Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

873 papersLast indexed Aug 31, 2026
Search papers

Paper index

873 results · page 27 of 37

Clear filters
Mar 23, 2021·Computer Communications
43 cites
A security framework for Ethereum smart contracts

Antonio López Vivar, Ana Lucila Sandoval Orozco, Luis Javier García Villalba

The use of blockchain and smart contracts have not stopped growing in recent years. Like all software that begins to expand its use, it is also beginning to be targeted by hackers who will try to exploit vulnerabilities in both the underlying technology and the smart contract code itself. While many tools already exist for analyzing vulnerabilities in smart contracts, the heterogeneity and variety of approaches and differences in providing the analysis data makes the learning curve for the smart contract developer steep. In this article the authors present ESAF (Ethereum Security Analysis Framework), a framework for analysis of smart contracts that aims to unify and facilitate the task of analyzing smart contract vulnerabilities which can be used as a persistent security monitoring tool for a set of target contracts as well as a classic vulnerability analysis tool among other uses.

Open access
2 source records
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Advanced Malware Detection Techniques
Original source
Mar 19, 2021·Law and Safety
9 cites
Certain Aspects of the Analysis of Cryptocurrency Transactions during the Prevention and Investigation of Crimes

Віталій Носов, І. А. Манжай

The analysis of separate tools for the visualization of movement of cryptocurrency values, and also identification of users who carried out the corresponding transactions has been carried out. The advantages and disadvantages of cryptocurrency from the point of view of offenders and law enforcement agencies have been studied. The main directions of using cryptocurrency in a criminal environment have been determined. The current state and perspectives of normative and legal regulation of cryptocurrency in Ukraine have been analyzed. Theoretical principles of cryptocurrency functioning have been studied. The basic concepts used in this area have been revealed. The properties of cryptocurrency have been described. The mechanism of its issuance of guaranteeing pseudo-anonymity while working with cryptocurrency has been outlined. Some features of blockchain technology and formation of cryptocurrency addresses have been revealed. It has been noted that one of the first and most well-known cryptocurrency is bitcoin. The format of bitcoin address presentation has been described. It has been emphasized that bitcoin wallet software can operate with any number of addresses or each address can be served by a separate wallet. The technology of mixing transactions and the method of increasing the anonymity of CoinJoin have been described. The authors have revealed the possibilities of separate services intended for the analysis of cryptocurrency transactions (Maltego, Bitconeview, Bitiodine, OpReturnTool, Blockchain.info, Anyblockanalytics.com, Chainalysis, Elliptic, Ciphertrace, Blockchain Inspector). The process of risk assessment and construction of visual chains of cryptocurrency transactions has been demonstrated on the example of the “Crystal Expert” service. Different types of bitcoin addresses’ holders and risk levels have been described. The main and additional investigation tools used on the “Crystal Expert” platform have been revealed. Based on the conducted analysis, the authors have defined the main tasks for law enforcement agencies at the current stage of development of cryptocurrency. The basic requirements for tools designed for cryptocurrency analysis have been outlined. The authors have suggested some measures of law enforcement agencies’ respond to threats related to cryptocurrency.

Open access
Ukrainian Legal and Forensic Studies
Digital Transformation in Financial Services
Cybercrime and Law Enforcement Studies
Original source
Mar 18, 2021·Contributions to finance and accounting
7 cites
Cyber-Attacks, Cryptocurrencies and Cyber Security

Guglielmo Maria Caporale, Woo-Young Kang, Fabio Spagnolo, Nicola Spagnolo

This paper provides comprehensive evidence on the effects of cyber-attacks (cyber-crime, cyber espionage, cyber warfare and hacktivism) and cyber security on the risk-adjusted returns, realised volatilities and trading volumes of the three main cryptocurrencies (Bitcoin, Ethereum and Litecoin).We find that stronger cyber security is generally effective in increasing the riskadjusted returns of cryptocurrencies and trading activity even in the presence of cyber-attacks.Hacktivism appears to be the most significant threat to cryptocurrency investors.Further, cyberattackers hitting the cryptocurrency exchanges are most likely to attack other sectors (government, industry and finance) as well.In addition, in the case of the US they target the government and industry sectors in preference to the cryptocurrency exchanges given the corresponding potential benefits and costs.In all cases appropriate strategies should be designed to enhance cyber security.

Open access
2 source records
Blockchain Technology Applications and Security
Crime, Illicit Activities, and Governance
Cybercrime and Law Enforcement Studies
Original source
Mar 17, 2021·SSRN Electronic Journal
29 cites
An Implementation of Blockchain Technology in Forensic Evidence Management

Revathy Sathyaprakasan, Pratheeksha Govindan, Samina Alvi, Lipsa Sadath · 6 authors

Evidence management is crucial in the field of forensic science. Evidences obtained from a crime scene are important in solving the case and delivering justice to the parties involved. Hence, protecting these evidences from any form of alteration is of utmost important. Chain of Custody is the process which maintains the integrity of evidence. Inability to maintain the chain of custody will make the evidence inadmissible in court, eventually leading to the case dismissal. Digitalization of forensic evidence management system is a need of time as it is an environment friendly model. Blockchains are digitally distributed ledgers of transactions signed cryptographically in chronological order that are sorted into blocks and is completely open to anyone in the blockchain network. Hyperledger Fabric is a consortium blockchain framework created by the Linux foundation and is mainly used for enterprise use. Based on the concept of Hyperledger Fabric, present study aimed to create a framework and further propose an algorithm to implement Blockchain Technology to digitalize forensic evidence management system and maintain Chain of Custody.

Open access
4 source records
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Digital and Cyber Forensics
Original source
Mar 1, 2021·Journal of Physics Conference Series
45 cites
Attention-based Machine Learning Model for Smart Contract Vulnerability Detection

Yuhang Sun, Lize Gu

Abstract Ethereum attracts extensive attention due to its distinctive function of smart contract and decentralized applications (Dapps). Since the number of contracts on blockchain has increased vigorously, various security vulnerabilities come up. Researchers rely on static symbolic analysis method at first, and it seems to perform well in the accuracy of vulnerability detection. However, this method requires manual analysis in advance and it needs to traverse all the possible execution paths to find out the vulnerable ones. The deeper the path goes, the more time it costs to detect the contracts. This paper proposes an approach to detect smart contracts vulnerability on blockchain by using machine learning(ML) methods. This approach aims to build a general benchmark for new vulnerability detection in order to reduce the demand of expert manpower. Moreover, the high-speed-performance ML algorithm makes quick detection comes true. As long as we adjust the threshold of the model, it can work as a fast prefilter for the traditional symbolic analysis tools in further improvement of accuracy.

Open access
Blockchain Technology Applications and Security
Imbalanced Data Classification Techniques
Cybercrime and Law Enforcement Studies
Original source
Feb 22, 2021·ETIKONOMI
95 cites
Cryptocurrencies in Modern Finance: A Literature Review

Abderahman Rejeb, Karim Rejeb, John G. Keogh

The focus on cryptocurrencies in the finance and banking sectors is gaining momentum. In this paper, we investigate the role of cryptocurrencies in modern finance. We apply a narrative literature review method to synthesize prior research and draw insights into the opportunities and challenges of leveraging cryptocurrencies. The results indicate that cryptocurrencies offer businesses and individuals’ lower transaction costs, higher efficiencies, increased security and privacy, meaningful diversification benefits, alternative financing solutions, and financial inclusion.Challenges exist related to the integration of cryptocurrencies in modern finance. These include the lack of regulatory standards, the risk of criminal activity, high energy and environmental costs, regulatory bans and usage restrictions, security and privacy concerns, and the high volatility of cryptocurrencies.The current review is useful for scholars and managers, including those seeking to have a more balanced understanding of these emerging financial instruments.JEL Classification: E42, F30, F65, G21, G23How to Cite:Rejeb, A., Rejeb, K., & Keogh, J. G. (2021). Cryptocurrencies in Modern Finance: a Literature Review. Etikonomi, 20(1), 93 – 118. https://doi.org/10.15408/etk.v20i1.16911.

Open access
Blockchain Technology Applications and Security
FinTech, Crowdfunding, Digital Finance
Cybercrime and Law Enforcement Studies
Original source
Feb 17, 2021·Frontiers in Computer Science
45 cites
A Mechanism to Detect and Prevent Ethereum Blockchain Smart Contract Reentrancy Attacks

Ayman Alkhalifah, Alex Ng, Paul Watters, A. S. M. Kayes

In Ethereum blockchain, smart contracts are immutable, public, and distributed. However, they are subject to many vulnerabilities stemming from coding errors made by developers. Seven cybersecurity incidents occurred in Ethereum smart contracts between 2016 and 2018, which led to financial losses estimated to be over US$ 289 million. Reentrancy vulnerability was the cause of two of these incidents, and the impacts went far beyond financial loss. Several reentrancy countermeasures are available, which are based on predefined patterns that are used to prevent vulnerability exploitation before the deployment of a smart contract; however, several limitations have been identified in these countermeasures. Motivated by all these issues, the objective of this article is to help developers improve the cybersecurity of smart contracts by proposing a solution that calculates the difference between the contract balance and the total balance of all participants in a smart contract before and after any operation in a transaction that changes its state. Proof-of-concept implementations show that this solution can provide a detection and prevention mechanism against reentrancy attacks during the execution of any smart contract.

Open access
4 source records
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Cloud Data Security Solutions
Original source
Feb 15, 2021·Evaluation and Assessment in Software Engineering
2 cites
Dynamic Vulnerability Detection on Smart Contracts Using Machine Learning

Mojtaba Eshghie, Cyrille Artho, Dilian Gurov

In this work we propose Dynamit, a monitoring framework to detect reentrancy vulnerabilities in Ethereum smart contracts. The novelty of our framework is that it relies only on transaction metadata and balance data from the blockchain system; our approach requires no domain knowledge, code instrumentation, or special execution environment. Dynamit extracts features from transaction data and uses a machine learning model to classify transactions as benign or harmful. Therefore, not only can we find the contracts that are vulnerable to reentrancy attacks, but we also get an execution trace that reproduces the attack. Using a random forest classifier, our model achieved more than 90 percent accuracy on 105 transactions, showing the potential of our technique.

Open access
2 source records
cs.CR
cs.SE
Blockchain Technology Applications and Security
Original source
Feb 1, 2021·ENLIGHTEN (Jurnal Bimbingan dan Konseling Islam)
0 cites
Bitcoin burglaries and the Theft Act 1968

Alex Taylor, Mícheál Ó Floinn

Discusses the growing trend for criminals to burgle the homes of bitcoin holders and force them to disclose the password to their cryptocurrency. Reviews the operation of crypto asset systems, and considers, with reference to three hypothetical scenarios, how such "rubber hose" attacks might be prosecuted, including whether they constitute "property" offences for the purposes of theft and burglary convictions under the Theft Act 1968.

Open access
Cybercrime and Law Enforcement Studies
Original source
Jan 27, 2021·International Journal of Information Management Data Insights
61 cites
Cybersecurity Enhancement through Blockchain Training (CEBT) – A serious game approach

A.P. Mittal, Monika Gupta, Manmohan Chaturvedi, Shailesh R. Chansarkar · 5 authors

Blockchain technology is increasingly finding traction in diverse areas such as finance, supply-chain management, and cloud services because of its ability to provide robust cybersecurity inherent in its system of having decentralized data storage. The rising complexity in the architecture of popular blockchain platforms create barriers to correct adoption of the technology. It becomes imperative that pedagogical tools are inducted in the blockchain ecosystem to address this perceived or real impediments for the uptake of the technology. We propose one of the first such pedagogical tool for training in blockchain using an adversarial sandbox adaptive serious game approach for students and technology professionals. We further propose use of AI to enhance NPC interactivity based on player’s responses. We plan to evaluate this serious game on a subjective metrics that is based on a game experience questionnaire.

Open access
Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
Cybercrime and Law Enforcement Studies
Original source
Jan 16, 2021·Zenodo (CERN European Organization for Nuclear Research)
13 cites
A Study on Blockchain Technology as a Dominant Feature to Mitigate Reputational Risk for Indian Academic Institutions and Universities

Pradeep Kumar Rangi, P. S. Aithal

The paper-based certification is prone to manipulation and vulnerable to fraud. Instances of fraudulent degrees, manipulation of academic records, or compromised academic programs adversely impact and damage an academic institution's credibility. It also affects the Indian universities’ mission and prospects of the students graduating from such a university. What makes reputational risk a unique risk is that it may arise both from the university or institution's failure or the action outside the university. It is, therefore, essential to take an enterprise risk management approach to mitigate reputational risk. Robust credential verification and validation protocols are the most important protections against fake certifications. The legacy certificate verification solutions are highly centralized, i.e., utterly dependent on the issuing authority for certificates. Despite the University Grants Commission (UGC) taking strict measures against individuals, Indian universities, colleges, and associations, we do come across several acts of torts. Some of the technology-savvy institutions have moved to digital certificates and digital signatures. However, this has an inherent weakness, i.e., they still need to rely on a trusted third party. Blockchain technology has three foundational components, data structures based on cryptography that make it secure and tamperproof, consensus protocols that allow it to function truthfully and without any central authority or a third party smart contracts, which provide efficiency and business value transactions. These key features of blockchain, if implemented appropriately, effectively has the potential to mitigate the inherent reputational risk arising from fraudulent academic certificate matters. Niti Ayog is currently developing a blockchain-based proof of concepts to solve traditional educational qualifications related to identity misrepresentation and document forgery. The immutability attribute of the blockchain ensures that tampering and manipulation of the record are not attainable. This paper focuses on the reputational risk Indian universities and institution may face when its certifications are not easily verifiable. Therefore, it becomes easy targets for bad actors to exploit vulnerabilities by issuing counterfeit certificates. Secondary published data, including various scholarly journals, reports, industry publications, and website sources, are utilized to develop this case study. The paper also explores how blockchain technology with specific reference to the proof of concept SuperCert proposed by Niti Ayog for Indian academic institutions may provide effective preventive control to overcome such reputational risk using the ABCD analysis framework as a research case study.

Open access
Blockchain Technology Applications and Security
Imbalanced Data Classification Techniques
Cybercrime and Law Enforcement Studies
Original source
Jan 1, 2021·Colección Jornadas y congresos
1 cites
A review of Cybersecurity Threat Intelligence Knowledge Exchange based on blockchain

Raúl Riesco Granadino, Xavier Larriva-Novo, Víctor A. Villagrá

Although cyber threat intelligence (CTI) exchange is a theoretically useful technique for improving security of a society, the potential participants are often reluctant to share
\ntheir CTI and prefer to consume only, at least in voluntary based approaches. Such behavior destroys the idea of information exchange. On the other hand, governments are forcing specific entities and operators to report them specific incidents depending
\non their impact. Obligations and sanctions are usually discouraging participants to share information voluntarily. We propose a paradigm shift of cybersecurity information exchange by ntroducing a new way to encourage all participants involved, at
\nall levels, to share relevant information dynamically. Participants will have new and specific incentives to share, invest and consume threat intelligence and risk intelligence information depending on their different roles (producers, consumers, investors, donors and owner). Our proposal leverages from standards like Structured Threat Information Exchange (STIX™), W3C semantic web standards and from the Ethereum Blockchain to enable a workspace of knowledge related to behavioral threat intelligence patterning to characterize tactics, techniques and procedures (TTP) introducing new type of incentives.

Open access
Cybercrime and Law Enforcement Studies
Original source
Jan 1, 2021·˜The œInternational journal of networked and distributed computing
5 cites
Bountychain: Toward Decentralizing a Bug Bounty Program with Blockchain and IPFS

Alex Hoffman, Phillipe Austria, Chol Hyun Park, Yoohwan Kim

A C TBug Bounty Programs (BBPs) play an important role in providing and maintaining security in software applications.These programs allow testers to discover and resolve bugs before the general public is aware of them, preventing incidents of widespread abuse.However, they have shown problems such as organizations providing accountability of reporting bugs and nonrecognition of testers.In this paper, we discuss Bountychain, a decentralized application using Ethereum-based Smart Contracts (SCs) and the Interplanetary File System (IPFS), a distributed file storage system.Blockchain and SCs provide a safe, secure and transparent platform for a BBP.Testers can submit bug reports and organizations can accept or reject the defect via the SCs.Transactions on the blockchain serve as a persistent and transparent record of software bugs, while IPFS serves as a long-term storage system for bug details.Thus, Bountychain ensures organization accountability and allows testers to gain irrefutable recognition.

Open access
Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
Cybercrime and Law Enforcement Studies
Original source
Jan 1, 2021·Journal of Governance and Regulation
22 cites
Different types of government and governance in the blockchain

Jersain Zadamig Llamas Covarrubias, Irving Norehem Llamas Covarrubias

This research work, a study was carried out on blockchain technology and its types, as well as the creation of new models of government and governance from the scope of an organization, infrastructure and platform. Governance and commercial models were addressed, based on standardization of data and legal frameworks. On the other hand, it showed how operational governance causes consequences in business models, whether with transactions, multi-signature, forks, consensus mechanism, smart contracts, tokenization, online dispute resolution and decentralized application (World Economic Forum, 2020, pp. 97 196). It was discovered that at least in current business models, private blockchain networks are more useful than public networks because they have greater operational flexibility and data governance, without exempting that public networks must also have mechanisms of governance since sometimes a human consensus must be reached to make updates to protocols and technical rules (The Law Society, 2020, pp. 24-61). This paper shows the basic principles that must be observed about governance and regulation in the implementation of blockchain technologies in systems created by governments, corporations and/or organized civil societies.

Open access
Blockchain Technology Applications and Security
Ethics and Social Impacts of AI
Cybercrime and Law Enforcement Studies
Original source
Jan 1, 2021·UiTM Institutional Repositories (Universiti Teknologi MARA)
1 cites
Review on the Advantages and Disadvantages of Cryptocurrency Attacks

Najihah Rusli, Mohamad Fadli Zolkipli

The advantages and disadvantages of blockchain technology in cryptocurrency attacks will be explained in this article. Digital currency has been widely used around the world. The soaring value of digital currencies has also led to an increase in the use of cryptocurrency. Cryptocurrency is a form of payment that can be exchanged online for goods and services. The increasingly popular use of cryptocurrency around the world is causing criminals, and hackers are starting to attack cryptocurrency on an ongoing basis. With the advent of blockchain technology, it managed to save the digital currency system with the availability of a decentralized database. Each block has many transactions, and for new transactions will be recorded and added to a decentralized database with a cryptographic signature that does not change making it difficult for abuse and theft. The authors have examined the strengths and weaknesses of the blockchain in cryptocurrency attacks. As a result, the authors support that this blockchain technology can help deal with cryptocurrency attacks that occur.

Open access
2 source records
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Crime, Illicit Activities, and Governance
Original source
Jan 1, 2021·Interdisciplinary Journal of Information Knowledge and Management
11 cites
Establishing a Security Control Framework for Blockchain Technology

Maitha Al Ketbi, Khaled Shuaib, Ezedin Barka, Marton Gergely

Aim/Purpose: The aim of this paper is to propose a new information security controls framework for blockchain technology, which is currently absent from the National and International Information Security Standards. Background: Blockchain technology is a secure and relatively new technology of distributed digital ledgers, which is based on inter-linked blocks of transactions, providing great benefits such as decentralization, transparency, immutability, and automation. There is a rapid growth in the adoption of blockchain technology in different solutions and applications and within different industries throughout the world, such as finance, supply chain, digital identity, energy, healthcare, real estate, and the government sector. Methodology: Risk assessment and treatments were performed on five blockchain use cases to determine their associated risks with respect to security controls. Contribution: The significance of the proposed security controls is manifested in complementing the frameworks that were already established by the International and National Information Security Standards in order to keep pace with the emerging blockchain technology and prevent/reduce its associated information security risks. Findings: The analysis results showed that the proposed security controls herein can mitigate relevant information security risks in blockchain-based solutions and applications and, consequently, protect information and assets from unauthorized disclosure, modification, and destruction. Recommendations for Practitioners: The performed risk assessment on the blockchain use cases herein demonstrates that blockchain can involve security risks that require the establishment of certain measures in order to avoid them. As such, practitioners should not blindly assume that through the use of blockchain all security threats are mitigated. Recommendation for Researchers: The results from our study show that some security risks not covered by existing Standards can be mitigated and reduced when applying our proposed security controls. In addition, researchers should further justify the need for such additional controls and encourage the standardization bodies to incorporate them in their future editions. Impact on Society: Similar to any other emerging technology, blockchain has several drawbacks that, in turn, could have negative impacts on society (e.g., individuals, entities and/or countries). This is mainly due to the lack of a solid national and international standards for managing and mitigating risks associated with such technology. Future Research: The majority of the blockchain use cases in this study are publicly published papers. Therefore, one limitation of this study is the lack of technical details about these respective solutions, resulting in the inability to perform a comprehensive risk identification properly. Hence, this area will be expanded upon in our future work. In addition, covering other standardization bodies in the area of distributed ledger in blockchain technology would also prove fruitful, along with respective future design of relevant security architectures.

Open access
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Organizational and Employee Performance
Original source
Jan 1, 2021·Zbornik radova Pravnog fakulteta Nis
1 cites
Bitcoin and cryptocurrency clauses

Srđan Radulović

Nowadays, it is almost impossible to imagine an effective legal system that is not somehow inspired by nominalistic ideas. However, the principle of monetary nominalism is not necessary in correlation with other higher principles, such as the principle of fairness, for example. Thus, legislators build and implement corrective instruments in legal acts, most of the time allowing legal subjects to choose and adapt those instruments to best fit their economic interests. In that context, (foreign) currency clauses are probably the most frequently used instrument. Those norms, when implemented in contract, prevent the negative effects of domestic currency depreciation through the denomination of the amount of debt in foreign currency. Whether we regard them as currency or not, cryptocurrencies are increasingly becoming an important part of our digitalized economic world. So, unless the legislature strictly limits or abolishes the freedom of will (the principle of party autonomy) in contract law by banning cryptocurrencies, contracting parties can hedge against domestic currency depreciation by pegging the amount of debt to the exchange rate of one of thousands of existing cryptocurrencies. If parties choose to make such an agreement, it is most likely that they will peg the amount of debt to the Bitcoin exchange rate. If parties choose to make such an agreement, it is most likely that they will peg the amount of debt to the Bitcoin exchange rate. In this paper, the author analyzes (crypto)currency clauses nominated in Bitcoin and their effects on contract relations in the legal system of the Republic of Serbia. This research heavy relies on the advantages of the normative and the comparative method, and various techniques of the analytical method.

Open access
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Crime, Illicit Activities, and Governance
Original source
Jan 1, 2021·Communications in computer and information science
41 cites
Blockchain Phishing Scam Detection via Multi-channel Graph Classification

Dunjie Zhang, Jinyin Chen, Xiaosong Lu

With the popularity of blockchain technology, the financial security issues of blockchain transaction networks have become increasingly serious. Phishing scam detection methods will protect possible victims and build a healthier blockchain ecosystem. Usually, the existing works define phishing scam detection as a node classification task by learning the potential features of users through graph embedding methods such as random walk or graph neural network (GNN). However, these detection methods are suffered from high complexity due to the large scale of the blockchain transaction network, ignoring temporal information of the transaction. Addressing this problem, we defined the transaction pattern graphs for users and transformed the phishing scam detection into a graph classification task. To extract richer information from the input graph, we proposed a multi-channel graph classification model (MCGC) with multiple feature extraction channels for GNN. The transaction pattern graphs and MCGC are more able to detect potential phishing scammers by extracting the transaction pattern features of the target users. Extensive experiments on seven benchmark and Ethereum datasets demonstrate that the proposed MCGC can not only achieve state-of-the-art performance in the graph classification task but also achieve effective phishing scam detection based on the target users' transaction pattern graphs.

Open access
3 source records
cs.LG
Blockchain Technology Applications and Security
Spam and Phishing Detection
Original source
Jan 1, 2021·Lecture notes in computer science
6 cites
Rectifying Administrated ERC20 Tokens

Nikolay Ivanov, Hanqing Guo, Qiben Yan

The developers of Ethereum smart contracts often implement administrating patterns, such as censoring certain users, creating or destroying balances on demand, destroying smart contracts, or injecting arbitrary code. These routines turn an ERC20 token into an administrated token - the type of Ethereum smart contract that we scrutinize in this research. We discover that many smart contracts are administrated, and the owners of these tokens carry lesser social and legal responsibilities compared to the traditional centralized actors that those tokens intend to disrupt. This entails two major problems: a) the owners of the tokens have the ability to quickly steal all the funds and disappear from the market; and b) if the private key of the owner's account is stolen, all the assets might immediately turn into the property of the attacker. We develop a pattern recognition framework based on 9 syntactic features characterizing administrated ERC20 tokens, which we use to analyze existing smart contracts deployed on Ethereum Mainnet. Our analysis of 84,062 unique Ethereum smart contracts reveals that nearly 58% of them are administrated ERC20 tokens, which accounts for almost 90% of all ERC20 tokens deployed on Ethereum. To protect users from the frivolousness of unregulated token owners without depriving the ability of these owners to properly manage their tokens, we introduce SafelyAdministrated - a library that enforces a responsible ownership and management of ERC20 tokens. The library introduces three mechanisms: deferred maintenance, board of trustees and safe pause. We implement and test SafelyAdministrated in the form of Solidity abstract contract, which is ready to be used by the next generation of safely administrated ERC20 tokens.

Open access
3 source records
cs.CR
cs.CY
cs.DC
Original source