Han Yu, Tiantian Ji, Zhongru Wang, Hao Liu · 7 authors
A smart contract honeypot is a special type of smart contract. This type of contract seems to have obvious vulnerabilities in contract design. If a user transfers a certain amount of funds to the contract, then the user can withdraw the funds in the contract. However, once users try to take advantage of this seemingly obvious vulnerability, they will fall into a real trap. Consequently, the user’s investment in the contract cannot be retrieved. The honeypot induces other accounts to launch funds, which seriously threatens the security of property on the blockchain. Detection methods for honeypots are available. However, studying the manner by which to defend existing honeypots is insufficient to fight against honeypots. The new honeypots that may appear in the future from the perspective of an attacker must also be predicted. Therefore, we propose a type of adversarial honeypot. The code and behavioral features of honeypots are obtained through a comparative analysis of the 158,568 non-honeypots and 352 honeypots. To build an adversarial honeypot, we try to separately hide these features and make the honeypot bypass the existing detection technology. We construct 18 instances on the basis of the proposed adversarial honeypot and use an open-source honeypot detection tool to detect these instances. The experimental result shows that the proposed honeypot can bypass the detection tool with a 100% ratio. Therefore, this type of honeypot should be given attention, and defensive measures should be proposed as soon as possible.
Diego Cagigas, Judith Clifton, Daniel Díaz‐Fuentes, Marcos Fernández Gutiérrez
Blockchain is heralded as being “the next big thing” that promises to radically transform society and the economy in near-future applications. While scholarly literature on blockchain has largely focused on bitcoin and cryptofinance, in recent years, a body of scholarship has started to emerge on blockchain in the public sector. The characteristics of blockchain have made it a promising technology to transform many activities related to public policy and public service provision, such as administrative processes, welfare provision and regulation practices. This article provides, to the best of our knowledge, the first systematic literature review of the use of blockchain across all the main public services. This systematic review identifies the public services most likely to be impacted by the introduction of blockchain. It also highlights the main potential benefits, costs and risks of blockchain for government, civil servants and citizens. Governments are found to benefit mainly from improvements in efficiency and traceability, while regulatory uncertainty and questions around scalability represent major costs and risks for them. Civil servants, the least studied actor in the literature, could benefit from blockchain through the reduction of red tape and improvements in coordination between agencies. Their lack of blockchain knowledge and skills represent a major cost as regards adoption. Regarding citizens, security and transparency are identified as being the most important benefits, while risks are mainly associated with data security concerns. The article concludes by noting several limitations in the literature and providing suggestions towards fruitful lines of research.
Building on the groundswell of scholarly, practitioner, cultural, and investor interest in non-fungible tokens (NFTs), the aim of this paper is twofold. First, the paper presents early thoughts on the NFT space circa 2021, allowing for an ex-post evaluation of the assessments made at the time. Second, the paper recommends a multidisciplinary research agenda on NFTs, as encapsulated in the edited volume Non-Fungible Tokens (NFTs): Multidisciplinary Perspectives, highlighting the main areas of research promise and avenues of further enquiry. As such, the paper attempts to serve as a form of shorthand-guidebook for researchers interested in the domain of NFTs.
Since the inception of Bitcoin in 2009, the market of cryptocurrencies has grown beyond the initial expectations, as witnessed by the thousands of tokenised assets available on the market, whose daily trades amount to dozens of USD billions. The pseudonymity features of these cryptocurrencies have attracted the attention of cybercriminals, who exploit them to carry out potentially untraceable scams. The wide range of cryptocurrency-based scams observed over the last ten years has fostered the research on the analysis of their effects, and the development of techniques to counter them. However, doing research in this field requires addressing several challenges: for instance, although a few data sources about cryptocurrency scams are publicly available, they often contain incomplete or misclassified data. Further, there is no standard taxonomy of scams, which leads to ambiguous and incoherent interpretations of their nature. Indeed, the unavailability of reliable datasets makes it difficult to train effective automatic classifiers that can detect and analyse cryptocurrency scams. In this paper, we perform an extensive review of the scientific literature on cryptocurrency scams, which we systematise according to a novel taxonomy. By collecting and homogenising data from different public sources, we build a uniform dataset of thousands of cryptocurrency scams.We devise an automatic tool that recognises scams and classifies them according to our taxonomy.We assess the effectiveness of our tool through standard performance metrics.We also give an in-depth analysis of the classification results, offering several insights into threat types, from their features to their connection with other types. Finally, we provide a set of guidelines that policymakers could follow to improve user protection against cryptocurrency scams.
Bitcoin was conceptualized in response to perceived shortcomings in the monetary and financialsystem, not only related to large financial institutions but also to discretionary decision makingin monetary policy. Using high-frequency data and a weekly proxy VAR model, I study theimpact of monetary policy on Bitcoin. The paper shows that monetary shocks have sizableeffects on Bitcoin prices, but that these differ in sign: a disinflationary monetary tightening bythe ECB lowers valuations - consistent with the notion of Bitcoin as a digital gold -, whereasa Fed tightening increases Bitcoin prices. I document similar differences with respect to cen-tral bank information shocks and explore potential explanations by studying various aspects ofthe Bitcoin ecosystem. Exploiting both differences in Bitcoin valuations across currencies andblockchain transaction data, the paper shows that the increased demand for Bitcoin following aUS monetary tightening is primarily driven by emerging markets. I argue that this likely reflectsthe technological and institutional particularities of Bitcoin that make it sought after as globaldigital cashwhen international economic and financial conditions deteriorate.
O presente artigo tem por objetivo analisar a prática do crime de lavagem de dinheiro por meio da criptomoeda Bitcoin para, ao final, analisar possíveis medidas jurídicas para se coibir essa prática delituosa.
Money laundering activities related to the cryptocurrency market have seen an exponential increase over the last fifteen years as a consequence of technological developments and economic distresses, as the 2008 crisis and the 2020 pandemic. This essay will analyse the European Union legislation created in order to tackle this phenomenon, dwelling on the Fifth Anti-Money Laundering Directive and its similarities among international laws. In particular, it will be displayed the importance of intermediaries, such as money mules and mixing services, to ease money laundering and increase the anonymity. In this framework, the European Union finds itself almost powerless: the legality of the virtual currency source is assessed only when entering and exiting in the virtual market and not during in-market transactions as well as a complete lack of legislation on mixing services activities. Therefore, how can the European Union steam the misuse of such intermediaries with ex-ante and ex-post interventions? And, finally, are the European privacy policies so important to outrank the risk related to money laundering activities? This paper shows that one way to prevent cryptocurrency money laundering pullulation is launching sensitization and awareness programmes since young age through educational institutions and, most importantly, a narrower legislation is required, implementing those laws that proved to be effective in other countries, in defiance of privacy policies.
A growing stream of research finds several relations between the economic growth and corruption. Government implements various strategies to diminish the corruption and also technology often plays a dominant role to face it. Among various technologies alterations, Block-chain technology that becomes an effective and efficient way to resolve these issues related to corruption. This paper represents a brief knowledge related to the Block-Chain technology as it is a kind of distributed database or public ledger of all transactions that have been executed and shared among participating parties. Each and every transaction in the public ledger is verified by a majority of the participants registered in the system. The possible risk related to current scenario and give brief idea for resolving that problem with the help of blockchain technology. Non-Governmental Organization (NGOs) which aim is to tackle some of the issues faced by the society. NGO faces difficulty in terms of maintaining and gaining the support from donors in terms of funds. In recent decades there have been multiple examples of corruption misconduct scandals impacting the public image and reputation of NGOs. It is clear that trust of the people in NGOs is affected adversely by such events. Doubts arise in terms of where does the donation ends up? Who is leading the organization? Is donated money are used in a proper direction? So as a part of it, a need is raised to solve such issues for the betterment of the society. For the above stated problem regarding management of funds in NGOs, we propose a solution by using the Blockchain technology among various technologies alteration available. Blockchain offers the way to eliminate the doubts by providing data security, immutability and transparency. So, Blockchain Technology can offer the NGO industry to regain the trust of public.
A rede Bitcoin é um sucesso por permitir a transferência de criptomoeda com um baixo custo, de forma rápida, sem limites geográficos e sem a intervenção de um banco intermediador. Está sendo apontada como uma possível solução para mais de um bilhão de pessoas que não tem acesso ao sistema financeiro por causa dos altos custos. Por outro lado, a rede Biticoin é pseudo-anônima e tem sido usada para uma enorme variedade de atividades financeiras dúbias e ilegais. Este artigo investiga as atividades de lavagem de dinheiro na rede Bitcoin através de diversos mecanismos que procuram melhorar o desempenho de classificadores na análise de um conjunto de dados desbalanceado devido a uma classe minoritária com muito poucas amostras. A análise considera o conjunto de dados Elliptic com mais de 200 mil transações de Bitcoin, sendo o maior conjunto rotulado de dados publicamente disponível que existe hoje de todas as criptomoedas. Os experimentos realizados mostram a eficácia de cada estratégia na melhora da classificação das atividades de lavagem de dinheiro tais como: i) o percentual de repartição do conjunto de dados em treino e teste; ii) heurísticas de sobre-amostragem; ii) diferentes algoritmos de aprendizado de máquina; iv) algoritmo de reforço de aprendizado adaptativo e v) descoberta automática de características. Os resultados mostram um bom desempenho do algoritmo de sobre-amostragem AdaSyn e que o maior ganho em desempenho foi com o classificador floresta aleatória.
Abstract We study the fundamental differences that separate: Litecoin; Bitcoin Gold; Bitcoin Cash; Ethereum; and Zcash from Bitcoin, and draw some analysis to how these features are appreciated by the market, to ultimately make an inference as to how future successful cryptocurrencies may be invented and behave. We use Google Trend data, as well as price, volume and market capitalization data sourced from coinmarketcap.com to support this analysis. We find that Litecoin’s shorter block times offer benefits in commerce, but drawbacks in the mining process through orphaned blocks. Zcash holds a niche use for anonymous transactions, benefitting areas of the world lacking in economic freedom. Bitcoin Cash suffers from centralization in the mining process, while the greater decentralization of Bitcoin Gold has generally left it to stagnate. Ether’s greater functionality offers the greatest threat to Bitcoin’s dominance in the market. A coin that incorporates several of these features can be technically better than Bitcoin, but the first-to-market advantage of Bitcoin should keep its dominant position in the market.
Flash Loan, as an emerging service in the decentralized finance ecosystem, allows traders to request a non-collateral loan as long as the debt is repaid within the transaction. While providing convenience, it brings considerable challenges that Flash Loan allows speculative traders to leverage vulnerability of deployed protocols with vast capital and few risks and responsibilities. Most recently, attackers have gained over $15M profits from Eminence Finance via exploiting Flash Loans to repeatedly swap tokens (i.e., EMN and DAI). To be aware of foxy actions, we should understand what is the behavior running with the Flash Loan by traders. In this work, we propose ThunderStorm, a 3-phase transaction-based analysis framework, to systematically study Flash Loan on the Ethereum. Specifically, ThunderStorm first identifies Flash Loan transactions by applying observed transaction patterns, and then understands the semantics of the transactions based on primitive behaviors, and finally recovers the intentions of transactions according to advanced behaviors. To perform the evaluation, we apply ThunderStorm to existing transactions and investigate 11 well-known platforms. As the result, 22,244 transactions are determined to launch Flash Loan(s), and those Flash Loan transactions are further classified into 7 categories. Lastly, the measurement of financial behaviors based on Flash Loans is present to help further understand and explore the speculative usage of Flash Loan. The evaluation results demonstrate the capability of the proposed system.
Cryptocurrencies are decentralised virtual currencies, using blockchain technology to process peer-to-peer electronic payments. In 2009, the first successful cryptocurrency, Bitcoin, was established. This article discusses concepts of cryptocurrency, its relevance in the financial sector, its associated risks and establishes whether regulatory interference is necessary in order to combat money laundering using cryptocurrency. Currently, cryptocurrencies remain unregulated in South Africa. The article concludes that regulatory intervention is necessary and that cryptocurrencies should be integrated into relevant existing legislation.
Daniel Pérez, Sam M. Werner, Jiahua Xu, Benjamin Livshits
The trustless nature of permissionless blockchains renders overcollateralization a key safety component relied upon by decentralized finance (DeFi) protocols. Nonetheless, factors such as price volatility may undermine this mechanism. In order to protect protocols from suffering losses, undercollateralized positions can be liquidated. In this paper, we present the first in-depth empirical analysis of liquidations on protocols for loanable funds (PLFs). We examine Compound, one of the most widely used PLFs, for a period starting from its conception to September 2020. We analyze participants' behavior and risk-appetite in particular, to elucidate recent developments in the dynamics of the protocol. Furthermore, we assess how this has changed with a modification in Compound's incentive structure and show that variations of only 3% in an asset's dollar price can result in over 10m USD becoming liquidable. To further understand the implications of this, we investigate the efficiency of liquidators. We find that liquidators' efficiency has improved significantly over time, with currently over 70% of liquidable positions being immediately liquidated. Lastly, we provide a discussion on how a false sense of security fostered by a misconception of the stability of non-custodial stablecoins, increases the overall liquidation risk faced by Compound participants.
Ashish Rajendra Sai, Jim Buckley, Brian Fitzgerald, Andrew Le Gear
Bitcoin introduced delegation of control over a monetary system from a select few to all who participate in that system. This delegation is known as the decentralization of controlling power and is a powerful security mechanism for the ecosystem. After the introduction of Bitcoin, the field of cryptocurrency has seen widespread attention from industry and academia, so much so that the original novel contribution of Bitcoin, i.e., decentralization, may be overlooked, due to decentralizations’ assumed fundamental existence for the functioning of such crypto-assets. However, recent studies have observed a trend of increased centralization in cryptocurrencies such as Bitcoin and Ethereum. As this increased centralization has an impact the security of the blockchain, it is crucial that it is measured, towards adequate control. This research derives an initial taxonomy of centralization present in decentralized blockchains through rigorous synthesis using a systematic literature review. This is followed by iterative refinement through expert interviews. We systematically analyzed 89 research papers published between 2009 and 2019. Our study contributes to the existing body of knowledge by highlighting the multiple definitions and measurements of centralization in the literature. We identify different aspects of centralization and propose an encompassing taxonomy of centralization concerns. This taxonomy is based on empirically observable and measurable characteristics. It consists of 13 aspects of centralization, classified over six architectural layers: Governance, Network, Consensus, Incentive, Operational, and Application. We also discuss how the implications of centralization can vary depending on the aspects studied. We believe that this review and taxonomy provides a comprehensive overview of centralization in decentralized blockchains involving various conceptualizations and measures.
Financial Intelligence Units (FIUs) hold a central position in the chain of actors responsible for the monitoring of money movements in the European Union. In support of their role, which is to receive, analyse and disseminate suspicious transaction reports, they have been furnished with significant information processing powers. At present, FIUs feature prominently in the EU’s anti-money laundering and counterterrorist financing agendas and plans to further enhance their powers of information exchange are underway. At the same time, however, the legal challenges that arise from their constant empowerment, particularly for the protection of personal data, are being overlooked. This article focuses on the cooperation between FIUs in the EU and argues that the latter takes place under a complex legal framework, which raises significant challenges for data protection. In particular, it highlights the present-day uncertainty over the data protection framework that governs their operations and discusses whether FIUs should be subject to the General Data Protection Regulation or to its law enforcement counterpart, the Police Data Protection Directive. The remaining of the article focuses on the ‘ FIU.net ’ – the decentralized network for information exchanges between EU FIUs – and on the data protection challenges that emerged from the recent integration of this network into Europol.
While blockchain was designed as a ledger for cryptocurrency transactions, it can record transactions of anything of value. Blockchain is increasingly used to prove the integrity of commodities, tracing their supply chain journey from the source to the end user. Yet, transferring this technology from a cryptocurrency context to a supply chain setting is not without difficulties. This article explores the implications for multinational and transnational companies in using blockchain as a means to address modern slavery. The research identifies five challenges: verification, inclusion, trust, privacy, and normativity.
Erdinç Akyıldırım, Shaen Corbet, Douglas J. Cumming, Brian M. Lucey · 5 authors
Cryptocurrencies have been broadly scrutinised in recent times for a host of concerning regulatory and cybercriminality issues. Although steps have been taken to promote regulatory sufficiency in the near future, we examine the avenues through which this extremely high-risk industry can derive potentially devastating contagion channels, influencing both unwilling and unsuspecting investors. We focus this research on the expressions of interest by publicly traded companies across the world to utilise cryptocurrency and blockchain projects. We find evidence that there exists a substantial stock price premium and sustained increase in volatility in the aftermath of blockchain announcements, with emphasis on highly-speculative motives such as coin creation and corporate name changes. Changes in price discovery and information flows are found to be largely determined from cryptocurrency-based pricing sources in the aftermath of speculative announcements. We discuss the inherent ethical and legal issues, considering as to whether such announcements are simply an attempt to artificially manipulate share prices and take part in the current phase of crypto-exuberance.
Bithin Alangot, Daniël Reijsbergen, Sarad Venugopalan, Paweł Szałachowski
Clients of permissionless blockchain systems, like Bitcoin, rely on an underlying peer-to-peer network to send and receive transactions. It is critical that a client is connected to at least one honest peer, as otherwise the client can be convinced to accept a maliciously forked view of the blockchain. In such an eclipse attack, the client is unable to reliably distinguish the canonical view of the blockchain from the view provided by the attacker. The consequences of this can be catastrophic if the client makes business decisions based on a distorted view of the blockchain transactions. In this paper, we investigate the design space and propose two approaches for Bitcoin clients to detect whether an eclipse attack against them is ongoing. Each approach chooses a different trade-off between average attack detection time and network load. The first scheme is based on the detection of suspicious block timestamps. The second scheme allows blockchain clients to utilize their natural connections to the Internet (i.e., standard web activity) to gossip about their blockchain views with contacted servers and their other clients. Our proposals improve upon previously proposed eclipse attack countermeasures without introducing any dedicated infrastructure or changes to the Bitcoin protocol and network, and we discuss an implementation. We demonstrate the effectiveness of the gossip-based schemes through rigorous analysis using original Internet traffic traces and real-world deployment. The results indicate that our protocol incurs a negligible overhead and detects eclipse attacks rapidly with high probability, and is well-suited for practical deployment.
With the advance of Bitcoin technology, money laundering has been incentivised as a den of Bitcoin blockchain, in which the user's identity is hidden behind a pseudonym known as address. Although this trait permits concealing in the plain sight, the public ledger of Bitcoin blockchain provides more power for investigators and allows collective intelligence for anti-money laundering and forensic analysis. This fascinating paradox arises in the strength of Bitcoin technology. Machine learning techniques have attained promising results in forensic analysis, in order to spot suspicious behaviour in Bitcoin blockchain. This paper presents a comparative analysis of the performance of classical supervised learning methods using a recently published data set derived from Bitcoin blockchain, to predict licit and illicit transactions in the network. Besides, an ensemble learning method is utilised using a combination of the given supervised learning models, which outperforms the given classical methods. This experiment is performed using a newly published data set derived from Bitcoin blockchain. Our main contribution points out that using ensemble learning approach outperforms the performance of the classical learning models used in the original paper, using Elliptic data set, a time series of Bitcoin transaction graph with node transactions and directed payments flow edges. Using the same data set, we show that we are able to predict licit/illicit transactions with an accuracy of 98.13% and F1 score equals to 83.36% using the proposed method. We discuss the variety of supervised learning methods, and their capabilities of assisting forensic analysis, and propose future work directions.
Primavera De Filippi, Morshed Mannan, Wessel Reijers
Blockchain technology was created as a response to the trust crisis that swept the world in the wake of the 2008 financial crisis. Bitcoin and other blockchain-based systems were presented as a “trustless” alternative to existing financial institutions and even governments. Yet, while the trustless nature of blockchain technology has been heavily questioned, little research has been done as to what blockchain technologies actually bring to the table in place of trust. This article draws from the extensive academic discussion on the concepts of “trust” and “confidence” to argue that blockchain technology is not a ‘trustless technology’ but rather a ‘confidence machine’. First, the article provides a review of the multifaceted conceptualisations of trust and confidence, and the relationship between these two concepts. Second, the claim is made that blockchain technology relies on cryptographic rules, mathematics, and game-theoretical incentives in order to increase confidence in the operations of a computational system. Yet, such an increase in confidence ultimately relies on the proper operation and governance of the underlying blockchain-based network, which requires trusting a variety of actors. Third, the article turns to legal, constitutional and polycentric governance theory to explore the governance challenges of blockchain-based systems, in light of the tension between procedural confidence and trust.
Ransomware is malicious software (malware) that blocks access to someone’s computer system or files on the system and subsequently demands a ransom to be paid for unlocking the computer or files. Ransomware is considered one of the main threats in cybercrime today. Cryptoware is a specific type of ransomware, which encrypts files on computer systems. The ransom is often demanded in bitcoins. Based on desk research, a series of interviews, and the investigation of several police files, this paper investigates the modi operandi in which cybercriminals use ransomware and cryptoware to make profits and how they launder these profits. Two models, based on the payment of the ransom via vouchers and via bitcoins respectively, are identified and described. These methods allow criminals to launder profits in relative anonymity and prevent the seizure of the illegally obtained money.