Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

873 papersLast indexed Aug 31, 2026
Search papers

Paper index

873 results ¡ page 16 of 37

Clear filters
Nov 4, 2023¡2023 Eighth International Conference On Mobile And Secure Services (MobiSecServ)
8 cites
Analysis of Blockchain Security: Classic Attacks, Cybercrime and Penetration Testing

Shreshta Kaushik, Nour El Madhoun

Blockchain is an innovative technology that gives built-in security to any software or application. There is a wide range of applications for blockchain, from risk management to financial services, crypto-currencies and the Internet of Things (IoT). This innovation is based on transparency, immutability, security, efficiency and decentralization. It is a trending topic since cryptocurrencies are a hot topic in the market. Blockchain is a combination of mathematics, cryptography, algorithms and models. In this paper, we present a general overview of the security aspects of blockchain technology.

Open access
Blockchain Technology Applications and Security
Network Security and Intrusion Detection
Cybercrime and Law Enforcement Studies
Original source
Nov 2, 2023¡International Journal on Recent and Innovation Trends in Computing and Communication
1 cites
Blockchain Technology in the Intrusion Detection Domain

Et al. Issac K Varghese

The ability of blockchain technology to improve security and transparency across a range of industries has receivedA great deal of attention has been garnered lately in correcting the sentence.. In the domain of intrusion detection, where the identification and mitigation of cyber threats are paramount, blockchain has emerged as a promising solution. This abstract examines how blockchain is used in intrusion detection systems and emphasizes its advantages. Blockchain technology improves the security and integrity of intrusion detection systems by using a decentralized and immutable ledger. It provides an immutable audit trail, distributed consensus, and increased resilience to attacks. Moreover, blockchain fosters trust, transparency, and collaboration among stakeholders, enabling faster threat detection and response. This research can explore novel approaches to integrating blockchain into intrusion detection systems, providing stronger protection against cyber threats.Immutable Audit Trail: In the context of intrusion detection, the capacity of blockchain to produce an unalterable and transparent audit trail is of enormous value. Research in this area can focus on developing techniques to leverage the blockchain's audit trail for effective incident response, forensic investigations, and attribution of cyberattacks. We will use theweighted product model in this study, which is a research approach that gives weights to various factors and combines them to make conclusions based on their relative relevance in a weighted way. Taken as alternative is“IDS1, IDS2, IDS3, IDS4, IDS5, IDS6, IDS7, and IDS8”.Detection Quality, Performance, Stability, User Interface, Profile update, ConvenienceThe By this we can see that IDS4 has 1 RANK and IDS5 has the 8th RANK.In conclusion, blockchain technology holds great potential in the intrusion detection domain. Its decentralized and immutable nature can enhance the security and reliability of intrusion detection systems by providing transparent and tamper-proof logs of network activity. Blockchain-based solutions can improve threat detection, facilitate secure information sharing among entities, and enhance the overall resilience of intrusion detection systems. As the technology continues to evolve, further research and development in integrating blockchain with intrusion detection will unlock new possibilities for combating cyber threats.

Open access
Blockchain Technology Applications and Security
Network Security and Intrusion Detection
Cybercrime and Law Enforcement Studies
Original source
Nov 2, 2023¡arXiv (Cornell University)
6 cites
A Comprehensive Study of Governance Issues in Decentralized Finance Applications

Wei Ma, Chenguang Zhu, Ye Liu, Xiaofei Xie ¡ 5 authors

Decentralized Finance (DeFi) is a prominent application of smart contracts, representing a novel financial paradigm in contrast to centralized finance. While DeFi applications are rapidly emerging on mainstream blockchain platforms, their quality varies greatly, presenting numerous challenges, particularly in terms of their governance mechanisms. In this paper, we present a comprehensive study of governance issues in DeFi applications. Initially, we collected 3,165 academic papers and numerous industry reports. After thorough screening, we selected 44 academic papers and 11 industry reports for detailed analysis. Drawing upon insights from industry reports and academic research articles, we develop a taxonomy to categorize these governance issues. We collect and build a dataset of 4,446 audit reports from seventeen Web3 security companies, categorizing their governance issues according to our constructed taxonomy. We conducted a thorough analysis of governance issues and identified vulnerabilities in the governance design and implementation, e.g., voting sybil attack and proposal front-running. Our statistical analysis indicates that a significant portion (35.48%) of governance-related issues is classified as severe. Within these, ownership-related problems constitute the largest share (65.38%). Despite DeFi governance being essential for the long-term success of DeFi projects, our data shows that both auditors and development teams have not fully grasped its significance. Based on audit reports, we also analyzed common vulnerabilities and issues in the governance domain. Our research identifies two primary categories of DeFi governance issues: technology-centric and human-centric. Technology-centric issues can be addressed through technology updates and iterations, whereas human-centric issues are influenced not only by the development team's technical skills but also by their understanding of DeFi governance. Data analysis reveals that design and implementation issues are frequently overlooked; although not directly associated with vulnerabilities, these issues can impact the equitable distribution of project benefits. Furthermore, our analysis of 104 projects’ tokenomics configurations, including 15 collected from DeFi platforms, uncovered 27 inconsistent configurations, with only two projects exhibiting no issues. This suggests that such issues are relatively common. We therefore advise project teams to ensure consistency between their tokenomics design and the actual code. Our study culminates in providing several key practical implications for various DeFi stakeholders, including developers, users, researchers, and regulators, aiming to deepen the understanding of DeFi governance issues and contribute to the robust growth of DeFi systems.

Open access
3 source records
Blockchain Technology Applications and Security
FinTech, Crowdfunding, Digital Finance
Cybercrime and Law Enforcement Studies
Original source
Nov 1, 2023¡Electronic Journal of Business and Management
1 cites
Effectiveness of Blockchain Technology in Preventing Financial Fraud: A Study Among Public Listed Companies in Malaysia.

Anusha Ramesh, Meera Eeswaran, Faros Faizdnor Roslan, Dependent Variable

The main goal of this research is to examine how well blockchain technology functions to prevent financial fraud. The purpose of this study is to determine whether blockchain technology can effectively combat financial fraud, a type of white-collar crime that is dramatically increasing throughout the world. With this concern, this project aimed to identify the effectiveness of blockchain technology in preventing financial fraud among public listed companies in Malaysia. Since there are only a few studies have analysed various factors that influence financial fraud, this study intends to achieve the aim of the study which is to figure out the level of influence that the factors identified as independent variables on the dependent variable, financial fraud. The primary method is used by the researcher to acquire the data. The three factors examined in this study—immutability, consensus method, and distributed ledger technology—all have a major impact on financial fraud. The data was acquired from staff of public listed companies in Malaysia. Statistical Package of the Social Sciences (SPSS) is used to analyze the correlations between the three factors and all of the factors were shown to have a substantial link with financial fraud in Malaysian public listed companies. This study's findings suggest that individuals and businesses should be aware of the threats of financial theft that exist all around them and the value of having key tools that are resistant to phishing scams. The investigation raises awareness of the application of blockchain technology among customers as well as companies to prevent financial fraud.

Open access
Cybercrime and Law Enforcement Studies
Corporate Governance and Financial Management
Imbalanced Data Classification Techniques
Original source
Nov 1, 2023¡Heliyon
45 cites
Darkweb research: Past, present, and future trends and mapping to sustainable development goals

Raghu Raman, Vinith Kumar Nair, Prema Nedungadi, Indrakshi Ray ¡ 5 authors

The Darkweb, part of the deep web, can be accessed only through specialized computer software and used for illegal activities such as cybercrime, drug trafficking, and exploitation. Technological advancements like Tor, bitcoin, and cryptocurrencies allow criminals to carry out these activities anonymously, leading to increased use of the Darkweb. At the same time, computers have become an integral part of our daily lives, shaping our behavior, and influencing how we interact with each other and the world. This work carries out the bibliometric study on the research conducted on Darkweb over the last decade. The findings illustrate that most research on Darkweb can be clustered into four areas based on keyword co-occurrence analysis: (i) network security, malware, and cyber-attacks, (ii) cybercrime, data privacy, and cryptography, (iii) machine learning, social media, and artificial intelligence, and (iv) drug trafficking, cryptomarket. National Science Foundation from the United States is the top funder. Darkweb activities interfere with the Sustainable Development Goals (SDG) laid forth by the United Nations to promote peace and sustainability for current and future generations. SDG 16 (Peace, Justice, and Strong Institutions) has the highest number of publications and citations but has an inverse relationship with Darkweb, as the latter undermines the former. This study highlights the need for further research in bitcoin, blockchain, IoT, NLP, cryptocurrencies, phishing and cybercrime, botnets and malware, digital forensics, and electronic crime countermeasures about the Darkweb. The study further elucidates the multi-dimensional nature of the Darkweb, emphasizing the intricate relationship between technology, psychology, and geopolitics. This comprehensive understanding serves as a cornerstone for evolving effective countermeasures and calls for an interdisciplinary research approach. The study also delves into the psychological motivations driving individuals towards illegal activities on the Darkweb, highlighting the urgency for targeted interventions to promote pro-social online behavior.

Open access
Cybercrime and Law Enforcement Studies
Spam and Phishing Detection
Advanced Malware Detection Techniques
Original source
Nov 1, 2023¡ACM Computing Surveys
15 cites
Survey on Quality Assurance of Smart Contracts

Zhiyuan Wei, Jing Sun, Zijian Zhang, Xianhao Zhang ¡ 6 authors

As blockchain technology continues to advance, the secure deployment of smart contracts has become increasingly prevalent, underscoring the critical need for robust security measures. This surge in usage has led to a rise in security breaches, often resulting in substantial financial losses for users. This article presents a comprehensive survey of smart contract quality assurance, from understanding vulnerabilities to evaluating the effectiveness of detection tools. Our work is notable for its innovative classification of 40 smart contract vulnerabilities, mapping them to established attack patterns. We further examine nine defense mechanisms, assessing their efficacy in mitigating smart contract attacks. Furthermore, we develop a labeled dataset as a benchmark encompassing 10 common vulnerability types, which serves as a critical resource for future research. We also conduct comprehensive experiments to evaluate 14 vulnerability detection tools, providing a comparative analysis that highlights their strengths and limitations. In summary, this survey synthesizes state-of-the-art knowledge in smart contract security, offering practical recommendations to guide future research and foster the development of robust security practices in the field.

Open access
3 source records
Blockchain Technology Applications and Security
FinTech, Crowdfunding, Digital Finance
cs.CR
Original source
Oct 31, 2023¡International Journal of Cyber and IT Service Management
13 cites
Securing Enterprises: Harnessing Blockchain Technology Against Cybercrime Threats

Fallen Zidan, Dimas Nugroho, Baskara Adi Putra

In the face of increasingly sophisticated cybercrime threats, large companies now need innovative solutions to protect their data and interests. Blockchain technology, which is based on the principles of decentralization and strong encryption, offers great potential in improving corporate cybersecurity. This research investigates the implementation of blockchain technology in the context of enterprise security by developing a blockchain-based dynamic system model. These findings make an important contribution in changing the way audits and general accounting operations are carried out, presenting fundamental changes in the profession. This new approach integrates blockchain technology into various aspects of cybersecurity, embracing innovation and creativity in the face of current challenges. By creating accurate computer models, this research brings a breakthrough in understanding system responses to employee fraud in corporate environments that adopt blockchain technology. This research aims to explore the potential of blockchain technology in improving corporate cybersecurity by identifying security gaps and designing effective updates, creating a safe and trustworthy digital environment for companies in this digital era. The findings of this research highlight the importance of integrating blockchain technology in auditing and general accounting operations, creating a foundation for the development of robust cybersecurity systems. In the context of companies using blockchain technology, this research reveals improved system responsiveness to employee fraud, indicating positive potential in mitigating security risks. This research provides a solid foundation for further development in the field of enterprise cybersecurity, inspiring innovation in protecting businesses and digital assets in a rapidly evolving cyberspace.

Open access
Cybercrime and Law Enforcement Studies
Blockchain Technology Applications and Security
Crime, Illicit Activities, and Governance
Original source
Oct 27, 2023¡Scientific Reports
26 cites
Detection of Ponzi scheme on Ethereum using machine learning algorithms

Ifeyinwa Jacinta Onu, Abiodun Esther Omolara, Moatsum Alawida, Oludare Isaac Abiodun ¡ 5 authors

Abstract Security threats posed by Ponzi schemes present a considerably higher risk compared to many other online crimes. These fraudulent online businesses, including Ponzi schemes, have witnessed rapid growth and emerged as major threats in societies like Nigeria, particularly due to the high poverty rate. Many individuals have fallen victim to these scams, resulting in significant financial losses. Despite efforts to detect Ponzi schemes using various methods, including machine learning (ML), current techniques still face challenges, such as deficient datasets, reliance on transaction records, and limited accuracy. To address the negative impact of Ponzi schemes, this paper proposes a novel approach focusing on detecting Ponzi schemes on Ethereum using ML algorithms like random forest (RF), neural network (NN), and K-nearest neighbor (KNN). Over 20,000 datasets related to Ethereum transaction networks were gathered from Kaggle and preprocessed for training the ML models. After evaluating and comparing the three models, RF demonstrated the best performance with an accuracy of 0.94, a class-score of 0.8833, and an overall-score of 0.96667. Comparative evaluations with previous models indicate that our model achieves high accuracy. Moreover, this innovative work successfully detects key fraud features within the Ponzi scheme dataset, reducing the number of features from 70 to only 10 while maintaining a high level of accuracy. The main strength of this proposed method lies in its ability to detect clever Ponzi schemes from their inception, offering valuable insights to combat these financial threats effectively.

Open access
2 source records
Cybercrime and Law Enforcement Studies
Imbalanced Data Classification Techniques
Spam and Phishing Detection
Original source
Oct 13, 2023¡International Journal of Information Security
20 cites
Cashing out crypto: state of practice in ransom payments

Constantinos Patsakis, Eugenia Politou, Efthimios Alepis, Julio HernĂĄndez-Castro

Abstract The fast pace of blockchain technology and cryptocurrencies’ evolution makes people vulnerable to financial fraud and provides a relatively straightforward monetisation mechanism for cybercriminals, in particular ransomware groups which exploit crypto’s pseudo-anonymity properties. At the same time, regulatory efforts for addressing crimes related to crypto assets are emerging worldwide. In this work, we shed light on the current state of practice of ransomware monetisation to provide evidence of their payment traceability, explore future trends, and—above all—showcase that over-regulating cryptocurrencies is not the best way to mitigate their risks. For that purpose, first, we provide an overview of the legislative initiatives currently taken by the USA, the EU, and the OECD to regulate cryptocurrencies, showing that strict laws and the divergences between the regulatory regimes can hardly efficiently regulate the global phenomenon of cryptocurrency, which transcends borders and states. Next, we focus on illicit payments in bitcoin to ransomware groups, illustrating how these payments are siphoned off and how criminals cash out the ransom, often leaving traceable evidence behind. To this end, we leverage a publicly available dataset and a set of state-of-the-art blockchain analysis tools to identify payment patterns, trends, and transaction trails, which are provided in an anonymised form. Our work reveals that a significant amount of illicit bitcoin transactions can be easily traced, and consequently, many cyber crimes like ransomware can actually be tracked down and investigated with existing tools and laws, thus providing fertile ground for better and fairer legislation on crypto.

Open access
Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
Cybercrime and Law Enforcement Studies
Original source
Oct 7, 2023¡International Journal on Cybernetics & Informatics
0 cites
A Proposal for an Open-Source Bitcoin Forensics Tool

Pedro Henrique Resende Ribeiro, Pedro Leale, Ivan da Silva Sendin

Over recent decades, the global financial paradigm has experienced significant transformations, notably the emergence and adoption of cryptocurrencies. The escalating prominence of assets like Bitcoin has inadvertently catalysed a surge in illicit activities associated with the currency. Consequently, the forensic examination of transactions within blockchains becomes imperative for the detection and surveillance of malevolent undertakings. This research delineates a preliminary pipeline for a Bitcoin forensic analysis tool. Moving forward, the ambition is to conceptualize and empirically validate this tool utilizing data procured from blockchain and ancillary sources. The methodology will harness Open-Source Intelligence (OSINT), clustering of Bitcoin addresses, and an exhaustive financial analysis. Upon finalizing the pipeline, the implementation of an open-source instrument is envisioned, poised to confer substantial advantages to the broader cryptocurrency milieu.

Open access
Blockchain Technology Applications and Security
Crime, Illicit Activities, and Governance
Cybercrime and Law Enforcement Studies
Original source
Oct 6, 2023¡Journal of Cybersecurity
14 cites
Mapping the DeFi crime landscape: an evidence-based picture

Catherine Carpentier-Desjardins, Masarah Paquet-Clouston, Stefan Kitzler, Bernhard Haslhofer

*PLEASE REFER TO THE SECOND VERSION UPLOADED IN JANUARY 2025. THIS VERSION CONTAINS A FEW DUPLICATES. VERSION 2 IS AVAILABLE FOR DOWNLOAD HERE: https://zenodo.org/records/14706760 README - Crime Events Dataset This document provides a detailed overview of the structure of the dataset for the paper: "Mapping the DeFi crime landscape: An Evidence-based Picture". The following fields are included, each representing different aspects of the events collected. Data Fields 1. unique_key Description: A unique number assigned to identify each event in the dataset. 2. Agregators Description: The sources where the event is listed. Aggregators include: - De.Fi REKT - SlowMist - CryptoSec (rebranded to ChainSec as of February 2023) 3. DeFi actor involved Description: The name of the DeFi actor involved in the event (target, perpetrator, or intermediary). Sources: - On De.Fi REKT: Found as the "Title" of the event’s listing. - On SlowMist: Found under the “Hacked target” title. - On CryptoSec: Found in the "Title" of the event’s listing with the date. 4. REKT URL Description: The URL to the event's listing on De.Fi REKT. Process: Found by searching for the DeFi actor involved in the REKT Database: https://de.fi/rekt-database 5. SlowMist URL Description: The URL to the event's listing on SlowMist. Process: Available via https://hacked.slowmist.io/search/. Note that searching the actor's name will lead to the event but without an individualized URL. 6. CryptoSec URL Description: The URL to the event's listing on CryptoSec. Process: Found at https://chainsec.io/defi-hacks/. Events are listed on a single page; use traditional keyboard search to locate specific events. 7. Aggregator Summary Description: A summary of the event provided by the aggregator. Sources: - On De.Fi REKT: Found under "Quick Summary" and "Details of the Exploit". - On SlowMist: Under "Description of the event". - On CryptoSec: Below the title in quotation marks. 8. Aggregator sources URL Description: The URLs of references linked by the aggregator in the event’s listing. Sources: - On De.Fi REKT: Found at the bottom by clicking "Source" or "Archived link". - On SlowMist: Found by clicking "View Reference Sources". - On CryptoSec: Available by clicking the source’s name at the end of the summary. 9. Event date Description: The date the event occurred. Sources: - On De.Fi REKT: Listed under the "Date" field. - On SlowMist: At the top right of the listing. - On CryptoSec: Listed in parentheses behind the actor’s name. 10. Event year Description: The year the event occurred, extracted from the Event date. 11. Stolen amount USD Description: The total amount stolen, converted to USD. Sources: - On De.Fi REKT: Found under "Funds lost". - On SlowMist: Under the title “Amount of loss”. - On CryptoSec: Behind the title "Amount stolen". Note: If needed, conversions were manually performed using CoinMarketCap’s historical data as explained in the paper. 12. Implication of actor Description: Indicates whether the DeFi actor was a target, perpetrator, or intermediary in the event. Manually coded after reviewing the aggregator’s summary and linked sources. 13. Strategy Description: The main approach used to steal funds. Six categories are possible: Technical vulnerability, Human risks, Undetermined, Malicious use of contract, Misappropriation of funds, and Imitation. This was manually coded from the event summary and sources. 14. General tactic Description: The common techniques or methods used by malicious actors. Eleven categories are possible, defined in the appendix. Manually coded after reviewing the summary and linked sources. 15. Specific tactic Description: The precise technique used to commit the crime. Thirty-seven categories are possible, defined in the appendix. This was manually coded based on the event summary and sources. 16. Paper category Description: The main area of operation of the involved DeFi actor. Twelve categories are possible: Blockchain, Bridge, DApp, Derivatives, Exchange, Fungible Token (FT), Non-Fungible Token (NFT), Oracle, Yield, Staking, and Others. This was determined by the event summary and research on the actor. 17. Stack category Description: The technical layer of the DeFi Stack Reference (DSR) model corresponding to the paper category. Five categories are possible: DeFi Compositions (CP), DeFi Protocols (P), Cryptoassets (CA), Distributed Ledger Technology (DLT), and Interfaces (INT). --- For more detailed information on the tactics, strategies, or categories used, please refer to the appendix of the dataset or the associated documentation.

Open access
3 source records
Blockchain Technology Applications and Security
Crime, Illicit Activities, and Governance
Cybercrime and Law Enforcement Studies
Original source
Oct 6, 2023¡Cybersecurity
2 cites
Aparecium: understanding and detecting scam behaviors on Ethereum via biased random walk

Chuyi Yan, Chen Zhang, Meng Shen, Ning Li ¡ 8 authors

Abstract Ethereum’s high attention, rich business, certain anonymity, and untraceability have attracted a group of attackers. Cybercrime on it has become increasingly rampant, among which scam behavior is convenient, cryptic, antagonistic and resulting in large economic losses. So we consider the scam behavior on Ethereum and investigate it at the node interaction level. Based on the life cycle and risk identification points we found, we propose an automatic detection model named Aparecium . First, a graph generation method which focus on the scam life cycle is adopted to mitigate the sparsity of the scam behaviors. Second, the life cycle patterns are delicate modeled because of the crypticity and antagonism of Ethereum scam behaviors. Conducting experiments in the wild Ethereum datasets, we prove Aparecium is effective which the precision, recall and F1-score achieve at 0.977, 0.957 and 0.967 respectively.

Open access
Network Security and Intrusion Detection
Cybercrime and Law Enforcement Studies
Spam and Phishing Detection
Original source
Oct 2, 2023¡arXiv (Cornell University)
1 cites
Multi-triplet Feature Augmentation for Ponzi Scheme Detection in Ethereum

Chengxiang Jin, Jiajun Zhou, Shengbo Gong, Chenxuan Xie ¡ 5 authors

Blockchain technology revolutionizes the Internet, but also poses increasing risks, particularly in cryptocurrency finance. On the Ethereum platform, Ponzi schemes, phishing scams, and a variety of other frauds emerge. Existing Ponzi scheme detection approaches based on heterogeneous transaction graph modeling leverages semantic information between node (account) pairs to establish connections, overlooking the semantic attributes inherent to the edges (interactions). To overcome this, we construct heterogeneous Ethereum interaction graphs with multiple triplet interaction patterns to better depict the real Ethereum environment. Based on this, we design a new framework named multi-triplet augmented heterogeneous graph neural network (MAHGNN) for Ponzi scheme detection. We introduce the Conditional Variational Auto Encoder (CVAE) to capture the semantic information of different triplet interaction patterns, which facilitates the characterization on account features. Extensive experiments demonstrate that MAHGNN is capable of addressing the problem of multi-edge interactions in heterogeneous Ethereum interaction graphs and achieving state-of-the-art performance in Ponzi scheme detection.

Open access
3 source records
Spam and Phishing Detection
Network Security and Intrusion Detection
Misinformation and Its Impacts
Original source
Oct 2, 2023¡arXiv (Cornell University)
4 cites
Unmasking Role-Play Attack Strategies in Exploiting Decentralized Finance (DeFi) Systems

W. D. Li, Zhun Wang, Chenyu Li, H. F. Chen ¡ 8 authors

The rapid growth and adoption of decentralized finance (DeFi) systems have been accompanied by various threats, notably those emerging from vulnerabilities in their intricate design. In our work, we introduce and define an attack strategy termed as Role-Play Attack, in which the attacker acts as multiple roles concurrently to exploit the DeFi system and cause substantial financial losses. We provide a formal definition of this strategy and demonstrate its potential impacts by revealing the total loss of \$435.1M caused by 14 historical attacks with applying this pattern. Besides, we mathematically analyzed the attacks with top 2 losses and retrofitted the corresponding attack pattern by concrete execution, indicating that this strategy could increase the potential profit for original attacks by \$3.34M (51.4%) and \$3.76M (12.0%), respectively.

Open access
3 source records
Blockchain Technology Applications and Security
Crime, Illicit Activities, and Governance
Cybercrime and Law Enforcement Studies
Original source
Oct 2, 2023¡arXiv (Cornell University)
73 cites
Large Language Model-Powered Smart Contract Vulnerability Detection: New Perspectives

Sihao Hu, Tiansheng Huang, Fatih İlhan, Selim Furkan Tekin ¡ 5 authors

This paper provides a systematic analysis of the opportunities, challenges, and potential solutions of harnessing Large Language Models (LLMs) such as GPT-4 to dig out vulnerabilities within smart contracts based on our ongoing research. For the task of smart contract vulnerability detection, achieving practical usability hinges on identifying as many true vulnerabilities as possible while minimizing the number of false positives. Nonetheless, our empirical study reveals contradictory yet interesting findings: generating more answers with higher randomness largely boosts the likelihood of producing a correct answer but inevitably leads to a higher number of false positives. To mitigate this tension, we propose an adversarial framework dubbed GPTLens that breaks the conventional one-stage detection into two synergistic stages $-$ generation and discrimination, for progressive detection and refinement, wherein the LLM plays dual roles, i.e., auditor and critic, respectively. The goal of auditor is to yield a broad spectrum of vulnerabilities with the hope of encompassing the correct answer, whereas the goal of critic that evaluates the validity of identified vulnerabilities is to minimize the number of false positives. Experimental results and illustrative examples demonstrate that auditor and critic work together harmoniously to yield pronounced improvements over the conventional one-stage detection. GPTLens is intuitive, strategic, and entirely LLM-driven without relying on specialist expertise in smart contracts, showcasing its methodical generality and potential to detect a broad spectrum of vulnerabilities. Our code is available at: https://github.com/git-disl/GPTLens.

Open access
4 source records
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Artificial Intelligence in Law
Original source
Sep 26, 2023¡ACM Transactions on Knowledge Discovery from Data
3 cites
From Asset Flow to Status, Action and Intention Discovery: Early Malice Detection in Cryptocurrency

Ling Cheng, Feida Zhu, Yong Wang, Ruicheng Liang ¡ 5 authors

Cryptocurrency has been subject to illicit activities probably more often than traditional financial assets due to the pseudo-anonymous nature of its transacting entities. An ideal detection model is expected to achieve all three critical properties of (I) early detection, (II) good interpretability, and (III) versatility for various illicit activities. However, existing solutions cannot meet all these requirements, as most of them heavily rely on deep learning without interpretability and are only available for retrospective analysis of a specific illicit type. To tackle all these challenges, we propose Intention-Monitor for early malice detection in Bitcoin (BTC), where the on-chain record data for a certain address are much scarcer than other cryptocurrency platforms. We first define asset transfer paths with the Decision-Tree based feature Selection and Complement (DT-SC) to build different feature sets for different malice types. Then, the Status/Action Proposal Module (S/A-PM) and the Intention-VAE module generate the status, action, intent-snippet, and hidden intent-snippet embedding. With all these modules, our model is highly interpretable and can detect various illegal activities. Moreover, well-designed loss functions further enhance the prediction speed and model's interpretability. Extensive experiments on three real-world datasets demonstrate that our proposed algorithm outperforms the state-of-the-art methods. Furthermore, additional case studies justify our model can not only explain existing illicit patterns but can also find new suspicious characters.

Open access
3 source records
cs.LG
cs.AI
Blockchain Technology Applications and Security
Original source
Sep 22, 2023¡International Journal of Advances in Engineering and Pure Sciences
1 cites
Investigation of Cryptocurrency-Centered Money Laundering Scenarios in terms of Digital Forensics

Duzgun Kucuk, Emre ÇAKAR, Ömer Faruk Yakut, Fatih Ertam

One of the biggest innovations brought by the digitalized world is undoubtedly the invention of crypto money, which is decentralized, anonymous and complex, and connected to blockchain technology. This relatively new technology has attracted the attention of many people with its revolutionary changes in payment systems and great price movements in the market, as well as the economic balances it has changed around the world. In addition to this interest, it also attracted the attention of crime and crime organizations in a short time, and over time it turned into a tool used by illegal organizations such as laundering the proceeds of crime. Although this structure was initially exposed to the reaction of some states at the level of nation states, on the other hand, it managed to get the support of many states. However, although the spread of blockchain-based money laundering methods is an undeniable problem for all states, a significant cooperation has not been achieved by international collaborations and organizations to prevent this situation. On the other hand, it is of great importance for law enforcement and forensic analysts to clarify this situation and to fight against these structures in order to protect national interests. In this study; In this study, an approach that will detect money laundering is tried to be presented through sample scenarios by bringing a broad perspective to crypto money-based money laundering methods, which are very difficult to trace due to their nature. In addition, it is expected that the difficulties in implementation of the proposed approach will be clearly addressed and will shed light and inspire further study.

Open access
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Crime, Illicit Activities, and Governance
Original source
Sep 17, 2023¡arXiv (Cornell University)
0 cites
How NFT Collectors Experience Online NFT Communities: A Case Study of Bored Ape

Allison Sinnott, Kyrie Zhixuan Zhou

Non-fungible tokens (NFTs) are unique cryptographic assets representing the ownership of digital media. NFTs have soared in popularity and trading prices. However, there exists a large gap in the literature regarding NFTs, especially regarding the stakeholders and online communities that have formed around NFT projects. Bored Ape Yacht Club (BAYC) is one of the most influential NFT projects. Through an observational study of online BAYC communities across social media platforms and semi-structured interviews with four participants who owned BAYC NFTs, we explored the experiences of NFT collectors within the online NFT community. Positive community experiences, i.e., personal expression and identity, mutual support among BAYC holders, and exclusive access to online and offline events, were expressed. Encountered challenges included scams and "cash grab" NFT projects as well as trolling. The results of this study point towards the welcoming, positive nature of the NFT community, which is a possible causation factor of the initial rise in popularity of NFTs. Demotivators, on the other hand, countered the established trustworthiness of NFT technology among its consumers.

Open access
2 source records
cs.HC
cs.CR
cs.CY
Original source
Sep 15, 2023¡International Journal of Information Security
30 cites
Vulnsense: efficient vulnerability detection in ethereum smart contracts by multimodal learning with graph neural network and language model

Phan The Duy, Nghi Hoang Khoa, Nguyen Huu Quyen, Le Cong Trinh ¡ 7 authors

This paper presents VulnSense framework, a comprehensive approach to efficiently detect vulnerabilities in Ethereum smart contracts using a multimodal learning approach on graph-based and natural language processing (NLP) models. Our proposed framework combines three types of features from smart contracts comprising source code, opcode sequences, and control flow graph (CFG) extracted from bytecode. We employ Bidirectional Encoder Representations from Transformers (BERT), Bidirectional Long Short-Term Memory (BiLSTM) and Graph Neural Network (GNN) models to extract and analyze these features. The final layer of our multimodal approach consists of a fully connected layer used to predict vulnerabilities in Ethereum smart contracts. Addressing limitations of existing vulnerability detection methods relying on single-feature or single-model deep learning techniques, our method surpasses accuracy and effectiveness constraints. We assess VulnSense using a collection of 1.769 smart contracts derived from the combination of three datasets: Curated, SolidiFI-Benchmark, and Smartbugs Wild. We then make a comparison with various unimodal and multimodal learning techniques contributed by GNN, BiLSTM and BERT architectures. The experimental outcomes demonstrate the superior performance of our proposed approach, achieving an average accuracy of 77.96\% across all three categories of vulnerable smart contracts.

Open access
4 source records
Blockchain Technology Applications and Security
Crime, Illicit Activities, and Governance
Cybercrime and Law Enforcement Studies
Original source
Sep 8, 2023¡Healthcare
18 cites
Blockchain Revolutionizing in Emergency Medicine: A Scoping Review of Patient Journey through the ED

Tzu-Chi Wu, Chien‐Ta Bruce Ho

BACKGROUND: Blockchain technology has revolutionized the healthcare sector, including emergency medicine, by integrating AI, machine learning, and big data, thereby transforming traditional healthcare practices. The increasing utilization and accumulation of personal health data also raises concerns about security and privacy, particularly within emergency medical settings. METHOD: Our review focused on articles published in databases such as Web of Science, PubMed, and Medline, discussing the revolutionary impact of blockchain technology within the context of the patient journey through the ED. RESULTS: A total of 33 publications met our inclusion criteria. The findings emphasize that blockchain technology primarily finds its applications in data sharing and documentation. The pre-hospital and post-discharge applications stand out as distinctive features compared to other disciplines. Among various platforms, Ethereum and Hyperledger Fabric emerge as the most frequently utilized options, while Proof of Work (PoW) and Proof of Authority (PoA) stand out as the most commonly employed consensus algorithms in this emergency care domain. The ED journey map and two scenarios are presented, exemplifying the most distinctive applications of emergency medicine, and illustrating the potential of blockchain. Challenges such as interoperability, scalability, security, access control, and cost could potentially arise in emergency medical contexts, depending on the specific scenarios. CONCLUSION: Our study examines the ongoing research on blockchain technology, highlighting its current influence and potential future advancements in optimizing emergency medical services. This approach empowers frontline medical professionals to validate their practices and recognize the transformative potential of blockchain in emergency medical care, ultimately benefiting both patients and healthcare providers.

Open access
Blockchain Technology Applications and Security
Organizational and Employee Performance
Cybercrime and Law Enforcement Studies
Original source
Sep 7, 2023¡Sustainability
42 cites
Blockchain Technology and Related Security Risks: Towards a Seven-Layer Perspective and Taxonomy

Sepideh Mollajafari, Kamal Bechkoum

Blockchain technology can be a useful tool to address issues related to sustainability. From its initial foundation based on cryptocurrency to the development of smart contracts, blockchain technology promises significant business benefits for various industry sectors, including the potential to offer more trustworthy modes of governance, reducing the risks for environmental and economic crises. Notwithstanding its known benefits, and despite having some protective measures and security features, this emerging technology still faces significant security challenges within its different abstract layers. This paper classifies the critical cybersecurity threats and vulnerabilities inherent in smart contracts based on an in-depth literature review and analysis. From the perspective of architectural layering, each layer of the blockchain has its own corresponding security issues. In order to have a detailed look at the source of security vulnerabilities within the blockchain, a seven-layer architecture is used, whereby the various components of each layer are set out, highlighting the related security risks and corresponding countermeasures. This is followed by a taxonomy that establishes the inter-relationships between the vulnerabilities and attacks in a smart contract. A specific emphasis is placed on the issues caused by centralisation within smart contracts, whereby a “one-owner” controls access, thus threatening the very decentralised nature that blockchain is based upon. This work offers two main contributions: firstly, a general taxonomy that compiles the different vulnerabilities, types of attacks, and related countermeasures within each of the seven layers of the blockchain; secondly, a specific focus on one layer of the blockchain namely, the contract layer. A model application is developed that depicts, in more detail, the security risks within the contract layer, while enlisting the best practices and tools to use to mitigate against these risks. The findings point to future research on developing countermeasures to alleviate the security risks and vulnerabilities inherent to one-owner control in smart contracts.

Open access
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Original source
Sep 7, 2023¡Journal of Information Technology
8 cites
Competing stakeholder narratives on crypto-assets: Miracle or mirage?

Wendy L. Currie, Jonathan J. M. Seddon

Academic and practitioner interest in crypto-assets is gaining momentum. Different values and agendas influence regulatory policy. Competing ideologies and social norms about the efficacy of regulatory regimes, the influence of innovation philosophies, and the need to foster ethical principles and practices underpin debates on crypto-assets. Semi-structured interviews were carried out in the USA and UK with regulators, tech firms, institutional and retail investors, and crypto social media influencers. Stakeholder groups were classified as interventionists, innovators, influencers, and investors. The research builds a data structure from extant literature and empirical research. Aggregate dimensions of inchoate technology, regulatory intervention, and innovation social norms reflect complex and competing stakeholder positions on crypto assets. Findings show crypto-assets are not homogenous, but highly differentiated with potential effects and outcomes determined by algorithmic code. However, competing stakeholder agendas obfuscate policy development for decentralized finance.

Open access
FinTech, Crowdfunding, Digital Finance
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Original source
Sep 7, 2023¡arXiv (Cornell University)
10 cites
Cybercrime Bitcoin Revenue Estimations: Quantifying the Impact of Methodology and Coverage

Gibran GĂłmez, Kevin van Liebergen, Juan Caballero

Multiple works have leveraged the public Bitcoin ledger to estimate the revenue cybercriminals obtain from their victims. Estimations focusing on the same target often do not agree, due to the use of different methodologies, seed addresses, and time periods. These factors make it challenging to understand the impact of their methodological differences. Furthermore, they underestimate the revenue due to the (lack of) coverage on the target's payment addresses, but how large this impact remains unknown. In this work, we perform the first systematic analysis on the estimation of cybercrime bitcoin revenue. We implement a tool that can replicate the different estimation methodologies. Using our tool we can quantify, in a controlled setting, the impact of the different methodology steps. In contrast to what is widely believed, we show that the revenue is not always underestimated. There exist methodologies that can introduce huge overestimation. We collect 30,424 payment addresses and use them to compare the financial impact of 6 cybercrimes (ransomware, clippers, sextortion, Ponzi schemes, giveaway scams, exchange scams) and of 141 cybercriminal groups. We observe that the popular multi-input clustering fails to discover addresses for 40% of groups. We quantify, for the first time, the impact of the (lack of) coverage on the estimation. For this, we propose two techniques to achieve high coverage, possibly nearly complete, on the DeadBolt server ransomware. Our expanded coverage enables estimating DeadBolt's revenue at $2.47M, 39 times higher than the estimation using two popular Internet scan engines.

Open access
3 source records
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Crime, Illicit Activities, and Governance
Original source
Sep 6, 2023¡Journal of Global Information Management
10 cites
Blockchain-Enhanced Smart Contract for Cost-Effective Insurance Claims Processing

Qiping Wang, Raymond Y.K. Lau, Yain‐Whar Si, Haoran Xie · 5 authors

Blockchain-enabled smart contracts have revolutionized the insurance industry due to their potential to streamline backend operations, mitigate fraudulent claims, and enhance data security and transparency. Guided by the design science methodology, the authors propose two specific smart contract frameworks to enhance insurance claims processing related to vehicle damage claims and personal injury claims. These proposed frameworks can improve the overall efficiency and effectiveness of insurance claims processing by automating claims submission, review, analysis, and payment, while reducing fraud and data leakage, by merging various data sources and disintermediation. Furthermore, the authors design a smart contract template supported by eight operational algorithms to facilitate the processing of insurance claims with the help of smart contracts. This template provides practitioners with a standardized prototype for the development of secure and efficient insurance applications.

Open access
Blockchain Technology Applications and Security
FinTech, Crowdfunding, Digital Finance
Cybercrime and Law Enforcement Studies
Original source