Siddhartha R. Dalal, Zihe Wang, Siddhanth Sabharwal
Due to the pseudo-anonymity of the Bitcoin network, users can hide behind their bitcoin addresses that can be generated in unlimited quantity, on the fly, without any formal links between them. Thus, it is being used for payment transfer by the actors involved in ransomware and other illegal activities. The other activity we consider is related to gambling since gambling is often used for transferring illegal funds. The question addressed here is that given temporally limited graphs of Bitcoin transactions, to what extent can one identify common patterns associated with these fraudulent activities and apply them to find other ransomware actors. The problem is rather complex, given that thousands of addresses can belong to the same actor without any obvious links between them and any common pattern of behavior. The main contribution of this paper is to introduce and apply new algorithms for local clustering and supervised graph machine learning for identifying malicious actors. We show that very local subgraphs of the known such actors are sufficient to differentiate between ransomware, random and gambling actors with 85% prediction accuracy on the test data set.
A smart Ponzi scheme is a new form of economic crime that uses Ethereum smart contract account and cryptocurrency to implement Ponzi scheme. The smart Ponzi scheme has harmed the interests of many investors, but researches on smart Ponzi scheme detection is still very limited. The existing smart Ponzi scheme detection methods have the problems of requiring many human resources in feature engineering and poor model portability. To solve these problems, we propose a data-driven smart Ponzi scheme detection system in this paper. The system uses dynamic graph embedding technology to automatically learn the representation of an account based on multi-source and multi-modal data related to account transactions. Compared with traditional methods, the proposed system requires very limited human-computer interaction. To the best of our knowledge, this is the first work to implement smart Ponzi scheme detection through dynamic graph embedding. Experimental results show that this method is significantly better than the existing smart Ponzi scheme detection methods.
One of the most modern inventions of financial technology (FinTech) since after the global financial crisis of 2008 is the crypto or virtual currency/asset. Since the creation of the first cryptocurrency, the Bitcoin, in 2009, it is estimated that over five thousand variants of the Bitcoin and other cryptocurrencies have emerged. Virtual currencies have become widespread across the globe but their legal status and uses in various countries have remained uncertain. They have been variously classified as currencies, securities, properties, assets, commodities and tokens, and used as means of exchange but are not legally recognised as legal tender. In many jurisdictions their emergence was greeted with scepticism and express or tacit rejection by financial and securities markets regulators, but over time, owing to their increasing popularity, characteristics, positive and negative potentials, there has been a gradual shift towards their formal recognition and regulation. Regulatory authorities in many countries are now grappling with designing appropriate policy and regulatory framework for the crypto phenomenon. This paper interrogates the current legal status and efforts to regulate cryptocurrencies in two leading African nations, Nigeria and South Africa, and highlights the challenges of designing an appropriate regulatory framework for this enigmatic technology. The paper adopts the doctrinal legal research methodology, employing the descriptive, analytical, and comparative approaches. It follows a structured review and analysis of relevant extant legislation on currencies and securities in the countries to ascertain whether they cover cryptocurrencies. It then compares the current position of the law on the subject in the two countries. Bearing in mind that it may not be possible to totally ban dealing in cryptocurrencies, the paper concludes that regulation has become imperative. Drawing from the position on the subject in more developed nations, the United States of America (US) and the European Union (EU), this paper proposes a model of regulation of virtual currency not only for Nigeria and South Africa but also for other African countries.
Ehsan Rehman, Muhammad Asghar Khan, Tariq Rahim Soomro, Nasser Taleb · 6 authors
Non-governmental organizations (NGOs) in under-developed countries are receiving funds from donor agencies for various purposes, including relief from natural disasters and other emergencies, promoting education, women empowerment, economic development, and many more. Some donor agencies have lost their trust in NGOs in under-developed countries, as some NGOs have been involved in the misuse of funds. This is evident from irregularities in the records. For instance, in education funds, on some occasions, the same student has appeared in the records of multiple NGOs as a beneficiary, when in fact, a maximum of one NGO could be paying for a particular beneficiary. Therefore, the number of actual beneficiaries would be smaller than the number of claimed beneficiaries. This research proposes a blockchain-based solution to ensure trust between donor agencies from all over the world, and NGOs in under-developed countries. The list of National IDs along with other keys would be available publicly on a blockchain. The distributed software would ensure that the same set of keys are not entered twice in this blockchain, preventing the problem highlighted above. The details of the fund provided to the student would also be available on the blockchain and would be encrypted and digitally signed by the NGOs. In the case that a record inserted into this blockchain is discovered to be fake, this research provides a way to cancel that record. A cancellation record is inserted, only if it is digitally signed by the relevant donor agency.
Public blockchain records are widely studied in various aspects such as cryptocurrency abuse, anti-money-laundering, and monetary flow of businesses. However, the final blockchain records, usually available from block explorer services or querying locally stored data of blockchain nodes, do not provide abundant and dynamic event logs that are only visible from a live large-scale measurement. In this paper, we collect the network logs of three popular permissionless blockchains, that is, Bitcoin, Ethereum, and EOS. The discrepancy between observed events and the public block data is studied via a noble analysis model provided with the soundness of measurement. We share our key findings including a false universal assumption of previous mining-related studies and the block/transaction arrival characteristics.
Currently, life cannot be imagined without the use of bank cards for purchases or money transfers; however, their use provides new opportunities for money launderers and terrorist organizations. This paper proposes a blockchain-enabled transaction scanning (BTS) method for the detection of anomalous actions. The BTS method specifies the rules for outlier detection and rapid movements of funds, which restrict anomalous actions in transactions. The specified rules determine the specific patterns of malicious activities in the transactions. Furthermore, the rules of the BTS method scan the transaction history and provide a list of entities that receive money suspiciously. Finally, the blockchain-enabled process is used to restrict money laundering. To validate the performance of the proposed BTS method, a Spring Boot application is built based on the Java programming language. Based on experimental results, the proposed BTS method automates the process of investigating transactions and restricts money laundering incidents.
Evidence destruction and tempering is a time-tested tactic to protect the\npowerful perpetrators, criminals, and corrupt officials. Countries where law\nenforcing institutions and judicial system can be comprised, and evidence\ndestroyed or tampered, ordinary citizens feel disengaged with the investigation\nor prosecution process, and in some instances, intimidated due to the\nvulnerability to exposure and retribution. Using Distributed Ledger\nTechnologies (DLT), such as blockchain, as the underpinning technology, here we\npropose a conceptual model - 'EvidenceChain', through which citizens can\nanonymously upload digital evidence, having assurance that the integrity of the\nevidence will be preserved in an immutable and indestructible manner. Person\nuploading the evidence can anonymously share it with investigating authorities\nor openly with public, if coerced by the perpetrators or authorities.\nTransferring the ownership of evidence from authority to ordinary citizen, and\ncustodianship of evidence from susceptible centralized repository to an\nimmutable and indestructible distributed repository, can cause a paradigm shift\nof power that not only can minimize spoliation of evidence but human rights\nabuse too. Here the conceptual model was theoretically tested against some\nhigh-profile spoliation of evidence cases from four South Asian developing\ncountries that often rank high in global corruption index and low in human\nrights index.\n
David Sanz Bas, Carlos del Rosal, Sergio Luis Náñez Alonso, Miguel Ángel Echarte Fernández
Cryptocurrencies have been developing very rapidly in recent years, and their use is becoming more and more widespread in different areas. The use of digital currencies for legal uses is advancing along with technological development, but, at the same time, criminal activities are also emerging to take advantage of this boom. The aim of this paper has been, first, to analyze the various ways in which individuals and criminal organizations have taken advantage of the phenomenon of cryptocurrencies to carry out fraudulent activities such as laundering money of illicit origin and, second, to provide an overview of the legal tools that have been developed in this regard in Europe and, more specifically, in Spain to combat these activities. Undoubtedly, cryptocurrencies bring great benefits to the economy, but it is also necessary to know the risks and abuses that have been developed to prevent them.
Cryptocurrency has become a new venue for money laundering. Bitcoin mixing services deliberately obfuscate the relationship between senders and recipients, making it difficult to trace suspicious money flow. We believe that the key to demystifying the bitcoin mixing services is to discover agents’ roles in the money laundering process. We propose a goal-oriented approach to modeling, discovering, and analyzing different types of roles in the agent-based business process of the bitcoin mixing scenario using historical bitcoin transaction data. It adopts the agents’ goal perspective to study the roles in the bitcoin money laundering process. Moreover, it provides a foundation to discover real-world agents’ roles in bitcoin money laundering scenarios.
To execute transactional operations in the financial trading industry, cryptocurrencies like as bitcoin make use of decentralization, traceability, and anonymity properties. These digital currencies, which are based on new blockchain technology, are serving as the foundation for some of the world's biggest unregulated marketplaces. A variety of regulatory difficulties arise as a result, including the illegal acquisition of narcotics and weapons, money laundering, and the support of terrorist operations, among others. This chapter examines a variety of legal and ethical implications, as well as their consequences and potential solutions to the fundamental problems that policymakers and regulators are today confronted with on a daily basis. The authors present the findings of an analysis of 30 recently published peer-reviewed scientific publications, and they propose a number of mechanisms that can aid in the detection and prevention of illegal activities, which currently account for a significant portion of cryptocurrency trading at this time. These researchers propose methodologies and apps that may be used to detect dark markets in the future, should the need arise.
Carlos Eduardo Carvalho, Desirée Almeida Pires, Marcel Artioli, Giuliano Contento de Oliveira
Abstract This paper analyses the impacts of the innovation known as distributed ledger technology (DLT) on the monetary system and on financial activities. Private cryptocurrencies, such as Bitcoin, are permissionless means of payment, based on blockchain, a form of DLT. Evaluations suggested that these private cryptocurrencies could compete with the banks payment systems and even supplant state currency. The development of these technologies has the potential to modify profoundly monetary and financial practices, but there are no indications that they may threaten the centrality of state money and the banking system in the contemporary monetary order. Major international banks have developed cryptocurrencies for settlement systems and for interbank transactions, including the so-called stablecoins, issued by highly technological companies with on par conversion into state money. Some central banks are studying the launch of state cryptocurrencies that could coexist with their fiduciary state currency and even replace their paper currency. The use of this technology results in new challenges for regulation, including the fact that cryptocurrencies can be used for money laundering and by organized crime.
In recent years, as blockchain adoption has been expanding across a wide range of domains, e.g., digital asset, supply chain finance, etc., the confidentiality of smart contracts is now a fundamental demand for practical applications. However, while new privacy protection techniques keep coming out, how existing ones can best fit development settings is little studied. Suffering from limited architectural support in terms of programming interfaces, state-of-the-art solutions can hardly reach general developers. In this paper, we proposed the CLOAK framework for developing confidential smart contracts. The key capability of CLOAK is allowing developers to implement and deploy practical solutions to multi-party transaction (MPT) problems, i.e., transact with secret inputs and states owned by different parties by simply specifying it. To this end, CLOAK introduced a domain-specific annotation language for declaring privacy specifications and further automatically generating confidential smart contracts to be deployed with trusted execution environment (TEE) on blockchain. In our evaluation on both simple and real-world applications, developers managed to deploy business services on blockchain in a concise manner by only developing CLOAK smart contracts whose size is less than 30% of the deployed ones.
Decentralized Finance (DeFi) took shape in 2020. An unprecedented amount of over 14 billion USD moved into DeFi projects offering trading, loans and insurance. But its growth has also drawn the attention of malicious actors. Many projects were exploited as quickly as they launched and millions of USD were lost. While many developers understand integer overflows and reentrancy attacks, security threats to the DeFi ecosystem are more complex and still poorly understood. In this paper we provide the first overview of in-the-wild DeFi security incidents. We observe that many of these exploits are market attacks, weaponizing weakly implemented business logic in one protocol with credit provided by another to inflate appropriations. Rather than misusing individual protocols, attackers increasingly use DeFi's strength of permissionless composability against itself. By providing the first holistic analysis of real-world security incidents within the nascent financial ecosystem DeFi is, we hope to inform threat modeling in decentralized cryptoeconomic initiatives in the years ahead.
The research designs a new integrated system for the security enhancement of a decentralized network by preventing damages from attackers, particularly for the 51 percent attack. The concept of multiple layered design based on Blockchain Governance Games frameworks could handle multiple number of networks analytically. The Multi-Layered Blockchain Governance Game is an innovative analytical model to find the best strategies for executing a safety operation to protect whole multiple layered network systems from attackers. This research fully analyzes a complex network with the compact mathematical forms and theoretically tractable results for predicting the moment of a safety operation execution are fully obtained. Additionally, simulation results are demonstrated to obtain the optimal values of configuring parameters of a blockchain-based security network. The Matlab codes for the simulations are publicly available to help those whom are constructing an enhanced decentralized security network architecture through this proposed integrated theoretical framework.
Dado el creciente uso de las criptomonedas a nivel mundial, y dentro de estas el bitcoin (BTC), resulta necesario analizar el marco jurídico aplicable con el fin de detectar posibles cambios o actualizaciones. Uno de los aspectos incluidos en dicho análisis refiere a la posibilidad de efectuar el pago del salario de los trabajadores en bitcoins. En este artículo se busca, desde un abordaje principalmente jurídico y económico, conceptualizar jurídicamente al bitcoin para luego evaluar si la normativa vigente en Uruguay habilita el pago de salarios con esta criptomoneda. Se concluye que en Uruguay existen limitaciones legales para que los salarios mínimos se paguen con otros medios distintos de la moneda nacional, aunque podría establecerse un pago parcial con BTC mediante el mecanismo de los Consejos de Salarios. Para la parte del salario que supere el mínimo no habría inconvenientes, tanto se considere al BTC como dinero privado o como un bien incorporal “común”.
Bitcoin is extremely easy to be used in corruption cases due to its pseudonym, easy circulation, easy cross-border and other characteristics. As a decentralized electronic account book, the circulation of regulatory funds is jointly confirmed by each node in the bitcoin network, which can ensure the authenticity of the criminal evidence and is not easy to be lost or damaged. It provides great convenience for evidence collection in bitcoin corruption cases. However, there are also shackles in criminal governance, such as how to prove the subjective intent of the bribe takers, the impact of fluctuations in market value on the identification of the case and, most importantly, how to effectively recover stolen goods across borders. Therefore, the difficulty of bitcoin-related cases does not lie in the “anonymity” that some scholars believe, but lies in the determination of subjective intent, the determination of the amount of the crime and the international judicial assistance in recovering the stolen money.
Bitcoin uses blockchain technology to maintain transactions order and provides probabilistic guarantees to prevent double-spending, assuming that an attacker’s computational power does not exceed 50% of the network power. In this article, we design a novel bribery attack and show that this guarantee can be hugely undermined. Miners are assumed to be rational in this setup, and they are given incentives that are dynamically calculated. In this attack, the adversary misuses the Bitcoin protocol to bribe miners and maximize their gained advantage. We will reformulate the bribery attack to propose a general mathematical foundation upon which we build multiple strategies. We show that, unlike Whale Attack, these strategies are practical, especially in the future when halvings lower the mining rewards. In the so-called “guaranteed variable-rate bribing with commitment” strategy, through optimization by Differential Evolution (DE), we show how double-spending is possible in the Bitcoin ecosystem for any transaction whose value is above 218.9BTC, and this comes with 100% success rate. A slight reduction in the success probability, e.g., by 10%, brings the threshold down to 165BTC. If the rationality assumption holds, then this shows how vulnerable blockchain-based systems like Bitcoin are. We suggest a soft fork on Bitcoin to fix this issue at the end.
Massimo La Morgia, Alessandro Mei, Francesco Sassi, Julinda Stefa
Cryptocurrencies are increasingly popular. Even people who are not experts have started to invest in these assets, and nowadays, cryptocurrency exchanges process transactions for over 100 billion US dollars per month. Despite this, many cryptocurrencies have low liquidity and are highly prone to market manipulation. This paper performs an in-depth analysis of two market manipulations organized by communities over the Internet: The pump and dump and the crowd pump. The pump and dump scheme is a fraud as old as the stock market. Now, it has new vitality in the loosely regulated market of cryptocurrencies. Groups of highly coordinated people systematically arrange this scam, usually on Telegram and Discord. We monitored these groups for more than 3 years, detecting around 900 individual events. We report on three case studies related to pump and dump groups. We leverage our unique dataset of the verified pump and dumps to build a machine learning model able to detect a pump and dump in 25 seconds from the moment it starts, achieving the results of 94.5% of F1-score. Then, we move on to the crowd pump, a new phenomenon that hit the news in the first months of 2021, when a Reddit community inflated the price of the GameStop stocks (GME) by over 1,900% on Wall Street, the world’s largest stock exchange. Later, other Reddit communities replicated the operation on the cryptocurrency markets. The targets were DogeCoin (DOGE) and Ripple (XRP). We reconstruct how these operations developed and discuss differences and analogies with the standard pump and dump. We believe this study helps understand a widespread phenomenon affecting cryptocurrency markets. The detection algorithms we develop effectively detect these events in real-time and helps investors stay out of the market when these frauds are in action.
Natkamon Tovanich, Nicolas Soulié, Nicolas Heulot, Petra Isenberg
We provide an empirical analysis of pool hopping behavior among 15 mining pools throughout Bitcoin's history. Mining pools have emerged as major players to ensure that the Bitcoin system stays secure, valid, and stable. Individual miners join mining pools to benefit from a more predictable income. Many questions remain open regarding how mining pools have evolved throughout Bitcoin's history and when and why miners join or leave mining pools. We propose a heuristic algorithm to extract the payout flow from mining pools and detect the pools' migration of miners. Our results showed that payout schemes and pool fees influence miners' decisions to join, change, or exit from a mining pool, thus affecting the dynamics of mining pool market shares. Our analysis provides evidence that mining activity becomes an industry as miners' decisions follow classical economic rationale.
The rapid growth of Decentralized Finance (DeFi) boosts the Ethereum ecosystem. At the same time, attacks towards DeFi applications (apps) are increasing. However, to the best of our knowledge, existing smart contract vulnerability detection tools cannot be directly used to detect DeFi attacks. That's because they lack the capability to recover and understand high-level DeFi semantics, e.g., a user trades a token pair X and Y in a Decentralized EXchange (DEX). In this work, we focus on the detection of two types of new attacks on DeFi apps, including direct and indirect price manipulation attacks. The former one means that an attacker directly manipulates the token price in DEX by performing an unwanted trade in the same DEX by attacking the vulnerable DeFi app. The latter one means that an attacker indirectly manipulates the token price of the vulnerable DeFi app (e.g., a lending app). To this end, we propose a platform-independent way to recover high-level DeFi semantics by first constructing the cash flow tree from raw Ethereum transactions and then lifting the low-level semantics to high-level ones, including token trade, liquidity mining, and liquidity cancel. Finally, we detect price manipulation attacks using the patterns expressed with the recovered DeFi semantics. We have implemented a prototype named \tool{} and applied it to more than 350 million transactions. It successfully detected 432 real-world attacks in the wild. We confirm that they belong to four known security incidents and five zero-day ones. We reported our findings. Two CVEs have been assigned. We further performed an attack analysis to reveal the root cause of the vulnerability, the attack footprint, and the impact of the attack. Our work urges the need to secure the DeFi ecosystem.
Cryptocurrencies are often thought to operate out of the reach of national regulation, but in fact their valuations, transaction volumes and user bases react substantially to news about regulatory actions. The impact depends on the specific regulatory category to which the news relates: events related to general bans on cryptocurrencies or to their treatment under securities law have the greatest adverse effect, followed by news on combating money laundering and the financing of terrorism, and on restricting the interoperability of cryptocurrencies with regulated markets. News pointing to the establishment of specific legal frameworks tailored to cryptocurrencies and initial coin offerings coincides with strong market gains. These results suggest that cryptocurrency markets rely on regulated financial institutions to operate and that these markets are segmented across jurisdictions.
Marco Antonio Castillo Medina, César Vega Zárate, Leticia Murcia López
México se está enfrentando a una nueva era digitalizada, donde nuevos conceptos como economía digital o criptomoneda son cada vez más utilizados entre la población actual mexicana, sin embargo, la legislación de México se encuentra aún rezagada por lo menos en el tema de criptomoneda, caso concreto Bitcoin.Dado lo anterior este trabajo en cuestión es una recopilación de información sobre la criptomoneda llamada Bitcoin y todos los ámbitos que lo rodean. Con la finalidad de esclarecer a fondo el tema del Bitcoin.En sus inicios se explica que es el dinero y su evolución, para dar contexto al tema, posteriormente se habla sobre la criptomoneda y Bitcoin en general en todo lo que le atañe y por último se describe un panorama general del entorno jurídico mexicano para comprender como es que la criptomoneda se contabiliza y fiscaliza en el territorio mexicano con las nuevas reformas creadas.