Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

873 papersLast indexed Aug 31, 2026
Search papers

Paper index

873 results · page 26 of 37

Clear filters
Aug 31, 2021·Journal of risk and financial management
52 cites
The Ascent of Bitcoin: Bibliometric Analysis of Bitcoin Research

Ahmet Faruk Aysan, Hüseyin Bedir Demirtaş, Mustafa Saraç

Blockchain is a path-breaking paradigm, and cryptocurrencies are one of the main application areas of Blockchain technology. Bitcoin leads the cryptocurrency markets, both in terms of market capitalization and in scientific interest. In this paper, we performed a comprehensive bibliometric study of the Bitcoin-related literature. Using the Scopus database, we created a sample that comprises 4495 documents written in the 2011–2020 period. Furthermore, we provided insights about dimensions such as the change in the number of publications over the course of years, the main research areas, types of published documents, most important platforms and sources of Bitcoin publications, highly cited studies, productive authors, author’s countries, and finally main funders of Bitcoin-related research. Lastly, our bibliometric study manifests the current state and future path of Bitcoin literature from distinct perspectives.

Open access
2 source records
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Original source
Aug 30, 2021·Global Journal of Engineering and Technology Advances
1 cites
Cryptocurrency and cybercrime in Nigeria: A double-edged sword

Washima Tuleun

This paper explores how cryptocurrency affects Nigeria’s socio-economic and digital landscape, highlighting both its potential as an instrument of economic leveraging and its use in cybercrime. It explores how the decentralized characteristics of cryptocurrencies facilitate innovation and financial inclusion — and allow for anonymity, too, that enables cybercriminal activities. Today, cryptocurrency is a hot topic around the world. Nigeria, which registers some of the highest cryptocurrency adoption rates in the world, has used this class of digital asset as a key enabler of both breaking with traditional banking constraints and promoting economic resilience. But its decentralized and anonymous design also stands as a superpower to various forms of cybercrimes, from fraud and ransomware to money laundering. Such duality offers serious challenges to policymakers, law enforcement agencies, and financial institutions. The paper explores Nigeria’s regulatory experiences, technological barriers, and ethical dilemmas through in-depth analysis and case studies. This paper analyzes the phenomenon of cryptocurrency and cybercriminality in Nigeria, a phenomenon in which innovative technologies can be used as a vehicle for socioeconomic empowerment but also as a space for illegal activities. It examines case studies and statistical analyses revealing the systemic exploitation of cryptocurrency by cybercriminals and assessing the effectiveness of current legal and regulatory frameworks. This is against international best practices that expose Nigeria to grave dangers in tackling cybercrime linked to cryptocurrencies. We make sure that both the opportunities and threats it offers become bearable in how we balance the opportunities with threats this technology presents. Prescribing solutions for these challenges, the report highlights the importance of improving the regulatory environment, enhancing law enforcement capability in cyberspace, and developing a partnership between the private and public sectors to strike an appropriate balance between innovation and security. The research sent a clear message that articulated an approach to policy that would make the most of the potential of cryptocurrency while mitigating its weaknesses. Addressing these matters will allow Nigeria to seize the opportunities presented by cryptocurrency without compromising its frontier of digital security.

Open access
Cybercrime and Law Enforcement Studies
Spam and Phishing Detection
Original source
Aug 26, 2021·Applied Sciences
31 cites
Avoidance of Cybersecurity Threats with the Deployment of a Web-Based Blockchain-Enabled Cybersecurity Awareness System

Abdul Razaque, Abrar Al Ajlan, Noussaiba Melaoune, Munif Alotaibi · 9 authors

Modern information technology (IT) is well developed, and almost everyone uses the features of IT and services within the Internet. However, people are being affected due to cybersecurity threats. People can adhere to the recommended cybersecurity guidelines, rules, adopted standards, and cybercrime preventive measures to largely mitigate these threats. The ignorance of or lack of cybersecurity knowledge also causes a critical problem regarding confidentiality and privacy. It is not possible to fully avoid cybercrimes that often lead to sufficient business losses and spread forbidden themes (disgust, extremism, child porn, etc.). Therefore, to reduce the risk of cybercrimes, a web-based Blockchain-enabled cybersecurity awareness program (WBCA) process is introduced in this paper. The proposed WBCA trains users to improve their security skills. The proposed program helps with understanding the common behaviors of cybercriminals and improves user knowledge of cybersecurity hygiene, best cybersecurity practices, modern cybersecurity vulnerabilities, and trends. Furthermore, the proposed WBCA uses Blockchain technology to protect the program from potential threats. The proposed program is validated and tested using real-world cybersecurity topics with real users and cybersecurity experts. We anticipate that the proposed program can be extended to other domains, such as national or corporate courses, to increase the cybersecurity awareness level of users. A CentOS-based virtual private server is deployed for testing the proposed WBCA to determine its effectiveness. Finally, WBCA is also compared with other state-of-the-art web-based programs designed for cybersecurity awareness.

Open access
Cybercrime and Law Enforcement Studies
Information and Cyber Security
Advanced Malware Detection Techniques
Original source
Aug 26, 2021·arXiv (Cornell University)
2 cites
Understanding Money Trails of Suspicious Activities in a cryptocurrency-based Blockchain

Banwari Lal, Rachit Agarwal, Sandeep K. Shukla

The decentralization, redundancy, and pseudo-anonymity features have made permission-less public blockchain platforms attractive for adoption as technology platforms for cryptocurrencies. However, such adoption has enabled cybercriminals to exploit vulnerabilities in blockchain platforms and target the users through social engineering to carry out malicious activities. Most of the state-of-the-art techniques for detecting malicious actors depend on the transactional behavior of individual wallet addresses but do not analyze the money trails. We propose a heuristics-based approach that adds new features associated with money trails to analyze and find suspicious activities in cryptocurrency blockchains. Here, we focus only on the cyclic behavior and identify hidden patterns present in the temporal transactions graphs in a blockchain. We demonstrate our methods on the transaction data of the Ethereum blockchain. We find that malicious activities (such as Gambling, Phishing, and Money Laundering) have different cyclic patterns in Ethereum. We also identify two suspicious temporal cyclic path-based transfers in Ethereum. Our techniques may apply to other cryptocurrency blockchains with appropriate modifications adapted to the nature of the crypto-currency under investigation.

Open access
2 source records
cs.CR
cs.SI
Blockchain Technology Applications and Security
Original source
Aug 21, 2021·Machine Learning, IOT and Blockchain Technologies & Trends
9 cites
Identifying Ransomware Actors in the Bitcoin Network

Siddhartha R. Dalal, Zihe Wang, Siddhanth Sabharwal

Due to the pseudo-anonymity of the Bitcoin network, users can hide behind their bitcoin addresses that can be generated in unlimited quantity, on the fly, without any formal links between them. Thus, it is being used for payment transfer by the actors involved in ransomware and other illegal activities. The other activity we consider is related to gambling since gambling is often used for transferring illegal funds. The question addressed here is that given temporally limited graphs of Bitcoin transactions, to what extent can one identify common patterns associated with these fraudulent activities and apply them to find other ransomware actors. The problem is rather complex, given that thousands of addresses can belong to the same actor without any obvious links between them and any common pattern of behavior. The main contribution of this paper is to introduce and apply new algorithms for local clustering and supervised graph machine learning for identifying malicious actors. We show that very local subgraphs of the known such actors are sufficient to differentiate between ransomware, random and gambling actors with 85% prediction accuracy on the test data set.

Open access
4 source records
Cybercrime and Law Enforcement Studies
Blockchain Technology Applications and Security
Crime, Illicit Activities, and Governance
Original source
Aug 21, 2021·Sustainability
63 cites
A Traceable Online Insurance Claims System Based on Blockchain and Smart Contract Technology

Chin‐Ling Chen, Yong‐Yuan Deng, Woei-Jiunn Tsaur, Chun‐Ta Li · 6 authors

In the current medical insurance claims process, there are problems of low efficiency and complex services. When a patient applies for medical insurance claims, he/she must go to the hospital to apply for a diagnosis certificate and receipt and then send the relevant application documents to the insurance company. The patient will not receive compensation until the company completes the verification with the patient’s hospital. However, we can improve the current dilemma through blockchain technology. Blockchain technology can effectively open up the information channels of the insurance industry and medical institutions, promote industry integration, and enhance the ability of insurance companies to obtain information. In this research, we used blockchain and smart contract technology to make the following contributions to the development of Internet insurance. First, blockchain and smart contract technology can effectively solve the problem of online underwriting. Second, it is conducive to improving supervision. Third, it is conducive to solving risk control problems. Fourth, it is conducive to effective anti-money laundering. The proposed scheme fulfills the following security requirements: mutual authentication of identities, non-repudiation between each of two roles, and other major blockchain-based security requirements. In the event of a dispute, we also proposed an arbitration mechanism to divide responsibilities.

Open access
2 source records
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Original source
Aug 20, 2021·arXiv (Cornell University)
3 cites
Data-driven Smart Ponzi Scheme Detection

Yuzhi Liang, Weijing Wu, Kai Lei, Feiyang Wang

A smart Ponzi scheme is a new form of economic crime that uses Ethereum smart contract account and cryptocurrency to implement Ponzi scheme. The smart Ponzi scheme has harmed the interests of many investors, but researches on smart Ponzi scheme detection is still very limited. The existing smart Ponzi scheme detection methods have the problems of requiring many human resources in feature engineering and poor model portability. To solve these problems, we propose a data-driven smart Ponzi scheme detection system in this paper. The system uses dynamic graph embedding technology to automatically learn the representation of an account based on multi-source and multi-modal data related to account transactions. Compared with traditional methods, the proposed system requires very limited human-computer interaction. To the best of our knowledge, this is the first work to implement smart Ponzi scheme detection through dynamic graph embedding. Experimental results show that this method is significantly better than the existing smart Ponzi scheme detection methods.

Open access
2 source records
cs.LG
cs.AI
cs.CR
Original source
Aug 10, 2021·Security and Communication Networks
57 cites
A Novel Machine Learning-Based Analysis Model for Smart Contract Vulnerability

Yingjie Xu, Gengran Hu, Lin You, Chengtang Cao

In recent years, a lot of vulnerabilities of smart contracts have been found. Hackers used these vulnerabilities to attack the corresponding contracts developed in the blockchain system such as Ethereum, and it has caused lots of economic losses. Therefore, it is very important to find out the potential problems of the smart contracts and develop more secure smart contracts. As blockchain security events have raised more important issues, more and more smart contract security analysis methods have been developed. Most of these methods are based on traditional static analysis or dynamic analysis methods. There are only a few methods that use emerging technologies, such as machine learning. Some models that use machine learning to detect smart contract vulnerabilities cost much time in extracting features manually. In this paper, we introduce a novel machine learning-based analysis model by introducing the shared child nodes for smart contract vulnerabilities. We build the Abstract-Syntax-Tree (AST) for smart contracts with some vulnerabilities from two data sets including SmartBugs and SolidiFI-benchmark. Then, we build the Abstract-Syntax-Tree (AST) of the labeled smart contract for data sets named Smartbugs-wilds. Next, we get the shared child nodes from both of the ASTs to obtain the structural similarity, and then, we construct a feature vector composed of the values that measure structural similarity automatically to build our machine learning model. Finally, we get a KNN model that can predict eight types of vulnerabilities including Re-entrancy, Arithmetic, Access Control, Denial of Service, Unchecked Low Level Calls, Bad Randomness, Front Running, and Denial of Service. The accuracy, recall, and precision of our KNN model are all higher than 90%. In addition, compared with some other analysis tools including Oyente and SmartCheck, our model has higher accuracy. In addition, we spent less time for training .

Open access
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Spam and Phishing Detection
Original source
Jul 24, 2021·Electronics
24 cites
Blockchain-Enabled Transaction Scanning Method for Money Laundering Detection

Ammar Oad, Abdul Razaque, Askar Tolemyssov, Munif Alotaibi · 6 authors

Currently, life cannot be imagined without the use of bank cards for purchases or money transfers; however, their use provides new opportunities for money launderers and terrorist organizations. This paper proposes a blockchain-enabled transaction scanning (BTS) method for the detection of anomalous actions. The BTS method specifies the rules for outlier detection and rapid movements of funds, which restrict anomalous actions in transactions. The specified rules determine the specific patterns of malicious activities in the transactions. Furthermore, the rules of the BTS method scan the transaction history and provide a list of entities that receive money suspiciously. Finally, the blockchain-enabled process is used to restrict money laundering. To validate the performance of the proposed BTS method, a Spring Boot application is built based on the Java programming language. Based on experimental results, the proposed BTS method automates the process of investigating transactions and restricts money laundering incidents.

Open access
Crime, Illicit Activities, and Governance
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Original source
Jul 14, 2021·arXiv (Cornell University)
0 cites
Preventing Spoliation of Evidence with Blockchain: A Perspective from\n South Asia

Ali Shahaab, Chaminda Hewage, Imtiaz Ali Khan

Evidence destruction and tempering is a time-tested tactic to protect the\npowerful perpetrators, criminals, and corrupt officials. Countries where law\nenforcing institutions and judicial system can be comprised, and evidence\ndestroyed or tampered, ordinary citizens feel disengaged with the investigation\nor prosecution process, and in some instances, intimidated due to the\nvulnerability to exposure and retribution. Using Distributed Ledger\nTechnologies (DLT), such as blockchain, as the underpinning technology, here we\npropose a conceptual model - 'EvidenceChain', through which citizens can\nanonymously upload digital evidence, having assurance that the integrity of the\nevidence will be preserved in an immutable and indestructible manner. Person\nuploading the evidence can anonymously share it with investigating authorities\nor openly with public, if coerced by the perpetrators or authorities.\nTransferring the ownership of evidence from authority to ordinary citizen, and\ncustodianship of evidence from susceptible centralized repository to an\nimmutable and indestructible distributed repository, can cause a paradigm shift\nof power that not only can minimize spoliation of evidence but human rights\nabuse too. Here the conceptual model was theoretically tested against some\nhigh-profile spoliation of evidence cases from four South Asian developing\ncountries that often rank high in global corruption index and low in human\nrights index.\n

Open access
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Crime, Illicit Activities, and Governance
Original source
Jul 1, 2021·International Journal of Foreign Trade and International Business
1 cites
Cryptocurrency in India: An assessment of the prospects and challenges

Neha Aniruddha Gosavi, Sunil D Joshi

To execute transactional operations in the financial trading industry, cryptocurrencies like as bitcoin make use of decentralization, traceability, and anonymity properties. These digital currencies, which are based on new blockchain technology, are serving as the foundation for some of the world's biggest unregulated marketplaces. A variety of regulatory difficulties arise as a result, including the illegal acquisition of narcotics and weapons, money laundering, and the support of terrorist operations, among others. This chapter examines a variety of legal and ethical implications, as well as their consequences and potential solutions to the fundamental problems that policymakers and regulators are today confronted with on a daily basis. The authors present the findings of an analysis of 30 recently published peer-reviewed scientific publications, and they propose a number of mechanisms that can aid in the detection and prevention of illegal activities, which currently account for a significant portion of cryptocurrency trading at this time. These researchers propose methodologies and apps that may be used to detect dark markets in the future, should the need arise.

Open access
Blockchain Technology Applications and Security
Crime, Illicit Activities, and Governance
Cybercrime and Law Enforcement Studies
Original source
Jun 28, 2021·Jurnal Ilmiah Teunuleh
2 cites
ANALYSIS OF BITCOIN'S IMPACT ON USERS AND THEIR IMPACT ON THE VALUE OF THE RUPIAH AND THE ROLE OF THE GOVERNMENT IN THE PRESENCE OF BITCOIN

Cut Nova Rianda

Bitcoin has a peer to peer system that is in contrast to financial system by eliminating third parties in transactions. Countries in the world have different positions on Bitcoin, there are countries that are accept, reject or not both, so that understanding is needed more in depth to the factors that determine the position of the country above Bitcoin. This study aims to look for the influence of the development of Bitcoin, the performance of fiat money and the governance systems of countries in the world in determining its position on the legality of Bitcoin. Theories and concepts used inside this research is the international financial system and the state management system; with a quantitative approach as well as multinomial logistic regression analysis supported with secondary data. The results of the analysis in this study revealed that of the nine factors affecting the country's top position Bitcoin; it's just that the significance is different. Influencing Factors significant in determining the country's position on Bitcoin are factors political and economic factors have no significant effect. So it can be said that state acceptance of Bitcoin tends to be caused political reasons compared to the economy, even though Bitcoin itself is located on economic aspects. If Bitcoin acceptance is legalized, then the countries in the world still must accompany the role of government because Bitcoin is judged not to have clear rules and potentially detrimental to others.

Open access
Blockchain Technology Applications and Security
FinTech, Crowdfunding, Digital Finance
Cybercrime and Law Enforcement Studies
Original source
Jun 25, 2021·Lecture notes in computer science
1 cites
Vulnerability and Transaction behavior based detection of Malicious Smart Contracts

Rachit Agarwal, Tanmay Thapliyal, Sandeep K. Shukla

Smart Contracts (SCs) in Ethereum can automate tasks and provide different functionalities to a user. Such automation is enabled by the `Turing-complete' nature of the programming language (Solidity) in which SCs are written. This also opens up different vulnerabilities and bugs in SCs that malicious actors exploit to carry out malicious or illegal activities on the cryptocurrency platform. In this work, we study the correlation between malicious activities and the vulnerabilities present in SCs and find that some malicious activities are correlated with certain types of vulnerabilities. We then develop and study the feasibility of a scoring mechanism that corresponds to the severity of the vulnerabilities present in SCs to determine if it is a relevant feature to identify suspicious SCs. We analyze the utility of severity score towards detection of suspicious SCs using unsupervised machine learning (ML) algorithms across different temporal granularities and identify behavioral changes. In our experiments with on-chain SCs, we were able to find a total of 1094 benign SCs across different granularities which behave similar to malicious SCs, with the inclusion of the smart contract vulnerability scores in the feature set.

Open access
2 source records
cs.CR
cs.DC
cs.LG
Original source
Jun 25, 2021·Blockchain Research and Applications
12 cites
Identifying malicious accounts in Blockchains using Domain Names and associated temporal properties

Rohit Kumar Sachan, Rachit Agarwal, Sandeep K. Shukla

The rise in the adoption of blockchain technology has led to increased illegal activities by cybercriminals costing billions of dollars. Many machine learning algorithms are applied to detect such illegal behavior. These algorithms are often trained on the transaction behavior and, in some cases, trained on the vulnerabilities that exist in the system. In our approach, we study the feasibility of using the Domain Name (DN) associated with the account in the blockchain and identify whether an account should be tagged malicious or not. Here, we leverage the temporal aspects attached to the DN. Our approach achieves 89.53% balanced-accuracy in detecting malicious blockchain DNs. While our results identify 73769 blockchain DNs that show malicious behavior at least once, out of these, 34171 blockchain DNs show persistent malicious behavior, resulting in 2479 malicious blockchain DNs over time. Nonetheless, none of these identified malicious DNs were reported in new officially tagged malicious blockchain DNs.

Open access
2 source records
cs.CR
cs.LG
Spam and Phishing Detection
Original source
Jun 25, 2021·arXiv (Cornell University)
1 cites
Vulnerability and Transaction behavior based detection of Malicious\n Smart Contracts

Rachit Agarwal, Tanmay Thapliyal, Sandeep K. Shukla

Smart Contracts (SCs) in Ethereum can automate tasks and provide different\nfunctionalities to a user. Such automation is enabled by the `Turing-complete'\nnature of the programming language (Solidity) in which SCs are written. This\nalso opens up different vulnerabilities and bugs in SCs that malicious actors\nexploit to carry out malicious or illegal activities on the cryptocurrency\nplatform. In this work, we study the correlation between malicious activities\nand the vulnerabilities present in SCs and find that some malicious activities\nare correlated with certain types of vulnerabilities. We then develop and study\nthe feasibility of a scoring mechanism that corresponds to the severity of the\nvulnerabilities present in SCs to determine if it is a relevant feature to\nidentify suspicious SCs. We analyze the utility of severity score towards\ndetection of suspicious SCs using unsupervised machine learning (ML) algorithms\nacross different temporal granularities and identify behavioral changes. In our\nexperiments with on-chain SCs, we were able to find a total of 1094 benign SCs\nacross different granularities which behave similar to malicious SCs, with the\ninclusion of the smart contract vulnerability scores in the feature set.\n

Open access
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Spam and Phishing Detection
Original source
Jun 20, 2021·arXiv (Cornell University)
6 cites
Flash Crash for Cash: Cyber Threats in Decentralized Finance

Kris Oosthoek

Decentralized Finance (DeFi) took shape in 2020. An unprecedented amount of over 14 billion USD moved into DeFi projects offering trading, loans and insurance. But its growth has also drawn the attention of malicious actors. Many projects were exploited as quickly as they launched and millions of USD were lost. While many developers understand integer overflows and reentrancy attacks, security threats to the DeFi ecosystem are more complex and still poorly understood. In this paper we provide the first overview of in-the-wild DeFi security incidents. We observe that many of these exploits are market attacks, weaponizing weakly implemented business logic in one protocol with credit provided by another to inflate appropriations. Rather than misusing individual protocols, attackers increasingly use DeFi's strength of permissionless composability against itself. By providing the first holistic analysis of real-world security incidents within the nascent financial ecosystem DeFi is, we hope to inform threat modeling in decentralized cryptoeconomic initiatives in the years ahead.

Open access
2 source records
Blockchain Technology Applications and Security
Crime, Illicit Activities, and Governance
Cybercrime and Law Enforcement Studies
Original source
Jun 18, 2021·Evaluation and Assessment in Software Engineering
31 cites
HFContractFuzzer: Fuzzing Hyperledger Fabric Smart Contracts for Vulnerability Detection

Mengjie Ding, Peiru Li, Shanshan Li, He Zhang

With its unique advantages such as decentralization and immutability, blockchain technology has been widely used in various fields in recent years. The smart contract running on the blockchain is also playing an increasingly important role in decentralized application scenarios. Therefore, the automatic detection of security vulnerabilities in smart contracts has become an urgent problem in the application of blockchain technology. Hyperledger Fabric is a smart contract platform based on enterprise-level licensed distributed ledger technology. However, the research on the vulnerability detection technology of Hyperledger Fabric smart contracts is still in its infancy. In this paper, we propose HFContractFuzzer, a method based on Fuzzing technology to detect Hyperledger Fabric smart contracts, which combines a Fuzzing tool for golang named go-fuzz and smart contracts written by golang. We use HFContractFuzzer to detect vulnerabilities in five contracts from typical sources and discover that four of them have security vulnerabilities, proving the effectiveness of the proposed method.

Open access
3 source records
Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
Cybercrime and Law Enforcement Studies
Original source
Jun 16, 2021·Axioms. 2022; 11(1):27
6 cites
Multi-Layered Blockchain Governance Game

Song-Kyoo Kim

The research designs a new integrated system for the security enhancement of a decentralized network by preventing damages from attackers, particularly for the 51 percent attack. The concept of multiple layered design based on Blockchain Governance Games frameworks could handle multiple number of networks analytically. The Multi-Layered Blockchain Governance Game is an innovative analytical model to find the best strategies for executing a safety operation to protect whole multiple layered network systems from attackers. This research fully analyzes a complex network with the compact mathematical forms and theoretically tractable results for predicting the moment of a safety operation execution are fully obtained. Additionally, simulation results are demonstrated to obtain the optimal values of configuring parameters of a blockchain-based security network. The Matlab codes for the simulations are publicly available to help those whom are constructing an enhanced decentralized security network architecture through this proposed integrated theoretical framework.

Open access
2 source records
cs.CR
cs.NI
math.PR
Original source
Jun 16, 2021·Applied Sciences
128 cites
Security of Blockchain-Based Supply Chain Management Systems: Challenges and Opportunities

Sana Al-Farsi, M. Mazhar Rathore, Spiros Bakiras

Blockchain is a revolutionary technology that is being used in many applications, including supply chain management. Although, the primary motive of using a blockchain for supply chain management is to reduce the overall production cost while providing the comprehensive security to the system. However, current blockchain-based supply-chain management (BC-SCM) systems still hold the possibility of cyber attacks. Therefore, the goal of this study is to investigate practical threats and vulnerabilities in the design of BC-SCM systems. As a starting point, we first establish key requirements for the reliability and security of supply chain management systems, i.e., transparency, privacy and traceability, and then discern a threat model that includes two distinctive but practical threats including computational (i.e., the ones that threaten the functionality of the application) and communication (i.e., the ones that threaten information exchange among interconnected services of the application). For investigation, we follow a unique approach based on the hypothesis that reliability is pre-requisite of security and identify the threats considering (i) design of smart contracts and associated supply chain management applications, (ii) underlying blockchain execution environment and (iii) trust between all interconnected supply management services. Moreover, we consider both academic and industry solutions to identify the threats. We identify several challenges that hinder to establish reliability and security of the BC-SCM systems. Importantly, we also highlight research gaps that can help to establish desired security of the BC-SCM. To the best of our knowledge, this paper is the first effort that identifies practical threats to blockchain-based supply chain management systems and provides their counter measures. Finally, this work establishes foundation for future investigation towards practical security of BC-SCM system.

Open access
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Original source
May 31, 2021·2022 IEEE International Conference on Software Analysis, Evolution and Reengineering (SANER)
21 cites
A Bytecode-based Approach for Smart Contract Classification

Chaochen Shi, Yong Xiang, Jiangshan Yu, Longxiang Gao · 6 authors

With the development of blockchain technologies, the number of smart contracts deployed on blockchain platforms is growing exponentially, which makes it difficult for users to find desired services by manual screening. The automatic classification of smart contracts can provide blockchain users with keyword-based contract searching and helps to manage smart contracts effectively. Current research on smart contract classification focuses on Natural Language Processing (NLP) solutions which are based on contract source code. However, more than 94% of smart contracts are not open-source, so the application scenarios of NLP methods are very limited. Meanwhile, NLP models are vulnerable to adversarial attacks. This paper proposes a classification model based on features from contract bytecode instead of source code to solve these problems. We also use feature selection and ensemble learning to optimize the model. Our experimental studies on over 11K real-world Ethereum smart contracts show that our model can classify smart contracts without source code and has better performance than baseline models. Our model also has good resistance to adversarial attacks compared with NLP-based models. In addition, our analysis reveals that account features used in many smart contract classification models have little effect on classification and can be excluded.

Open access
3 source records
Blockchain Technology Applications and Security
Imbalanced Data Classification Techniques
Cybercrime and Law Enforcement Studies
Original source
May 16, 2021·ACM Transactions on Privacy and Security
5 cites
Is Bitcoin Future as Secure as We Think? Analysis of Bitcoin Vulnerability to Bribery Attacks Launched through Large Transactions

Ghader Ebrahimpour, Mohammad Sayad Haghighi

Bitcoin uses blockchain technology to maintain transactions order and provides probabilistic guarantees to prevent double-spending, assuming that an attacker’s computational power does not exceed 50% of the network power. In this article, we design a novel bribery attack and show that this guarantee can be hugely undermined. Miners are assumed to be rational in this setup, and they are given incentives that are dynamically calculated. In this attack, the adversary misuses the Bitcoin protocol to bribe miners and maximize their gained advantage. We will reformulate the bribery attack to propose a general mathematical foundation upon which we build multiple strategies. We show that, unlike Whale Attack, these strategies are practical, especially in the future when halvings lower the mining rewards. In the so-called “guaranteed variable-rate bribing with commitment” strategy, through optimization by Differential Evolution (DE), we show how double-spending is possible in the Bitcoin ecosystem for any transaction whose value is above 218.9BTC, and this comes with 100% success rate. A slight reduction in the success probability, e.g., by 10%, brings the threshold down to 165BTC. If the rationality assumption holds, then this shows how vulnerable blockchain-based systems like Bitcoin are. We suggest a soft fork on Bitcoin to fix this issue at the end.

Open access
2 source records
Blockchain Technology Applications and Security
Crime, Illicit Activities, and Governance
Cybercrime and Law Enforcement Studies
Original source
Apr 30, 2021·arXiv (Cornell University)
30 cites
DeFiRanger: Detecting Price Manipulation Attacks on DeFi Applications

Siwei Wu, Dabao Wang, Jianting He, Yajin Zhou · 8 authors

The rapid growth of Decentralized Finance (DeFi) boosts the Ethereum ecosystem. At the same time, attacks towards DeFi applications (apps) are increasing. However, to the best of our knowledge, existing smart contract vulnerability detection tools cannot be directly used to detect DeFi attacks. That's because they lack the capability to recover and understand high-level DeFi semantics, e.g., a user trades a token pair X and Y in a Decentralized EXchange (DEX). In this work, we focus on the detection of two types of new attacks on DeFi apps, including direct and indirect price manipulation attacks. The former one means that an attacker directly manipulates the token price in DEX by performing an unwanted trade in the same DEX by attacking the vulnerable DeFi app. The latter one means that an attacker indirectly manipulates the token price of the vulnerable DeFi app (e.g., a lending app). To this end, we propose a platform-independent way to recover high-level DeFi semantics by first constructing the cash flow tree from raw Ethereum transactions and then lifting the low-level semantics to high-level ones, including token trade, liquidity mining, and liquidity cancel. Finally, we detect price manipulation attacks using the patterns expressed with the recovered DeFi semantics. We have implemented a prototype named \tool{} and applied it to more than 350 million transactions. It successfully detected 432 real-world attacks in the wild. We confirm that they belong to four known security incidents and five zero-day ones. We reported our findings. Two CVEs have been assigned. We further performed an attack analysis to reveal the root cause of the vulnerability, the attack footprint, and the impact of the attack. Our work urges the need to secure the DeFi ecosystem.

Open access
2 source records
cs.CR
Blockchain Technology Applications and Security
Crime, Illicit Activities, and Governance
Original source
Mar 31, 2021·Athens Journal of Law
11 cites
Money Laundering using Cryptocurrency: The Case of Bitcoin!

Gaspare Jucan Sicignano

The bitcoin, one of the most discussed topics in recent years, is a virtual currency with enormous potential and can be used almost immediately with no intervention from financial institutions. It has spread rapidly over the last few years, and all financial and governmental institutions have warned of the risk of its use for money laundering. The paper focuses on this aspect in order to understand if any purchases of bitcoins, using illicit money, can come under the anti-money laundering criminal law. Keywords: Bitcoin; Money laundering; Italian law; Cryptocurrency.

Open access
Crime, Illicit Activities, and Governance
Cybercrime and Law Enforcement Studies
Blockchain Technology Applications and Security
Original source
Mar 26, 2021·arXiv
0 cites
Preventing Spoliation of Evidence with Blockchain: A Perspective from South Asia

Ali Shahaab, Chaminda Hewage, Imtiaz Khan

Evidence destruction and tempering is a time-tested tactic to protect the powerful perpetrators, criminals, and corrupt officials. Countries where law enforcing institutions and judicial system can be comprised, and evidence destroyed or tampered, ordinary citizens feel disengaged with the investigation or prosecution process, and in some instances, intimidated due to the vulnerability to exposure and retribution. Using Distributed Ledger Technologies (DLT), such as blockchain, as the underpinning technology, here we propose a conceptual model - 'EvidenceChain', through which citizens can anonymously upload digital evidence, having assurance that the integrity of the evidence will be preserved in an immutable and indestructible manner. Person uploading the evidence can anonymously share it with investigating authorities or openly with public, if coerced by the perpetrators or authorities. Transferring the ownership of evidence from authority to ordinary citizen, and custodianship of evidence from susceptible centralized repository to an immutable and indestructible distributed repository, can cause a paradigm shift of power that not only can minimize spoliation of evidence but human rights abuse too. Here the conceptual model was theoretically tested against some high-profile spoliation of evidence cases from four South Asian developing countries that often rank high in global corruption index and low in human rights index.

Open access
2 source records
cs.CY
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Original source