In recent years, a more advanced form of phishing has arisen on Ethereum, surpassing early-stage, simple transaction phishing.This new form, which we refer to as payload-based transaction phishing (PTXPHISH), manipulates smart contract interactions through the execution of malicious payloads to deceive users.PTXPHISH has rapidly emerged as a significant threat, leading to incidents that caused losses exceeding $70 million in 2023 reports.Despite its substantial impact, no previous studies have systematically explored PTXPHISH.In this paper, we present the first comprehensive study of the PTXPHISH on Ethereum.Firstly, we conduct a long-term data collection and put considerable effort into establishing the first ground-truth PTXPHISH dataset, consisting of 5,000 phishing transactions.Based on the dataset, we dissect PTXPHISH, categorizing phishing tactics into four primary categories and eleven sub-categories.Secondly, we propose a rule-based multidimensional detection approach to identify PTXPHISH, achieving an F1-score of over 99% and processing each block in an average of 390 ms.Finally, we conduct a large-scale detection spanning 300 days and discover a total of 130,637 phishing transactions on Ethereum, resulting in losses exceeding $341.9 million.Our in-depth analysis of these phishing transactions yielded valuable and insightful findings.Scammers consume approximately 13.4 ETH daily, which accounts for 12.5% of the total Ethereum gas, to propagate address poisoning scams.Additionally, our analysis reveals patterns in the cash-out process employed by phishing scammers, and we find that the top five phishing organizations are responsible for 40.7% of all losses.Furthermore, our work has made significant contributions to mitigating real-world threats.We have reported 1,726 phishing addresses to the community, accounting for 42.7% of total community contributions during the same period.Additionally, we have sent 2,539 on-chain alert messages, assisting 1,980 victims.This research serves as a valuable reference in combating the emerging PTXPHISH and safeguarding users' assets.
Consumers and brands are at serious risk due to the growth of counterfeit goods, especially in regions like Nigeria. Conventional techniques, such border inspections and market raids by the Standards Organization of Nigeria (SON), are inadequate for detecting counterfeit goods. To ensure traceability, transparency, and immutability in the supply chain, this article suggests utilizing blockchain technology. The decentralized and encrypted characteristics of blockchain, when bolstered by smart contracts, enable efficient product tracking from producers to end users, hence impeding the infiltration of fake goods. Using a permissioned blockchain network, this system attempts to confirm the legitimacy of products at every point along the supply chain—manufacturers, distributors, retailers, and end users. The Remix IDE is used to deploy and test Ethereum-based smart contracts that were created in Solidity for the proposed system. This blockchain-based strategy aims to decrease the spread of counterfeit goods, protect consumer confidence, and preserve brand reputation. To offer a user-friendly interface for wider accessibility, future advancements will link this system with decentralized apps (DApps).
Abstract In recent years, the widespread adoption of Ethereum-based transactions, such as cryptocurrencies and blockchain technologies, have revolutionized the way financial transactions are conducted. These decentralized and transparent systems offer numerous advantages, including enhanced security, immutability, and reduced transaction costs. However, alongside their benefits, Ethereum-based transactions have also attracted the attention of malicious actors seeking to exploit unsuspecting users through phishing scams. Phishing scams have thus become frequent in this scenario. Therefore, it is required to implement an effective and reliable phishing scam detection method. In this paper, we present the implementation of a highly efficient detection method by carrying out a graph-like data network formation, over which we then apply models that are based on graph neural networks like Magnet Link Prediction and Graph AutoEncoder Pathfinder Discovery Network Algorithm (GAE_PDNA). This helps in extracting useful information from the nodes of the graph. After relevant embeddings have been obtained, the classification of the phishing account is performed using AdaBoost classifier that helps in complex decision-making and detects the accounts related to the phishing scams. Our best model attains a precision of 0.99 and an F1 score of 0.99. Highlights
Purpose The trend among the financial investors to integrate cryptocurrencies, the very first completely digital assets, in their investment portfolio, has increased during the last decade. Even though cryptocurrencies share certain common characteristics with other investment products, they have their own distinct characteristic features, and the behavior of this asset class is currently being studied by the research scholars interested in this domain. Design/methodology/approach Using the text mining approach, this article examines research trends in the field of cryptocurrencies to identify prospective research needs. To narrow down to ten topics, the abstracts and the indexed keywords of 1,387 research publications on cryptocurrency, blockchain and Bitcoins published between 2013 and 2022 were analyzed using the topic modeling technique and Latent Dirichlet allocation (LDA). Findings The findings show a wide range of study trends on various aspects of cryptocurrencies. In the recent years, there have been lots of research and publications on the topics such as cryptocurrency markets, cryptocurrency transactions and use of blockchain in transactions and security of Bitcoin. In comparison, topics such as use of blockchain in fintech, cryptocurrency regulations, blockchain smart contract protocols and legal issues in cryptocurrency have remained relatively underexplored. After using the LDA, this paper further analyzes the significance of each topic, future directions of individual topics and its popularity among researchers in the discussion section. Originality/value While similar studies exist, no other work has used topic modeling to comprehensively analyze the cryptocurrencies literature by considering diverse fields and domains.
Kai Wang, Michael Wen Tong, Jun Pang, Jitao Wang · 5 authors
Recently, there is a surge in ransomware activities that encrypt users’ sensitive data and demand bitcoins for ransom payments to conceal the criminal’s identity. It is crucial for regulatory agencies to identify as many ransomware addresses as possible to accurately estimate the impact of these ransomware activities. However, existing methods for detecting ransomware addresses rely primarily on time-consuming data collection and clustering heuristics, and they face two major issues: (1) The features of an address itself are insufficient to accurately represent its activity characteristics, and (2) the number of disclosed ransomware addresses is extremely less than the number of unlabeled addresses. These issues lead to a significant number of ransomware addresses being undetected, resulting in a substantial underestimation of the impact of ransomware activities. To solve the above two issues, we propose an optimized ransomware address detection method based on Bitcoin transaction relationships, named XRAD , to detect more ransomware addresses with high performance. To address the first one, we present a cascade feature extraction method for Bitcoin transactions to aggregate features of related addresses after exploring transaction relationships. To address the second one, we build a classification model based on Positive-unlabeled learning to detect ransomware addresses with high performance. Extensive experiments demonstrate that XRAD significantly improves average accuracy, recall, and F1 score by 15.07%, 19.71%, and 34.83%, respectively, compared to state-of-the-art methods. In total, XRAD detects 120,335 ransomware activities from 2009 to 2023, revealing a development trend and average ransom payment per year that aligns with three reports by FinCEN, Chainalysis, and Coveware.
Jan Kalbantner, Konstantinos Markantonakis, Darren Hurley-Smith, Carlton Shepherd
In the realm of Distributed Ledger Technology, privacy and regulatory challenges loom large for marketplaces. Regulation requires to conduct Know Your Customer (KYC) procedures to verify the identity of participants, while privacy concerns necessitate the protection of personal data. Current approaches to KYC are inefficient and are potentially even harmful to privacy due to centralization and data exposure. This paper proposes a zero-knowledge proof enabled KYC scheme, utilizing Soulbound Tokens (SBT) to create a discreet, compliant, and secure KYC process. We present a privacy-preserving mechanism that shares only essential information while adhering to Self-Sovereign Identity (SSI) principles, placing users in the full control of their data. The proposed scheme further introduces the usage of SBTs for reputation to incentivize good conduct and build trust within marketplaces.
Information sharing on social media, especially about daily news and events, is a major focus area. Timely identification of urgent needs, sharing relevant posts, and delivering accurate information are crucial tasks. To combat the spread of fake news, a Reinforcement Learning (RL) technique is used alongside blockchain security to verify social media content. Twitter, a key platform with a major influence on public discourse, is particularly susceptible to false information due to its rapid news dissemination. The approach involves collecting news articles and their metadata, which are then pre-processed to clean and tokenize the data. An RL agent is trained on attributes like word frequency and readability, learning to distinguish between genuine and fake news through rewards and penalties. The trained RL agent classifies new news as true or false based on learned patterns. While blockchain's role in enhancing security is highlighted, further details are necessary to clarify its integration. This approach aims to reduce the spread of misinformation in digital news effectively.
Private information retrieval (PIR) over Web 3.0 introduces a sophisticated dimension to data access and privacy protection. It enables users to retrieve specific information from databases without disclosing the exact data being accessed. In decentralized networks, where privacy and data security are critical, PIR techniques play a pivotal role in safeguarding user confidentiality. By employing cryptographic protocols, PIR ensures that users can query decentralized databases while preserving anonymity and preventing unauthorized data interception. This chapter delves into the intricate mechanics of PIR algorithms tailored for Web 3.0 environments, exploring how these techniques facilitate secure information retrieval and uphold privacy standards amidst distributed ledger technologies and decentralized applications (dApps). It examines the integration of PIR within emerging decentralized search engines, highlighting the advancements and challenges in deploying privacy-preserving mechanisms across decentralized networks.
Tuan-Dung Tran, Nguyen Anh Tai, Tran The Anh, Phan The Duy · 5 authors
The proliferation of connectivity through modern telecommunications has led to increased unwanted and disruptive calls. Such communications negatively impact user experience and trust in platforms. Currently, call filtering relies on centralized architectures that aggregate vast troves of sensitive user data within single entities, compromising privacy and ownership. Users have limited visibility into how inputs inform labeling, challenging autonomy and oversight. We present the Sentinel Call Platform, a novel blockchain-powered decentralized framework to mitigate unsolicited calls. It establishes a permissionless blockchain tailored for immutable storage of call logs and community rules, and employs a Proof-of-Spam consensus, facilitating transparent flagging of suspicious numbers through democratic participation. An initial prototype demonstrates authenticating calls while preserving anonymity. By removing centralized data flow and governance models, the solution aims to restore transparency, autonomy and trust. The modular framework integrates applications and consensus optimization. Evaluations indicate ability to handle throughput loads. This decentralized alternative enhances user protection against disruptive communications through distributed, open solutions with implications for blockchain application across data sovereignty domains.
El-hacen Diallo, Rouwaida Abdallah, Mohammad Dib, Omar Dib
This paper introduces an innovative response to the pressing challenge of rapid and effective incident detection and management in urban settings. The proposed solution is a decentralized incident reporting system (IRS) harnessing blockchain technology and decentralized data storage systems. By empowering residents to report incidents, the proposed IRS enables seamless real-time monitoring and intervention by relevant departments. Built on a blockchain foundation, the proposed solution ensures immutability, transparency, security, and auditability, enhancing data resilience and comprehensive applicability. The proposed system leverages the InterPlanetary File System (IPFS) for the storage of incident proofs to manage the blockchain size effectively. Through the proposed IRS, transparency is upheld, enabling complete auditability of incident details and required interventions by citizens, societal bodies, and governmental bodies. Moreover, an incentive model is introduced to encourage active participation in incident reporting, thereby enhancing the system’s overall effectiveness and long-term sustainability. The proposed IRS integrates mobile technology to facilitate user engagement and data submission, essential for urban emergency management. Empirical validation using the Quorum–Raft blockchain demonstrates the feasibility of the proposed approach in terms of system throughput, incident reporting delay, blockchain size, and deployment cost. Specifically, the system maintains a latency of under 15 s even at high transaction rates, can handle up to 200 incidents per second, and is cost-effective, with deployment estimates for 16 organizations over five years being under 1.99 million USD. The method involves extensive testing with simulated incidents and user interactions to ensure robustness and scalability, showcasing the system’s potential for effective emergency management in urban environments.
Amjad Aldweesh, Mohammad Alauthman, Ahmad Al–Qerem, Abdelraouf Ishtaiwi · 6 authors
Blockchain's decentralized trust models are spurring rapid advances in applied cryptography. This chapter explores the accelerating convergence between cryptographic innovations and next-gen blockchain platforms. The authors provide background on modern cryptography and the distributed ledger tech behind blockchains. They then analyze how blockchain architectures are driving progress in zero-knowledge proofs, digital signatures, and secure multiparty computation. In turn, these advancing cryptographic mechanisms enable critical blockchain capabilities around privacy, scalability, accountability, and governance. The authors highlight gaps in existing cryptography-blockchain integration and present post-quantum research directions that fulfill decentralized ledgers' unique security needs. Their work frames a symbiotic blockchain-cryptography ecosystem where progress in both fields builds on each other to overcome limitations. This interdisciplinary synergy will catalyze more secure, functional, and efficient decentralized technologies.
Blockchain fuelled the innovation of numerous application fields. In particular, Web3 applications benefit the most because blockchain can be used to implement a rewarding system for users that contribute the most, thus increasing the overall social good provided by these platforms. One of the sectors that has benefited most from blockchain technology is the gaming sector through the so-called Play-to-Earn (P2E) model. The P2E Blockchain Video Games allow players to earn rewards in the form of tokens or NFTs, by having an impact on the social good. Unfortunately, bot accounts could exploit these platforms, which defeats the purpose of having a reward system because they invalidate the social good introduced by the rewards. In this paper, we provide an analysis geared towards detecting suspicious behaviour in P2E blockchain-based games by exploiting Gods Unchained as a case study. Using the game’s official APIs, we download 12 months’ worth of players’ activity. Analysing the data, we detect two groups of players with abnormal activity. Additionally, analysing the players’ graph, we find communities made of the best players with similar activity. Lastly, we observe that users with suspicious behaviour belong to these communities.
This paper explores the vulnerability of machine learning models, specifically Random Forest, Decision Tree, and K-Nearest Neighbors, to very simple single-feature adversarial attacks in the context of Ethereum fraudulent transaction detection. Through comprehensive experimentation, we investigate the impact of various adversarial attack strategies on model performance metrics, such as accuracy, precision, recall, and F1-score. Our findings, highlighting how prone those techniques are to simple attacks, are alarming, and the inconsistency in the attacks' effect on different algorithms promises ways for attack mitigation. We examine the effectiveness of different mitigation strategies, including adversarial training and enhanced feature selection, in enhancing model robustness.
The rampant fraudulent activities on Ethereum hinder the healthy development of the blockchain ecosystem, necessitating the reinforcement of regulations. However, multiple imbalances involving account interaction frequencies and interaction types in the Ethereum transaction environment pose significant challenges to data mining-based fraud detection research. To address this, we first propose the concept of meta-interactions to refine interaction behaviors in Ethereum, and based on this, we present a dual self-supervision enhanced Ethereum fraud detection framework, named Meta-IFD. This framework initially introduces a generative self-supervision mechanism to augment the interaction features of accounts, followed by a contrastive self-supervision mechanism to differentiate various behavior patterns, and ultimately characterizes the behavioral representations of accounts and mines potential fraud risks through multi-view interaction feature learning. Extensive experiments on real Ethereum datasets demonstrate the effectiveness and superiority of our framework in detecting common Ethereum fraud behaviors such as Ponzi schemes and phishing scams. Additionally, the generative module can effectively alleviate the interaction distribution imbalance in Ethereum data, while the contrastive module significantly enhances the framework's ability to distinguish different behavior patterns. The source code will be available in https://github.com/GISec-Team/Meta-IFD.
Ransomware attacks, exploiting cryptocurrencies like Bitcoin for ransom payments, represent a significant cybersecurity threat. Detecting these malicious activities within the Bitcoin network is challenging due to complex transaction patterns and blockchain’s inherent anonymity. Understanding these patterns is crucial for effective defense mechanisms. However, existing research lacks comprehensive analysis of ransomware behavior on the Bitcoin network, leaving gaps in understanding. Moreover, current detection strategies often struggle to accurately identify ransomware activities. To address these gaps, this study conducted experimental research using the BitcoinHeist dataset. Employing machine learning techniques and feature engineering, the analysis aims to decipher transaction patterns and identify ransomware characteristics. The model achieves an accuracy of 85%, demonstrating its effectiveness in detecting ransomware activities. By bridging theoretical knowledge with empirical analysis, this research enhances understanding and aids in developing robust defense strategies against ransomware attacks.
With the vigorous development of the blockchain industry, cross-chain transactions can effectively solve the problem of “islands of value” caused by the inability to interact between different chains. However, security risks in reputation management caused by cross-chain transactions implemented through notary solutions have always existed. Consequently, this paper proposes a blockchain cross-chain transaction method based on decentralized dynamic reputation value assessment. The notary election phase addresses the issue of the continually changing behaviour of notaries in actual transactions by designing a dynamic evaluation window mechanism based on an RNN. Moreover, a reputation-rating decay mechanism is introduced to avoid the problem of reputation value recovery caused by malicious notaries being inactive for a long time. Relative to alternative reputation assessment models, the proposed method offers a thorough evaluation of user behavior and effectively identifies malicious activities in real-time. Finally, the method was tested by deploying it on the Ethereum blockchain. Our approach offers more dynamic settings for window parameters, adapting to changes in notary behavior and reducing the number of detections within the same timeframe by approximately 59.14%. The weight factor settings are also optimized, allowing for adjustments based on specific situations to achieve accurate reputation values. Overall, this method not only enhances the security of cross-chain transactions but also reduces operational costs by 53.3% compared to traditional technologies.
In the rapidly evolving landscape of blockchain technology, security emerges as a paramount concern. This paper introduces an innovative blockchain security threat awareness platform, designed to comprehensively address the multifaceted security challenges within blockchain networks, particularly focusing on Ethereum contracts. Central to the platform is a dual-database architecture, blending a NoSQL database with a graph database, enhancing data management, and enabling intricate transaction network visualizations. The platform's Threat Detection module, utilizing Large Language Models (LLMs) in conjunction with traditional methods, offers a novel approach to identifying and categorizing vulnerabilities in Ethereum smart contracts. Complementing this, the Threat Evidence Collection module provides detailed post-attack analysis, tracing transactions to their sources and evaluating address risks. This module's capabilities extend to producing statistical reports, including the transactional history and risk evaluation of individual addresses. Demonstrated on the Ethereum blockchain, the platform showcases its proficiency in handling complex data, rapid threat detection, and extensive forensic analysis, presenting a robust solution to fortifying blockchain security and offering a proactive defense mechanism for users and developers in the blockchain environment.
Distributed Applications (DApps), powered by smart contracts, have sparked a significant transformation in the Web3 ecosystem by enabling the execution of real-world contracts on decentralized networks. However, the growing popularity of DApps has also led to an increase in malicious activities exploiting smart contracts, thereby exposing users to greater financial risks. Inspired by the FICO score system in traditional finance, we introduce WIRE, a reputation engine designed to evaluate the trustworthiness of deployed DApps. WIRE first derives diverse properties from contract activities, rather than relying solely on potentially irrelevant or unavailable source code. Based on selected properties, WIRE trains a machine learning model for assessing the trustworthiness of individual contracts. Further-more, WIRE utilizes a bytecode disassembler to identify related contracts of a DApp, thus determining its overall trustworthiness score. Moreover, WIRE's dashboard offers explainable and detailed reports that are accessible to users without professional knowledge. The evaluation results show that WIRE can provide a reliable and explainable reputation score for DApps. As a result, WIRE's users can distinguish between benign and malicious DApps or contracts with a high confidence.
In recent years, blockchain has emerged as a promising technology with extensive applications in various fields. One of its most notable applications is cryptocurrency. However, the prevalence of phishing scams in blockchain transaction networks has led to significant economic losses and poses a severe threat to transaction security within the cryptocurrency ecosystem. Existing methods for phishing scams detection often employ traditional machine learning techniques or graph embedding methods to extract key information that distinguishes phishing addresses. Nevertheless, these methods often overlook the temporal information within transaction networks, failing to fully capture the dynamic nature of the blockchain transaction network, resulting in suboptimal detection performance. In this paper, we propose a Temporal Graph Attention Network for blockchain phishing scams detection. Specifically, we use a Long Short-Term Memory (LSTM) network to obtain temporal transaction representations. Additionally, we utilize an attention mechanism to aggregate transaction features and features between neighboring nodes. Finally, by incorporating the obtained node representations and the topological characteristics of nodes, we identify phishing addresses using a Multilayer Perceptron (MLP). Experimental results on three real-world Ethereum phishing scams detection datasets indicate that our proposed method significantly outperforms competing approaches.
Authentication is a crucial security service on the Internet. In real-world applications, multiple independent trust domains often exist, with each recognizing only certain identities within their own systems. During cross-domain access, users cannot directly use their original certificates, which presents a cross-domain authentication problem. Traditional centralized schemes typically employ a trusted third party (TTP) to facilitate the transfer of identity trust across domains. These schemes inevitably inherit the vulnerabilities associated with single points of failure. In contrast, blockchain-based decentralized schemes effectively eliminate the potential threats posed by TTPs. However, the openness and transparency of the blockchain also bring new security issues, such as privacy leakage. In this paper, we propose a zk-SNARK-based anonymous scheme on the blockchain for cross-domain authentication. Specifically, our scheme adopts an authorization-then-proof structure, which strikes a delicate balance between anonymity and revocability. We provide theoretical proofs for the security of our scheme and explain how it achieves proactive revocability. Experimental evaluation results demonstrated that our scheme is both secure and efficient, and the revocation could be accomplished by introducing only 64 bytes of on-chain storage with one hash comparison.
A. Bendada, Mouhamed Amine Bouchiha, Mourad Rabah, Yacine Ghamri-Doudane
Current blockchain-based reputation solutions for crowdsourcing fail to tackle the challenge of ensuring both efficiency and privacy without compromising the scalability of the block chain. Developing an effective, transparent, and privacy-preserving reputation model necessitates on-chain implementation using smart contracts. However, managing task evaluation and reputation updates alongside crowdsourcing transactions on-chain substantially strains system scalability and performance. This paper introduces RollupTheCrowd, a novel blockchain-powered crowdsourcing framework that leverages zkRollups to enhance system scalability while protecting user privacy. Our framework includes an effective and privacy-preserving reputation model that gauges workers' trustworthiness by assessing their crowdsourcing interactions. To alleviate the load on our blockchain, we employ an off-chain storage scheme, optimizing RollupTheCrowd's performance. Utilizing smart contracts and zero-knowledge proofs, our Rollup layer achieves a significant 20x reduction in gas consumption. To prove the feasibility of the proposed framework, we developed a proof-of-concept implementation using cutting-edge tools. The experimental results presented in this paper demonstrate the effectiveness and scalability of RollupTheCrowd, validating its potential for real-world application scenarios.
In recent years, phishing scams have seriously threatened Ethereum's ecological security and caused massive economic losses. Moreover, the significant disparity between the number of normal addresses and phishing addresses on Ethereum poses a challenge for detecting phishing scams. Existing studies primarily employ methods such as oversampling, filtering rules, and traditional machine learning models to resolve the Ethereum data imbalance problem. However, these methods disregard topological structure features of the transaction network and the link relationship between nodes. In this paper, we propose an Ethereum phishing scams detection model based on Generative Adversarial Graph Networks called EGAGN to alleviate imbalanced data, enhance node representation, and then improve detection performance. Specifically, the graph generator and discriminator play with each other to generate synthetic nodes that satisfy the real nodes distribution to balance Ethereum data and extract effective network structural features. We further extract statistical features from the transaction network and aggregate transaction records based on time series to obtain trading features. The complete representation of nodes is composed of the above three types of features to detect phishing nodes. Experimental results on the real-world Ethereum dataset show that EGAGN outperforms existing models and is far ahead in recall, which indicates that our model can effectively detect Ethereum phishing scams.