and show that under rational player behavior, deviating from the honest strategy can be profitable for a miner with less than 50% of the mining power. We show that even when miners do not collaborate, it is at times rational for smaller miners to join the attack. Finally, we propose a mitigation to address the identified vulnerability.
We introduce SCooLS, our Smart Contract Learning (Semi-supervised) engine. SCooLS uses neural networks to analyze Ethereum contract bytecode and identifies specific vulnerable functions. SCooLS incorporates two key elements: semi-supervised learning and graph neural networks (GNNs). Semi-supervised learning produces more accurate models than unsupervised learning, while not requiring the large oracle-labeled training set that supervised learning requires. GNNs enable direct analysis of smart contract bytecode without any manual feature engineering, predefined patterns, or expert rules. SCooLS is the first application of semi-supervised learning to smart contract vulnerability analysis, as well as the first deep learning-based vulnerability analyzer to identify specific vulnera-ble functions. SCooLS's performance is better than existing tools, with an accuracy level of 98.4%, an F1 score of 90.5%, and an exceptionally low false positive rate of only 0.8%. Furthermore, SCooLS is fast, analyzing a typical function in 0.05 seconds. We leverage SCooLS's ability to identify specific vulnerable functions to build an exploit generator, which was successful in stealing Ether from 76.9% of the true positives.
We introduce the Deep Learning Vulnerability Analyzer (DLVA) for Ethereum smart contracts based on neural networks. We train DLVA to judge bytecode even though the supervising oracle can only judge source. DLVA's training algorithm is general: we extend a source code analysis to bytecode without any manual feature engineering, predefined patterns, or expert rules. DLVA's training algorithm is also robust: it overcame a 1.25% error rate mislabeled contracts, and--the student surpassing the teacher--found vulnerable contracts that Slither mislabeled. DLVA is much faster than other smart contract vulnerability detectors: DLVA checks contracts for 29 vulnerabilities in 0.2 seconds, a 10-1,000x speedup. DLVA has three key components. First, Smart Contract to Vector (SC2V) uses neural networks to map smart contract bytecode to a high-dimensional floating-point vector. We benchmark SC2V against 4 state-of-the-art graph neural networks and show that it improves model differentiation by 2.2%. Second, Sibling Detector (SD) classifies contracts when a target contract's vector is Euclidian-close to a labeled contract's vector in a training set; although only able to judge 55.7% of the contracts in our test set, it has a Slither-predictive accuracy of 97.4% with a false positive rate of only 0.1%. Third, Core Classifier (CC) uses neural networks to infer vulnerable contracts regardless of vector distance. We benchmark DLVA's CC with 10 ML techniques and show that the CC improves accuracy by 11.3%. Overall, DLVA predicts Slither's labels with an overall accuracy of 92.7% and associated false positive rate of 7.2%. Lastly, we benchmark DLVA against nine well-known smart contract analysis tools. Despite using much less analysis time, DLVA completed every query, leading the pack with an average accuracy of 99.7%, pleasingly balancing high true positive rates with low false positive rates.
Contrats intelligents pour les enchères : de l'évaluation expérimentale à la confidentialité La sécurité et la transparence des blockchains semblent fournir un environnement adaptépour les enchères. Nous nous focalisons sur l'enchère Vickrey-Clarke-Groves pour larecherche sponsorisée (VCG) pour évaluer cette hypothèse. Nous proposons et utilisonsune méthodologie pour la comparaison de différents blockchains du point de vue descontrats intelligents (smart contracts). En utilisant VCG, nous avons comparé Ethereumet Tezos ainsi que les mises à jour récentes d’Ethereum sous la forme d'Ethereum Mergeet Polygon POS. Enfin, nous analysons les conséquences du manque de confidentialitédes blockchains dans une enchère telle que VCG, en proposant trois nouveauxalgorithmes pour en atténuer les effets négatifs.