To address the challenges of internal security policy compliance and dynamic threat response in organizations, we present a novel framework that integrates artificial intelligence (AI), blockchain, and smart contracts. We propose a system that automates the enforcement of security policies, reducing manual effort and potential human error. Utilizing AI, we can analyse cyber threat intelligence rapidly, identify non-compliances and automatically adjust cyber defence mechanisms. Blockchain technology provides an immutable ledger for transparent logging of compliance actions, while smart contracts ensure uniform application of security measures. The framework's effectiveness is demonstrated through simulations, showing improvements in compliance enforcement rates and response times compared to traditional methods. Ultimately, our approach provides for a scalable solution for managing complex security policies, reducing costs and enhancing the efficiency while achieving compliance. Finally, we discuss practical implications and propose future research directions to further refine the system and address implementation challenges.
Terrorism is a phenomenon that changes very quickly with time. One of the key factors to survey and evaluate its success is its flexibility and the ease with which it mutates into new forms that adapt its actions depending on their goals and their facility to get funding. International terrorism uses international corporations’ structure and management methods adapted to new technologies to produce a new form of decentralized terrorism that is complicated to fight with only the classical tools of legal enforcement agencie, as at present.
Oladipo Sopitan, Kayode S Adetola, Azeezat Wahab Morenikeji, Joye Ahmed Shonubi · 5 authors
Blockchain combined with smart contracts in banking and business dealings has emerged as an innovative method to enhance financial transparency while reducing potential risks. The earlier decentralized immutable ledger known as blockchain ensures transaction security and verification while minimizing fraudulent activities and operational shortcomings. Smart contracts function as self-expiring agreements withBlockchain and Smart Contracts for Financial Transparency and Risk Mitigation in Banking and Business Transactions https://iaeme.com/Home/journal/IJBC 2
Billions of dollars have been lost due to vulnerabilities in smart contracts. To counteract this, researchers have proposed attack frontrunning protections designed to preempt malicious transactions by inserting "whitehat" transactions ahead of them to protect the assets. In this paper, we demonstrate that existing frontrunning protections have become ineffective in real-world scenarios. Specifically, we collected 158 recent real-world attack transactions and discovered that 141 of them can bypass state-of-the-art frontrunning protections. We systematically analyze these attacks and show how inherent limitations of existing frontrunning techniques hinder them from protecting valuable assets in the real world. We then propose a new approach involving 1) preemptive hijack, and 2) attack backrunning, which circumvent the existing limitations and can help protect assets before and after an attack. Our approach adapts the exploit used in the attack to the same or similar contracts before and after the attack to safeguard the assets. We conceptualize adapting exploits as a program repair problem and apply established techniques to implement our approach into a full-fledged framework, BACKRUNNER. Running on previous attacks in 2023, BACKRUNNER can successfully rescue more than \$410M. In the real world, it has helped rescue over \$11.2M worth of assets in 28 separate incidents within two months.
With the widespread adoption of smart contracts in automated financial transactions, the accurate and efficient processing of image data related to financial transactions has become a critical challenge.The successful execution of smart contracts relies on the precise verification of transaction voucher images, yet existing image processing technologies still face limitations in dealing with background complexity, noise interference, and text extraction accuracy.To address these issues, this study proposes a comprehensive image processing approach aimed at enhancing the automation of financial transaction verification.The research focuses on four key areas: separation of table lines and text regions in images, application of Sauvola local adaptive binarization, table detection and reconstruction, and text extraction and fracture restoration techniques.Through these efforts, the study aims to provide more efficient and reliable technical support for financial transaction verification in smart contracts, thereby advancing the development of smart contract technologies.
Blockchain technology and smart contracts are emerging as transformative tools for enhancing transparency and efficiency in supply chain management and vendor relations. Traditional supply chains often face challenges such as inefficiencies, lack of transparency, and susceptibility to fraud (Kouhizadeh & Sarkis, 2018). Blockchain, a decentralized ledger technology, coupled with smart contracts, which are self-executing contracts with the terms directly written into code, offers promising solutions to these challenges (Wang, Han, & Beynon-Davies, 2019). This paper explores the application of blockchain and smart contracts in these domains, examining their potential to provide immutable records, streamline processes, and mitigate risks (Casado-Vara et al., 2018). Through a comprehensive analysis of current literature and case studies, we identify key benefits including improved transparency, enhanced efficiency, and better risk management (Christidis & Devetsikiotis, 2016; Tian, 2016). Our findings suggest that blockchain and smart contracts can significantly improve supply chain transparency and vendor management, though their implementation requires careful consideration of technical, regulatory, and organizational factors (Saberi et al., 2019). Notable case studies, such as Walmart’s blockchain pilot for food safety and De Beers' diamond tracking initiative, illustrate the practical benefits and challenges of adopting these technologies in real-world scenarios (Casino, Dasaklis, & Patsakis, 2019; Kshetri, 2018). Despite the promising outlook, further research is needed to address scalability, interoperability, and regulatory compliance issues to fully realize the potential of blockchain and smart contracts in supply chain management (Hughes et al., 2019).
In the realm of smart contract security, transaction malice detection has been able to leverage properties of transaction traces to identify hacks with high accuracy. However, these methods cannot be applied in real-time to revert malicious transactions. Instead, smart contracts are often instrumented with some safety properties to enhance their security. However, these instrumentable safety properties are limited and fail to block certain types of hacks such as those which exploit read-only re-entrancy. This limitation primarily stems from the Ethereum Virtual Machine's (EVM) inability to allow a smart contract to read transaction traces in real-time. Additionally, these instrumentable safety properties can be gas-intensive, rendering them impractical for on-the-fly validation. To address these challenges, we propose modifications to both the EVM and Ethereum clients, enabling smart contracts to validate these transaction trace properties in real-time without affecting traditional EVM execution. We also use past-time linear temporal logic (PLTL) to formalize transaction trace properties, showcasing that most existing detection metrics can be expressed using PLTL. We also discuss the potential implications of our proposed modifications, emphasizing their capacity to significantly enhance smart contract security.
Combining AI with blockchain smart contracts is possible and can significantly improve smart contracts' functionality, flexibility, and performance. In this paper, concepts of intelligent contracts, advanced through artificial intelligence, are described as potential solutions for increasing the efficiency and security of numerous industries. Some of these are explained by showing the application of the technology in financial services, supply chains, healthcare, and legal processes, as well as the practical enhancements brought about by this technology. Furthermore, the paper explores the prospects for developing the AI smart contract regarding compatibility, expansibility, ethical artificial intelligence, and superior automation. AI and blockchain integration are predicted to have immense impacts on economics and social advancements that will lead to increased automation and decentralization.
Non-Fungible Tokens (NFTs) have emerged as a significant innovation in the digital economy, particularly in India, where the intersection of art, technology, and finance is evolving rapidly. NFTs are unique digital tokens secured through blockchain technology, representing ownership of digital or physical assets such as art, music, collectibles, and virtual real estate. Their rise in India is marked by increasing participation from creators, investors, and technology platforms.Despite their growing popularity, NFTs operate within a fragmented and ambiguous legal environment. India currently lacks specific legislation dedicated to NFTs, leading to reliance on existing laws such as the Indian Contract Act, 1872; the Information Technology (IT) Act, 2000; intellectual property laws; and provisions in the Finance Act, 2022 concerning virtual digital assets. However, these frameworks offer limited clarity on issues such as copyright ownership, contract enforceability via smart contracts, taxation, and consumer protection.This research paper undertakes a comprehensive examination of the legal standing of NFTs in India. It evaluates the applicability of current legal instruments, identifies regulatory and operational gaps, and explores international best practices. The study also emphasizes the need for a clear, forward-looking legal framework that fosters innovation while ensuring adequate safeguards against fraud, misuse, and environmental concerns. A balanced regulatory approach is essential for India to harness the full potential of NFTs and position itself as a leader in the digital asset economy.
The role of Web3 technologies was examined specifically regarding SmartCharity and their effect on the financing and delivery of public goods in developing countries. The research focused on the case of SmartCharity, its role in making fund distribution more transparent and efficient, and the role of NFTs and smart contracts’ efficacy in changing. For primary data, the cross-sectional study used interviews and questionnaires administered to the critical actors in or close to SmartCharity initiatives; secondary data came from project reports and publicly accessible sources. Quantitative analysis uses statistics to identify trends and correlations in data, whereas qualitative data analysis identifies such trends and patterns. This paper aimed to establish an appreciation of the strengths and weaknesses of Web3 innovation in public good management and make future suggestions for improvement.
Smart contracts are central to a myriad of critical blockchain applications, from financial transactions to supply chain management. However, their adoption is hindered by security vulnerabilities that can result in significant financial losses. Most vulnerability detection tools and methods available nowadays leverage either static analysis methods or machine learning. Unfortunately, as valuable as they are, both approaches suffer from limitations that make them only partially effective. In this survey, we analyze the state of the art in machine-learning vulnerability detection for Ethereum smart contracts, by categorizing existing tools and methodologies, evaluating them, and highlighting their limitations. Our critical assessment unveils issues such as restricted vulnerability coverage and dataset construction flaws, providing us with new metrics to overcome the difficulties that restrain a sound comparison of existing solutions. Driven by our findings, we discuss best practices to enhance the accuracy, scope, and efficiency of vulnerability detection in smart contracts. Our guidelines address the known flaws while at the same time opening new avenues for research and development. By shedding light on current challenges and offering novel directions for improvement, we contribute to the advancement of secure smart contract development and blockchain technology as a whole.
This research paper delves into the intricate world of smart contract derivatives, aiming to unravel the technical intricacies and explore their applications. Smart contract derivatives represent a burgeoning intersection of blockchain technology and financial instruments, providing decentralized and automated solutions for derivative trading. The paper navigates through the complex landscape of smart contract derivatives, addressing both the technical aspects of their implementation and the diverse range of applications they unlock. Through a comprehensive review of existing literature, case studies, and real-world examples, this research aims to provide a holistic understanding of the challenges, opportunities, and implications associated with smart contract derivatives. By comprehensively addressing both the technical intricacies and practical applications of smart contract derivatives, this study contributes valuable insights into the rapidly evolving field of decentralized finance.
Modern blockchains support the execution of application-level code in the form of smart contracts, allowing developers to devise complex Distributed Applications (DApps). Smart contracts are typically written in high-level languages, such as Solidity, and after deployment on the blockchain, their code is executed in a distributed way in response to transactions or calls from other smart contracts. As a common piece of software, smart contracts are susceptible to vulnerabilities, posing security threats to DApps and their users.
The advent of blockchain technology and its adoption across various sectors have raised critical discussions about the need for regulatory mechanisms to ensure consumer protection, maintain financial stability, and address privacy concerns without compromising the foundational principles of decentralization and immutability inherent in blockchain platforms. We examine the existing mechanisms for smart contract termination across several major blockchain platforms, including Ethereum, BNB Smart Chain, Cardano, Solana, Hyperledger Fabric, Corda, IOTA, Apotos, and Sui. We assess the compatibility of these mechanisms with the requirements of the EU Data Act, focusing on aspects such as consumer protection, error correction, and regulatory compliance. Our analysis reveals a diverse landscape of approaches, from immutable smart contracts with built-in termination conditions to upgradable smart contracts that allow for post-deployment modifications. We discuss the challenges associated with implementing the so-called smart contract "kill switches," such as the balance between enabling regulatory compliance and preserving the decentralized ethos, the technical feasibility of such mechanisms, and the implications for security and trust in the ecosystem.
Christopher De Baets, Basem Suleiman, Armin Chitizadeh, Imran Razzak
In the growing field of blockchain technology, smart contracts exist as transformative digital agreements that execute transactions autonomously in decentralised networks. However, these contracts face challenges in the form of security vulnerabilities, posing significant financial and operational risks. While traditional methods to detect and mitigate vulnerabilities in smart contracts are limited due to a lack of comprehensiveness and effectiveness, integrating advanced machine learning technologies presents an attractive approach to increasing effective vulnerability countermeasures. We endeavour to fill an important gap in the existing literature by conducting a rigorous systematic review, exploring the intersection between machine learning and smart contracts. Specifically, the study examines the potential of machine learning techniques to improve the detection and mitigation of vulnerabilities in smart contracts. We analysed 88 articles published between 2018 and 2023 from the following databases: IEEE, ACM, ScienceDirect, Scopus, and Google Scholar. The findings reveal that classical machine learning techniques, including KNN, RF, DT, XG-Boost, and SVM, outperform static tools in vulnerability detection. Moreover, multi-model approaches integrating deep learning and classical machine learning show significant improvements in precision and recall, while hybrid models employing various techniques achieve near-perfect performance in vulnerability detection accuracy. By integrating state-of-the-art solutions, this work synthesises current methods, thoroughly investigates research gaps, and suggests directions for future studies. The insights gathered from this study are intended to serve as a seminal reference for academics, industry experts, and bodies interested in leveraging machine learning to enhance smart contract security.
Smart Contract Vulnerability Detection (SCVD) is crucial to guarantee the quality of blockchain-based systems. Graph neural networks have been shown to be effective in learning semantic representations of smart contract code and are commonly adopted by existing deep learning-based SCVD. However, the current methods still have limitations in their utilization of graph sampling or subgraph pooling based on predefined rules for extracting crucial components from structure graphs of smart contract code. These predefined rule-based strategies, typically designed using static rules or heuristics, demonstrate limited adaptability to dynamically adjust extraction strategies according to the structure and content of the graph in heterogeneous topologies of smart contract code. Consequently, these strategies may not possess universal applicability to all smart contracts, potentially leading to false positives or omissions. To address these problems, we propose AFPNet, a novel vulnerability detection model equipped with a feature perception module that has dynamic weights for comprehensive scanning of the entire smart contract code and automatic extraction of crucial code snippets (the $P$ snippets with the largest weights). Subsequently, the relationship perception attention module employs an attention mechanism to learn dependencies among these code snippets and detect smart contract vulnerabilities. The efforts made by AFPNet consistently enable the capture of crucial code snippets and enhance the performance of SCVD optimization. We conduct an evaluation of AFPNet in the several large-scale datasets with vulnerability labels. The experimental results show that our AFPNet significantly outperforms the state-of-the-art approach by 6.38\%-14.02\% in term of F1-score. The results demonstrate the effectiveness of AFPNet in dynamically extracting valuable information and vulnerability detection.
Smart contracts, known for their immutable nature to ensure trust via automated enforcement, have evolved to require upgradeability due to unforeseen vulnerabilities and the need for feature enhancements post-deployment. This contradiction between immutability and the need for modifications has led to the development of upgradeable smart contracts. These contracts are immutable in principle yet upgradable by design, allowing updates without altering the underlying data or state, thus preserving the contract's intent while allowing improvements. This study aims to understand the application and implications of upgradeable smart contracts on the Ethereum blockchain. By introducing a dataset that catalogs the versions and evolutionary trajectories of smart contracts, the research explores key dimensions: the prevalence and adoption patterns of upgrade mechanisms, the likelihood and occurrences of contract upgrades, the nature of modifications post-upgrade, and their impact on user engagement and contract activity. Through empirical analysis, this study identifies upgradeable contracts and examines their upgrade history to uncover trends, preferences, and challenges associated with modifications. The evidence from analyzing over 44 million contracts shows that only 3% have upgradeable characteristics, with only 0.34% undergoing upgrades. This finding underscores a cautious approach by developers towards modifications, possibly due to the complexity of upgrade processes or a preference for maintaining stability. Furthermore, the study shows that upgrades are mainly aimed at feature enhancement and vulnerability mitigation, particularly when the contracts' source codes are accessible. However, the relationship between upgrades and user activity is complex, suggesting that additional factors significantly affect the use of smart contracts beyond their evolution.
The paper offers a generalized author’s view on the new phenomenon of the digital world, backed tokenized assets, as a tool for asset accounting in digital accounting systems. This view is new and currently unpopular in the literature since the main aspect of tokenized asset presentation is related to speculation on financial markets, widespread creation of unbacked assets around objects of human life, graphics, etc. The aim of the paper is to determine the essence, generic features and technological basis of the use of tokenized assets for their implementation in the digital and platform-based economy. In accordance with this aim, the author logically presents the material from the general to the specific, analyzing the essential features of 7 main related concepts: distributed ledger, distributed ledger technologies, blockchain technology, tokens and consensus algorithm, tokenized asset, decentralized information platform and blockchain-based ecosystem of services. The author persists in the opinion that a tokenized asset is a type of virtual asset. It is a tool for certifying sufficient and confirmed legal rights: rights of access to products and services, rights to a certain product or service, rights to receive a fixed income or percentage of profits, management rights, rights to purchase a certain asset at a certain price in the future, etc. The paper offers the original definition of a tokenized asset: tokenized asset is a type of virtual asset that exists in a digital data accounting system based on the distributed ledger technology in the form of a record with an identifier of information derived from the original asset. A tokenized asset can be used as a tool for implementing a method of recording, accounting and managing property rights to assets. Moreover, a tokenized asset can be used as a tool for certifying any rights; providing services; recording events; generating, processing and submitting statistical and analytical information; ensuring logistics, etc. Depending on the purpose of creating a specific tokenized asset and, as a result, certain inherent properties envisaged by the creator, this tokenized asset can be classified as a separate type.
Yishun Wang, Xiaoqi Li, Ye, Shipeng, Xie, Lei · 5 authors
Smart contracts with external data are crucial for functionality but pose security and reliability concerns. Statistical and quantitative studies on this interaction are scarce. To address this gap, we analyzed 10,500 smart contracts, retaining 9,356 valid ones after excluding outdated or erroneous ones. We employed code parsing to transform contract code into abstract syntax trees and identified keywords associated with external data dependencies. We conducted a quantitative analysis by comparing these keywords to a reference list. We manually classified the 9,356 valid smart contracts to ascertain their application domains and typical interaction methods with external data. Additionally, we created a database with this data to facilitate research on smart contract dependencies. Moreover, we reviewed over 3,600 security audit reports, manually identifying 249 (approximately 9%) related to external data interactions and categorized their dependencies. We explored the correlation between smart contract complexity and external data dependency to provide insights for their design and auditing processes. These studies aim to enhance the security and reliability of smart contracts and offer practical guidance to developers and auditors.
Upgradable smart contracts play an important role in the decentralized application ecosystem, to support routine maintenance, security patching, and feature additions. In this paper, we conduct an empirical study on proxy-based upgradable smart contracts to understand the characteristics of contract upgrading. Through our study on 57,118 open source proxy contracts, we found that 583 contracts have ever been upgraded on Ethereum, involving 973 unique implementation contract versions. The results show that developers often intend to improve usability of contracts if upgrading, where functionality addition and update are the most frequent upgrade intentions. We investigated the practical impacts of contract upgrades, e.g., breaking changes causing compatibility issues, storage collisions and initialization risks leading to security vulnerabilities. The results demonstrate that there are 4,334 ABI breaking changes due to the upgrades of 276 proxies, causing real-world broken usages within 584 transactions witnessed by the blockchain; 36 contract upgrades had storage collisions and five proxies with 59 implementation contracts are vulnerable to initialization attacks.
Angela Maria Vargas Ariza, Marleny Corzo Marín, Mayeth Lizeth Duran Duran
Results and contributions: Specific financial assurance procedures adapted to the context of the Metaverse are presented, addressing the particular challenges of virtual assets and smart contracts, where a risk assessment and the appropriate implementation of audit procedures are carried out. Contributing to the adequate preservation of these digital elements to guarantee security and lay the foundation for the future of the digital economy. Purpose: The objective is to describe the financial assurance procedures applicable to virtual assets and smart contracts generated in the metaverse, taking into account their financial, economic, legal and accounting characterization. Gap: The financial, accounting and legal characterization of digital assets in the Metaverse, I contribute to presenting audit procedures in accordance with international financial assurance standards that allow the integrity and reliability of transactions in this rapidly evolving virtual environment. Relevance: It is relevant to accountants and auditors who need to evaluate the integrity and reliability of financial operations in the Metaverse, as well as to any person or entity participating in this environment. Impact: The study will provide a solid foundation to address financial challenges in the metaverse, in the face of adequate procedures to audit and financially support virtual assets, thus contributing to the legality and reliability of operations. Methodology: the methodology is qualitative and descriptive, with a non-experimental transectional design. It begins with a review of the existing standard on financial assurance, virtual assets and smart contracts. It is then characterized by examining the applicable financial principles and regulations, as well as the legal and accounting aspects that influence their management and assurance, and the procedures and their applicability in the context of the Metaverse are evaluated.
Krzysztof Gogol, Johnnatan Messias, Deborah Miori, Claudio J. Tessone · 5 authors
This study quantifies the potential non-atomic MEV on Layer-2 (L2) blockchains by measuring the arbitrage opportunities between cross-rollup and DEX-CEX. Over recent years, we observe a shift in trading activities from Ethereum to rollups, with swaps on rollups occurring 2-3 times more frequently, albeit with lower trade volumes. By analyzing the costs of swap on L2s and price discrepancies cross-rollup and DEX-CEX, we identify more than 500 000 unexplored arbitrage opportunities. In particular, we find that these opportunities persist, on average, for 10 to 20 blocks, necessitating the modification of the Loss Versus Rebalancing (LVR) metric to prevent double-counting. Our findings indicate that the arbitrage opportunities in Arbitrum, Base, and Optimism range between 0.03% and 0.05% of the trading volume, while in the ZKsync it fluctuates around 0.25%.
Blockchain technology has emerged as a disruptive force in the realm of finance, offering decentralized and transparent mechanisms for conducting financial transactions. This paper explores the landscape of blockchain-based financial transactions, focusing on risk analysis, anomaly detection, regulatory frameworks, and ethical considerations. Drawing on interdisciplinary insights from finance, computer science, economics, law, and ethics, the study investigates the opportunities and challenges presented by blockchain finance. Leveraging quantitative analysis, machine learning algorithms, case studies, and regulatory reviews, the research sheds light on the complexities of blockchain ecosystems. Key findings include the importance of robust risk management strategies, the role of anomaly detection in safeguarding financial integrity, and the evolving regulatory landscape surrounding blockchain transactions. The study identifies gaps in current research and proposes avenues for future investigation, emphasizing the need for interdisciplinary approaches to address the multifaceted challenges of blockchain-based finance. Ultimately, this research aims to inform stakeholders about the implications of blockchain technology in financial transactions and foster responsible innovation and sustainable development in digital finance ecosystems.