The future of security in Financial Technology (FinTech) hinges on achieving a delicate balance between safeguarding user privacy, ensuring regulatory compliance, and embracing technological advancements.As FinTech continues to disrupt traditional financial systems with innovative solutions, the industry faces increasing challenges from sophisticated cyber threats, evolving privacy concerns, and stringent regulatory frameworks.This article examines the critical interplay between these elements and explores strategies for building resilient, secure, and future-ready FinTech ecosystems.The discussion begins with an analysis of current trends in FinTech security, highlighting vulnerabilities associated with digital payment systems, decentralized finance (DeFi), and third-party integrations.Advanced technologies such as artificial intelligence (AI), blockchain, and quantum cryptography are presented as transformative tools for enhancing security, with applications in fraud detection, secure transactions, and real-time threat mitigation.The importance of adopting privacy-first principles, including data minimization and encryption, is underscored as essential for building user trust.The article also delves into the complexities of complying with global regulatory standards, such as GDPR, CCPA, and PSD2, emphasizing the need for adaptive compliance strategies to accommodate rapidly evolving technologies.By analysing case studies and best practices, it provides actionable insights for FinTech firms and policymakers to address challenges while fostering innovation.Ultimately, this work envisions a future where FinTech security frameworks not only protect users but also promote transparency, inclusivity, and growth.The convergence of technology, regulation, and ethical practices will shape a secure, privacy-respecting FinTech landscape that drives global financial inclusion and trust.
Dakai Kang, Junchao Chen, Tien Tuan Anh Dinh, Mohammad Sadoghi
The rise of cryptocurrencies like Bitcoin and Ethereum has driven interest in blockchain database technology, with smart contracts enabling the growth of decentralized finance (DeFi). However, research has shown that adversaries exploit transaction ordering to extract profits through attacks like front-running, sandwich attacks, and liquidation manipulation. This issue affects blockchains where block proposers have full control over transaction ordering. To address this, a more fair transaction ordering mechanism is essential. Existing fairness protocols, such as Pompe and Themis, operate on leader-based consensus protocols, which not only suffer from low throughput caused by the single-leader bottleneck, but also allow adversarial block proposers to manipulate transaction ordering. To address these limitations, we propose a new framework, FairDAG, that runs fairness protocols on top of DAG-based consensus protocols. FairDAG improves protocol performance in both throughput and fairness quality by leveraging the multi-proposer design and validity property of DAG-based consensus protocols. We conducted a comprehensive analytical and experimental evaluation of two FairDAG variants - FairDAG-AB and FairDAG-RL. Our results demonstrate that FairDAG outperforms prior fairness protocols in both throughput and fairness quality.
Abstract This paper thoroughly explores the complex interplay between blockchain technology and the General Data Protection Regulation (GDPR) of the European Union, alongside the substantial challenges and potential opportunities stemming from their interaction. While the challenges of decentralization and immutability in blockchain are well-documented, this paper advances the discussion by incorporating legal developments, such as evolving interpretations of joint controllership and new advisory opinions. It also evaluates emerging use cases, including blockchain integration in digital currencies like Worldcoin, highlighting contemporary compliance challenges and innovative solutions. By proposing actionable frameworks that leverage technological advancements like chameleon hashes and zero-knowledge proofs, this paper provides a forward-looking analysis of how blockchain systems can align with GDPR principles, offering theoretical insights and practical pathways for compliance. The conclusion underscores the urgent need for clear regulatory frameworks. These frameworks are crucial to enable a balanced approach that fosters innovation while ensuring robust data protection compliance, and their absence could hinder the potential impact of the research.
It is anticipated that cybercrime activities will be widespread in the urban metaverse ecosystem due to its high economic value with new types of assets and its immersive nature with a variety of experiences. Ensuring reliable urban metaverse cyberspaces requires addressing two critical challenges, namely, cybersecurity and privacy protection. This study, by analysing potential cyberthreats in the urban metaverse cyberspaces, proposes a blockchain-based Decentralised Privacy-Preserving Machine Learning (DPPML) authentication and verification methodology, which uses the metaverse immersive devices and can be instrumented effectively against identity impersonation and theft of credentials, identity, or avatars. Blockchain technology and Federated Learning (FL) are merged in the developed DPPML approach not only to eliminate the requirement of a trusted third party for the verification of the authenticity of transactions and immersive actions, but also, to avoid Single Point of Failure (SPoF) and Generative Adversarial Networks (GAN) attacks by detecting malicious nodes. The developed methodology has been tested using Motion Capture Suits (MoCaps) in a co-simulation environment with the Proof-of-Work (PoW) consensus mechanism. The preliminary results suggest that the built techniques in the DPPML approach can prevent unreal transactions, impersonation, identity theft, and theft of credentials or avatars promptly before any transactions have been executed or immersive experiences have been shared with others. The proposed system will be tested with a larger number of nodes involving the Proof-of-Stake (PoS) consensus mechanism using several other metaverse immersive devices as a future job.
Christos Karapapas, Iakovos Pittaras, George C. Polyzos, Constantinos Patsakis
The InterPlanetary File System~(IPFS) offers a decentralized approach to file storage and sharing, promising resilience and efficiency while also realizing the Web3 paradigm. Simultaneously, the offered anonymity raises significant questions about potential misuse. In this study, we explore methods that malicious actors can exploit IPFS to upload and disseminate harmful content while remaining anonymous. We evaluate the role of pinning services and public gateways, identifying their capabilities and limitations in maintaining content availability. Using scripts, we systematically test the behavior of these services by uploading malicious files. Our analysis reveals that pinning services and public gateways lack mechanisms to assess or restrict the propagation of malicious content.
Blockchain technology has become a game-changer in strengthening data security and transparency within decentralized systems. This study examines its role in tackling major challenges related to data integrity, access control, and auditability, with a focus on industries like finance, decentralized finance (DeFi), and supply chain management. Using data analysis, case studies, and expert opinions, the research highlights how blockchain provides a secure, transparent, and efficient framework for digital transactions. The findings reveal that blockchain enhances security by eliminating weaknesses found in traditional centralized systems. With features like immutable record-keeping, cryptographic encryption, and decentralized control, blockchain ensures transactions remain secure, tamper-proof, and resilient against fraud and cyber threats. Additionally, its ability to maintain a shared, verifiable ledger fosters transparency and builds trust among stakeholders. Smart contracts further improve efficiency by automating processes and ensuring compliance with predefined rules. However, despite its many benefits, blockchain adoption faces hurdles such as scalability challenges, regulatory uncertainties, and integration difficulties. To overcome these barriers, the study suggests developing clear regulatory guidelines, implementing advanced scalability solutions, increasing awareness and technical training, promoting cross-industry collaboration, and adopting hybrid blockchain models that balance security with privacy. In conclusion, this research emphasizes blockchain’s potential to reshape data security and transparency across various sectors. By addressing existing challenges, blockchain can drive innovation, streamline operations, and enhance trust in digital ecosystems.
This article explores the transformation of the state’s role in regulating personal data in the post-GDPR world. The author analyzes the impact of the EU’s General Data Protection Regulation (GDPR) on the evolution of the global privacy protection landscape, identifying trends towards harmonization and fragmentation of national legislations. The changing functions of the state as a regulator and guarantor of personal data protection in the context of digitalization are unveiled. The potential of blockchain technologies and distributed ledgers in ensuring user control over data is investigated. The influence of the development of the data market and new business models on the regulatory approaches of states and corporations is analyzed. The consequences of the spread of decentralized services for the relationships between the state, business, and civil society are considered. Priority directions for improving Ukrainian legislation in the field of personal data protection are substantiated, taking into account the realities of Web 3.0 and the need to balance innovation and security. The key idea is that the post-GDPR world stands at a crossroads between further fragmentation of the regulatory landscape and a long path towards harmonizing privacy standards. The choice of development trajectory depends on the coordinated political will of states, corporations, and global civil society to protect personal data as a shared value that unites humanity in the digital age. The article delves into the complex interplay of technological, legal, and societal factors shaping the future of data governance, offering insights into the challenges and opportunities ahead. It highlights the need for adaptive and inclusive regulatory frameworks that balance individual rights, economic interests, and public goods in an increasingly data-driven world.
Oqeili Saleh, Abu-alzanat Thamer, Alkaraimah Qutaibah, al smadi Takialddin
CAPTCHA, which stands for Completely Automated Public Turing Test to Tell Computers and Humans Apart, is a commonly employed security measure to distinguish between humans and computers. The Turing Test, designed to guarantee network security, is the foundation of this security technique. Usability is a crucial concern that can prevent human users from engaging in laborious and time-consuming tasks. When designing CAPTCHA, security and usability must be addressed simultaneously. When designing CAPTCHA, it is crucial to address security and usability simultaneously. A concerted effort is required to protect online data and guarantee privacy and security. The personal information of Internet users remains susceptible to theft. This study uses an information extraction technique called CAPTCHA to investigate the hazards associated with violating user privacy. It is a highly harmful process due to hacking, theft, unauthorized reuse, and the breach of user information. This study proposes a privacy preservation system employing concurrent encryption techniques, multilateral security computing, and zero-knowledge proof. The objective is to create a system that allows for uncomplicated and secure puzzle-solving using dice gas. CAPTCHA limits access to users' information. In the overview and application of evidentiary measurable methods, we can draw significant conclusions about the more extensive client group's discernments and encounters with CAPTCHA as a privacy-preserving component.
Purpose Blockchain technology has been labeled as the most disruptive technological innovation of the current decade due to its impact on almost every major industry. Based on privacy calculus theory and prior adoption literature on emerging technologies, this research investigates the impact of blockchain technology in the consumer technology segment. It elaborated on the mechanism through which blockchain technology influences users’ willingness to share information with technology products enabled by blockchain. Design/methodology/approach Taking a heterogeneous pool of users, this study conducted multiple experiments with the application of blockchain (vs. regular database) technology to high (vs. low) sensitive data to study the impact of blockchain perception on users’ information-sharing tendencies. Findings Through a mediated moderation analysis, the result shows that the use of blockchain technology enhances the sense of security among users. However, the impact of this heightened sense of security only develops a higher willingness to share information when the data is highly sensitive. Practical implications The research reflects on the perception of blockchain technology and the leading impact on willingness to share information with firms. This could be a critical criterion for determining investment in blockchain technologies for consumer products, particularly based on the sensitivity of the data the consumer is sharing. Originality/value This research focuses on the perception of blockchain technology among consumers and its impact on consumers’ decision-making related to their data sharing. People have a higher sense of safety when it comes to blockchain-enabled products. However, we find that it would not be the same for all contexts, and the sensitivity of the data collected would have an impact on this relationship and consumers’ data-sharing decisions.
This paper addresses the challenge of preserving user privacy within the Internet of Things (IoT) ecosystem using blockchain technology. Several approaches consider using blockchain and encryption to enhance the privacy of IoT applications and constrained IoT devices. However, existing blockchain platforms such as Ethereum and Hyperledger Fabric already use encryption to store data blocks and secure communication. Therefore, introducing an additional cryptographic layer on top of these platforms could potentially increase processing overhead and reduce response time. In this work, we investigate the integration of IoT and blockchain for privacy preservation. More specifically, we propose a new model that leverages the properties of private blockchain and smart contracts to ensure user data privacy when shared with others. We define policy-based algorithms and notations to assist users in managing smart contracts responsible for registering and controlling their IoT devices. We also specify multiple smart contracts designed to enhance privacy by creating a private channel for communication between the user and the blockchain network.
Metaverses may present innovative channels for business and finance , education, and workplaces. Drawing from the Diffusion of Innovation Theory and the Unified Theory of Acceptance and Use of Technology (UTAUT) as well as the literature on digital equality, this research attempts to unravel the dynamics of digital equality and trust in AI-empowered metaverses for various industry sectors. Three cross-sectional surveys ( N Total = 1086) examined US Internet users' intention to adopt metaverses for business, education, and workplaces. Structural equation models were estimated using Mplus 8.8. Study 1 indicates dynamic relationships among digital equality (commerce dimension), blockchain transparency, privacy concerns, and adoption intention. Study 2 shows dynamic associations among digital equality (educational, social, and political dimensions), digital adaptability, loneliness, and adoption intention. Study 3 demonstrates dynamic interconnections among digital equality (labor, government, and health dimensions), digital adaptability, identity threat, and adoption intention. Across three datasets, trust mediates the relationship between digital equality and adoption intention. Theoretical contributions to the emerging literature on decentralized finance (DeFi), AI-driven digital transformation, and AI-VR-convergence are discussed. DeFi businesses, enterprises, policy makers, educators, professional training providers, and workforce developers need to consider third-level digital (in)equality and digital adaptability in developing equitable, sustainable, and inclusive user experience (UX) in AI-empowered metaverses.
This study aims to identify and assess AI and blockchain solutions in relation to journalistic authenticity and integrity. Central to our exploration is the role of blockchain technology in verifying content provenance. As a key component of a global Web3 framework, blockchain could offer a foundation for authenticating the origins of content. In this article, we explore how blockchain, with its capacity for creating immutable and cryptographically signed data records, could be applied by journalists to verify photos, videos and documents. Our analysis identified nine blockchain-based solutions for content verification, with three platforms–Attestiv, OriginStamp, and Fact Protocol–showing particular promise for journalistic workflows. We conclude that while AI and blockchain solutions are currently available to journalists today, they require high-level technical expertise. Many media companies are now venturing into this field as well, thus affecting the professional role of journalists in general. In our study, it is evident that integrating AI and blockchain in journalism is not merely about adopting new tools but also about understanding their broader implications for journalism as a profession and the convergence in society. The focus must remain on enhancing journalistic integrity and public trust to ensure that these technological advances benefit the field of journalism and, by extension, the democratic processes it supports.
The rapid convergence of urbanization and digital technologies is fundamentally reshaping city governance through data-driven systems. This transformation, however, is largely controlled by surveillance capitalist entities, raising profound concerns for democratic values and citizen rights. As private interests extract behavioral data from public spaces without adequate oversight, the principles of transparency and civic participation are increasingly threatened. This erosion of data sovereignty represents a critical juncture in urban development, demanding urgent interdisciplinary attention. This comment proposes a paradigm shift in urban data governance, advocating for the reclamation of data sovereignty to prioritize community interests over corporate profit motives. The paper explores socio-technical pathways to achieve this goal, focusing on grassroots approaches that assert ‘data dignity’ through privacy-enhancing technologies and digital anonymity tools. It argues for the creation of distributed digital commons as viable alternatives to proprietary data silos, thereby democratizing access to and control over urban data. The discussion extends to long-term strategies, examining the potential of blockchain technologies and decentralized autonomous organizations in enabling self-sovereign data economies. These emerging models offer a vision of ‘crypto-cities’ liberated from extractive data practices, fostering environments where residents retain autonomy over their digital footprints. By critically evaluating these approaches, the paper aims to catalyze a reimagining of smart city technologies aligned with principles of equity, shared prosperity, and citizen empowerment. This realignment is essential for preserving democratic values in an increasingly digitized urban landscape.
This paper presents an approach for the verification of access control in smart contracts written in the Digital Asset Modeling Language (DAML). The approach utilizes Colored Petri Nets (CPNs) and their analysis tool CPN Tools. It is a model-driven-based approach that employs a new meta-model for capturing access control requirements in DAML contracts. The approach is supported by a suite of tools that fully automates all of the steps: parsing DAML code, generating DAML model instances, transforming the DAML models into CPN models, and model checking the generated CPN models. The approach is tested using several DAML scripts involving access control extracted from different domains of blockchain applications.
Web3, also known as the Decentralized Web, is a vision for the next generation of Web applications, supported by blockchain technology, where users have stronger ownership over their data and identity. One of the key components in Web3 is wallets, which hold a user’s public and private keys, manage digital tokens, and sign transaction details. Despite their significance in securely managing digital identities, wallets also introduce vulnerabilities that, if overlooked, can compromise users’ privacy and security, particularly during data exchange with network endpoints. We investigate how popular wallets like MetaMask can inadvertently expose sensitive information to RPC endpoints, even when no transactions are made. Additionally, we examine the confidentiality risks associated with the registration requirements of major node providers, highlighting how the collection of personal and financial details can further threaten user privacy. We briefly report on ongoing work in analyzing the characteristics of wallets across various blockchain networks to identify key security and privacy features that can be integrated into new wallet designs. This research aims to address the challenges inherent in wallet security and privacy within Web3.
Purpose: To aim of the study was to analyze the role of blockchain technology in enhancing data security. Methodology: This study adopted a desk methodology. A desk study research design is commonly known as secondary data collection. This is basically collecting data from existing resources preferably because of its low cost advantage as compared to a field research. Our current study looked into already published studies and reports as the data was easily accessed through online journals and libraries. Findings: Blockchain technology is increasingly recognized in Germany for its potential to enhance data security across various sectors. Its decentralized and immutable nature significantly reduces the risks of data tampering and unauthorized access, thereby fostering trust among users. In industries such as finance, healthcare, and supply chain management, blockchain provides transparent and secure methods for recording transactions and managing sensitive information. Additionally, German regulatory frameworks are evolving to accommodate blockchain applications, promoting innovation while ensuring compliance with data protection laws like the GDPR. Unique Contribution to Theory, Practice and Policy: Technological acceptance model (TAM), diffusion of innovations (DOI) & resource-based View (RBV) may be used to anchor future studies on the role of blockchain technology in enhancing data security. Organizations should implement pilot projects to assess the effectiveness of blockchain in enhancing data security in their specific contexts. Policymakers should develop clear regulatory frameworks to support the adoption of blockchain technology across sectors.
Peter Howson, Antulio Rosales, Olivier Jutel, Inte Gloerich · 8 authors
This paper explores how so-called ‘Web3’ blockchain projects are materially and socially constituted. A blockchain is an append-only distributed database. The technology is being hyped as applicable for a whole range of industries, social service provisions, and as a fix for economic disparities in communities left behind by mainstream financial systems. Drawing on case studies from our ongoing research we explain how, despite being virtual, Web3 projects are dependent on clearly defined spaces of production from which they derive their speculative value. We conceptualise this relationship as Crypto/Space, where space and blockchain software are mutually constituted. We consider how Crypto/Spaces are produced in three ways: 1) how project developers are adopting a parasitic relationship with host locations to appropriate energy, infrastructure, and local resources; 2) how projects enable ‘virtual land grabs’ where developers are engaging in land acquisitions, and associated displacement of local people, with no real intention to use the land for the declared purpose; and 3) how blockchain technology and speculative finance imaginaries are inspiring new anarcho-capitalist crypto-utopian ‘Exit zones’, often in the Global South. Far from being a zero-sum virtual game world, we argue that cryptocurrency projects are parasitic, often requiring predation on poor and otherwise marginalised communities to appropriate resources, onboard new users and enable favourable regulation.
This article explores how decentralized Web3 is reshaping Internet governance by enabling the emergence of new forms of nation-statehood and redefining traditional concepts of state sovereignty. Based on fieldwork conducted in Silicon Valley since August 2022, this article systematically addresses the following research question: How is decentralized Web3 reshaping Internet governance and influencing the rise in new nation-statehood paradigms? It compares three emerging paradigms around Web3: (i) Network States (Srinivasan), envisioning digital entities rooted in crypto-libertarian principles; (ii) Network Sovereignties (De Filippi), emphasizing communal governance aligned with digital commons; and (iii) Algorithmic Nations (Calzada), drawing on Arendtian thought and demonstrating how communities—such as indigenous and stateless groups, as well as e-diasporas—can attain self-determination through data sovereignty. This article contributes a unique conceptual analysis of these paradigms based on fieldwork action research in Silicon Valley, responding to evolving technologies and their potential to reshape Internet governance. This article argues that decentralized Web3 provides a transformative vision for Internet governance but requires careful evaluation to ensure that it promotes inclusivity and equity. It advocates for a hybrid approach that balances global and local dynamics, emphasizing the need for solidarity, digital justice, and an internationalist perspective in shaping future Internet governance protocols.
Hari Mohan, Kaustubh Kumar Shukla, Lilia Tightiz, Sanjeevikumar Padmanaban
The integration of blockchain technology with the IoToffers numerous opportunities to enhance the privacy, security, and integrity. This study comprehensively analyze the challenges, scope, and potential solutions associated with integrating blockchain technology and the IoT, with a specific emphasis on nuclear energy applications. We discuss the roles and various aspects of blockchain and the IoT, highlighting their multiple dimensions and applications. Our study develops a secure data management framework that incorporates encryption, integrity verification, an integrated communication network, and a robust data flow architecture. We explore the several aspects of data security, privacy, and integrity, along with the potential solutions in the integration of blockchain and IoT. The study also investigates the secure transaction process, with a specific focus on cryptographic, mathematical, and algorithmic perspectives. We demonstrated the use of blockchain technology in the nuclear energy sector using flow charts, comprehensively addressing the associated security and privacy concerns. While emphasizing the applicability of our methodology to the nuclear sector, we also acknowledge limitations such as requirements for practical validation, challenges with resource-constrained IoT environments, increasing cyberthreats, and limited real-time data availability. The future scope of our study focuses on standardization, scalable blockchain, post-quantum cryptography, privacy, regulations, real-world testbeds, and deep learning for nuclear sector security. Our findings highlight that the integration of blockchain and IoT can significantly enhance the security and privacy of nuclear energy applications, although practical validation and optimization are necessary.
IT has made significant progress in various fields over the past few years, with many industries transitioning from paper-based to electronic media. However, sharing electronic medical records remains a long-term challenge, particularly when patients are in emergency situations, making it difficult to access and control their medical information. Previous studies have proposed permissioned blockchains with limited participants or mechanisms that allow emergency medical information sharing to pre-designated participants. However, permissioned blockchains require prior participation by medical institutions, and limiting sharing entities restricts the number of potential partners. This means that sharing medical information with local emergency doctors becomes impossible if a patient is unconscious and far away from home, such as when traveling abroad. To tackle this challenge, we propose an emergency access control system for a global electronic medical information system that can be shared using a public blockchain, allowing anyone to participate. Our proposed system assumes that the patient wears a pendant with tamper-proof and biometric authentication capabilities. In the event of unconsciousness, emergency doctors can perform biometrics on behalf of the patient, allowing the family doctor to share health records with the emergency doctor through a secure channel that uses the Diffie-Hellman (DH) key exchange protocol. The pendant's biometric authentication function prevents unauthorized use if it is stolen, and we have tested the blockchain's fee for using the public blockchain, demonstrating that the proposed system is practical.
Abstract Non-Fungible Tokens (NFTs) are becoming increasingly popular as a way to represent and own digital property. However, the usage of NFTs also prompts questions about privacy. In this work, we show that it is possible to use NFTs to retrieve enough information to fingerprint users. By doing so, we can uniquely associate users with blockchain accounts. This would allow linking several blockchain accounts to the same user. This work focuses on the vulnerabilities presented by some popular NFT marketplaces. Since NFTs may have HTML files embedded, they allow the use of fingerprinting techniques if not handled carefully. Finally, we provide recommendations and countermeasures for the different actors in this ecosystem to avoid these kinds of tracking methods and, in doing so, safeguard user privacy.
Open access
Advanced Steganography and Watermarking Techniques