Smart contracts deployed on blockchain platforms are vulnerable to various security vulnerabilities. However, only a small number of Ethereum contracts have released their source code, so vulnerability detection at the bytecode level is crucial. This paper introduces SmartBugBert, a novel approach that combines BERT-based deep learning with control flow graph (CFG) analysis to detect vulnerabilities directly from bytecode. Our method first decompiles smart contract bytecode into optimized opcode sequences, extracts semantic features using TF-IDF, constructs control flow graphs to capture execution logic, and isolates vulnerable CFG fragments for targeted analysis. By integrating both semantic and structural information through a fine-tuned BERT model and LightGBM classifier, our approach effectively identifies four critical vulnerability types: transaction-ordering, access control, self-destruct, and timestamp dependency vulnerabilities. Experimental evaluation on 6,157 Ethereum smart contracts demonstrates that SmartBugBert achieves 90.62% precision, 91.76% recall, and 91.19% F1-score, significantly outperforming existing detection methods. Ablation studies confirm that the combination of semantic features with CFG information substantially enhances detection performance. Furthermore, our approach maintains efficient detection speed (0.14 seconds per contract), making it practical for large-scale vulnerability assessment.
ABSTRACT Ensuring the security and privacy of sensitive health data in Internet of Things (IoT)‐based healthcare systems (HCS) is a critical challenge. This paper proposes a robust security framework by integrating blockchain mechanisms and deep learning (DL) approaches to enhance security and data privacy. The proposed framework leverages the Ethereum blockchain with zero knowledge proof (ZKP) to ensure data integrity and confidentiality, while the interplanetary file system (IPFS) provides secure and efficient data storage. Additionally, a novel At‐GAN‐BiLSTM model is introduced for intrusion detection by combining the attention mechanism, generative adversarial networks (GAN) and bidirectional long short‐term memory (Bi‐LSTM) to improve detection accuracy and also help to enhance model robustness. The proposed model is evaluated by two different benchmark datasets, namely CICIDS‐2018 (D1) and ToN‐IoT (D2), achieving accuracies of 99.9% and 99.1%, respectively. Comparative investigation shows that the proposed approach reduces false alarm rates (FAR) and performs better than current models in identifying impersonation, insider, and man‐in‐the‐middle (MITM) attacks. By integrating blockchain and DL, the proposed framework significantly enhances intrusion detection, data security, and overall system resilience, addressing key vulnerabilities in IoT‐based healthcare security.
Smart contracts are fundamental pillars of the blockchain, playing a crucial role in facilitating various business transactions. However, these smart contracts are vulnerable to exploitable bugs that can lead to substantial monetary losses. A recent study reveals that over 80% of these exploitable bugs, which are primarily functional bugs, can evade the detection of current tools. Automatically identifying functional bugs in smart contracts presents challenges from multiple perspectives. The primary issue is the significant gap between understanding the high-level logic of the business model and checking the low-level implementations in smart contracts. Furthermore, identifying deeply rooted functional bugs in smart contracts requires the automated generation of effective detection oracles based on various bug features.To address these challenges, we design and implement PromFuzz, an automated and scalable system to detect functional bugs in smart contracts. In PromFuzz, we first propose a novel Large Language Model (LLM)-driven analysis framework, which leverages a dual-agent prompt engineering strategy to pinpoint potentially vulnerable functions for further scrutiny. We then implement a dual-stage coupling approach, which focuses on generating invariant checkers that leverage logic information extracted from potentially vulnerable functions. Finally, we design a bug-oriented fuzzing engine, which maps the logical information from the high-level business model to the low-level smart contract implementations, and performs the bug-oriented fuzzing on targeted functions. We evaluate PromFuzz from 4 perspectives on 5 ground-truth datasets and compare it with multiple state-of-the-art methods. The results show that PromFuzz achieves 86.96% recall and 93.02% F1-score in detecting functional bugs, marking at least a 50% improvement in both metrics over state-of-the-art methods. Moreover, we perform an in-depth analysis on 10 real-world DeFi projects and detect 30 zero-day bugs. Our further case studies, the risky first deposit bug and the AMM price oracle manipulation bug on real-world DeFi projects, demonstrate the serious risks of the exploitable functional bugs in smart contracts. Up to now, 24 zero-day bugs have been assigned CVE IDs. Our discoveries have safeguarded assets totaling $18.2 billion from potential monetary losses.
Junhao Wu, Yixin Yang, Chengxiang Jin, Silu Mu · 8 authors
With the widespread adoption of Ethereum, financial frauds such as Ponzi schemes have become increasingly rampant in the blockchain ecosystem, posing significant threats to the security of account assets. Existing Ethereum fraud detection methods typically model account transactions as graphs, but this approach primarily focuses on binary transactional relationships between accounts, failing to adequately capture the complex multi-party interaction patterns inherent in Ethereum. To address this, we propose a hypergraph modeling method for the Ponzi scheme detection method in Ethereum, called HyperDet. Specifically, we treat transaction hashes as hyperedges that connect all the relevant accounts involved in a transaction. Additionally, we design a two-step hypergraph sampling strategy to significantly reduce computational complexity. Furthermore, we introduce a dual-channel detection module, including the hypergraph detection channel and the hyper-homo graph detection channel, to be compatible with existing detection methods. Experimental results show that, compared to traditional homogeneous graph-based methods, the hyper-homo graph detection channel achieves significant performance improvements, demonstrating the superiority of hypergraph in Ponzi scheme detection. This research offers innovations for modeling complex relationships in blockchain data.
Ahmed Mohamed Abdallah, Heba K. Aslan, Mohamed S. Abdallah, Young Im Cho · 5 authors
In recent years, the rapid growth of cryptocurrency markets has highlighted the urgent need for advanced security solutions capable of addressing a spectrum of unique threats, from phishing and wallet hacks to complex blockchain vulnerabilities. This paper presents a comprehensive approach to fortifying cryptocurrency systems by harnessing the structural symmetry inherent in transactional patterns. By leveraging local large language models (LLMs), embeddings, and vector databases, we develop an intelligent and scalable security expert system that exploits symmetry-based anomaly detection to enhance threat identification. Cryptocurrency networks face increasing threats from sophisticated attacks that often exploit asymmetric vulnerabilities. To counteract these risks, we propose a novel security expert system that integrates symmetry-aware analysis through LLMs and advanced embedding techniques. Our system efficiently captures symmetrical transaction patterns, enabling robust detection of anomalies and threats while preserving structural integrity. By integrating a modular framework with LangChain and a vector database (Chroma DB), we achieve improved accuracy, recall, and precision by leveraging the symmetry of transaction distributions and behavioral patterns. This work sets a new benchmark for LLM-driven cybersecurity solutions, offering a scalable and adaptive approach to reinforcing the security symmetry in cryptocurrency systems. The proposed expert system was evaluated using a benchmark dataset of cryptocurrency transactions, including real-world threat scenarios involving phishing, fraudulent transactions, and blockchain anomalies. The system achieved an accuracy of 92%, a precision of 89%, and a recall of 93%, demonstrating a 10% improvement over existing security frameworks. Compared to traditional rule-based and machine learning-based detection methods, our approach significantly enhances real-time threat detection while reducing false positives. The integration of LLMs with embeddings and vector retrieval enables more efficient contextual anomaly detection, setting a new benchmark for AI-driven security solutions in the cryptocurrency domain.
Kyounggon Kim, Seok‐Hee Lee, Sundaresan Ramachandran, Ibrahim Alzahrani
Cybercriminals are employing sophisticated techniques to illegally obtain money from victims, with ransomware, that is the most notorious malware utilized for financial gain. This paper focuses on the Arab world, a prime target region for ransomware gangs. Due to rapid economic growth and digitalization in this region, cybercriminals are increasingly targeting it. However, there is a lack of research on ransomware crime syndication in the Arab region. Data on claimed ransomware victims from 2020 to 2023 was collected from the darknet. Analysis of ransomware gangs in this area revealed significant findings. Based on three years of data collection and analysis, 20 ransomware gangs primarily operating in the Arab region were identified in 2023. Three major ransomware gangs-LockBit, ALPHV/BlackCat, and CL0P-are predominantly targeting the Arab world, with the United Arab Emirates and Saudi Arabia being major targets, along with the manufacturing industry. In addition to identifying the ransomware gangs, the tactics, techniques, and procedures (TTP) used by them were also identified. There was 17 TTPs used by ransomware gangs. This study has also developed a platform to track ransomware gangs and cryptocurrency transactions. Bitcoin’s anonymity and popularity made it the most preferred cryptocurrency by ransomware gangs. This research lays the groundwork for further studies to understand the exact trends and data related to ransomware in the Arab world.
• Agent-based modeling can be used to study the sociotechnical dynamics associated with technology implementation. • Ethereum’s ERC-721protocol can be leveraged to facilitate reducing the prevalence of counterfeit electronic parts. • Widespread adoption of blockchain is required to reduce the flow of counterfeit electronic parts. • Adoption is sensitive to the direct and indirect cost associated with blockchain implementation. • Integerating blockchain with business practice verification can reduces its cost, leading to an increase in adoption. Safety-critical, mission-critical, and infrastructure-critical systems (e.g., aerospace, transportation, defense, and power generation) are forced to source parts over exceptionally long periods of time from a supply chain that they do not control. Such systems are exposed to the dual risks of the impacts of system failure and the exposure to an unauthorized electronics marketplace over decades. Therefore, critical systems operators, manufacturers, and sustainers, must implement policies and technologies to reduce the risk of obtaining counterfeit parts. Blockchain technology, as a distributed ledger platform, has shown promise for resolving the issues associated with a lack of trust, transparency in peer-to-peer transactional networks, and compromised supply chains. There are opportunities to apply blockchain for supply chain concepts to mitigate the risks associated with part authenticity in the electronic part supply chain. This paper introduces a supply-chain blockchain framework resilient to aging (e.g., the loss of involvement of the original component manufacture and its authorized distributors, and loss of part transaction history). An agent-based model is introduced as a novel platform to test the impact of the proposed blockchain framework on supply-chain parties as well as the prevalence of counterfeits in the electronics supply chain. The model can validate the proposed protocol over the entire life cycle of a part (i.e., from active production to discontinuance and beyond) and predict the parties’ adoption rates, and changes in the prevalence of counterfeit parts. Application of the model to a public participation blockchain based on Ethereum ERC- 721 protocols indicates that the participation level of independent distributors directly affects the efficacy of blockchain in the prevention of transactions containing counterfeit parts. A proposed certification-based blockchain participation approach can be effective if certifications require large enough test accuracy limits and high previous owner certification thresholds.
With the rapid development of blockchain technology, P2P networks are facing increasing security threats, among which Eclipse attacks, as a type of network isolation attack, have seriously affected the normal operation of the network and the integrity of data. To address this challenge, this study implements node authentication and dynamic reputation evaluation by leveraging a dynamic hash computation mechanism that integrates challenge strings, node identifiers, and the latest active time, ensuring the uniqueness of node identities and the authenticity of operations. Based on a dynamic hash chain behavior evaluation mechanism, node behaviors are quantified across three dimensions: integrity, consistency, and temporal consistency, enabling precise identification of anomalous nodes. Furthermore, a network prevention repository framework is proposed, which dynamically adjusts the trust index of nodes by combining historical behavior with real-time data, effectively detecting and defending against stealthy Eclipse attacks. In addition, extensive testing on both Bitcoin and Ethereum platforms has shown that the method proposed in this study not only can effectively coexist on these two platforms, but also significantly improves the security and stability of the network, effectively reducing the occurrence of Eclipse attacks.
Detecting fraudulent activities such as Ponzi schemes within smart contract transactions is a critical challenge in decentralized finance. Existing methods often fail to capture the heterogeneous, multi-faceted nature of blockchain data, and many graph-based models overlook the contextual patterns that are vital for effective anomaly detection. In this paper, we propose MVCG-SPS, a Multi-View Contrastive Graph Neural Network designed to address these limitations. Our approach incorporates three key innovations: (1) Meta-Path-Based View Construction, which constructs multiple views of the data using meta-paths to capture different semantic relationships; (2) Reinforcement-Learning-Driven Multi-View Aggregation, which adaptively combines features from multiple views by optimizing aggregation weights through reinforcement learning; and (3) Multi-Scale Contrastive Learning, which aligns embeddings both within and across views to enhance representation robustness and improve anomaly detection performance. By leveraging a multi-view strategy, MVCG-SPS effectively integrates diverse perspectives to detect complex fraudulent behaviors in blockchain ecosystems. Extensive experiments on real-world Ethereum datasets demonstrated that MVCG-SPS consistently outperformed state-of-the-art baselines across multiple metrics, including F1 Score, AUPRC, and Rec@K. Our work provides a new direction for multi-view graph-based anomaly detection and offers valuable insights for improving security in decentralized financial systems.
Ethereum, the first blockchain platform to support smart contracts, has become a target for various cybercrimes, particularly financial frauds like Ponzi schemes. Ponzi schemes on Ethereum are known as Smart Ponzi Schemes (or Ponzi Contracts) and have caused huge financial losses. Current Ponzi contract detection models face three main challenges: simple opcode sequence processing does not effectively distinguish Ponzi from non-Ponzi contracts, single-feature-based models lack accuracy, and reliance on transaction records hinders early detection. To address these issues, this paper proposes a Multi-Feature Ponzi Scheme Detection Model (MFDPonzi). MFDPonzi tracks the changes in stack, memory, and storage parameters during the execution of smart contracts, reconstructing opcode sequences and extracting diverse features, including semantic and developer features. Finally, a multi-feature fusion algorithm is used to enhance model stability. Additionally, MFDPonzi can identify Ponzi contracts at the early stage of smart contract creation without relying on transaction data. Experimental results show that MFDPonzi achieves an 85.9% recall and an 88.7% F-score on Ethereum smart contracts, outperforming baselines in both performance and robustness.
Y. T. Zhang, Guojun Wang, Peiqiang Li, Wanyi Gu · 5 authors
Abstract With the rapid evolution of blockchain technologies, Ethereum has emerged as a central platform for advanced financial applications but has concurrently experienced a rise in security vulnerabilities, particularly from front-running attacks. These attacks exploit transaction sequencing for illegal gains. To combat this, we introduce FRACE (Front-Running Attack Classification using Ensemble Learning), a novel methodology that classifies front-running attacks into displacement, insertion, and suppression using an ensemble learning model. This precise classification facilitates tailored defensive strategies, enhancing the robustness and accuracy of attack detection. Our approach achieves an accuracy of 95.36% and an F1-score of 95.30%, significantly improving the security of decentralized applications. Extensive analysis and validation on Ethereum confirm these results. Future efforts will refine these models and extend their application to other blockchain platforms, striving for a universally secure, transparent, and reliable digital transaction ecosystem.
Detecting Ethereum phishing scams is extremely urgent. In this paper, we propose a novel Hybrid Attention Model for Ethereum phishing scams detection called HATTM to solve the problem of irregular transaction series in Ethereum, fully extract account features and then improve detection performance. Specifically, we take a novel perspective by regarding each transaction of an account as a separate amount-time point to handle irregular data. In the hybrid attention model, we capture intra-account and inter-account trading features through intra-account attention of EPS-FORMER and inter-account attention of EPSGAT, respectively. We further extract Intra-account and Inter-account statistical features to enrich the account representation. The complete representation of accounts is composed of the above four types of features to detect phishing accounts. Experimental results on the real-world Ethereum dataset show that HATTM outperforms existing models and is far ahead in the recall, which indicates that our model can effectively detect Ethereum phishing scams.
IoT-enabled smart agriculture enhances farming with real-time data insights but faces security and scalability challenges. This study integrates IOTA’s distributed ledger technology into smart irrigation systems, leveraging its Tangle architecture for fee-less, lightweight, and scalable transactions. The system ensures tamper-proof data integrity and real-time decision-making, crucial for precision agriculture. Experimental results show efficient data transmission (336 bytes) with processing times of 0.7–1.3 seconds and rapid data retrieval (1×10⁻⁶– 4×10⁻⁶ seconds). A comparative analysis highlights IOTA’s superiority over traditional blockchain systems, demonstrating its robustness, scalability, and efficiency for secure, real-time IoT-based smart farming.
In recent years, the proliferation of malware has reached unprecedented levels, leading to escalating cybercrime costs. Signatures extracted by static analysis of files have been widely adopted for malware detection: vendors maintain databases of known malware signatures that are shared with registered users. The recent literature has proposed the use of private and consortium (thus, permissioned) blockchains for spreading signatures among blockchain users. These approaches require controlled access to enhance trust and accountability but restrict the widespread sharing of up-to-date signatures because users must be registered. In this paper, we present a novel technique that leverages a public blockchain to enable the massive dissemination of malware signatures among any users since a public blockchain is permissionless. On the other hand, the use of a public blockchain introduces new challenges related to security and data privacy, which our solution solves. The main benefit and outcome of our solution is that any users can securely access and verify malware signatures facilitating real-time detection of malicious files. We implemented our solution in Ethereum and exploited a smart contract written in Solidity to demonstrate that our approach is highly cost-effective.
Oshoke Samson Igonor, Muhammad Bilal Amin, Saurabh K. Garg†
Blockchain technology has risen in recent years from its initial application in finance to gain prominence across diverse sectors, including digital forensics. The possible application of blockchain technology to digital forensics is now becoming increasingly explored with many researchers now looking into the unique inherent properties that blockchain possesses to address the inherent challenges in this sector such as evidence tampering, the lack of transparency, and inadmissibility in court. Despite the increasing interest in integrating blockchain technology into the field of digital forensics and its domains, no systematic literature review currently exists to provide a holistic perspective on this integration. It is a challenge to find a comprehensive resource that examines how blockchain is being applied to enhance the digital forensics process. This paper provides a systematic literature review to explore the application of blockchain technology in digital forensics, focusing on its potential to address these challenges and enhance forensic methodologies. Through a rigorous review process, this paper examines selected studies to identify diverse frameworks, methodologies, and blockchain-driven enhancements applied to digital forensic investigations. The discussion highlights how blockchain properties such as immutability, transparency, and automation have been leveraged to improve evidence management and forensic workflows. Furthermore, this paper explores the common applications of blockchain-based forensic solutions across various domains and phases while addressing the associated limitations and challenges. Open issues and future research directions, including unexplored domains and operational gaps, are also discussed. This study provides valuable insights for researchers, investigators, and policymakers by offering a comprehensive overview of the state of the art in blockchain-based digital forensics, summarizing key contributions and limitations, and identifying pathways for advancing the field.
Independent Researcher, San Francisco, CA, USA, Sahaj Tushar Gandhi
Smart contracts, which allow for decentralized, automated transactions on blockchains, have been the source of repeated financial loss from hacking and coding flaws. This article introduces an AI-based deep learning approach to automated detection of vulnerabilities in smart contracts on Ethereum. The architecture integrates code- token embeddings (CodeBERT-style), control- and data-flow graph representations, and a hierarchical graph neural network (HGNN) with attention-based multimodal fusion to allow for comprehensive understanding of human-written programs. We train on labelled datasets from real-world contracts, utilising data augmentation and addressing class imbalance (focal loss + over sampling). For the experimental study, we compare the performance of our framework with existing solely-static and sequence-based transformers approaches apart from other GNN models on public datasets; ScrawlD, SmartBugs and manually curated Github-derived samples. Results The fused HGNN model performs with an average F1-score of 0.91, precision of 0.89, recall of 0.93 and AUC of 0.95 better than transformer- only (F1 = 0.86) and static-tool baselines (F1 = 0.71). The method shows strong generality to a wide range of vulnerability forms (reentrancy, integer overflow, unchecked calls, access control bugs) and enhances the precision for function-level localization. We further develop an interpretation module to map attention weights back to AST/CFG regions for human auditors. The paper also addresses limitations on dataset bias, obfuscation-resilience and adversarial examples and provides ideas for further investigation such as few-shot adaptation with one-class VAEs, integration with continuous deployment pipelines. The contributions: a multimodal deep-learning model for vulnerability detection and localization, an empirical study on state-of-the-art performance in multiple benchmark projects with large amounts of code; and advice how to deploy the AI-assisted contract auditing in development workflows.
Faisal Alamri, Anand K. Bapatla, Venkata K. V. V. Bathalapalli, Saraju P. Mohanty · 5 authors
The Vaccine Supply Chain (VSC) is a crucial component of the Healthcare Cyber-Physical System (H-CPS), enabling seamless coordination among various entities to ensure the timely delivery of safe and effective vaccines. Given the extensive number of interactions and the stringent requirements for monitoring environmental parameters, the VSC features a highly complex architecture with intricate operational dynamics. This complexity, coupled with the reliance on multiple centralized systems, often results in lack of transparency, making it challenging to monitor the vaccine movement withing the supply chain network as well as recording the temperature excursions. To address these challenges, a novel blockchain-based system that provides a transparent and secure mechanism for storing and accessing vaccine records is proposed. By leveraging the IOTA Tangle data structure, system meets the high throughput demands of the application while ensuring data integrity and scalability. A proof-of-concept implementation was developed and analyzed to evaluate its scalability and adaptability for real-world deployment, demonstrating its potential to revolutionize the VSC by enhancing transparency and efficiency.
Owing to the swift advancement of technology and the unfamiliarity of the execution environment, the development of Solidity smart contracts from scratch often results in significant vulnerabilities.In contrast, automated code generation enhances productivity, minimizes development time, and enables developers to focus on high-level tasks and fundamental logic.In consideration of these two viewpoints, this paper examines the utilization of large language models (LLMs) for the automatic generation of Solidity smart contracts based on specified criteria, while simultaneously ensuring the elimination of vulnerabilities through a novel masking strategy.To achieve this, we propose SolGen, a framework for generating secure Solidity smart contract code using LLMs.We assess the performance of existing LLMs (i.e.ChatGPT and Meta AI) for secure Solidity code generation.Our research indicates that ChatGPT outperforms Meta AI in performance, yielding a greater percentage of syntactically accurate and secure code.Additionally, we examine the impact of temperature adjustment on the security of generated contracts using an open-source LLM, Llama3.Our findings suggest that a temperature setting of 0.7 is optimal for the generation of Solidity code, considerably exceeding the performance of both lower and higher settings (0.1 and 1.2), especially with regard to the compilability of the code.
The popularity of smart contracts has cemented their place in the Blockchain Ecosystem.This is because of the immense number of use cases smart contracts provide.They have become the go-to solution for improving transparency and security for all parties involved in the transaction.Furthermore, a smart contract is immutable after it is deployed.Thus optimization of the smart contract is very important before deployment.Sol-Repairer is a tool that provides the implementation for identifying dead code segments from solidity-written smart contracts and then repairing them.Extensive experiments show that Sol-Repairer optimizes dead code better than the solidity compiler.The study also demonstrates that optimizing dead code reduces gas consumption significantly for smart contracts. CCS Concepts• Software and its engineering → Software testing and debugging.
Abstract Applying Distributed Ledger Technologies to securely manage intercommunicated data between IoT applications has recently been adopted on an enormous scale. They enable data integrity, privacy, and robustness to public, open, permission-less P2P networks. Voting-based consensus algorithms proved high efficiency even with limited computing and less power IoT devices. Moreover, they can identify legitimate information and isolate malicious attackers through repetitive voting queries to adjacent peers asking their opinions about the validity of each transaction. Several lightweight validation models are introduced to enrich IoT networks with better performance and higher security. Nevertheless, the current algorithms struggle to find adequate parameters that balance network security and operability, in addition to balancing fairness in distributed environments. This paper introduces an Autonomous Lightweight Ledger Constructor to resolve common defects and threats. Based on Reinforcement Learning, it can dynamically construct a valid distributed ledger in limited-computing systems under several adversarial conditions. The validity of transactions in this approach is calculated based on their cumulative weights and the issuer’s reputation, which are inferred subjectively by a lightweight Bayesian-like function. A new simulator is developed to evaluate ALLC performance and security. The experimental results demonstrate reasonable performance and high resistance against known compromises targeting Distributed Ledger Technologies.
In smart contract fuzz testing, it is crucial to consider the inter-dependencies between the contract functions. To effectively test the business logic of a contract, its functions must be invoked in a meaningful order. In this paper, we propose techniques that utilize static analysis on Ethereum bytecode to tackle this challenge. When compared with the current state-of-the-art, our approach takes Solidity compiler’s variable packing optimization into account and allows more precise analysis of the data-flows between functions. In addition, we devise a novel test case initialization algorithm for fuzz testing, which minimizes the redundancy in the generated seed set. Our algorithm reduces test cases that share similar function call patterns and leads to more effective testing of the contract code during the fuzz testing. Experimental results show that the proposed techniques improve the effectiveness of smart contract fuzz testing for vulnerability detection. Specifically, our techniques enabled the fuzz testing tool to trigger the target bugs in the benchmark 3.0 times faster on average.