Decentralized Finance (DeFi) has emerged as a transformative force in the financial landscape, bringing about challenges in ensuring blockchain security. This paper systematically examines prominent DeFi incidents from June 2022 to May 2023. Our findings underscore the significance of continuous vigilance in DeFi operations.
Izdehar M. Aldyaflah, Wenbing Zhao, Shunkun Yang, Xiong Luo
Stemming vulnerabilities out of a smart contract prior to its deployment is essential to ensure the security of decentralized applications. As such, numerous tools and machine-learning-based methods have been proposed to help detect vulnerabilities in smart contracts. Furthermore, various ways of encoding the smart contracts for analysis have also been proposed. However, the impact of these input methods has not been systematically studied, which is the primary goal of this paper. In this preliminary study, we experimented with four common types of input, including Word2Vec, FastText, Bag-of-Words (BoW), and Term Frequency–Inverse Document Frequency (TF-IDF). To focus on the comparison of these input types, we used the same deep-learning model, i.e., convolutional neural networks, in all experiments. Using a public dataset, we compared the vulnerability detection performance of the four input types both in the binary classification scenarios and the multiclass classification scenario. Our findings show that TF-IDF is the best overall input type among the four. TF-IDF has excellent detection performance in all scenarios: (1) it has the best F1 score and accuracy in binary classifications for all vulnerability types except for the delegate vulnerability where TF-IDF comes in a close second, and (2) it comes in a very close second behind BoW (within 0.8%) in the multiclass classification.
Wuqi Zhang, Zhuo Zhang, Qingkai Shi, Lu Liu · 8 authors
Smart contracts are susceptible to front-running attacks, in which malicious users leverage prior knowledge of upcoming transactions to execute attack transactions in advance and benefit their own portfolios. Existing contract analysis techniques raise a number of false positives and false negatives in that they simplistically treat data races in a contract as front-running vulnerabilities and can only analyze contracts in isolation. In this work, we formalize the definition of exploitable front-running vulnerabilities based on previous empirical studies on historical attacks, and present Nyx, a novel static analyzer to detect them. Nyx features a Datalog-based preprocessing procedure that efficiently and soundly prunes a large part of the search space, followed by a symbolic validation engine that precisely locates vulnerabilities with an SMT solver. We evaluate Nyx using a large dataset that comprises 513 real-world front-running attacks in smart contracts. Compared to six state-of-the-art techniques, Nyx surpasses them by 32.64%-90.19% in terms of recall and 2.89%-70.89% in terms of precision. Nyx has also identified four zero-days in real-world smart contracts.
Price Oracle Manipulation Attacks (POMAs) are increasingly occurring in blockchain systems, and result in significant financial loss. Prior work on detecting POMAs only considers single-transaction attacks, in which the entire attack is contained within a single transaction. We systematically study POMAs in blockchain systems (Ethereum). We find that POMAs that span multiple transactions have become much more frequent than single-transaction POMAs. Thus, there is a compelling need for a framework that can detect POMAs spanning multiple transactions. Moreover, there is a need to come up with generic rules for detecting POMAs rather than rely on past attack patterns like prior work has done.We first devise first-principle rules for detecting POMAs based on traditional stock market manipulation attacks. We then propose POMABuster, which leverages these rules to detect POMAs spanning both single and multiple transactions. POMABuster leverages common characteristics of POMA attackers’ behavior to optimize its detection. We evaluate POMABuster on 2.5 years’ worth of transactions from the blockchain, as well as a dataset compiled from the Code4rena audit reports. Our results demonstrate that POMABuster detects nearly 6.5X more POMAs than prior work. Further, POMABuster has a 1% worst-case false positive rate, and zero false negative rate, both of which significantly outperform prior work.
In the current era of rapid technological advancement, while numerous problems have been addressed, the issue of data security has emerged as a significant challenge. This concern is prevalent across various sectors, including finance, healthcare, and daily activities, where protecting sensitive data is paramount. Against this backdrop, blockchain technology, characterized by its decentralized nature, presents a compelling solution to these security difficulties. This paper aims to shed light on the efficacy of blockchain as a robust security tool, emphasizing its potential to safeguard data in an increasingly vulnerable digital landscape. In this paper, we explore the strengths of blockchain security and the prospective advancements that promise to fortify data protection shortly.
Jaime Govea, Walter Gaibor-Naranjo, William Villegas-Ch
Currently, in the digital era, critical infrastructure is increasingly exposed to cyber threats to their operation and security. This study explores the use of blockchain technology to address these challenges, highlighting its immutability, decentralization, and transparency as keys to strengthening the resilience of these vital structures. Through a methodology encompassing literature review, use-case analysis, and the development and evaluation of prototypes, the effective implementation of the blockchain in the protection of critical infrastructure is investigated. The experimental results reveal the positive impact of the blockchain on security and resilience, presenting a solid defense against cyber-attacks due to its immutable and decentralized structure, with a 40% reduction in security incidents. Despite the observed benefits, blockchain integration faces significant challenges in scalability, interoperability, and regulations. This work demonstrates the potential of the blockchain to strengthen critical infrastructure. It marks progress towards the blockchain’s practical adoption, offering a clear direction for future research and development in this evolving field.
This conceptual paper delves into the intriguing intersection between Ponzi schemes and cryptocurrency, shedding light on the unique dynamics, challenges, and implications arising from their convergence. While Ponzi schemes have long been recognized as fraudulent investment schemes, the emergence of cryptocurrency has introduced novel avenues for perpetrating such schemes. This paper examines the underlying mechanisms that facilitate the fusion of Ponzi schemes and cryptocurrency. It explores the emergence, characteristics, impact, and regulatory challenges. This paper contributes to a deeper understanding of the complex dynamics at play and provides insights into safeguarding investors and promoting the integrity of cryptocurrency markets.
Cryptocurrencies are becoming increasingly important for the modern economy. Prior literature focuses on aligning actor incentives to ensure the secure and efficient operation of cryptocurrencies against adversarial threats that are unobserved in the wild. In this work, we address the gap between the theory and practice of cryptocurrencies by advancing realistic approaches to analyze the economics and security of key cryptocurrency components: consensus mechanisms, transaction fee mechanisms (TFMs), and the application layer. We present novel models of these components that we evaluate both theoretically and using cryptocurrency clients. We augment our evaluation with the first evidence of an in-the-wild attack on a major cryptocurrency, highlighting our approach's practicality. Results contained in our work were adopted by cryptocurrency platforms that hold user assets worth over 300 billion.
Decentralized Finance, known as DeFi (Decentralized Finance), refers to the use of blockchain and digital assets or crypto-assets for the provision of financial services. Through DeFi applications, services such as loans, insurance, crypto-asset exchanges, among others, are offered, and are structured based on crypto-assets and technologically decentralized applications. This paper will discuss the concept of DeFi and how it challenges the traditional market infrastructures of the financial sector, demystifying the idea of absolute decentralization, generally mentioned in the crypto-asset arena. Subsequently, the paper will analyze the opportunities and challenges of DeFi for consumers, financial institutions, new competitors and financial regulators. Among the opportunities, it will present how DeFi could contribute to financial inclusion, to the automation of certain financial products, and how it is a key factor for the development of metaverses. As part of the challenges, the paper will analyze the problems of money laundering and terrorist financing in these markets, financial consumer protection, corporate governance issues, the lack of transparency of these products, cybersecurity risks and systemic risk. Finally, the paper will address some early regulatory responses that policymakers have proposed in response to some of these challenges in different jurisdictions.
Sabuj Saha, Ahmed Rizvan Hasan, Alvi Mahmud, Nujhat Ahmed · 6 authors
The use of cryptocurrency for financial crimes has increased in recent years because of its decentralized and anonymous nature. This study extracted scholarly articles from the Scopus database and adopted bibliographic and content analysis to review financial fraud research in cryptocurrency. In addition, this study discussed the top ten cryptocurrency scams, potential reasons for falling into those traps, and associated theories to explore scammers’ behavior and outlined comprehensive future research guidelines for a safer financial world. Since 2018, the publication trend of revealing cryptocurrency frauds has gained momentum, and research on this topic has increased significantly in the last two years. The USA is the most significant contributor to cryptocurrency scam research. We found that both developed and developing countries are fairly concerned about combatting crypto fraudsters even though there are no regulated guidelines across the countries. The research potential has shifted from malware, bitcoin, and blockchain to fintech-based crimes such as money laundering, pump-and-dump schemes, and phishing. We observed that ICO fraud, money laundering, Ponzi schemes, phishing, darknet market transactions, ransomware, and pumps and dumps are some of the predominant crimes in crypto and that investor overconfidence, speculative expectations, low barriers to entry, decentralization, and anonymity are the primary reasons for crimes in cryptocurrency. This study suggests studying the socioeconomic impacts of cryptocurrencies, the necessity for standardized global regulation, and the integration of interdisciplinary research. Future research should emphasize exploring the innovation cycle in cryptocurrency assets, understanding cybercrime dynamics, guarding against crypto market manipulation, and developing automated scam prevention.
Dan Lin, Jiajing Wu, Yunmei Yu, Qishuang Fu · 6 authors
In recent years, money laundering crimes on blockchain, especially on Ethereum, have become increasingly rampant, resulting in substantial losses. The unique features of money laundering on Ethereum, such as decentralization and pseudonymity, pose new challenges for Ethereum anti-money laundering. Specifically, the existence of dense and extensive laundering gangs and intricate multilayered laundering pathways makes it exceptionally challenging for regulators to identify suspicious accounts and trace money flows. To address this issue, we propose an innovative DenseFlow framework that effectively identifies and traces money laundering activities by finding dense subgraphs and applying the maximum flow idea. We conduct multiple experiments on four datasets from Ethereum to validate the effectiveness of our approach. The precision of our DenseFlow is 16.34% higher than the start-of-the-art comparison methods on average, highlighting its distinctive contribution to tackling money laundering issues on blockchain.
Purpose Earthquakes pose a significant challenge to human safety and the durability of infrastructure, highlighting the urgent need for innovative disaster management strategies. This study addresses the gap in current earthquake disaster management approaches, which are often related to issues of transparency, centralization and sluggish response times. By exploring the integration of blockchain technology into seismic hazard management, the purpose of the research is to overcome these limitations by offering a novel framework for integrating blockchain technology into earthquake risk mitigation and disaster management strategies of smart cities. Design/methodology/approach This study develops an innovative approach to address these issues by introducing a blockchain-based seismic monitoring and automated decision support system for earthquake disaster management in smart cities. This research aims to capitalize on the benefits of blockchain technology, specifically its real-time data accessibility, decentralization and automation capabilities, to enhance earthquake disaster management. The methodology employed integrates seismic monitoring data into a blockchain framework, ensuring accurate, reliable and comprehensive information. Additionally, smart contracts are utilized to handle decision-making and enable rapid responses during earthquake disasters, offering an effective alternative to traditional approaches. Findings The study results highlight the system’s potential to foster reliability, decentralization and efficiency in earthquake disaster management, promoting enhanced collaboration among stakeholders and facilitating swift actions to minimize human and capital loss. This research lays the foundation for further exploration of blockchain technology’s practical applications in other disaster management contexts and its potential to transform traditional practices. Originality/value Current methodologies, while contributing to the reduction of earthquake-related impacts, are often hindered by limitations such as lack of transparency, centralization and slow response times. In contrast, the adoption of blockchain technology can address these challenges and offer benefits over various aspects, including decentralized control, improved security, real-time data accessibility and enhanced inter-organizational collaboration.
I explore how criminals use cryptocurrencies in ransomware operations and leverage the vulnerability of virtual currencies to evade legal restrictions and international scrutiny. I do so by examining three drivers of the ‘merger’ between ransomware and cryptocurrency. First, criminal groups have embraced cutting-edge technologies to make their attacks more effective and maximise benefits that cryptocurrency presents, which include the convenience of fast payment and money laundering and the ease of hacking the currencies themselves. Second, ransomware groups have exploited the legal vacuum in the widespread use of rapidly circulating monetary instruments. Finally, groups have adopted cryptocurrencies because states – primary regulators of international financial transactions – remain in such disagreement over the control of digital activities that they have failed to address problems associated with them. In sum, this article presents a set of technical, legal and political reasons why groups have incorporated crypto in their operations.
In this article, a case-law from the Republic of Moldova of money laundering through cryptocurrencies is analyzed. The case finally reached the Supreme Court of Justice. In this sense, the errors committed by the courts were highlighted and concrete solutions were offered. Also, the relevant normative framework was analyzed and some legislative oversights were pointed out. Last but not least, it was emphasized that in the Republic of Moldova the provision of services regarding virtual assets is prohibited.
Abstract Financial transactions involving cryptocurrencies have seen significant growth in recent years. Individuals and companies are using cryptocurrencies as a medium of exchange. This unstoppable process has brought opportunities for the cost-effective performance of financial transactions, but at the same time challenges for law enforcement institutions. A significant portion of cryptocurrency transactions are conducted outside the conventional banking financial system. Such transactions are difficult for law enforcement authorities to trace. There is a high possibility that cryptocurrencies will be used by money launderers to hide their identity and launder their proceeds of crime. Offshore Financial Centers, which apply a high degree of anonymity, are widely using cryptocurrencies. Countries and international institutions should take coordinated action to tackle money laundering in the field of virtual currencies as it is very difficult for one country, alone, to fight the phenomenon of money laundering in the world of cryptocurrencies. The study focuses on the difficulties faced by financial institutions and law enforcement authorities in tracking cryptocurrency transactions in the context of prevention of money laundering, seen from the Albanian perspective.
The project titled “Rise Together: A Crowdfunding platform” introduces a groundbreaking Crowdfunding Platform on the Ethereum blockchain, revolutionizing traditional fundraising models. Leveraging smart contracts for seamless automation and execution of campaigns, the platform ensures transparency, security, and efficiency. Ethereum's decentralization eliminates intermediaries, reducing costs, and enhancing accessibility. Key features include a user-friendly interface, contribution tracking, and real time campaign monitoring. Utilizing Ether as the native cryptocurrency streamlines contributions, offering a secure and standardized means of support. Positioned at the intersection of blockchain and fundraising, this project contributes to the evolution of decentralized finance, showcasing Ethereum's potential for secure, inclusive, and innovative crowdfunding. Key Words: Rise Together, Crowdfunding, Blockchain, Smart Contract, Transparency, Decentralization, Wallet Integration.
Zhiyang Chen, Ye Liu, Sidi Mohamed Beillahi, Yi Li · 5 authors
Smart contract transactions associated with security attacks often exhibit distinct behavioral patterns compared with historical benign transactions before the attacking events. While many runtime monitoring and guarding mechanisms have been proposed to validate invariants and stop anomalous transactions on the fly, the empirical effectiveness of the invariants used remains largely unexplored. In this paper, we studied 23 prevalent invariants of 8 categories, which are either deployed in high-profile protocols or endorsed by leading auditing firms and security experts. Using these well-established invariants as templates, we developed a tool Trace2Inv which dynamically generates new invariants customized for a given contract based on its historical transaction data. We evaluated Trace2Inv on 42 smart contracts that fell victim to 27 distinct exploits on the Ethereum blockchain. Our findings reveal that the most effective invariant guard alone can successfully block 18 of the 27 identified exploits with minimal gas overhead. Our analysis also shows that most of the invariants remain effective even when the experienced attackers attempt to bypass them. Additionally, we studied the possibility of combining multiple invariant guards, resulting in blocking up to 23 of the 27 benchmark exploits and achieving false positive rates as low as 0.32%. Trace2Inv outperforms current state-of-the-art works on smart contract invariant mining and transaction attack detection in terms of both practicality and accuracy. Though Trace2Inv is not primarily designed for transaction attack detection, it surprisingly found two previously unreported exploit transactions, earlier than any reported exploit transactions against the same victim contracts.
This study explores the transformative impact of blockchain technology on the stock market, emphasizing its implications for transparency, security, and operational efficiency. Investigating key aspects such as stock trading, securities tracing, margin financing, and market risk surveillance, the analysis anticipates revolutionary changes. The advent of decentralized exchanges and tokenization is poised to enhance market accessibility and reduce settlement times. Blockchain's immutability is expected to streamline securities tracing, mitigating fraud risks, while smart contracts may automate margin financing processes, minimizing counterparty risk. Additionally, real-time data feeds and immutable audit trails promise more effective market risk surveillance. The study underscores regulatory, scalability, and privacy concerns, emphasizing collaborative solutions and suggesting a future research agenda that includes exploring emerging trends, regulatory adaptations, and sustainable solutions for a comprehensive understanding of blockchain's evolving role in the financial sector.
Luo Feng, Ruijie Luo, Ting Chen, Ao Qiao · 8 authors
Smart contracts are integral to blockchain's growth, but their vulnerabilities pose a significant threat. Traditional vulnerability detection methods rely heavily on expert-defined complex rules that are labor-intensive and dificult to adapt to the explosive expansion of smart contracts. Some recent studies of neural network-based vulnerability detection also have room for improvement. Therefore, we propose SCVHunter, an extensible framework for smart contract vulnerability detection. Specifically, SCVHunter designs a heterogeneous semantic graph construction phase based on intermediate representations and a vulnerability detection phase based on a heterogeneous graph attention network for smart contracts. In particular, SCVHunter allows users to freely point out more important nodes in the graph, leveraging expert knowledge in a simpler way to aid the automatic capture of more information related to vulnerabilities. We tested SCVHunter on reentrancy, block info dependency, nested call, and transaction state dependency vulnerabilities. Results show remarkable performance, with accuracies of 93.72%, 91.07%, 85.41%, and 87.37% for these vulnerabilities, surpassing previous methods.
Lien Thi Huong Nguyen, Hanh Hong Vu, Anh Phuong Le
Since its public introduction in 2009, Bitcoin has grown to be the most well-known cryptocurrency worldwide. There is still debate as to whether Bitcoin may be used as a hedge against other assets. The purpose of this study is to investigate the correlation between Bitcoin and conventional commodity markets such as gold, crude oil, stock markets, and investor interest (quantified via Google Trends). In addition, the paper also tests Bitcoin’s safe haven role compared to other commodity markets. The Vector Autoregression model using daily database collected during the period 2013–2021 is employed to investigate the relationship between Bitcoin and traditional commodity markets. The impulse response function is used to analyze Bitcoin price movements against economic shocks from gold, oil prices, and the Dow Jones Industrial Average. In addition, the value-at-risk (VaR) model is used to test Bitcoin’s safe-haven property compared to other conventional commodity markets. The research results show that Bitcoin has negative impacts on gold, crude oil prices, and the stock market. Besides, Bitcoin responds negatively to a sharp decline in investor interest. Furthermore, the results of the VaR model show that Bitcoin is the second most volatile and risky asset, only after the crude oil market, and much riskier than gold. This result proves that Bitcoin cannot yet be considered a safe-haven instrument. These findings have several implications for investors and policymakers to minimize the risks associated with this cryptocurrency. AcknowledgmentThe authors would like to send their sincere thanks to the Reviewers and Editorial Board of the Journal. Their valuable comments and helpful support helped improve the paper’s quality. No funding was granted for this study.
The paper's recognition of the emerging phenomenon of cryptocurrencies. The rise of cryptocurrencies’ value on the market and the growing recognition around the arena open some demanding situations and concerns for business and commercial economics. The studies changed realized by way of the technique description, literature evaluation, and carried out research. This paper discusses the primary developments in the academic studies related to the Present Scenario of Cryptocurrency, a short overview of Cryptocurrency, cryptocurrencies through market capitalization, Cryptocurrencies Trending in Asia, Cryptocurrency in India, Cryptocurrency Exchanges, and cryptocurrency rules internationally. Keywords: Cryptocurrency, Bitcoin, Ethereum, Ripple, Virtual Currency, Blockchain *, Cyber Security, Blockchain Wallets, Distributed Ledger.
Ethereum and its native cryptocurrency, Ether, have played a worthy attention in the development of the blockchain and cryptocurrency space. Its programmability and smart contract capabilities have made it a foundational platform for decentralized applications and innovations across various industries. Because of its anonymous and decentralized structure, the hotheaded expansion of cryptocurrencies in the payment space has created both enormous potential and concerns related to cybercrime, including money laundering, financing terrorism, illegal and dangerous services. As more financial institutions attempt to integrate cryptocurrencies into their networks, there is an increasing need to create a more transparent network that can withstand these kinds of attacks. In this work, we are using different classification techniques, such as logistic regression (LR), random forest (RF), k-nearest neighbors (KNN), adaptive boosting (AdaBoost), and extreme gradient boosting (XGBoost) for Ethereum fraud detection. The dataset we are using includes rows of legitimate transactions done using the cryptocurrency Ethereum as well as known fraudulent transactions. The “XGBoost” model, which is noteworthy, detects variations that might attract notice and prevent potential issues in this chore.