Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

873 papersLast indexed Aug 31, 2026
Search papers

Paper index

873 results · page 18 of 37

Clear filters
Jun 15, 2023·Applied Network Science
8 cites
Is Bitcoin gathering dust? An analysis of low-amount Bitcoin transactions

Matteo Loporchio, Anna Bernasconi, Damiano Di Francesco Maesa, Laura Ricci

Abstract In the Bitcoin protocol, dust refers to small amounts of currency that are lower than the fee required to spend them in a transaction. Although “economically irrational”, dust is commonly used for achieving unconventional side effects, rather than exchanging value. For instance, dust might be linked to on-chain services or to malicious activity, such as dust attacks attempting to break users’ pseudonymity. To study this phenomenon, this paper presents an in depth analysis of Bitcoin transactions involving dust, showing how dust is created and consumed. We identify the top dust creators and consumers and discuss how consumption has evolved over time. Finally, we use the data to identify transactions suspected of being part of dust attacks and quantify their impact on address deanonymization. Our results show that dust is mainly related to on-chain betting services. Transactions likely to be part of dust attacks are a minority of dust creating transactions but, despite their relatively low number, they have a disproportionately high effect on helping attackers to break address pseudonymity.

Open access
Blockchain Technology Applications and Security
Crime, Illicit Activities, and Governance
Cybercrime and Law Enforcement Studies
Original source
Jun 14, 2023·Düzce Üniversitesi Sosyal Bilimler Dergisi
1 cites
BLOCKCHAIN ÜZERİNE YENİ BİR HALKA: NON-FUNGIBLE TOKEN (NFT)'NİN BİLİNİRLİĞİ ÜZERİNE BİR ARAŞTIRMA

Fatih KONAK, Esra ÖZKAHVECİ

Her geçen gün önemi daha belirgin hale gelen blockchain, açık anahtarlı şifreleme ile güvence altına alınan ve blok dizisinden oluşan sayı dizisidir. Günümüzde blockchain tabanlı oluşturulan yüzlerce kripto para birimi bulunmaktadır. Yakın zamanda kripto para piyasanın gelişmesi ile birlikte Non-Fungible Token olarak ifade edilen dijital bir varlık dikkatleri üzerine çekmiştir. Benzersiz kimlikleri olan NFT, koleksiyon, sanat eserleri, sanal dünyadaki nesneler ve diğer oyunlardan dijitalleştirilmiş karakterlerdir. Non-Fungible Tokenler yatırımcılara bir nesneyi satın alma veya satma yolunu tanıtırlar. Ayrıca bu varlıklar çevrimiçi olarak, çoğunlukla kripto para birimiyle işlem görürler ve bir blok zincirindeki akıllı sözleşmeler içinde kodlanırlar. Bu perspektifte araştırmanın amacı, 2020-2022 yakın dönemde "Non-Fungible Token" ve kısaltması "NFT" terimlerinin Google aranma sıklıklarını ‘finans’ alt segmentinde inceleyerek, ABD ve Türkiye ülkelerinde karşılaştırmalı olarak tespit etmektedir. Araştırma sonucunda elde edilen Google Trends verileri, kullanıcı/yatırımcının "Non-Fungible Token"den ziyade baş harflerinden oluşan "NFT" kavramını 2021 yılı itibarıyla daha çok bildiğini işaret etmiştir. Bu kapsamda araştırma güçlü bir pazar haline gelen ve yatırımcının bir anda dikkatini çekmeyi başaran "Non-Fungible Token" ve kısaltması "NFT" kavramlarının finans literatüründeki bilinirlilik düzeyini belirleme aşamasında ulusal literatüre özgün değer katmaktadır.

Open access
Blockchain Technology Applications and Security
FinTech, Crowdfunding, Digital Finance
Cybercrime and Law Enforcement Studies
Original source
Jun 12, 2023·INTERANTIONAL JOURNAL OF SCIENTIFIC RESEARCH IN ENGINEERING AND MANAGEMENT
1 cites
Blockchain-Based Approach for Tracking Global Criminals

Anand Karambe

Blockchain is the latest technology, which is now widely used in various fields due to its benefits such as higher tamper-proof security. Each transaction is stored in an immutable distributed ledger on each blockchain node. Criminal records are confidential and should be kept safe from hackers and intruders. Law enforcement agencies or investigative agencies can use these security recordings to analyze and detect criminal activity. Due to the lack of a global online system, Investigative agencies are having difficulty locating and researching the past of anonymous foreign criminal who is committing crimes abroad. This problem will only be solved if investigative agencies have a common global criminal database and applications to extract information. Investigation agencies, Copes, and other organizations can access global crime data using this technology on the distributed node of the blockchain in their nation. Authorities can instantly and efficiently access global criminal histories from local blockchain databases and identify the names and details of anonymous individuals in response to any foreigners suspected of engaging in unsocial activities in their country of origin. This will reduce the time and process of gathering information from the country where the suspect is located. The system would eliminate the possibility of falsification and tamper with criminal records. Key Words: Blockchain, light, Global Criminal, Criminal information

Open access
Cybercrime and Law Enforcement Studies
Original source
Jun 7, 2023·Journal of Systems and Software
24 cites
Vulnerable smart contract function locating based on Multi-Relational Nested Graph Convolutional Network

Haiyang Liu, Yuqi Fan, Lin Feng, Zhenchun Wei

The immutable and trustable characteristics of blockchain enable smart contracts to be applied in various fields. Unfortunately, smart contracts are subject to various vulnerabilities, which are frequently exploited by attackers, causing financial damage to users.In this paper, we study the problem of vulnerable smart contract function locating. We construct a novel Multi-Relational Nested contract Graph (MRNG) to better characterize the rich syntactic and semantic information in the smart contract code, including the relationships between data and instructions. An MRNG represents a smart contract, where each node represents a function in the smart contract and each edge describes the calling relationship between the functions. In addition, we create a Multi-Relational Function Graph (MRFG) for each function, which characterizes the corresponding function code. That is, each function is characterized as an MRFG, which corresponds to a node in the MRNG. Each MRFG uses different types of edges to represent the different control and data relationships between nodes within a function. We also propose a Multi-Relational Nested Graph Convolutional Network (MRN-GCN) to process the MRNG. MRN-GCN first extracts and aggregates features from each MRFG, using the edge-enhanced graph convolution network and self-attention mechanism. The extracted feature vector is then assigned to the corresponding node in the MRNG to obtain a new Featured Contract Graph (FCG) for the smart contract. Graph convolution is used to further extract features from the FCG. Finally, a feed forward network with a Sigmoid function is used to locate the vulnerable functions. Experimental results on the real-world smart contract datasets show that model MRN-GCN can effectively improve the accuracy, precision, recall and F1-score performance of vulnerable smart contract function locating.

Open access
3 source records
Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
Cybercrime and Law Enforcement Studies
Original source
Jun 6, 2023·arXiv
4 cites
Russo-Ukrainian War: Prediction and explanation of Twitter suspension

Alexander Shevtsov, Despoina Antonakaki, Ioannis Lamprou, Ioannis Kontogiorgakis · 6 authors

On 24 February 2022, Russia invaded Ukraine, starting what is now known as the Russo-Ukrainian War, initiating an online discourse on social media. Twitter as one of the most popular SNs, with an open and democratic character, enables a transparent discussion among its large user base. Unfortunately, this often leads to Twitter's policy violations, propaganda, abusive actions, civil integrity violation, and consequently to user accounts' suspension and deletion. This study focuses on the Twitter suspension mechanism and the analysis of shared content and features of the user accounts that may lead to this. Toward this goal, we have obtained a dataset containing 107.7M tweets, originating from 9.8 million users, using Twitter API. We extract the categories of shared content of the suspended accounts and explain their characteristics, through the extraction of text embeddings in junction with cosine similarity clustering. Our results reveal scam campaigns taking advantage of trending topics regarding the Russia-Ukrainian conflict for Bitcoin and Ethereum fraud, spam, and advertisement campaigns. Additionally, we apply a machine learning methodology including a SHapley Additive explainability model to understand and explain how user accounts get suspended.

Open access
2 source records
cs.SI
cs.AI
cs.LG
Original source
May 30, 2023·Future Internet
74 cites
Securing Wireless Sensor Networks Using Machine Learning and Blockchain: A Review

Shereen Ismail, Diana W. Dawoud, Hassan Reza

As an Internet of Things (IoT) technological key enabler, Wireless Sensor Networks (WSNs) are prone to different kinds of cyberattacks. WSNs have unique characteristics, and have several limitations which complicate the design of effective attack prevention and detection techniques. This paper aims to provide a comprehensive understanding of the fundamental principles underlying cybersecurity in WSNs. In addition to current and envisioned solutions that have been studied in detail, this review primarily focuses on state-of-the-art Machine Learning (ML) and Blockchain (BC) security techniques by studying and analyzing 164 up-to-date publications highlighting security aspect in WSNs. Then, the paper discusses integrating BC and ML towards developing a lightweight security framework that consists of two lines of defence, i.e, cyberattack detection and cyberattack prevention in WSNs, emphasizing the relevant design insights and challenges. The paper concludes by presenting a proposed integrated BC and ML solution highlighting potential BC and ML algorithms underpinning a less computationally demanding solution.

Open access
Blockchain Technology Applications and Security
Network Security and Intrusion Detection
Cybercrime and Law Enforcement Studies
Original source
May 29, 2023·Electronics
18 cites
A Blockchain-Based Incentive Mechanism for Sharing Cyber Threat Intelligence

Xingbang Ma, Dongsheng Yu, Yanhui Du, Lanting Li · 6 authors

With the development of the Internet, cyberattacks are becoming increasingly complex, sustained, and organized. Cyber threat intelligence sharing is one of the effective ways to alleviate the pressure on organizational or individual cyber security defense. However, the current cyber threat intelligence sharing lacks effective incentive mechanisms, resulting in mutual distrust and a lack of motivation to share among sharing members, making the security of sharing questionable. In this paper, we propose a blockchain-based cyber threat intelligence sharing mechanism (B-CTISM) to address the problems of free riding and lack of trust among sharing members faced in cyber threat intelligence sharing. We use evolutionary game theory to analyze the incentive strategy; the resulting evolutionarily stable strategy achieves the effect of promoting sharing and effectively curbing free-riding behavior. Then, the incentive strategy is deployed to smart contracts running in the trusted environment of blockchain, whose decentralization and tamper-evident properties can provide a trusted environment for participating members and establish trust without a third-party central institution to achieve secure and efficient cyber threat intelligence sharing. Finally, the effectiveness of the B-CTISM in facilitating and regulating threat intelligence sharing is verified through experimental simulation and comparative analysis.

Open access
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Original source
May 29, 2023·arXiv (Cornell University)
39 cites
Blockchain Censorship

Anton Wahrstätter, Jens Ernstberger, Aviv Yaish, Liyi Zhou · 11 authors

Permissionless blockchains promise to be resilient against censorship by a single entity. This suggests that deterministic rules, and not third-party actors, are responsible for deciding if a transaction is appended to the blockchain or not. In 2022, the U.S. Office of Foreign Assets Control (OFAC) sanctioned a Bitcoin mixer and an Ethereum application, putting the neutrality of permissionless blockchains to the test. In this paper, we formalize quantify and analyze the security impact of blockchain censorship. We start by defining censorship, followed by a quantitative assessment of current censorship practices. We find that 46% of Ethereum blocks were made by censoring actors that intend to comply with OFAC sanctions, indicating the significant impact of OFAC sanctions on the neutrality of public blockchains. We further uncover that censorship not only impacts neutrality, but also security. We show how after Ethereum's move to Proof-of-Stake (PoS) and adoption of Proposer-Builder Separation (PBS) the inclusion of censored transactions was delayed by an average of 85%. Inclusion delays compromise a transaction's security by, e.g., strengthening a sandwich adversary. Finally we prove a fundamental limitation of PoS and Proof-of-Work (PoW) protocols against censorship resilience.

Open access
4 source records
Blockchain Technology Applications and Security
Internet Traffic Analysis and Secure E-voting
Privacy-Preserving Technologies in Data
Original source
May 25, 2023·arXiv
87 cites
Demystifying Fraudulent Transactions and Illicit Nodes in the Bitcoin Network for Financial Forensics

Youssef Elmougy, Ling Liu

Blockchain provides the unique and accountable channel for financial forensics by mining its open and immutable transaction data. A recent surge has been witnessed by training machine learning models with cryptocurrency transaction data for anomaly detection, such as money laundering and other fraudulent activities. This paper presents a holistic applied data science approach to fraud detection in the Bitcoin network with two original contributions. First, we contribute the Elliptic++dataset, which extends the Elliptic transaction dataset to include over 822k Bitcoin wallet addresses (nodes), each with 56 features, and 1.27M temporal interactions. This enables both the detection of fraudulent transactions and the detection of illicit addresses (actors) in the Bitcoin network by leveraging four types of graph data: (i) the transaction-to-transaction graph, representing the money flow in the Bitcoin network, (ii) the address-to-address interaction graph, capturing the types of transaction flows between Bitcoin addresses, (iii) the address-transaction graph, representing the bi-directional money flow between addresses and transactions (BTC flow from input address to one or more transactions and BTC flow from a transaction to one or more output addresses), and (iv) the user entity graph, capturing clusters of Bitcoin addresses representing unique Bitcoin users. Second, we perform fraud detection tasks on all four graphs by using diverse machine learning algorithms. We show that adding enhanced features from the address-to-address and the address-transaction graphs not only assists in effectively detecting both illicit transactions and illicit addresses, but also assists in gaining in-depth understanding of the root cause of money laundering vulnerabilities in cryptocurrency transactions and the strategies for fraud detection and prevention. The Elliptic++ dataset is released at https://www.github.com/git-disl/EllipticPlusPlus.

Open access
2 source records
Crime, Illicit Activities, and Governance
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Original source
May 22, 2023·Electronics
19 cites
Ethereum Smart Contract Vulnerability Detection Model Based on Triplet Loss and BiLSTM

Meiying Wang, Zheyu Xie, Xuefan Wen, Jianmin Li · 5 authors

The wide application of Ethereum smart contracts in the Internet of Things, finance, medical, and other fields is associated with security challenges. Traditional detection methods detect vulnerabilities by stacking hard rules, which are associated with the bottleneck of a high false-positive rate and low detection efficiency. To make up for the shortcomings of traditional methods, existing deep learning methods improve model performance by combining multiple models, resulting in complex structures. From the perspective of optimizing the model feature space, this study proposes a vulnerability detection scheme for Ethereum smart contracts based on metric learning and a bidirectional long short-term memory (BiLSTM) network. First, the source code of the Ethereum contract is preprocessed, and the word vector representation is used to extract features. Secondly, the representation is combined with metric learning and the BiLSTM model to optimize the feature space and realize the cohesion of similar contracts and the discreteness of heterogeneous contracts, improving the detection accuracy. In addition, an attention mechanism is introduced to screen key vulnerability features to enhance detection observability. The proposed method was evaluated on a large-scale dataset containing four types of vulnerabilities: arithmetic vulnerabilities, re-entrancy vulnerabilities, unchecked calls, and inconsistent access controls. The results show that the proposed scheme exhibits excellent detection performance. The accuracy rates reached 88.31%, 93.25%, 91.85%, and 90.59%, respectively.

Open access
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Original source
May 13, 2023·Journal of risk and financial management
7 cites
Phishing Attacks on Cryptocurrency Investors in the Arab States of the Gulf

Marzooq Hadi Marzooq Alyami, Reem Alhotaylah, Sawsan Alshehri, Abdullah Alghamdi

With the rapid development of technology in all fields, including the financial field, people have flocked to invest in cryptocurrencies, sometimes without prior knowledge or experience. This has prompted hackers to prey on inexperienced investors through many types of fraud and attacks, especially phishing attacks. Cryptocurrency investment transactions take place without intermediaries such as banks and monetary institutions. Investing in cryptocurrencies is a form of peer-to-peer transaction and takes place without the involvement of physical wallets. This study addresses cases where people may become victims of phishing attacks due to the nature of cryptocurrency investments. The aim of this study was to understand the concepts of various phishing attacks on cryptocurrencies and to measure the awareness of cryptocurrency investors in the Arab Gulf countries regarding the security risks associated with cryptocurrency investments. This research was conducted by distributing a questionnaire among cryptocurrency investors and collecting and analyzing all the survey responses. The results reveal a lack of awareness about how to deal with the security risks associated with cryptocurrency investments. The research concludes that the majority of cryptocurrency investors are unaware of how to deal with phishing attacks. Finally, we address future research directions and recommend actions that can be taken to increase investors’ awareness of this issue.

Open access
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Spam and Phishing Detection
Original source
May 12, 2023·arXiv (Cornell University)
1 cites
Novel bribery mining attacks in the bitcoin system and the bribery miner's dilemma

Junjie Hu, Chunxiang Xu, Zhe Jiang, Jiwu Cao

Mining attacks allow adversaries to obtain a disproportionate share of the mining reward by deviating from the honest mining strategy in the Bitcoin system. Among them, the most well-known are selfish mining (SM), block withholding (BWH), fork after withholding (FAW) and bribery mining. In this paper, we propose two novel mining attacks: bribery semi-selfish mining (BSSM) and bribery stubborn mining (BSM). Both of them can increase the relative extra reward of the adversary and will make the target bribery miners suffer from the bribery miner dilemma. All targets earn less under the Nash equilibrium. For each target, their local optimal strategy is to accept the bribes. However, they will suffer losses, comparing with denying the bribes. Furthermore, for all targets, their global optimal strategy is to deny the bribes. Quantitative analysis and simulation have been verified our theoretical analysis. We propose practical measures to mitigate more advanced mining attack strategies based on bribery mining, and provide new ideas for addressing bribery mining attacks in the future. However, how to completely and effectively prevent these attacks is still needed on further research.

Open access
2 source records
cs.GT
cs.CE
cs.CR
Original source
May 10, 2023·Institute of Electrical and Electronics Engineers (IEEE)
0 cites
Security of the Current Blockchain Technologies: Viewpoint from 2023

Petar Radanliev

The first cryptocurrency was invested in 2008/09, but the Blockchain-Web3 concept is still in its infancy, and the cyber risk is constantly changing. Our cybersecurity should also be adapting to these changes to ensure security of personal data and continuation of business for organisations. This review paper starts with a comparison of existing cybersecurity standards and regulations from the National Institute of Standards and Technology (NIST) and the International Organization for Standardization (ISO) - ISO27001, followed by a discussion on more specific and recent standards and regulations, such as the Markets in Crypto-Assets Regulation (MiCA), Committee on Payments and Market Infrastructures and the International Organisation of Securities Commissions (CPMI-IOSCO), and more general cryptography and post-quantum cryptography, in the context of cybersecurity. These topics are followed up by a review of recent technical reports on cyber risk/security and a discussion on cloud security questions. Comparison of Blockchain cyber risk is also performed on the recent EU standards on cyber security, including European Cybersecurity Certification Scheme (EUCS) – cloud, and additional US standards – The National Vulnerability Database (NVD) Common Vulnerability Scoring System (CVSS). The study includes a review of Blockchain endpoint security, and new technologies e.g., IoT. The research methodology applied is a review and case study analysing secondary data on cybersecurity. The research significance is the integration of knowledge from the United States (US), the European Union (EU), the United Kingdom (UK), and international standards and frameworks on cybersecurity that can be alighted to new Blockchain projects. The results show that cybersecurity standards are not designed in close cooperation between the two major western blocks - US and EU. In addition, while the US is still leading in this area, the security standards for cryptocurrencies, internet-of-things, and blockchain technologies have not evolved as fast as the technologies have. The key finding from this study is that although the crypto market has grown into a multi-trillion industry, the crypto market has also lost over 70% since its peak, causing significant financial loss for individuals and cooperation’s. Despite this significant impact to individuals and society, cybersecurity standards and financial governance regulations are still in their infancy.

Open access
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Cloud Data Security Solutions
Original source
Apr 29, 2023·arXiv
6 cites
A technique to avoid Blockchain Denial of Service (BDoS) and Selfish Mining Attack

Md. Ahsan Habib, Md. Motaleb Hossen Manik

Blockchain denial of service (BDoS) and selfish mining are the two most crucial attacks on blockchain technology. A classical DoS attack targets the computer network to limit, restrict, or stop accessing the system of authorized users which is ineffective against renowned cryptocurrencies like Bitcoin, Ethereum, etc. Unlike the conventional DoS, the BDoS affects the system's mechanism design to manipulate the incentive structure to discourage honest miners to participate in the mining process. In contrast, in a selfish mining attack, the adversary miner keeps its discovered block private to fork the chain intentionally that aiming to increase the incentive of the adversary miner. This paper proposed a technique to successfully avoid BDoS and selfish mining attacks. The existing infrastructure of blockchain technology does not need to be changed a lot to incorporate the proposed solution.

Open access
2 source records
cs.CR
Blockchain Technology Applications and Security
Spam and Phishing Detection
Original source
Apr 28, 2023·Electronics
40 cites
Enhancing Smart-Contract Security through Machine Learning: A Survey of Approaches and Techniques

Fan Jiang, Kailin Chao, Jianmao Xiao, Qinghua Liu · 7 authors

As blockchain technology continues to advance, smart contracts, a core component, have increasingly garnered widespread attention. Nevertheless, security concerns associated with smart contracts have become more prominent. Although machine-learning techniques have demonstrated potential in the field of smart-contract security detection, there is still a lack of comprehensive review studies. To address this research gap, this paper innovatively presents a comprehensive investigation of smart-contract vulnerability detection based on machine learning. First, we elucidate common types of smart-contract vulnerabilities and the background of formalized vulnerability detection tools. Subsequently, we conduct an in-depth study and analysis of machine-learning techniques. Next, we collect, screen, and comparatively analyze existing machine-learning-based smart-contract vulnerability detection tools. Finally, we summarize the findings and offer feasible insights into this domain.

Open access
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Imbalanced Data Classification Techniques
Original source
Apr 26, 2023·Proceedings of the ACM Web Conference 2023
71 cites
Cross-Modality Mutual Learning for Enhancing Smart Contract Vulnerability Detection on Bytecode

Peng Qian, Zhenguang Liu, Yifang Yin, Qinming He

Over the past couple of years, smart contracts have been plagued by multifarious vulnerabilities, which have led to catastrophic financial losses. Their security issues, therefore, have drawn intense attention. As countermeasures, a family of tools has been developed to identify vulnerabilities in smart contracts at the source-code level. Unfortunately, only a small fraction of smart contracts is currently open-sourced. Another spectrum of work is presented to deal with pure bytecode, but most such efforts still suffer from relatively low performance due to the inherent difficulty in restoring abundant semantics in the source code from the bytecode.

Open access
2 source records
Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
Cybercrime and Law Enforcement Studies
Original source
Apr 22, 2023·International Journal of Current Science Research and Review
6 cites
The Impact of Cryptocurrency on Global Trade and Commerce

Researcher and Assistant Professor Dr. & Scarborough Street, Southport, Gold Coast, Queensland, 4215, Australia, Bundit Anuyahong, Nipol Ek-udom

<strong>ABSTRACT: </strong>This study aimed to investigate the impact of cryptocurrency on global trade and commerce. The research objectives included examining the extent to which the adoption of cryptocurrency has disrupted traditional financial systems and affected cross-border transactions, as well as investigating the potential benefits and challenges of using cryptocurrency for global trade and commerce. A mixed-methods research design was used, incorporating both quantitative and qualitative data collection and analysis techniques. The study involved an extensive literature review, a survey of businesses involved in international trade, and interviews with key stakeholders. The results showed that cryptocurrency offers benefits such as reduced transaction costs, faster settlement times, and increased transparency in transactions. However, there are also challenges such as regulatory and legal hurdles, security concerns, and limited understanding of cryptocurrency. The study also highlights the factors that influence the adoption of cryptocurrency in international trade, including regulatory and legal frameworks, security concerns, awareness and understanding of cryptocurrency, transaction costs, and integration with existing systems. Finally, the attitudes and perceptions of businesses towards cryptocurrency are discussed, with the study showing that confidence in the reliability and security of cryptocurrency is a significant factor for adoption. Overall, the study provides insights into the potential opportunities and challenges presented by cryptocurrency in global trade and commerce, and the implications for policymakers, businesses, and investors.

Open access
2 source records
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Economic Growth and Development
Original source
Apr 15, 2023·Laws
20 cites
When Criminals Abuse the Blockchain: Establishing Personal Jurisdiction in a Decentralised Environment

Casey Watters

In August of 2022, the United States Department of Treasury sanctioned the virtual currency mixer Tornado Cash, an open-source and fully decentralised piece of software running on the Ethereum blockchain, subsequently leading to the arrest of one of its developers in the Netherlands. Not only was this the first time the Office of Foreign Assets Control (OFAC) extended its authority to sanction a foreign ‘person’ to software, but the decentralised nature of the software and global usage highlight the challenge of establishing jurisdiction over decentralised software and its global user base. The government claims jurisdiction over citizens, residents, and any assets that pass through the country’s territory. As a global financial center with most large tech companies, this often facilitates the establishment of jurisdiction over global conduct that passes through US servers. However, decentralised programs on blockchains with nodes located around the world challenge this traditional approach as either nearly all countries can claim jurisdiction over users, subjecting users to criminal laws in countries with which they have no true interaction, or they limit jurisdiction, thereby risking abuse by bad actors. This article takes a comparative approach to examine the challenges to establishing criminal jurisdiction on cryptocurrency-related crimes.

Open access
Blockchain Technology Applications and Security
Crime, Illicit Activities, and Governance
Cybercrime and Law Enforcement Studies
Original source
Apr 6, 2023·arXiv (Cornell University)
58 cites
Smart Contract and DeFi Security Tools: Do They Meet the Needs of Practitioners?

Stefanos Chaliasos, Marcos Antonios Charalambous, Liyi Zhou, Rafaila Galanopoulou · 7 authors

The growth of the decentralized finance (DeFi) ecosystem built on blockchain technology and smart contracts has led to an increased demand for secure and reliable smart contract development. However, attacks targeting smart contracts are increasing, causing an estimated \$6.45 billion in financial losses. Researchers have proposed various automated security tools to detect vulnerabilities, but their real-world impact remains uncertain. In this paper, we aim to shed light on the effectiveness of automated security tools in identifying vulnerabilities that can lead to high-profile attacks, and their overall usage within the industry. Our comprehensive study encompasses an evaluation of five SoTA automated security tools, an analysis of 127 high-impact real-world attacks resulting in \$2.3 billion in losses, and a survey of 49 developers and auditors working in leading DeFi protocols. Our findings reveal a stark reality: the tools could have prevented a mere 8% of the attacks in our dataset, amounting to \$149 million out of the \$2.3 billion in losses. Notably, all preventable attacks were related to reentrancy vulnerabilities. Furthermore, practitioners distinguish logic-related bugs and protocol layer vulnerabilities as significant threats that are not adequately addressed by existing security tools. Our results emphasize the need to develop specialized tools catering to the distinct demands and expectations of developers and auditors. Further, our study highlights the necessity for continuous advancements in security tools to effectively tackle the ever-evolving challenges confronting the DeFi ecosystem.

Open access
3 source records
Blockchain Technology Applications and Security
FinTech, Crowdfunding, Digital Finance
Cybercrime and Law Enforcement Studies
Original source
Apr 3, 2023·The Review of Socionetwork Strategies
20 cites
Review and Comparison of US, EU, and UK Regulations on Cyber Risk/Security of the Current Blockchain Technologies: Viewpoint from 2023

Petar Radanliev

&lt;p&gt;The first cryptocurrency was invested in 2008/09, but the Blockchain-Web3 concept is still in its infancy, and the cyber risk is constantly changing. Our cybersecurity should also be adapting to these changes to ensure security of personal data and continuation of business for organisations. This review paper starts with a comparison of existing cybersecurity standards and regulations from the National Institute of Standards and Technology (NIST) and the International Organization for Standardization (ISO) - ISO27001, followed by a discussion on more specific and recent standards and regulations, such as the Markets in Crypto-Assets Regulation (MiCA), Committee on Payments and Market Infrastructures and the International Organisation of Securities Commissions (CPMI-IOSCO), and more general cryptography and post-quantum cryptography, in the context of cybersecurity. These topics are followed up by a review of recent technical reports on cyber risk/security and a discussion on cloud security questions. Comparison of Blockchain cyber risk is also performed on the recent EU standards on cyber security, including European Cybersecurity Certification Scheme (EUCS) – cloud, and additional US standards – The National Vulnerability Database (NVD) Common Vulnerability Scoring System (CVSS). The study includes a review of Blockchain endpoint security, and new technologies e.g., IoT. The research methodology applied is a review and case study analysing secondary data on cybersecurity. The research significance is the integration of knowledge from the United States (US), the European Union (EU), the United Kingdom (UK), and international standards and frameworks on cybersecurity that can be alighted to new Blockchain projects. The results show that cybersecurity standards are not designed in close cooperation between the two major western blocks - US and EU. In addition, while the US is still leading in this area, the security standards for cryptocurrencies, internet-of-things, and blockchain technologies have not evolved as fast as the technologies have. The key finding from this study is that although the crypto market has grown into a multi-trillion industry, the crypto market has also lost over 70% since its peak, causing significant financial loss for individuals and cooperation’s. Despite this significant impact to individuals and society, cybersecurity standards and financial governance regulations are still in their infancy.&lt;/p&gt;

Open access
4 source records
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Information and Cyber Security
Original source
Mar 27, 2023·Institute of Electrical and Electronics Engineers (IEEE)
0 cites
Classifying ransomware-Bitcoin nodes using graph embeddings

Adam W. Turner, Muhammad Ikram, Allon J. Uhlmann

This research develops a methodology to identify transactions through data-driven tracking and analysis of ransomware-Bitcoin payment networks [30]. We demonstrate the methodology by applying the GraphSAGE embedding algorithm to the WannaCry ransomware-Bitcoin cash-out network. The paper takes a data-driven approach to building a machine learning system that allows analysts to define features relevant to ransomware-Bitcoin payment networks.

Open access
2 source records
Advanced Malware Detection Techniques
Cybercrime and Law Enforcement Studies
Crime, Illicit Activities, and Governance
Original source
Mar 27, 2023·Institute of Electrical and Electronics Engineers (IEEE)
2 cites
Feature Engineering for Anomaly Detection and Classification of Blockchain Transactions

Samantha Jeyakumar, Eugene Yugarajah Andrew Charles, Punit Rathore, Marimuthu Palaniswami · 6 authors

The study analysed the importance of blockchain transaction features to identify suspicious activities. The feature engineering process involves exploiting domain knowledge, applying intuition, and performing a time-consuming series of trial-and-error extractions. Manually overseeing this process significantly impacts the performance of model generation. We address this challenge with an automated feature engineering approach to extract the various features from blockchain transactions. Also, we engineered a set of new features based on statistical measures and graph representation. We demonstrate that the proposed approach can be applied to various blockchain transaction datasets, including Bitcoin and Ethereum. The engineered features were tested against eight classifiers, including random forest, XG-boost, Silas, and neural network-based classifiers to identify the suspicious behaviour of transactions

Open access
2 source records
Blockchain Technology Applications and Security
Imbalanced Data Classification Techniques
Cybercrime and Law Enforcement Studies
Original source
Mar 25, 2023·Advanced Information Technologies and Applications
2 cites
GSVD: Common Vulnerability Dataset for Smart Contracts on BSC and Polygon

Ziniu Shen, Yunfang Chen, Wei Zhang

The blockchain 2.0 age, marked by smart contract and Ethereum, has arrived couple years ago. Its technologies have expanded the application scenarios of blockchain technology and driven the boom of decentralized Finance. However, smart contract vulnerabilities and security issues are also emerging one after another. Hackers have exploited these vulnerabilities to cause huge economic losses. In recent years, a large amount of research on the analysis and detection of smart contract vulnerabilities has emerged, but there has been no common detection tool and corresponding test dataset. In this paper, we build GSVD dataset (Generalized Smart Contract Vulnerability Dataset) consisting four offline datasets using smart contracts on two chains, Polygon and BSC: two small Solidity datasets consisting of 153 labeled smart contract source codes, which can be used to test the performance of vulnerability mining tools; two large Solidity datasets consisting of 52,202 un labeled real smart contract source codes that can be used to verify the correctness of various theories and tools under a large number of real data conditions. At the same time, this paper integrates the scripting framework accompanying the GSVD dataset, which can execute a variety of popular automated vulnerability detection tools on top of these datasets and generate analysis results of contracts and potential vulnerabilities. We tested the Minor dataset under GSVD using three tools (Slither, Manticore, Mythril) that are kept up to date and found that the combined use of all tools detected 61.1% of labeled vulnerabilities, of which Mythril has the highest detection rate of 42.6%. It is not difficult to conclude that there`re still ample room for advancement for current smart contract vulnerability mining tools because of their underlying methods. Besides, our dataset can contribute to the ultimate target greatly by providing mining tools plenty real contracts information.

Open access
Blockchain Technology Applications and Security
Spam and Phishing Detection
Cybercrime and Law Enforcement Studies
Original source