The Metaverse—which is a burgeoning virtual environment where users engage in social, educational, and commercial activities—has introduced new complexities in digital payment systems. This chapter examines the various vulnerabilities inherent in Metaverse payment systems, ranging from smart contract flaws to phishing and social engineering attacks. As these systems often involve real-world financial transactions or cryptocurrencies, they present attractive targets for exploitation. Through case studies and analysis, this chapter highlights common attack vectors, including quick response (QR) code manipulation, identity theft, and API vulnerabilities, while also providing mitigation strategies such as smart contract best practices, secure authentication mechanisms, and user education. This chapter also discusses future challenges, such as the evolving threat landscape posed by artificial intelligence (AI) and quantum computing, and the growing influence of decentralized finance (DeFi) within the Metaverse. The findings underscore the urgent need for robust security measures and collaborative efforts to protect users and ensure the integrity of payment systems in this rapidly evolving virtual world.
Smart contracts represent a predefined set of rules invoked when specific conditions are met within blockchain networks, eliminating the need for centralized authority to validate transactions. The absence of central authority can potentially expose smart contracts to fraudulent behavior. Moreover, implementation flaws in smart contracts can be exploited to cause unintended behavior, resulting in security or financial risks. Traditionally, the identification of vulnerabilities in smart contracts has relied on methods such as pattern matching, data flow analysis, and input testing. While these techniques are foundational, they are constrained by human limitations and may not comprehensively address the full spectrum of potential issues. This necessitates more advanced approaches to ensure robust security and reliability. Therefore, in the literature, numerous researchers have leveraged different Machine Learning (ML) and Deep Learning (DL) techniques to classify normal and malicious smart contracts. However, existing literature either grapples with class imbalance issues or relies on conventional methods. Moreover, existing research often falls short of locating the exact location of malicious code within the smart contracts. Therefore, to address these gaps, this paper proposes a novel model called the Dual-Branch Encoder Siamese Network (DBESN) for detecting malicious smart contracts. Furthermore, this model is extended to precisely identify the region of the vulnerable code fragment within the smart contract using the Local Interpretable Model-Agnostic Explanations (LIME) algorithm. Experimental results demonstrated a performance Accuracy of 98.62% and 99.30% F1-Score with an inference time of 0.296 seconds. Given the high performance coupled with the low inference time of the proposed DBESN model, it is suitable for deployment within blockchain networks to detect and identify malicious smart contracts effectively and efficiently.
1. Abstract The abstract introduces the growing issue of counterfeit products affecting global supply chains and consumer safety. It states that traditional methods—like barcodes, holograms, and watermarks—are increasingly ineffective due to technological advancements in forgery. To address this, the paper proposes a hybrid authentication framework combining the security of blockchain with the convenience and accessibility of QR codes (smart codes). It summarizes the methodology, highlights real-world examples, and touches on the system’s benefits, including enhanced traceability, consumer trust, and tamper-resistance. The abstract concludes by noting the paper’s focus on methodology, performance evaluation, future scope, and supporting case studies.
Information disorder has become a major societal challenge, impacting public discourse and democracy. This phenomenon has been exacerbated by the spread of social media platforms, affecting various areas, ranging from national elections to public health. Addressing fake news through a manual approach (e.g., human fact-checking) is unfeasible due to the rapid production of textual content. At the same time, applying automatic tools is equally challenging, primarily due to the ambiguity of natural language. In this paper, we addressed online information disorder from a different perspective by proposing a platform that supports trustworthy and reputable news producers and enhances awareness among readers across various social media. Specifically, the proposed platform enables news producers to automatically embed a unique watermark in the text they create, ensuring that the news cannot be manipulated or misattributed. The watermarking is embedded in a fine-grained way, allowing even small extracts of the news to be shared while preserving traceability. Additionally, the association between the watermark and the news item is recorded in a distributed ledger, preventing further manipulation that could arise from centralised management. The aim is to enable readers to make more informed decisions about the content they encounter, even when engaging with excerpts of the original document, minimising reliance on external fact-checking organisations.
The integration of AI and DLT presents great opportunities and unique challenges in the realm of cybersecurity. This paper will examine how AI strengthens the processes of detection and response in cybersecurity, while DLT presents a decentralized and immutable premise for data management. The convergence of these two technologies may improve security for several sectors; finance, healthcare, and supply chain being prominent examples. AI's nature of being able to analyze large masses of data in the quest for threat anomaly detection complements DLT's decentralization and immutability as it affords more resilience in cybersecurity. Integration fosters technical and ethical challenges as well as regulations that need to be overcome in order for these technologies to be effective. This paper discusses the integrations of AI and DLT: Some of the best case studies and their future potential for augmenting cybersecurity protocols are also explained.
Smart contracts are changing many business areas with blockchain technology, but they still have vulnerabilities that can cause major financial losses. Because deployed smart contracts (SCs) are irreversible once deployed, fixing these vulnerabilities before deployment is critical. This research introduces a new method that combines code embedding with Generative Adversarial Networks (GANs) to find integer overflow vulnerabilities in smart contracts. Using Abstract Syntax Trees, we can vectorize the source code of smart contracts while keeping all of the important contract characteristics and going beyond what can be achieved with conventional textual or structural analysis. Synthesizing contract vector data using GANs alleviates data scarcity and facilitates source code acquisition for training our detection system. The proposed method is very good at finding vulnerabilities because it uses both GAN discriminator feedback and vector similarity measures based on cosine and correlation coefficients. Experimental results show that our GAN-based proactive analysis method achieves up to 18.1% improvement in accuracy over baseline tools such as Oyente and sFuzz.
Luca Ruschioni, Robert Shuttleworth, Rumyana Neykova, Barbara Re · 5 authors
Solidity is the predominant programming language for blockchain-based smart contracts, and its characteristics pose significant challenges for code analysis and maintenance. Traditional software analysis approaches, while effective for conventional programming languages, often fail to address Solidity-specific features such as gas optimization and security constraints. This paper introduces micro-patterns - recurring, small-scale design structures that capture key behavioral and structural peculiarities specific to a language - for Solidity language and demonstrates their value in understanding smart contract development practices. We identified 18 distinct micro-patterns organized in five categories (Security, Functional, Optimization, Interaction, and Feedback), detailing their characteristics to enable automated detection. To validate this proposal, we analyzed a dataset of 23258 smart contracts from five popular blockchains (Ethereum, Polygon, Arbitrum, Fantom and Optimism). Our analysis reveals widespread adoption of micro-patterns, with 99% of contracts implementing at least one pattern and an average of 2.76 patterns per contract. The Storage Saver pattern showed the highest adoption (84.62% mean coverage), while security patterns demonstrated platform-specific adoption rates. Statistical analysis revealed significant platform-specific differences in pattern adoption, particularly in Borrower, Implementer, and Storage Optimization patterns.
Blockchain technology, originally associated with digital currencies, possesses key features such as decentralization, anonymity, robustness, and resistance to tampering, making it an ideal platform for building covert communication channels. This chapter begins by introducing the concept of network covert channels, discussing their definition, historical development, and the architecture of blockchain technology with an exploration of traditional network covert channels. It then highlights the advantages of blockchain-based covert communication channels over conventional methods. The chapter classifies blockchain network covert channels based on several key components. It provides a detailed analysis of the advantages and disadvantages of these channels in terms of covert nature, transmission efficiency, and communication costs. Finally, the chapter addresses existing challenges and limitations within blockchain network covert channels and offers insights into future research directions to improve their efficiency, security, and scalability in the context of secure communication.
Advanced Steganography and Watermarking Techniques
Blockchain technology, with its inherent security, transparency, and immutability, presents a novel approach to addressing critical challenges in public health. This paper explores the potential of blockchain to revolutionize data management, enhance disease surveillance, and empower communities in public health initiatives. We examine how blockchain can secure sensitive health data, facilitate interoperability among disparate systems, and enable decentralized data sharing for research and interventions. Furthermore, we discuss the applications of blockchain in supply chain management for pharmaceuticals, vaccine distribution, and the creation of secure digital identities for individuals. By leveraging blockchain's distributed ledger technology, we can foster trust, improve data integrity, and promote community engagement in public health, ultimately leading to more effective and equitable health outcomes.
This paper explores the vulnerability of machine learning models to simple single-feature adversarial attacks in the context of Ethereum fraudulent transaction detection. Through comprehensive experimentation, we investigate the impact of various adversarial attack strategies on model performance metrics. Our findings, highlighting how prone those techniques are to simple attacks, are alarming, and the inconsistency in the attacks' effect on different algorithms promises ways for attack mitigation. We examine the effectiveness of different mitigation strategies, including adversarial training and enhanced feature selection, in enhancing model robustness and show their effectiveness.
Gerardo Iuliano, Luigi Allocca, Matteo Cicalese, Dario Di Nucci
The security of smart contracts is critical in blockchain systems, where even minor vulnerabilities can lead to substantial financial losses. Researchers proposed several vulnerability detection tools evaluated using existing benchmarks. However, most benchmarks are outdated and focus on a narrow set of vulnerabilities. This work evaluates whether mutation seeding can effectively inject vulnerabilities into Solidity-based smart contracts and whether state-of-the-art static analysis tools can detect the injected flaws. We aim to automatically inject vulnerabilities into smart contracts to generate large and wide benchmarks. We propose MuSe, a tool to generate vulnerable smart contracts by leveraging pattern-based mutation operators to inject six vulnerability types into real-world smart contracts. We analyzed these vulnerable smart contracts using Slither, a static analysis tool, to determine its capacity to identify them and assess their validity. The results show that each vulnerability has a different injection rate. Not all smart contracts can exhibit some vulnerabilities because they lack the prerequisites for injection. Furthermore, static analysis tools fail to detect all vulnerabilities injected using pattern-based mutations, underscoring the need for enhancements in static analyzers and demonstrating that benchmarks generated by mutation seeding tools can improve the evaluation of detection tools.
In recent years, the Ethereum Name Service (ENS) has garnered significant attention within the community for enabling the use of Unicode in domain names, thereby facilitating the inclusion of a wide array of character sets such as Greek, Cyrillic, Arabic, and Chinese. While this feature enhances the versatility and global accessibility of domain names, it concurrently introduces a substantial security vulnerability due to the presence of homoglyphs-characters that are visually similar to others across Unicode and ASCII sets. These similarities can be exploited in homoglyph attacks, posing a distinct threat to domain name integrity. Despite community efforts to counteract this issue through a normalization process prior to domain resolution, our analysis uncovers significant discrepancies in how the normalization processes are applied across various applications. This inconsistency could result in the same domain name being resolved to different addresses in different applications, underscoring a critical vulnerability. We also discovered the new attack scenario in ENS which may cause legitimate domains resolved into malicious addresses even when they are verified by authorities. To systematically evaluate this inconsistency, we designed a tool for detecting application-level discrepancies in domain normalization process without requiring access to the application's source code. Our evaluation on hundreds of real-world Web3 applications identifies widespread deviations from established homoglyph mitigation practices, with more than 60% digital wallets and 80% dApps (decentralized applications) not able to produce consistent ENS resolving results, potentially impacting millions of users. This analysis underscores the urgent need for a standardized implementation of normalization processes to safeguard the integrity and security of ENS domains.
Xinyao Xu, Ziyu Mao, Jianzhong Su, Xingwei Lin · 7 authors
The rapid growth of decentralized applications, while revolutionizing financial transactions, has created an attractive target for malicious attacks.Existing approaches to detecting attacks often rely on predefined rules or simplistic and overly-specialized models, which lack the flexibility to handle the wide spectrum of diverse and dynamically changing attack types.To address this challenge, we present a general and extensible framework, MoE (Monitoring Ethereum), that leverages runtime verification to detect a wide range of attacks on Ethereum.MoE features an expressive attack modeling language, based on Metric First-order Temporal Logic (MFOTL), that can formalize a wide range of attacks.We integrate a novel semantic lifting approach that extracts system behaviors relevant for various attacks, which can be analyzed using the monitoring tool MonPoly.Furthermore, we also equip MoE with quantitative capabilities to evaluate the similarity between a transaction and an attack formula to enhance its performance in identifying attacks, including near-miss attacks.We carry out extensive experiments with MoE on a labeled benchmark and a large-scale dataset containing over one million transactions.On the labeled benchmark, MoE successfully detects 92.0% attacks and achieves a 45.0% higher recall rate than competing state-of-the-art tool.MoE finds 3,319 attacks with 95.4% precision on the large dataset.Furthermore, MoE uses quantitative analysis to uncover 8% additional attacks.Finally, the average time for * Xinyao Xu and Ziyu Mao contributed equally.
In recent years, a large number of on-chain attacks have emerged in the blockchain empowered Web3 ecosystem. In the year of 2023 alone, on-chain attacks have caused losses of over 585 million. Attackers use blockchain transactions to carry out on-chain attacks, for example, exploiting vulnerabilities or business logic flaws in Web3 applications. A wealth of efforts have been devoted to detecting on-chain attack transactions through expert patterns and machine learning techniques. However, in this ever-evolving ecosystem, the performance of current methods is limited in detecting new on-chain attacks, due to the obsoleting of attack recognition patterns or the reliance on on-chain attack samples. In this paper, we propose a universal approach for detecting on-chain attacks even when there are few or even no new on-chain attack samples. Specifically, an in-depth analysis of the transaction characteristics is conducted, and we propose a new insight to train a generic attack transaction detecting model, i.e., transaction reconstruction. Particularly, to overcome the over-fitting in the transaction reconstruction task, we use the web-scale function comments related to transactions as supervision information, rather than expert-confirmed labels. Experimental results demonstrate that the proposed approach surpasses the supervised state-of-the-art by 13% in AUC, with just 30 known on-chain attack samples. Moreover, without any known attack samples, our method can still detect new on-chain attacks in the wild (with a precision of 61.83%). Among attacks detected in the wild, we confirm 1,692 address poisoning attacks, a new type of on-chain attack targeting token holders. Our code is available at: https://github.com/wuzhy1ng/attack_trans_detection_www25.
With the booming development of blockchain technology, smart contracts have been widely used in finance, supply chain, Internet of things and other fields in recent years. However, the security problems of smart contracts become increasingly prominent. Security events caused by smart contracts occur frequently, and the existence of malicious codes may lead to the loss of user assets and system crash. In this paper, a simple study is carried out on malicious code detection of intelligent contracts based on machine learning. The main research work and achievements are as follows: Feature extraction and vectorization of smart contract are the first step to detect malicious code of smart contract by using machine learning method, and feature processing has an important impact on detection results. In this paper, an opcode vectorization method based on smart contract text is adopted. Based on considering the structural characteristics of contract opcodes, the opcodes are classified and simplified. Then, N-Gram (N=2) algorithm and TF-IDF algorithm are used to convert the simplified opcodes into vectors, and then put into the machine learning model for training. In contrast, N-Gram algorithm and TF-IDF algorithm are directly used to quantify opcodes and put into the machine learning model training. Judging which feature extraction method is better according to the training results. Finally, the classifier chain is applied to the intelligent contract malicious code detection.
As Ethereum continues to thrive, the Ethereum Virtual Machine (EVM) has become the cornerstone powering tens of millions of active smart contracts. Intuitively, security issues in EVMs could lead to inconsistent behaviors among smart contracts or even denial-of-service of the entire blockchain network. However, to the best of our knowledge, only a limited number of studies focus on the security of EVMs. Moreover, they suffer from 1) insufficient test input diversity and invalid semantics; and 2) the inability to automatically identify bugs and locate root causes. To bridge this gap, we propose O p D iffer , a differential testing framework for EVM, which takes advantage of LLMs and static analysis methods to address the above two limitations. We conducted the largest-scale evaluation, covering nine EVMs and uncovering 26 previously unknown bugs, 22 of which have been confirmed by developers and three have been assigned CNVD IDs. Compared to state-of-the-art baselines, O p D iffer can improve code coverage by at most 71.06%, 148.40% and 655.56%, respectively. Through an analysis of real-world deployed Ethereum contracts, we estimate that 7.21% of the contracts could trigger our identified EVM bugs under certain environmental settings, potentially resulting in severe negative impact on the Ethereum ecosystem.
Serving as the first touch point for users to the cryptocurrency world, cryptocurrency wallets allow users to manage, receive, and transmit digital assets on blockchain networks and interact with emerging decentralized finance (DeFi) applications. Unfortunately, cryptocurrency wallets have always been the prime targets for attackers, and incidents of wallet breaches have been reported from time to time. Although some recent studies have characterized the vulnerabilities and scams related to wallets, they have generally been characterized in coarse granularity, overlooking potential risks inherent in detailed designs of cryptocurrency wallets, especially from perspectives including user interaction and advanced features. To fill the void, in this paper, we present a fine-grained security analysis on browser-based cryptocurrency wallets. To pinpoint security issues of components in wallets, we design WalletProbe, a mutation-based testing framework based on visual-level oracles. We have identified 13 attack vectors that can be abused by attackers to exploit cryptocurrency wallets and exposed 21 concrete attack strategies. By applying WalletProbe on 39 widely-adopted browser-based wallet extensions, we astonishingly figure out all of them can be abused to steal crypto assets from innocent users. Identified potential attack vectors were reported to wallet developers timely and 26 issues have been patched already. It is, hence, urgent for our community to take action to mitigate threats related to cryptocurrency wallets. We promise to release all code and data to promote the development of the community.
Alexander Plotkin, E. Kuznetsov, K. Starodubov, Yuri Gromov
The paper considers the solution of the problem of ensuring the resistance of key infrastructure in distributed registry systems to some destructive influences with the help of multi-factor authentication. Potentially possible destructive influences depending on defects in authentication systems, in particular on network nodes, are presented. Possible methods of providing resistance against such destructive influences are analyzed.
As a novel decentralized computing paradigm, blockchain is expected to disrupt the existing e-commerce architecture and process. Secure smart contracts are the crucial foundation for e-commerce based on blockchain. However, vulnerabilities in smart contracts occur from time to time and cause significant financial losses in e-commerce. Some static verification methods have been developed to guarantee security for e-commerce smart contracts at design time, but they cannot support complex scenarios at runtime. As a lightweight verification method, runtime verification is a potential method for secure e-commerce smart contracts. The existing runtime verification methods are based on the manual instrument, which leads to additional overheads and gas consumption. To deal with this, we propose a passive learning-based runtime verification framework for e-commerce smart contracts. Firstly, by exploring the Genetic algorithm to evolve state merging and automaton reorganizing in order to simultaneously split time and gas behaviors, we propose a passive learning method to model runtime information for e-commerce smart contracts (PL4ESC). It directly learns P2TA (priced probabilistic timed automaton) from runtime traces without any prior knowledge. Then, we integrate PL4ESC with the open-source PAT (Process Analysis Toolkit) to automatically verify the security of runtime e-commerce smart contracts. The experiments show that PL4ESC is better at accuracy and precision than state-of-the-art passive learning methods. It improves accuracy by 1 to 4 percent compared to TAG and RTI+. As far as we know, it is not only the first learning method that can learn a P2TA from traces, but it is also the first automated runtime verification framework for e-commerce smart contracts. This will provide security guarantees for blockchain-based e-commerce.
Smart contracts facilitate transactions on the blockchain, while their vulnerabilities can lead to financial losses for the parties involved. Recent significant security incidents e.g., DAO attacks, have prompted more researchers to explore vulnerability detection in smart contracts. Most existing studies convert smart contract source code into sequences or graphs for feature extraction, while they typically focus solely on capturing the sequential features within sequences or the spatial features of graphs, failing to explore both sequential and spatial correlations implicit in the source code. Although converting source code into a graph helps capture complex spatial relationships, this inevitably loses some information, e.g., data flow is ignored in the control flow graph. Moreover, these methods often design complicated data processing or complex network structures to extract such features. To address the issues, we propose a Multi-Teacher Knowledge Distillation method (i.e., teacher-student framework) for more accurate and efficient Smart Contract Vulnerability Detection, namely MTKD-SCVD. Specifically, we designed a simple dual-channel student model that can extract both sequential and spatial characteristics from sequence and graph data, thus facilitating a comprehensive understanding of vulnerability patterns. Since the superior performance of existing methods in feature extraction from a certain aspect (e.g., spatial), we consider using these state-of-the-art (SOTA) models as teacher models, thus distilling effective features to guide the student model learning. Therefore, MTKD-SCVD can enable the student model to achieve more accurate vulnerability detection with a simple network structure. We conduct extensive experiments on smartbugs public datasets, demonstrating the effectiveness of MTKD-SCVD over SOTA models.
As the development of Solidity contracts on Ethereum , more developers are reusing them on other compatible blockchains. However, developers may overlook the differences between the designs of the blockchain system, such as the Gas Mechanism and Consensus Protocol , leading to the same contracts on different blockchains not being able to achieve consistent execution as on Ethereum . This inconsistency reveals design flaws in reused contracts, exposing code smells that hinder code reusability, and we define this inconsistency as EVM-Inequivalent Code Smells . In this paper, we conducted the first empirical study to reveal the causes and characteristics of EVM-Inequivalent Code Smells . To ensure the identified smells reflect real developer concerns, we collected and analyzed 1,379 security audit reports and 326 Stack Overflow posts related to reused contracts on EVM-compatible blockchains, such as Binance Smart Chain (BSC) and Polygon . Using the open card sorting method, we defined six types of EVM-Inequivalent Code Smells . For automated detection, we developed a tool named EquivGuard . It employs static taint analysis to identify key paths from different patterns and uses symbolic execution to verify path reachability. Our analysis of 905,948 contracts across six major blockchains shows that EVM-Inequivalent Code Smells are widespread, with an average prevalence of 17.70%. While contracts with code smells do not necessarily lead to financial loss and attacks, their high prevalence and significant asset management underscore the potential threats of reusing these smelly Ethereum contracts. Thus, developers are advised to abandon Copy-and-Paste programming practices and detect EVM-Inequivalent Code Smells before reusing Ethereum contracts.
In an era where securing Internet of Things (IoT) devices within Metaverse environments is increasingly critical, existing frameworks often lack robust, quantum-resistant protection suitable for resource-constrained devices. This study aims to develop a comprehensive quantum-resistant security framework designed for IoT-enabled Metaverse applications. Our multilayered architecture incorporates Ideal Coset Lattice Cryptography (ICLC) and a Hypercomplex Multivariate Encryption Scheme (HMES) across the Device, Network, and Metaverse layers. ICLC provides lightweight, quantum-resistant encryption for devices with limited computational resources, while HMES enhances security through complex algebraic structures resistant to quantum attacks. We implement a Zero-Knowledge Proof Authentication mechanism over Hypercomplex Algebras (ZKPHA) to authenticate devices without exposing private keys. An edge computing strategy that employs convex optimization minimizes latency and computational load, ensuring scalability and efficiency. Simulations over a 260-minute period compared our framework with six state-of-the-art methods under various conditions. The results show that our framework reduces the rate of successful cyberattacks on encrypted data to 0.15%, achieves encryption and decryption times of 2.2 milliseconds per operation, and maintains 98.5% system availability during attacks.
Decentralized applications (DApps) face significant security risks due to vulnerabilities in smart contracts, with traditional detection methods struggling to address emerging and machine-unauditable flaws. This paper proposes a novel approach leveraging fine-tuned Large Language Models (LLMs) to enhance smart contract vulnerability detection. We introduce a comprehensive dataset of 215 real-world DApp projects (4,998 contracts), including hard-to-detect logical errors like token price manipulation, addressing the limitations of existing simplified benchmarks. By fine-tuning LLMs (Llama3-8B and Qwen2-7B) with Full-Parameter Fine-Tuning (FFT) and Low-Rank Adaptation (LoRA), our method achieves superior performance, attaining an F1-score of 0.83 with FFT and data augmentation via Random Over Sampling (ROS). Comparative experiments demonstrate significant improvements over prompt-based LLMs and state-of-the-art tools. Notably, the approach excels in detecting non-machine-auditable vulnerabilities, achieving 0.97 precision and 0.68 recall for price manipulation flaws. The results underscore the effectiveness of domain-specific LLM fine-tuning and data augmentation in addressing real-world DApp security challenges, offering a robust solution for blockchain ecosystem protection.