Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

873 papersLast indexed Aug 31, 2026
Search papers

Paper index

873 results ¡ page 9 of 37

Clear filters
Jan 1, 2025¡Asian Journal of Research in Computer Science
1 cites
Assessing the Effectiveness of Cybersecurity Frameworks in Mitigating Cyberattacks in the Banking Sector and its Applicability to Decentralized Finance (DeFi)

Abayomi Titilola Olutimehin

This study evaluates the effectiveness of cybersecurity frameworks in mitigating cyber threats in traditional banking while assessing their applicability to Decentralized Finance (DeFi). Using financial sector reports, cybersecurity incident databases, and DeFi security audits, we analyze compliance with NIST CSF, ISO/IEC 27001, and PCI-DSS alongside factors such as bank size, IT security investments, and regulatory fines to determine their impact on cyber resilience. Logistic regression results indicate that compliance with cybersecurity frameworks reduces cyberattack likelihood (p = 0.0689, marginally significant), while larger institutions face fewer threats (p = 0.0256, statistically significant). However, increased IT security budgets paradoxically correlate with higher attack frequencies (p = 0.0385, statistically significant), suggesting larger attack surfaces may offset security investments. In contrast, DeFi faces disproportionately higher smart contract exploits, flash loan attacks, and oracle manipulation, leading to significantly greater financial losses (F = 216.92, p < 0.001, highly significant) than traditional banking cyber incidents. Regulatory compliance and industry collaboration show promise in reducing attack occurrences, with cyber incidents projected to decline by over 40% by 2029 under stricter enforcement. However, traditional frameworks are insufficient for DeFi’s decentralized structure, necessitating AI-driven threat detection, mandatory smart contract audits, secure oracle mechanisms, and adaptive regulatory frameworks. This study highlights the urgent need for tailored DeFi cybersecurity strategies while reinforcing the effectiveness of compliance-driven models in banking. It provides actionable insights for financial institutions, regulators, and cybersecurity professionals seeking to enhance resilience across centralized and decentralized financial systems.

Open access
2 source records
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Information and Cyber Security
Original source
Dec 29, 2024¡Laws
1 cites
Cryptocurrencies as a Threat to U.S. Homeland Security Interests

Austen D. Givens

The use of cryptocurrencies in transnational criminal activities has grown in recent years. The scholarly literature on cryptocurrencies recognizes this trend. Yet, there has been comparatively little attention paid to the degree to which cryptocurrencies pose a direct threat to U.S. homeland security interests. This article fills a gap in the scholarly literature on cryptocurrencies by presenting evidence that cryptocurrencies are a threat to U.S. homeland security interests, specifically because of their uses for financing terrorism, enabling human and drug trafficking, and evading international financial sanctions.

Open access
Crime, Illicit Activities, and Governance
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Original source
Dec 27, 2024¡Journal of Economic Criminology
7 cites
Metaverse crimes in virtual (Un)reality: Fraud and sexual offences under English law

Andreas Karapatakis

The technological evolution has not only opened new frontiers but has also become an indispensable part of our daily lives. However, the technology that enhances our lives presents a dual reality—it offers opportunities for criminals while creating challenges for law enforcement. Fraud, particularly, has become a pervasive issue. In response, virtual asset service providers must take measures to tackle cryptocurrency-related fraud. Nevertheless, this becomes challenging if the perpetrator exists solely within the virtual world. In 1992, Neal Stephenson used the term ‘Metaverse’ to describe a virtual world where people interact with each other using avatars. Over time, the Metaverse has transformed into a complex concept akin to 'cyberspace'. The Metaverse is a virtual environment that uses technologies to mimic the real world. As this virtual space became intertwined with financial transactions, especially through cryptocurrencies, the Metaverse evolved into a medium for perpetrating scams. Within this context, the article addresses the challenges associated with criminal activity in the Metaverse. Considering the potential applications of AI, cryptocurrencies and Non-Fungible Tokens, three main challenges can be identified: 1) decentralisation, 2) anonymity of the user, and 3) lack of regulation. This article examines the applicability of existing legislation to regulate criminal activity in the Metaverse through doctrinal research. Using a comparative approach, it analyses the challenges of addressing virtual crimes by contrasting fraud (Fraud Act 2006) with sexual assault (Sexual Offences Act 2003), highlighting the complexity of addressing crimes involving physical contact in virtual spaces compared to financial crimes.

Open access
Sexuality, Behavior, and Technology
Law in Society and Culture
Cybercrime and Law Enforcement Studies
Original source
Dec 25, 2024¡Computer Fraud & Security
8 cites
Mitigating Financial Fraud and Cybercrime in Financial Services with Security Protocols and Risk Management Strategies

K P N V Satya Sree

This present study demonstrates the new methods of preventing financial fraud and cybercrime with the integration of blockchain technology in finance services from a regulatory framework, such as GDPR and PCI DSS. Blockchain provides decentralized and immutable ledger qualities which add to transparency and security in transactions, while GDPR and PCI DSS ensure strict compliance with standards for data protection. The proposed approach demonstrates a significant advantage in fraud detection, reduction of data breaches, and compliance efficiency and offers a robust framework for securing financial services in the digital era.

Open access
Cybercrime and Law Enforcement Studies
Blockchain Technology Applications and Security
Original source
Dec 21, 2024¡Computer Fraud & Security
0 cites
Exploring the Role of Blockchain in Preventing Cyber Fraud in Financial Systems

Rupali Gangarde

Blockchain technology plays a pivotal role in enhancing the security of financial systems, providing a robust framework to prevent cyber fraud. As cyber threats in financial transactions escalate, blockchain's decentralized and tamper-resistant nature offers an innovative solution for fraud mitigation. By leveraging distributed ledger technology (DLT), blockchain ensures transparency, traceability, and immutability in transactions, significantly reducing the risk of unauthorized alterations or manipulations. Smart contracts, a feature of blockchain, automate and secure transactions, minimizing human error and preventing malicious interventions. Additionally, consensus mechanisms like proof-of-work and proof-of-stake enhance security by requiring agreement from multiple nodes before validating a transaction, thus eliminating the risk of single points of failure. Financial institutions adopting blockchain can secure payment processing, authenticate identities, and prevent fraudulent activities such as double-spending or phishing attacks. Blockchain also ensures compliance with regulatory standards through real-time auditing and secure data sharing between financial entities. However, despite its advantages, challenges like scalability and regulatory acceptance remain. This paper explores the potential of blockchain in preventing cyber fraud within financial systems, highlighting its impact on security, trust, and fraud detection, while addressing existing challenges in adoption and implementation.

Open access
Blockchain Technology Applications and Security
FinTech, Crowdfunding, Digital Finance
Cybercrime and Law Enforcement Studies
Original source
Dec 19, 2024¡Journal Of Social Research
1 cites
Reform of Law Enforcement to Strengthen the Legal System in Eradicating Money Laundering Through Cryptocurrency Investments

Rusman Rusman, Zudan Arief Fakrulloh

Cryptocurrency investments are rapidly developing worldwide, including in Indonesia. Behind its profit potential, digital assets also open opportunities for criminals to commit money laundering offenses. The anonymity, pseudonymity, and decentralization of blockchain technology underlying cryptocurrencies create challenges for law enforcement in tracking illegal activities that exploit these assets. This study aims to examine the role of existing regulations in preventing the use of digital assets as a means of money laundering and to identify the challenges faced by law enforcement in enforcing rules against suspected cryptocurrency transactions. The research will analyze the extent to which the existing regulations, both at the national and international levels, are effective in preventing the use of cryptocurrencies for money laundering crimes. The second subtitle will explore various technical and legal constraints faced by law enforcement, including the lack of international cooperation, limitations of monitoring technology, and the low level of technical expertise among law enforcement officials.

Open access
Crime, Illicit Activities, and Governance
Cybercrime and Law Enforcement Studies
Wildlife Conservation and Criminology Analyses
Original source
Dec 18, 2024¡Journal of Geography Politics and Society
2 cites
Cybercrimes in the cryptocurrency domain: identifying types, understanding motives and techniques, and exploring future directions for technology and regulation

Shobhit Navani, Giuseppe T. Cirella

Cryptocurrency has emerged as a lucrative yet volatile landscape for cybercriminal activity, presenting novel challenges for law enforcement and policymakers alike. This review seeks to explore the diverse array of cybercrimes occurring within the cryptocurrency domain, examining their types, motives, techniques, and the regulatory responses shaping this complex ecosystem. Utilizing a scoping literature search methodology, this study analyzes 228 pertinent sources drawn from a pool of over 4,000 reviewed publications. The findings elucidate the intricate interplay between cryptocurrencies and illicit activities, revealing the multifaceted nature of cybercrimes within this realm. From the exploitation of the dark web for illicit transactions to the pervasive threat of crypto ransomware targeting entities globally, the review underscores the diverse methods and motivations driving such nefarious endeavors. By shedding light on the evolving tactics employed by cybercriminals and exploring future directions for technological and regulatory measures adopted by governments, this paper offers valuable insights to navigate this dynamic landscape effectively.

Open access
Cybercrime and Law Enforcement Studies
Law, AI, and Intellectual Property
Digital and Cyber Forensics
Original source
Dec 14, 2024¡arXiv
4 cites
Serial Scammers and Attack of the Clones: How Scammers Coordinate Multiple Rug Pulls on Decentralized Exchanges

Phuong Duy Huynh, Son Hoang Dau, Nicholas Huppert, Joshua Cervenjak ¡ 8 authors

We explored the ubiquitous phenomenon of serial scammers, each of whom deployed dozens to thousands of addresses to conduct a series of similar Rug Pulls on popular decentralized exchanges. We first constructed two datasets of around 384,000 scammer addresses behind all one-day Simple Rug Pulls on Uniswap (Ethereum) and Pancakeswap (BSC), and identified distinctive scam patterns including star, chain, and major (scam-funding) flow. These patterns, which collectively cover about $40\%$ of all scammer addresses in our datasets, reveal typical ways scammers run multiple Rug Pulls and organize the money flow among different addresses. We then studied the more general concept of scam cluster, which comprises scammer addresses linked together via direct ETH/BNB transfers or behind the same scam pools. We found that scam token contracts are highly similar within each cluster (average similarities $>70\%$) and dissimilar across different clusters (average similarities $<30\%$), corroborating our view that each cluster belongs to the same scammer/scam organization. Lastly, we analyze the scam profit of individual scam pools and clusters, employing a novel cluster-aware profit formula that takes into account the important role of wash traders. The analysis shows that the existing formula inflates the profit by at least $32\%$ on Uniswap and $24\%$ on Pancakeswap.

Open access
2 source records
cs.CR
Blockchain Technology Applications and Security
Spam and Phishing Detection
Original source
Dec 13, 2024¡Proceedings of the 2024 the 12th International Conference on Information Technology (ICIT)
1 cites
Exploring GCN, GAT, and GIN Fusion for Illicit Transaction Classification in Cryptocurrency Networks

Gaoxuan Li, Xinyu Tang

The rise of blockchain and cryptocurrency networks has fueled financial innovation, yet it also presents new opportunities for illicit activities such as fraud and money laundering. Traditional detection approaches struggle with the non-Euclidean, large-scale nature of cryptocurrency transaction networks. Graph Neural Networks offer a promising solution for capturing complex relational data. This paper proposes four fusion architectures—Triple Parallel Layer, Hierarchical Staging, Attention-Weighted Residual Fusion, and Multi-View Feature Aggregation—combining Graph Convolutional Network, Graph Attention Network, and Graph Isomorphism Network to enhance classification of illicit transactions. Experiments on the Elliptic Bitcoin dataset show that the proposed models achieve classification accuracies up to 97.17%, significantly outperforming standalone Graph Convolutional Network, Graph Attention Network, and Graph Isomorphism Network models. These results underscore the superior performance and robustness of the fusion architectures, with improvements in accuracy ranging from 1.1% to 2.9% over individual models, marking a step forward in financial crime detection within decentralized networks.

Open access
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Crime, Illicit Activities, and Governance
Original source
Dec 12, 2024¡Sustainability
12 cites
Managing Digital Evidence in Cybercrime: Efforts Towards a Sustainable Blockchain-Based Solution

Md. Hasibul Alam Ratul, Sepideh Mollajafari, MartĂ­n Wynn

Digital evidence plays a crucial role in cybercrime investigations by linking individuals to criminal activities. Data collection, preservation, and analysis can benefit from emerging technologies like blockchain to provide a secure, distributed ledger for managing digital evidence. This study proposes a blockchain-based solution for managing digital evidence in cybercrime cases in the judicial domain. The proposed solution provides the basis for the development of a new model that leverages a consortium blockchain, allowing secure collaboration among judicial stakeholders, while ensuring data integrity and admissibility in court. An extensive literature review demonstrates blockchain’s potential to create a more secure, efficient evidence management system. The proposed model was implemented in a test environment using a localised blockchain for developing and testing smart contracts, as well as integrating a web interface, with off-chain storage for managing evidence data. The system was subsequently deployed in both the Polygon and Ethereum test networks, simulating real-world blockchain environments, revealing that the operational cost in the Polygon network is reduced by 99.96% compared to Ethereum, thereby offering scalability without compromising security. This study underscores blockchain’s potential to revolutionise the chain of custody procedures, improving dependability and security in evidence management and providing more sustainable solutions within the criminal justice system.

Open access
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Ethics and Social Impacts of AI
Original source
Dec 12, 2024¡IEEE Transactions on Visualization and Computer Graphics
2 cites
PonziLens+: Visualizing Bytecode Actions for Smart Ponzi Scheme Identification

Xiaolin Wen, Tai D. Nguyen, Shaolun Ruan, Qiaomu Shen ¡ 7 authors

With the prevalence of smart contracts, smart Ponzi schemes have become a common fraud on blockchain and have caused significant financial loss to cryptocurrency investors in the past few years. Despite the critical importance of detecting smart Ponzi schemes, a reliable and transparent identification approach adaptive to various smart Ponzi schemes is still missing. To fill the research gap, we first extract semantic-meaningful actions to represent the execution behaviors specified in smart contract bytecodes, which are derived from a literature review and in-depth interviews with domain experts. We then propose PonziLens+, a novel visual analytic approach that provides an intuitive and reliable analysis of Ponzi-scheme-related features within these execution behaviors. PonziLens+ has three visualization modules that intuitively reveal all potential behaviors of a smart contract, highlighting fraudulent features across three levels of detail. It can help smart contract investors and auditors achieve confident identification of any smart Ponzi schemes. We conducted two case studies and in-depth user interviews with 12 domain experts and common investors to evaluate PonziLens+. The results demonstrate the effectiveness and usability of PonziLens+ in achieving an effective identification of smart Ponzi schemes.

Open access
2 source records
cs.HC
Spam and Phishing Detection
Cybercrime and Law Enforcement Studies
Original source
Dec 9, 2024¡IEICE Transactions on Information and Systems
1 cites
Propagation-Based Code Clone Analysis for Detecting Smart Contract Vulnerability

Zhuo Zhang, Donghui Li, Kun Jiang, Ya Li ¡ 6 authors

Smart contracts are self-executing programs that operate on a blockchain. Once deployed, they cannot be altered, which introduces distinct maintenance challenges unlike those found in traditional software systems. Bugs and vulnerabilities in smart contracts have led to significant economic losses, drawing increased attention to their security. The immutability of smart contracts has made thorough security checks prior to deployment a priority. In this paper, we introduce a smart contract timestamp vulnerability detection technique PropaDT with propagation-based code clone analysis. The core idea of this technique involves using dataflow analysis based on an Abstract Syntax Tree (AST) to extract propagation chains that reveal how variables interact, potentially leading to vulnerabilities. Next, we extract code snippets based on the propagation chains and compare them with known vulnerability patterns in a database. This allows us to determine whether the tested smart contract contains a timestamp vulnerability, facilitating the detection of potential timestamp vulnerabilities in the code.

Open access
Cybercrime and Law Enforcement Studies
FinTech, Crowdfunding, Digital Finance
Law, AI, and Intellectual Property
Original source
Dec 5, 2024¡International Journal of Advanced Research in Science Communication and Technology
1 cites
Blockchain Based Police Complaint Management System

Mandar Gujalwar, Abhishek More, Vinayak Khade, Ganesh Falak ¡ 5 authors

The Police Complaint Management System (PCMS) is a decentralized application template designed to modernize the processes of lodging, tracking, and resolving complaints within law enforcement systems. Leveraging the Next.js framework, Web3 technologies, and blockchain integration, the system ensures tamper-proof complaint records, real-time updates, and enhanced transparency for citizens and authorities. By utilizing Wagmi and Ethers.js for seamless wallet connections, IPFS for decentralized evidence storage, and a user-friendly interface styled with Tailwind CSS, the PCMS provides a scalable, efficient, and accessible platform. With automated processes for complaint categorization and routing, as well as immutable blockchain records, the system fosters greater accountability and trust in public services. Built with TypeScript for reliability and enhanced with modular tools for rapid deployment, the PCMS exemplifies a modern, citizen-centric approach to grievance management, ensuring data security and operational efficiency in law enforcement agencies

Open access
Cybercrime and Law Enforcement Studies
Crime, Illicit Activities, and Governance
Crime Patterns and Interventions
Original source
Dec 3, 2024¡Information Communication & Society
0 cites
The better bandit: decentralised infrastructure, crypto-States, and the rematerialisation of virtual worlds

Kelsie Nabben, Ellie Rennie

This paper examines the role of hardware security as the basis for order in the decentralised metaverse. It does this by considering the infrastructural tools and governance practices at the heart of KONG Land, an example of a blockchain-based decentralised autonomous organisation (DAO) and decentralised physical infrastructure network (DePIN) project. KONG Land manufactures open-source microchips to create verifiable hardware that anyone can use or integrate into their own application. KONG Land’s focus on the materiality of infrastructure led them to pursue a governance model as a digital-physical, politically decentralised polity. By foregrounding the physicality and affordances of decentralised efforts to manufacture microchips, this paper shows how rematerialising digital domains leads back to questions of statehood and its purpose and provides an explanation for emerging sovereignties. Building on Olson’s (1993. Dictatorship, democracy, and development. American Political Science Review , 87 (3), 567–576) theory of the stationary bandit, the paper positions projects like KONG Land as an attempt to create a ‘better bandit’ – one that sets out to provide its citizens with a superior level of security than that offered by either nation states or the corporate metaverse, with the intention of creating the conditions for Web3 production and expansion.

Open access
2 source records
Cybersecurity and Cyber Warfare Studies
Cybercrime and Law Enforcement Studies
Digital Games and Media
Original source
Dec 2, 2024
5 cites
Derecho: Privacy Pools with Proof-Carrying Disclosures

Josh Beal, Ben Fisch

A privacy pool enables clients to deposit units of a cryptocurrency into a shared pool where ownership of deposited currency is tracked via a system of cryptographically hidden records. Clients may later withdraw from the pool without linkage to previous deposits. Some privacy pools also support hidden transfer of currency ownership within the pool. In August 2022, the U.S. Department of Treasury sanctioned Tornado Cash, the largest Ethereum privacy pool, on the premise that it enables illicit actors to hide the origin of funds, citing its usage by the DPRK-sponsored Lazarus Group to launder over $455 million dollars worth of stolen cryptocurrency. This ruling effectively made it illegal for U.S. persons/institutions to use or accept funds that went through Tornado Cash, sparking a global debate among privacy rights activists and lawmakers. Against this backdrop, we present Derecho, a system that institutions could use to request cryptographic attestations of fund origins rather than naively rejecting all funds coming from privacy pools. Derecho is a novel application of proof-carrying data, which allows users to propagate allowlist membership proofs through a privacy pool's transaction graph. Derecho is backwards-compatible with existing Ethereum privacy pool designs, adds no overhead in gas costs, and costs users only a few seconds to produce attestations.

Open access
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Privacy-Preserving Technologies in Data
Original source
Nov 27, 2024¡ACM Distributed Ledger Technologies: Research and Practice, 2025
1 cites
Proving and Rewarding Client Diversity to Strengthen Resilience of Blockchain Networks

Javier Ron, Zheyuan He, Martin Monperrus

Client diversity is a cornerstone of blockchain resilience, yet most networks suffer from a dangerously skewed distribution of client implementations. This monoculture exposes the network to very risky scenarios, such as massive financial losses in the event of a majority client failure. In this article, we present a novel framework that combines verifiable execution and economic incentives to provably identify and reward the use of minority clients, thereby promoting a healthier, more robust ecosystem. Our approach leverages state-of-the-art verifiable computation (zkVMs and TEEs) to generate cryptographic proofs of client execution, which are then verified on-chain. We design and implement an end-to-end prototype of verifiable client diversity in the context of Ethereum by modifying the popular Lighthouse client and by deploying our novel diversity-aware reward protocol. Through comprehensive experiments, we quantify the practicality of our approach, from overheads of proof production and verification to the effectiveness of the incentive mechanism. This work demonstrates, for the first time, a practical and economically viable path to encourage and ensure provable client diversity in blockchain networks. Our findings inform the design of future protocols that seek to maximize the resilience of decentralized systems.

Open access
2 source records
cs.SE
cs.CR
Blockchain Technology Applications and Security
Original source
Nov 26, 2024¡arXiv (Cornell University)
0 cites
Assessing Vulnerability in Smart Contracts: The Role of Code Complexity Metrics in Security Analysis

Masoud Jamshidiyan Tehrani

Software built on poor structural patterns often shows higher exposure to security defects. When code differs from established best practices, verification and maintenance become increasingly difficult, thereby raising the risk of unintentional vulnerabilities. In the context of blockchain technology, where immutable smart contracts handle high-value transactions, the need for strict security assurance is important. This research analyzes the utility of software complexity metrics as diagnostic tools for identifying vulnerable Solidity smart contracts. We evaluate the hypothesis that complexity measures serve as vital, complementary signals for security assessment. Through an empirical examination of 21 distinct metrics, we analyzed their inter-dependencies, statistical association with vulnerabilities, and discriminative capabilities. Our findings indicate a significant degree of redundancy among certain metrics and a relatively low correlation between any single metric and the presence of vulnerabilities. However, the data demonstrates that these metrics possess strong power to distinguish between secure and vulnerable code when analyzed collectively. Notably, with only three exceptions, vulnerable contracts consistently exhibited higher mean complexity scores than their neutral counterparts. While our results show a statistical association, we emphasize that complexity is an indicator rather than a direct cause of vulnerability.

Open access
2 source records
cs.CR
cs.SE
Cybercrime and Law Enforcement Studies
Original source
Nov 22, 2024¡Investment Analysts Journal
5 cites
Gender preferences in cryptocurrency systems: Sentiment analysis and predictive modelling

Samer Muthana Sarsam, Ahmed Ibrahim Alzahrani, Hosam Al‐Samarraie, Fahad Alblehai

This study explored the role of gender preferences in cryptocurrency investments using sentiment analysis. X (Twitter) users’ gender (male/female) together with relevant sentiments (positive/negative) were extracted and investigated in this study. The Latent Dirichlet Allocation technique was utilised to model gender-related topics in an attempt to understand male and female users’ preferences to invest in cryptocurrency. The Apriori algorithm was employed to predict the highly associated investment terminologies with each gender. A predictive model was built to predict the type of digital currency preferred by X users. Using sentiment-based gender data, the results showed a high prediction accuracy (98.64%) of digital currency preferences. The study demonstrated that male users would most likely use Bitcoin, compared to female users who preferred Ethereum. This study further offers a novel mechanism to predict users’ preferences for cryptocurrency platforms using their sentiment features. It extends the knowledge of cryptocurrencies in the financial business profile by revealing how investors’ gender contributes to investment-related decisions.

Open access
Opinion Dynamics and Social Influence
Spam and Phishing Detection
Cybercrime and Law Enforcement Studies
Original source
Nov 22, 2024¡Electronics
6 cites
MultiTagging: A Vulnerable Smart Contract Labeling and Evaluation Framework

Shikah J. Alsunaidi, Hamoud Aljamaan, Mohammad Hammoudeh

Identifying vulnerabilities in Smart Contracts (SCs) is crucial, as they can lead to significant financial losses if exploited. Although various SC vulnerability identification methods exist, selecting the most effective approach remains challenging. This article examines these challenges and introduces solutions to enhance SC vulnerability identification. It introduces MultiTagging, a modular SC multi-labeling framework designed to overcome limitations in existing SC vulnerability identification approaches. MultiTagging automates SC vulnerability tagging by parsing analysis reports and mapping tool-specific tags to standardized labels, including SC Weakness Classification (SWC) codes and Decentralized Application Security Project (DASP) ranks. Its mapping strategy and the proposed vulnerability taxonomy resolve tool-level labeling inconsistencies, where different tools use distinct labels for identical vulnerabilities. The framework integrates an evaluation module to assess SC vulnerability identification methods. MultiTagging enables both tool-based and vote-based SC vulnerability labeling. To improve labeling accuracy, the article proposes Power-based voting, a method that systematically defines voter roles and voting thresholds for each vulnerability. MultiTagging is used to evaluate labeling across six tools: MAIAN, Mythril, Semgrep, Slither, Solhint, and VeriSmart. The results reveal high coverage for Mythril, Slither, and Solhint, which identified eight, seven, and six DASP classes, respectively. Tool performance varied, underscoring the impracticality of relying on a single tool to identify all vulnerability classes. A comparative evaluation of Power-based voting and two threshold-based methods—AtLeastOne and Majority voting—shows that while voting methods can increase vulnerability identification coverage, they may also reduce detection performance. Power-based voting proved more effective than pure threshold-based methods across all vulnerability classes.

Open access
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Spam and Phishing Detection
Original source
Nov 7, 2024¡Distributed Ledger Technologies Research and Practice
1 cites
A Comparative Evaluation of Deep Learning Techniques for Smart Contract Vulnerability Classification

Martina Rossini, Stefano Ferretti

Smart contracts are self-executing digital contracts that run on a blockchain network. They enable the automation and decentralization of various operations and have become increasingly popular in recent years. However, smart contracts are susceptible to vulnerabilities, and their deployment without proper security testing can result in severe consequences, such as financial losses and reputational damage. In this article, we explore the use of deep learning techniques, particularly Convolutional Neural Networks (CNNs), for detecting and classifying vulnerabilities in smart contracts deployed on the Ethereum main net. We compare different kinds of neural architectures, i.e., a baseline LSTM, multiple 1D CNNs working on the smart contracts’ bytecode, a Vision Transformer (Swin v2 Tiny), and various 2D CNNs that work on RGB images obtained from the bytecode (i.e., ResNet-50, ResNeXt-50, Inception v3, and EfficientNetv2 Small). We provide an in-depth analysis of these techniques to classify a dataset of smart contracts we have collected. Our study shows that the use of deep neural networks can represent a promising technique to automatically assess smart contracts’ correctness and classify potential vulnerabilities. According to our experiments, the ResNet 1D CNN working directly on the smart contract bytecode offers the best results in terms of classification capabilities. Moreover, due to the unbalanced sizes of the different classes, the classification resulted in more effectiveness for the unchecked calls and reentrancy vulnerability classes while still providing good results for others.

Open access
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Insurance and Financial Risk Management
Original source
Oct 28, 2024¡IEEE Transactions on Dependable and Secure Computing
3 cites
Interaction-Aware Vulnerability Detection in Smart Contract Bytecodes

Wenkai Li, Xiaoqi Li, Yingjie Mao, Yuqing Zhang

The detection of vulnerabilities in smart contracts remains a significant challenge. While numerous tools are available for analyzing smart contracts in source code, only about 1.79% of smart contracts on Ethereum are open-source. For existing tools that target bytecodes, most of them only consider the semantic logic context and disregard function interface information in the bytecodes. In this paper, we propose COBRA, a novel framework that integrates semantic context and function interfaces to detect vulnerabilities in bytecodes of the smart contract. To our best knowledge, COBRA is the first framework that combines these two features. Moreover, to infer the function signatures that are not present in signature databases, we propose SRIF, automatically learn the rules of function signatures from the smart contract bytecodes. The bytecodes associated with the function signatures are collected by constructing a control flow graph (CFG) for the SRIF training. We optimize the semantic context using the operation code in the static single assignment (SSA) format. Finally, we integrate the context and function interface representations in the latent space as the contract feature embedding. The contract features in the hidden space are decoded for vulnerability classifications with a decoder and attention module. Experimental results demonstrate that SRIF can achieve 94.76% F1-score for function signature inference. Furthermore, when the ground truth ABI exists, COBRA achieves 93.45% F1-score for vulnerability classification. In the absence of ABI, the inferred function feature fills the encoder, and the system accomplishes an 89.46% recall rate.

Open access
2 source records
Blockchain Technology Applications and Security
Privacy-Preserving Technologies in Data
Cybercrime and Law Enforcement Studies
Original source