Sybil attacks remain a primary challenge for Proof-of-Stake (PoS) blockchain systems, as low-cost identity creation can distort validator participation and limit consensus reliability. This study proposes a hybrid participationâgovernance framework that integrates Attribute-Based Access Control (ABAC) and Reputation-Based Access Control (RpBAC) with a trust-based PoS workflow to reduce the influence of suspicious identities during validator selection and block validation. The proposed framework also incorporates graylisting and dynamic rewardâpenalty updates to support adaptive participation control. The strategy was evaluated in a simulation environment informed by Ethereum-derived block metadata, using network sizes ranging from 100 to 1000 nodes and Sybil attack ratios of 30%, 40%, and 50%. Its performance was compared with PoS-only and PoS + ABAC baselines using both security and performance indicators. The results show that the full ABAC + RpBAC configuration achieved the strongest and most stable security performance across the evaluated settings while introducing additional overhead at larger network sizes. These findings suggest that combining policy-based eligibility control with behavior-based reputation control strengthens the resilience against Sybil in PoS-like blockchain environments. However, this improvement requires a measurable trade-off between security and performance.
Aleksei Adadurov, Sergey Barseghyan, Anton Chtepine, Antero Eloranta ¡ 6 authors
Ethereum block builders run sealed auctions among searchers, but nothing in the protocol forces a builder to honor the auction outcome after observing submitted bundles. This paper studies the commitment problem. We model a builder who defects with probability $\varepsilon$ and, upon defection, replicates a type-specific fraction $Îł(Ď)$ of the winning MEV opportunity. Searchers anticipate this behavior and choose between a risky first-price bid and a safe deterrence bid that makes frontrunning unprofitable. The resulting equilibrium is piecewise, with the cost of imperfect commitment depending jointly on replicability and competition. Using the libMEV dataset, we estimate $Îł(Ď)$ from right-tail bribe plateaus and decompose observed auction revenue against the surplus a defecting builder could capture. The results show sharp heterogeneity across MEV types: sandwich opportunities are already highly competitive, while naked arbitrage and liquidations leave substantially more surplus exposed to builder defection. Credible MEV auctions, therefore, require not only an auction format, but also constraints on the builder's ability to use observed bid and payload information ex post.
ABSTRACT TRSP Digital Coin (TDC) â The Next Evolution of Digital Currency: Quantum-Permanent, Physically Unbreakable, Theft-Proof by Physics Built on: Temporal Rotation Security Protocol (TRSP) v3, DOI: 10.5281/zenodo.20324081. First public documentation: May 2026. TDC is not a replacement for Bitcoin, Ethereum, or any existing digital currency. It is the next evolutionary step for the entire field â the first digital currency architecture whose security is grounded not in mathematical complexity but in physical law. Every existing digital currency rests on one assumption: that breaking the cryptographic protection requires more computational resources than any adversary possesses. Quantum computing is dismantling this assumption. Harvest-now-decrypt-later attacks mean every blockchain transaction recorded today remains permanently vulnerable to any future computational advance. TDC responds with a different premise: a signing key that no longer exists cannot be recovered by any computation, quantum or classical, regardless of future advances. TDC inherits the temporal rotation architecture of TRSP v3. Transaction signing keys rotate every 10â100 milliseconds from physical hardware entropy and are permanently destroyed after each rotation. CRATON-anchored ownership proof replaces persistent private key storage: ownership is demonstrated through a one-time physical commitment derived from the unique state of the signing device at transaction time â used once, permanently destroyed, impossible to forge, impossible to extract, impossible to replay. Three attack paths are structurally closed: private key extraction (no stored key exists), quantum key recovery (key destroyed before computation converges), and harvest-now-decrypt-later (signing key permanently gone â no target for any future computation). Part 9 (Identity Without Storage) documents a five-factor distributed identity architecture in which no single factor and no single location holds everything required to authorise a transaction: biometric presence; primary device CRATON anchor; memorised PIN with distress code variant; Remote Guardian Device in a separate geographic location; and time lock with geo-anchor. The distress PIN architecture triggers a silent alert and time-delayed freeze while providing apparent confirmation to an adversary â making the coercion attack structurally ineffective. Wallet recovery requires no seed phrase: a five-step multi-factor re-enrollment protocol using biometric presence, guardian confirmation, and a 72-hour cancellation window replaces the stored backup phrase that represents the primary theft surface of every existing wallet. Part 10 (Real Identity Enrollment) documents a biometric enrollment architecture that exceeds current KYC bank account standards: NFC chip reading of government-issued documents (cryptographic verification against issuing government public key â not photo or scan), live 3D facial biometric with active liveness detection, all-finger fingerprint enrollment, and a CRATON physical moment binding that ties the enrollment to the unique physical state of the enrollment device at that exact moment. Raw biometric data is deleted after enrollment â only a non-reversible binding token is retained. Identity is distributed across three separately held, individually insufficient components: Enrollment Authority, blockchain, and device. No single party holds all three. Legitimate financial privacy is preserved. The enrollment barrier is structurally higher than any existing digital currency. AML, KYC, GDPR, FATF Travel Rule, and sanctions compliance are structural properties, not regulatory overlays. Part 12 (Implementation Roadmap) documents a four-phase deployment pathway modelled on pharmaceutical clinical trial methodology. Phase 1 (Year 1â2): proof of concept with small high-security institutions â private banks, family offices, university research groups â using software-only TRSP daemon and TEE-based CRATON. Phase 2 (Year 2â4): institutional pilot with mid-size financial institutions and government treasury departments â dedicated CRATON hardware module, Remote Guardian architecture, orbital quorum activated above threshold. Phase 3 (Year 3â5): national pilot with CBDC programmes and full jurisdiction regulatory validation â complete five-factor identity, consumer enrollment refined at national scale. Phase 4 (Year 5â10): global rollout â CRATON chip standardisation licensable to semiconductor manufacturers, TLS 1.3 extension standardised through IETF, "Secured by TDC" certification programme. Each phase generates performance data that validates and de-risks the subsequent phase. The worst outcome at any phase is a parameter adjustment â no user loses funds, no system collapses. Part 13 (Digital Estate Architecture) addresses the inheritance problem that every existing digital currency has left unsolved: what happens to assets when the owner dies. Three mechanisms work together. Designated Heir Enrollment: heirs are biometrically pre-registered at wallet setup â enrolled but cryptographically inactive during the owner's lifetime, with no access to balance or transaction history. Death Verification Protocol: succession requires three simultaneous conditions â official government-issued death certificate verified by the Enrollment Authority, 2-of-N Remote Guardian confirmation, and a mandatory 90-day waiting period during which the owner can cancel with biometric presence. Dead Man's Switch: an optional owner-defined inactivity window that triggers Guardian alerts and initiates the succession protocol if neither owner nor Guardian responds within the alert window. For owners without designated heirs: charitable designation to enrolled organisations, institutional estate trustee, or deliberate coin retirement. Owner financial privacy is maintained completely during lifetime. Post-succession historical access is configurable by the owner at setup. Novel contribution NC-TDC-17 is placed on the public record as defensive prior art. Privacy architecture clarification: the default state of every TDC wallet is complete financial anonymity. Identity disclosure is exclusively owner-initiated â the owner may selectively disclose individual transactions for tax certification, charitable donation receipts, regulatory compliance, or proof of funds. No court order, no government authority, and no institution can access wallet identity or transaction history without the owner's willing biometric participation. The three-part distributed binding token architecture makes bypass technically impossible â not merely legally prohibited. This is not a policy decision. It is a physical property of the architecture enforced by the requirement for live owner biometric activation of the device component. Novel contributions NC-TDC-13 (Geographic Coercion Evidence Layer), NC-TDC-14 (Phased Validation Rollout Architecture), NC-TDC-15 (Owner-Controlled Selective Disclosure), NC-TDC-16 (Enrollment-Anchored Privacy Architecture), and NC-TDC-17 (Digital Estate Architecture) are hereby placed on the public record as defensive prior art. Novel contributions NC-TDC-1 through NC-TDC-17 are placed on the public record as defensive prior art: quantum-permanent transaction signing; CRATON-anchored ownership proof; Generation 4 digital currency architecture; five-factor distributed identity; distress PIN with silent alert; Remote Guardian Device architecture; seed-phrase-free recovery protocol; biometric-CRATON enrollment binding; privacy-preserving three-part identity distribution; AML/KYC compliance by architecture; tiered enrollment framework; orbital CRATON quorum for sovereign transfers. The architectural frameworks described in this concept represent technical design guidelines only and are not legal advice, regulatory guidance, or binding specifications. Actual implementation in any jurisdiction will require adaptation to applicable local law including inheritance law, data protection regulation, anti-money laundering legislation, and financial services licensing requirements. Version 2 introduces four formal additions. Mathematical Formalization (Part 6.1.5): the transaction pipeline is formally specified as a four-step ephemeral verification protocol â KDF ephemeral key generation from physical entropy (sk_eph, pk_eph) = KDF(E_phys); Non-Interactive Zero-Knowledge Proof binding the ephemeral public key to the enrollment token without exposing persistent identity credentials; hardware-enforced destructive readout with thermodynamic irreversibility anchored in Landauer's Principle (ÎW ⼠n¡k_B¡T¡ln2); and deterministic public-parameter-only ledger validation. Formal Threat Model (Part 4.5): three adversary classes formally defined â quantum network attacker (A_network, unbounded computational resources), malware/hardware attacker (A_local, full OS compromise), and coercion attacker (A_kinetic, physical duress) â with security proofs against each. Part 7b (AI-to-AI Micropayment Architecture, NC-TDC-21) documents the application of TDC quantum-permanent transaction signing to autonomous AI agent commerce. Every existing AI payment mechanism â static API keys, server-stored crypto wallets, centralised billing â represents a permanent credential attack surface vulnerable to quantum decryption. TDC coin eliminates this: each AI-to-AI transaction generates a CRATON commitment from the hardware entropy of the transacting inference node at that exact millisecond, used once to sign the micropayment and immediately destroyed. No stored credential on any server. Five new markets are documented: pay-per-inference settlement (USD 50B+ annual market), CRATON-anchored API key replacement, autonomous multi-agent revenue distribution at service delivery, AI training data micropayments for individual contributions, and cross-agent behavioural monitoring via the AI Guardian Layer at machine speed. The AI Guardian Layer (NC-TDC-19) monitors t
Ankit Sitaula, Ashraf Uddin, John Ayoade, Nam H. Chu ¡ 5 authors
Counterfeit and unsafe medicines pose significant risks to patient safety and undermine trust in healthcare systems. This paper presents ACTMeds, a blockchain-supported pharmaceutical traceability and recall platform that considers pharmaceutical supply chain requirements and public health operational needs relevant to the Australian Capital Territory (ACT). The system integrates Ethereum smart contracts, developed using Ganache, with a React-based web application providing regulator, operator, pharmacy, and auditor interfaces, alongside a public verification portal leveraging QR and GS1 barcodes. In addition, role-based access control is enforced across the medicine lifecycle, including manufacture, custody transfer, dispensing, and recall, with immutable on-chain events generated to support auditability and accountability. To balance transparency with confidentiality, the platform prototypes a zero-knowledge (ZK) recall mechanism in which regulators can cryptographically prove that recall conditions meet predefined policy requirements without disclosing sensitive incident details. Threat modeling was conducted using the STRIDE framework, and security evaluation combined static application security testing (Solhint and ESLint) and dynamic testing. The paper further discusses deployment options, cost considerations, ZK recall performance analysis, ethical implications, and future enhancements. Security testing validated the platformâs resilience, with no high-severity vulnerabilities identified and medium-severity issues related to HTTP security headers addressed. The results indicate that a regulator-led, privacy-preserving, tamper-evident ledger can improve medicine authenticity verification and recall responsiveness while maintaining compliance and data protection obligations.
Muhammad Farooq Shaikh, Muhammad Saad Iqbal, Davide Piaggio
Introduction Public-sector grant disbursement and fundraising systems are vulnerable to corruption due to limited transparency, weak auditability, unauthorized approvals, and poor traceability of financial transactions. This study proposes a blockchain-based framework to improve accountability and monitoring in public financial management. Methods An Ethereum-compatible ERC-20 test network was used to develop a blockchain-enabled architecture integrating smart contracts, decentralized application (DApp) components, and a Proof-of-Authority (PoA)-based governance mechanism. The framework was evaluated using simulation-based testing, transaction validation scenarios, corruption-detection workflows, and indicative gas-cost analysis under controlled conditions. Results The proposed framework enabled tamper-resistant audit trails, timestamping, and end-to-end traceability of grant transactions. A hierarchical governance model incorporating multi-level institutional approvals reduced unilateral control and improved transaction accountability. Simulation-based evaluation demonstrated improved transparency, auditability, and transaction monitoring efficiency, while maintaining relatively low indicative gas costs. Discussion The findings suggest that blockchain-supported governance mechanisms may strengthen transparency and accountability in public-sector financial systems under controlled conditions. The proposed framework demonstrates the potential of combining institutional governance structures with blockchain-based validation to support secure and traceable grant management and fundraising processes.
Abstract The traditional Byzantine quorum-system model assumes a pre-existing, global agreement on the set of quorums (typically defined as the sets consisting of more than two-thirds of the participants). This assumption is problematic in permissionless systems, which strive to allow anyone to join or leave the system dynamically. While proof-of-stake permissionless systems like Ethereum require newly joining participants to register into the system, other permissionless systems like the Ripple Ledger or the Stellar network allow participants to join the system without synchronization by forgoing agreement on the set of quorums. This results in what we call a heterogeneous quorum system, where each participant has its own, personal set of quorums. An important question is to determine under what condition is it possible to solve synchronization problems like reliable broadcast or consensus in a heterogeneous quorum system. In this work, we show that the traditional quorum intersection and quorum availability conditions are not sufficient in heterogeneous quorum systems. Moreover, we propose quorum subsumption, a new condition which, together with quorum availability and quorum intersection, is sufficient to allow solving reliable broadcast and consensus. Finally, we propose protocols for reliable broadcast and consensus in heterogeneous quorum systems that satisfy quorum subsumption. In particular, we present a practical consensus protocol called Satrapy which in contrast to abstract consensus protocols uses finite state and messages.
Penelitian ini berfokus pada pengembangan framework autentikasi tanpa kata sandi (passwordless) berbasis Web3 yang diimplementasikan pada platform mobile guna mengatasi kerentanan metode tradisional terhadap serangan phishing dan brute force. Framework yang diusulkan mengintegrasikan aplikasi mobile dengan backend Node.js/Express.js dan smart contract standar ERC-5192 pada jaringan Ethereum Sepolia Testnet sebagai representasi identitas digital Soulbound Tokens (SBT) yang permanen dan non-transferable. Demi menjaga privasi, sistem ini menerapkan teknologi Zero-Knowledge Proof (ZKP) berbasis zk-SNARKs skema Groth16 menggunakan Circom dan SnarkJS yang dieksekusi di sisi klien (client-side browser) menggunakan WebAssembly (WASM), serta dipadukan dengan struktur data Merkle Tree tingkat kedalaman 20 dan mekanisme nullifier untuk mencegah replay attack. Hasil pengujian menunjukkan tingkat keberhasilan autentikasi mencapai 100% dari 50 kali percobaan. Pemindahan beban komputasi sirkuit ZKP (5.359 konstrain) ke sisi klien terbukti efisien dengan waktu eksekusi komputasi lokal jika diakumulasikan dari tahap awal koneksi wallet (0,8 detik), pembuatan witness (1,2 detik), pembuatan proof (4,8 detik), hingga verifikasi smart contract (210 ms), maka Total Authentication Time adalah sebesar 6,3 detik. Nilai ini membuktikan kelayakan framework ini sebagai solusi manajemen identitas yang aman, privat, dan responsif.
Ivan Vynyavskyy, Stefan Kitzler, Bernhard Haslhofer, Aviv Yaish
Modern Portfolio Theory (MPT) prescribes how to maximise the return of an asset portfolio for a given level of risk. The optimal trade-off between return and variance defines the efficient frontier. Whether actual cryptoasset portfolios approximate this prescription and whether proximity to the frontier translates into realised performance remain difficult to test at large scale in traditional markets due to their opaque nature and the inaccessibility of data. As we show, public blockchains make these questions measurable: every token transfer is recorded, thus enabling complete portfolio reconstruction for every account at any point in time. We leverage this transparency to reconstruct cryptoasset portfolios for over 116M Ethereum accounts across the full chain history (2015-2025), measure their distance to the constrained efficient frontier, and quantify how deviations translate into realised performance. Here we show that market entry timing, not allocation choice, is the dominant predictor of realised cryptoasset returns. On-chain wealth is highly concentrated and portfolios are pervasively under-diversified, with single-asset holdings accounting for 83.35% of accounts. Two-asset portfolios sit closest to the efficient frontier defined by their held assets, a proximity that reflects the narrowness of their opportunity set rather than deliberate optimisation. Passive market-capitalisation weighting outperforms every MPT optimisation strategy in median realised return, and entry month alone explains 70-79% of the variance in returns, far exceeding the contribution of allocation choice. Mean-variance optimisation therefore appears neither descriptive of observed behaviour nor prescriptively useful in the cryptoasset domain, even if MPT retains its value as a normative benchmark.
Dappfort is a blockchain-focused Web3 development company that helps businesses harness the power of decentralized technologies to build secure, scalable, and future-ready digital solutions. Headquartered in Madurai, India, with additional presence in London, Dappfort works across a broad range of industries â including finance, healthcare, gaming, retail, and supply chain â delivering tailored blockchain and Web3 applications to startups, enterprises, and global organizations. The companyâs core services include the design and development of decentralized applications (DApps), crypto exchanges (centralized and decentralized), crypto wallets, NFT marketplaces, DeFi platforms, token creation, smart contract development, and enterprise Web3 integration. Dappfort also expands into related areas such as Web3 e-commerce, AI-powered blockchain solutions, and metaverse experiences, supporting clients from strategy and consulting through deployment and ongoing support. With expertise in major blockchain networks like Ethereum, Solana, Binance Smart Chain, and others, Dappfort positions itself as a full-stack partner for businesses aiming to enter or grow in the decentralized digital economy. While the company promotes a strong innovation- and security-oriented approach, external reviews on third-party platforms show mixed feedback from users about project delivery and quality.
Open access
2 source records
Internet of Things and AI
Blockchain Technology Applications and Security
Innovations and Analysis in Business and Education
Daniel GonzĂĄlez CortĂŠs, Monomita Nandy, Suman Lodh
Abstract This research analyzes the performance and interconnectedness of major global stock market indices and decentralized finance assets, specifically cryptocurrencies, over the period from 2015 to 2025. The study includes indices such as the S&P 500 and Nasdaq Composite from the United States, the FTSE 100, DAX, and CAC 40 from Europe, and the Nikkei 225 from Japan, and two more indices from China and India representing different economic regions. Additionally, Bitcoin and Ethereum are included to assess the impact of decentralized finance on traditional financial indices and asset allocation strategies. By employing Artificial Intelligence algorithms like ConvLSTM, the research measures the dynamic asset allocation and volatility management through an interconnected spillover matrix. The findings reveal that integrating ConvLSTM enhances the understanding of the interconnectedness between cryptocurrencies and traditional assets, offering improved diversification opportunities due to their low correlation, decentralization, and inflation-hedge characteristics. The studyâs results suggest that investors can make more informed decisions regarding dynamic asset allocation in high-volatility portfolios, providing indicators of rising systemic risk and market stress.
Agricultural trade in developing countries continues to depend on informal agreements, multi-tier intermediary networks, and centralized payment mechanisms, resulting in payment delays of 30â90 days, information asymmetry, and weakened bargaining power for smallholder farmers. This paper presents AgriHandshake, a blockchain-based smart contract platform enabling direct crop trading between farmers and vendors through an automated escrow payment mechanism deployed on the Ethereum network. The system employs a hybrid architecture that stores cryptographic state hashes and escrow logic onchain while offloading trade metadata and delivery documentation to the InterPlanetary File System (IPFS), reducing average transaction gas costs to approximately 85,000â210,000 gas units per operation. A Solidity-based escrow contract enforces a structured four-state machine (CREATEDâFUNDEDâDELIVEREDâCOMPLETED/DISPUTED) with a 72-hour automatic payment-release timer implemented via block.timestamp. Experimental evaluation on the Ethereum Sepolia testnet demonstrates average smart contract function execution latency under 15 seconds, end-to-end trade confirmation within 3â8 minutes including IPFS upload, and strong resistance to reentrancy and front-running attacks. Comparative analysis against eNAM, FarMarket, and AgriOnBlock confirms that AgriHandshake is the first platform to combine a dedicated escrow payment guarantee, decentralized off-chain storage, and a farmer-centric usability model within a single deployable framework
The rapid digitalization of global infrastructure has amplified the vulnerabilities inherent in centralized cloud storage systems, where single points of failure, administrative access abuses, and external cyberattacks routinely compromise sensitive data.Traditional cloud architectures rely on centralized trust models that frequently succumb to data breaches and censorship.To address these critical flaws, this paper proposes De-Drive, a zeroknowledge, hybrid decentralized storage application (DApp) that seamlessly integrates Web3 architecture with robust cryptographic protocols.De-Drive leverages a hybrid storage model: heavy file payloads are stored off-chain on the decentralized InterPlanetary File System (IPFS) via Pinata nodes, while the immutable reference links-Content Identifiers (CIDs)-are permanently logged on the Ethereum blockchain (Sepolia Testnet) utilizing a custom, highly gas-optimized Solidity smart contract.To solve the inherent privacy flaws of public IPFS networks, De-Drive implements strict client-side Advanced Encryption Standard (AES) cryptography.Files are converted to Base64 strings and encrypted locally within the React frontend utilizing a user-defined symmetric key prior to network transmission.This architecture ensures absolute zero-knowledge storage; neither the IPFS nodes hosting the data nor the blockchain observers auditing the ledger can decipher the underlying content without the specific decryption key.The proposed architecture successfully resolves the blockchain storage trilemma by delivering a decentralized, immutable, and strictly private data vault, demonstrating significant improvements in cost-efficiency and security over both traditional cloud services and purely on-chain storage alternatives.
The article examines digital financial assets as an instrument of investment portfolio diversification in the Ukrainian investment context. The study argues that Bitcoin and Ethereum should not be assessed through general statements about financial innovation, but through their measurable contribution to portfolio return, volatility and risk-adjusted performance. The empirical part is based on an annual scenario model for 2020â2025 and compares portfolios with 0%, 1%, 3%, 5% and 10% exposure to BTC and ETH. The benchmark portfolio includes domestic government bonds, the USD/UAH currency component, gold and the S&P 500 as a global equity benchmark, while the local Ukrainian equity segment is interpreted cautiously because of its limited liquidity. The results show that portfolios with 1â5% exposure to BTC and ETH improved risk-adjusted efficiency compared with the baseline portfolio. The P3 scenario provided the most balanced relationship between return growth and risk growth, while P5 generated a higher average annual return with still acceptable volatility. The P10 scenario produced the highest geometric average annual return but almost tripled volatility compared with the baseline portfolio, making it more suitable for an aggressive investor profile. The article concludes that digital financial assets may have practical value only as a limited high-risk addition to a diversified portfolio, not as a stable hedging instrument or a substitute for traditional instruments.
Every BFT consensus protocol uses collision-resistant hashes to compare validator state. Collision resistance destroys distance: two validators agreeing on 19 of 20 transactions produce unrelated hashes, indistinguishable from validators sharing nothing. This forces three design constraints across the BFT literature: validators must synchronize state before voting, agreement quality cannot be measured until votes are counted, and hierarchical committees must be large enough for independent BFT, limiting tree depth. This paper introduces distance-preserving transaction digests, a primitive that replaces collision-resistant hashes with commutative vector sums in 8-dimensional space. The primitive has three properties hashes lack: distance is proportional to disagreement, weighted means are exact, and set differences are identifiable via bloom filter diff. We demonstrate three applications: a two-phase BFT protocol (Proxima) that achieves single-round finality when validators agree; tree-structured consensus with groups of 10 validators (vs 128 in Ethereum), enabled because distance filtering replaces per-group BFT; and cross-shard consistency verification at 128 bytes per shard pair, replacing the per-transaction coordination of two-phase commit. Safety is proved: fewer than N/3 Byzantine validators cannot cause conflicting finalization, independent of Phase 1 clustering or tree topology. At N =100,000, Proxima Tree uses 2.2x fewer messages than HotStuff (a structural property unaffected by parallelism). Single-core finality is 0.9s vs 18s for HotStuff; multi-core BLS narrows but does not eliminate this gap.
Manuel Lagos RodrĂguez, Hilda Romero Velo, Ălvaro Leitao RodrĂguez, Javier Pereira Loureiro ¡ 5 authors
Ethereum use as a decentralized platform for executing smart contracts has driven the adoption of standards that optimize interoperability in industrial environments. Ethereum Requests for Comments (ERC) establish uniform patterns for smart contracts, facilitating their integration and operation in network nodes, which are essential for industrial applications such as supply chain management or process automation. However, this standardization can propagate vulnerabilities or inefficiencies in critical systems if the contracts are not optimized, affecting the reliability of industrial processes. Since operations in Ethereum consume computational resources (measured in gas) with associated economic costs, poor design can lead to significant losses in industrial settings. This paper evaluates the efficiency and security of ERC standards by examining their functional diversity and technical complexity. Thus, it analyzes existing implementations to identify common errors and proposes improvements to enhance the robustness and optimization of three of the most popular standards: ERC-20, ERC-1400 and ERC-3643. The ultimate goal is to support the effective adoption of ERCs in industrial applications. Considering the Ethereum network incentives on lower complexity logic and the obtained results, it is advisable to use simple standards, which also reduce error risks and ease maintainability.
This article discusses the practical implementation of a prototype academic transcript storage system based on blockchain technology and smart contracts. The digital transformation of higher education requires reliable mechanisms for ensuring the integrity and verifiability of academic documents. It presents the design and experimental validation of a blockchain-based system for storing and verifying academic transcripts within the higher education system of the Republic of Kazakhstan. The proposed solution is based on an Ethereum Virtual Machine-compatible smart contract implemented in Solidity and deployed on a test network. The testnet was used as the experimental environment, and transaction monitoring was performed using the BlockScout v11.0.3 explorer. The architecture of the TranscriptStorage smart contract is presented, including a role-based access model, a data indexing mechanism using keccak-256, and storage of transcripts in a mapping structure (bytes32 => Transcript[ ]). The experimental results confirm the successful recording of the Transcript in the distributed ledger, event recording (Logs), and the correctness of the ABI encoding of input parameters (Raw Input), as well as a change in state (State Changes) reflecting the fee payment. The use of events is shown to enable cost-effective third-party data verification without the need to store the entire text in the contract state. The comparative results showed that the proposed system reduced gas consumption by 804.5% compared to Blockcerts, 48.8% compared to ECertChain, 82.5% compared to ShikkhaChain, and 43.5% compared to zkEVM. These improvements were achieved while maintaining high scalability, robust privacy features, and security, making it a practical solution for Kazakhstanâs educational system.
Eunchan Park, Kyonghwa Song, Won Hoi Kim, Wonho Song ¡ 5 authors
Traditional blockchain untraceability schemes, such as mixers and privacy coins, obscure the sender-receiver relationship by placing transfers within an anonymity set. This paper studies a stronger goal: whether the transfer event itself can be made unobservable by blending into common decentralized-finance (DeFi) activity. We introduce Deniable Covert Asset Transfer (DCAT), a class of transfers that stage common loss-producing events, such as sandwich and arbitrage operations, so that a sender appears to suffer an ordinary loss while the receiver appears to profit from it. We design and validate two DCAT instantiations: a sandwich-based transfer on Ethereum and an arbitrage-based transfer on Arbitrum. Our experiments show that, under the evaluated settings, DCAT transfers are empirically unobservable on both chains. They are syntactically identical to corresponding maximal extractable value (MEV) activities, classified as ordinary extractions by standard MEV detection tools, and leave the sender and receiver unlinked under representative forensic tools. Since syntactic inspection cannot distinguish DCAT from ordinary MEV activity, we examine whether economic semantics provide useful forensic signals. Through a large-scale study of MEV losses on Ethereum and Arbitrum, we show that key semantic features follow power laws. Extreme losses and repeatedly exploited addresses occur in the wild, and thus are not by themselves definitive evidence of collusion. This gives staged transfers plausible deniability and makes fixed-threshold detection prone to false positives. We therefore develop a multivariate statistical method for forensic triage that ranks incidents by the joint rarity of their economic footprint. Applied to real-world DeFi activity, our method narrows a large search space to suspicious cases for manual investigation; we present three such cases to illustrate this prioritization.
Smart cities require the efficient and secure integration of key infrastructure domains such as water, energy, transportation, smart lighting and waste management deploying a myriad of data-generating IoT sensors and devices. Current management systems feature single points of failure, lack of auditability, insufficient privacy protection and lack of scalability as IoT nodes increase in density. In this paper, we present SmartChain, a three-tier multilayered blockchain based architecture that incorporates a permissioned distributed ledger, an AIbased anomaly detection module (ADM) and a dual-layered privacy preservation approach that combines Zero-Knowledge Proofs (ZKP) and Ciphertext-Policy Attribute-Based Encryption (CP-ABE). SmartChain is tested on a large dataset - 2000 timestamped transactions involving Smart Citiesâ five infrastructure types across several zones of a city. The results show a mean throughput of 3,421 transactions per second (TPS), a mean transaction latency of 3,847 milliseconds and a mean privacy score of 82.4 out of 100. The machine learning based anomaly module produces an F1-Score of over 97% and an AUROC score of 0.991 with Random Forest as the classifier. Benchmarking against Hyperledger Fabric 2.5, Ethereum 2.0 and the IOTA Tangle demonstrate the scalability, security, privacy and efficiency of SmartChain. This research renders SmartChain a practical production-level platform for management of new smart city infrastructure.
Vote Chain is a fully implemented, decentralized e-voting application (DApp) built on Ethereum. Existing blockchain-based voting systems often suffer from either high computational overhead due to homomorphic encryption or lack of fully deployable, adversarially tested implementations. To address these limitations, VoteChain employs a keccak256-based commitâreveal protocol to preserve ballot secrecy during the voting phase, with Solidity 0.8.20 smart contracts enforcing all election rules autonomously. Wallet-based authentication via MetaMask eliminates centralized identity management. The system is validated through 14 automated unit tests (all passing in 615 ms) covering correctness, access control, double-voting, hash forgery, and phase-bypass attacks. Per-voter gas cost is approximately 120,000 units (commit and reveal combined). An ablation study confirms the non-redundant contribution of each architectural component. Comparative analysis shows that VoteChain achieves vote privacy without homomorphic encryption while maintaining full decentralization and implementation completeness. The system is evaluated and validated on a local Hardhat network, with the architecture readily extensible to Layer-2 rollups for large-scale elections.
The Ethereum blockchain utilizes the EIP-1559 algorithm to manage transaction inclusion and block assembly. However, EIP-1559 and much of the existing literature study this problem from a static perspective, focusing on price evolution without modelling transaction dynamics within the mempool. Motivated by this limitation, we study a dynamic transaction scheduling problem in which transactions with heterogeneous sizes and per-unit values arrive over time and remain in the mempool until scheduled. To capture the stochastic mempool evolution, we formulate the problem as a Markov Decision Process (MDP) whose state represents the mempool configuration and whose actions correspond to block prices. We first provide a primal-dual interpretation of the static EIP-1559 mechanism, showing that block prices arise naturally as dual variables of a social-welfare maximization problem. Building on this perspective, we extend the framework to the dynamic setting and formulate an objective that maximizes long-run discounted reward while incorporating holding costs and overshoot penalties. We then employ a Natural Policy Gradient (NPG) algorithm to compute the optimal policy. Our results show that dynamic pricing stabilizes the mempool while maximizing long-run discounted reward. In particular, as the overshoot penalty increases, the average scheduled transaction volume converges to the target block capacity, and the resulting NPG updates closely resemble the EIP-1559 price update rule. Finally, we study two special cases of the MDP formulation: homogeneous transactions and uniform arrivals. In the homogeneous setting, where the protocol directly controls scheduled volume, we show that the optimal policy has a threshold structure. We then propose a bang-bang pricing mechanism for uniform arrivals and derive a lower bound on the block capacity needed to ensure system stability.
Abstract This study uses high-frequency price data to analyze risk connectivity among 15 cryptocurrencies, focusing on moments such as volatility, skewness, kurtosis, and jumps during the pre-COVID-19 era, the COVID-19 epidemic, and Russian-Ukrainian tensions. The results indicate that Ethereum Classic is a major shock transmitter in all periods, and this effect becomes more pronounced during geopolitical crises. In contrast, Stellar, Tezos, and Tron are important shock absorbers, particularly during market volatility. Jump risk analysis confirms the dominance of Ethereum Classic and its capacity to increase spillover risks during crises. For higher-order moments, the findings reveal that Bitcoin, Ethereum, and Dash are significant transmitters of skewness spreads, whereas Dash and Eos are significant transmitters of kurtosis spreads. Jump risk analysis confirms the dominance of Ethereum Classic and its capacity to increase spillover risks during crises. These findings highlight the need for targeted risk management strategies adjusted to cryptocurrency market dynamics.
Federated Learning (FL) enables collaborative model training while preserving data privacy but relies on centralized aggregation servers, leading to issues such as lack of transparency, vulnerability to malicious updates, and single points of failure. This paper proposes a decentralized federated learning framework integrating blockchain technology and the InterPlanetary File System (IPFS) to eliminate central authority and enhance trust. Smart contracts deployed on the Ethereum Sepolia testnet manage model submission, validation, incentive distribution, and reputation tracking. Model updates are stored off-chain using IPFS, while their hashes are recorded on the blockchain to ensure integrity and immutability. A staking and slashing mechanism is introduced to encourage honest participation, where valid contributions are rewarded and malicious updates are penalized. A reputation system further evaluates participant reliability over time. The system is implemented using PyTorch, Solidity, Web3.py, and React.js. Experimental results demonstrate improved security, transparency, and efficient decentralized coordination, highlighting the feasibility of integrating federated learning with blockchain and decentralized storage for scalable and trustworthy machine learning applications.
Autonomous AI agents are increasingly deployed on blockchain platforms, yet the design space that governs their interaction remains poorly understood. This convergence, where autonomous agents operate on and within decentralized systems, is a defining feature of the emerging Web~4.0 paradigm. This paper presents a Systematization of Knowledge organized around a bidirectional trust framework. In the B $\boldsymbol{\rightarrow}$ A direction, we examine how blockchain provides trust infrastructure for agents, spanning identity and account abstraction, permission and delegation, intent-centric execution, and tokenized agent economies. In the A $\boldsymbol{\rightarrow}$ B direction, we examine the reverse: how AI agents participate in core blockchain mechanisms including security auditing, consensus, and governance. A Trust Foundation of verifiable computation underpins both directions, with each primitive offering different trade-offs between trust minimality, computational overhead, and deployment readiness. We formalize the interaction as an Agent-Blockchain Interaction Model (ABIM), catalog 70 Ethereum EIPs/ERCs, examine 20 representative industry projects, and review 118 academic papers, applying a five-dimensional framework assessing Verifiability, Minimality of Trust, Expressiveness, Composability, and Maturity. Our analysis uncovers significant gaps: the agent-specific standards ecosystem is overwhelmingly immature, intent architectures lack formal analysis, and while isolated works have begun to explore AI participation in consensus and governance, a unified security framing that treats AI as a first-class actor at the protocol layer remains absent. We propose a three-dimensional taxonomy, identify nine concrete open problems, and highlight the sharpest research opportunities at this intersection.
Smart contract security has progressed from vulnerability detection toward a broader research agenda that includes semantic reasoning, automated repair, adversarial robustness, and real-time exploit detection. This paper develops a capstone-oriented research narrative around four directions: foundation-model-based smart contract semantics and vulnerability reasoning [1], automated smart contract repair with formal guarantees [2], adversarial learning for robust malicious contract and transaction detection [3], and real-time transaction-level exploit detection at blockchain scale [4]. We connect these directions to two recent studies that characterize the current frontier: a diagnostic analysis of where smart contract security analyzers fall short [5] and a scalable real-time system for malicious Ethereum transaction detection [6]. The resulting framework is intended to help students formulate capstone projects that are technically grounded, empirically measurable, and aligned with contemporary smart contract security research.