Md Jahangir Alam, Ismail Hossain, Sai Puppala, Sajedul Talukder
Identity attacks, such as impersonation, identity theft, and fraudulent account creation, pose significant threats to the security and trustworthiness of Online Social Networks (OSNs). In this paper, we propose a robust and secure framework to verify user identities without compromising their privacy by developing a multi-layered framework leveraging zero-knowledge proof (ZKP) and Hyperledger Fabric private blockchain. We introduce a blockchain-based government identity provider system, coupled with a zero-knowledge proof-based signup process for social networks. Our prototype authenticates user identities in multiple layers, effectively mitigating fraudulent, cloned, and multiple account creations. Our experiments with n (n = 50) users showed a 100% success rate for our system, highlighting its effectiveness compared to other OSNs.
With the increased use of blockchain technology, the significance of digital currencies has grown, making it crucial to ensure the security of blockchain wallets. A blockchain wallets private key serves as proof of digital asset ownership, thus, it must be protected at all times. Security threats such as phishing attacks can result in severe digital asset losses. Therefore, implementing rigorous authentication protocols is of vital importance to prevent unauthorized access. This paper proposes a secure implementation of a blockchain wallet website by integrating four different multifactor authentication settings to enhance cryptographic keys and digital asset management. We developed a comprehensive system model to visualize the system interactions and provide an adequate understanding of its architecture. Furthermore, the solution was implemented using Python and Ethereum libraries, followed by extensive evaluation and testing. The results show that system models enhance and facilitate the implementation and validation of blockchain wallets, thereby contributing to the development of robust security measures.
Trust is a critical element when it comes to news articles, and an important problem is how to ensure trust in the published information on news websites. First, this paper describes the inner workings of a proposed news-retrieval and aggregation architecture employed by a blockchain-based solution for fighting disinformation; this includes a comparison between existing information retrieval solutions. The decentralized nature of the solution is achieved by separating the crawling (i.e., extracting the web page links) from the scraping (i.e., extracting the article information) and having third-party actors extract the data. A majority-rule mechanism is used to determine the correctness of the information, and the blockchain network is used for traceability. Second, the steps needed to deploy the distributed components in a cloud environment seamlessly are discussed in detail, with a special focus on the open-source OpenStack cloud solution. Lastly, novel methods for achieving a truly decentralized architecture based on community input and blockchain technology are presented, thus ensuring maximum trust and transparency in the system. The results obtained by testing the proposed news-retrieval system are presented, and the optimizations that can be made are discussed based on the crawling and scraping test results.
Web3 systems expose a fundamentally different security landscape from centralized platforms, characterized by composability, pseudonymous identities, decentralized governance, and rapidly evolving attack strategies that span social, application, and protocol layers. Existing security mechanisms, such as static smart contract analysis, blacklist-based phishing detection, and network-level mitigation, operate in isolation and assume fixed threat models, limiting their effectiveness against adaptive, cross-layer adversaries. This position paper argues that securing Web3 requires a shift from static, tool-centric defenses to learning-driven security primitives capable of continuous reasoning, adaptation, and actuation. We introduce AI-powered smart certificates as a new security abstraction: programmable, continuously updated trust artifacts that integrate on-chain verifiability with off-chain machine learning signals derived from user behavior, transaction dynamics, and social context. Unlike traditional certificates or audits, these certificates maintain state, learn under distribution shift, and support automated policy enforcement and revocation in response to evolving threats. We argue that existing paradigms, formal verification, threat modeling, and isolated anomaly detection, are structurally limited in capturing the non-stationary and socio-technical nature of Web3 attacks. We outline an architecture in which AI-powered smart certificates serve as cross-layer sentinels that coordinate heterogeneous security signals in real time, and position smart certificates as a research direction, raising questions around learning under partial observability, adversarial adaptation, and trustworthy ML deployment in decentralized systems.
As an emerging technology, blockchain provides a range of advantages, such as decentralized and transparent data storage, secure access control, and enhanced data traceability. However, it is rarely applied in the field of public safety. This paper presents an in-depth survey of blockchain technology, focusing on its potential applications and implications within the field of public safety research. We explore the practical needs of multi-party data collaboration in emergency management and discusses the applicability and value of blockchain technology in this context. Additionally, this paper introduces and compares several popular blockchain platforms. By providing a comprehensive examination of blockchain technology and its potential benefits for public safety, this paper seeks to enhance understanding of the technology's capabilities, encourage further research, and inspire innovation in this domain.
Nov 1, 2023·2023 International Conference on Research Methodologies in Knowledge Management, Artificial Intelligence and Telecommunication Engineering (RMKMATE)
B. Sriman, Sushrut Kumar, S. Dhanushram, Kalava Balaji · 5 authors
In this paper, we examine Crypto Jacking which is the significant threat to the world and how this threat is handled by the advanced technologies like Artificial Intelligence. Cryptocurrencies are based on blockchain, a distributed public ledger that keeps track of all transactions that are updated and held by currency holders. Rise of the Cryptocurrency has also led to the rise of Crypto-malware. Crypto jacking is a type of cyber-attack in which cyber criminals use the target's computational power illegally for mining cryptocurrencies. The worldwide danger landscape is becoming dominated by crypto-jacking. The European Union Agency for Cybersecurity's (ENISA) annual study ranked crypto jacking as the third most common cybersecurity threat in 2021. Monero (NMR) is the most popular cryptocurrency for malicious mining since it offers a high level of anonymity for the users and their transactions. Coin Hive is an in-built browser for cryptocurrency mining and this browser allows the malicious software and their programs to mine the Monero (XMR). Though Coin Hive was used legally for the purposes like raising funds it was predominately used for these kinds of illegal mining activities.
Raghu Raman, Vinith Kumar Nair, Prema Nedungadi, Indrakshi Ray · 5 authors
The Darkweb, part of the deep web, can be accessed only through specialized computer software and used for illegal activities such as cybercrime, drug trafficking, and exploitation. Technological advancements like Tor, bitcoin, and cryptocurrencies allow criminals to carry out these activities anonymously, leading to increased use of the Darkweb. At the same time, computers have become an integral part of our daily lives, shaping our behavior, and influencing how we interact with each other and the world. This work carries out the bibliometric study on the research conducted on Darkweb over the last decade. The findings illustrate that most research on Darkweb can be clustered into four areas based on keyword co-occurrence analysis: (i) network security, malware, and cyber-attacks, (ii) cybercrime, data privacy, and cryptography, (iii) machine learning, social media, and artificial intelligence, and (iv) drug trafficking, cryptomarket. National Science Foundation from the United States is the top funder. Darkweb activities interfere with the Sustainable Development Goals (SDG) laid forth by the United Nations to promote peace and sustainability for current and future generations. SDG 16 (Peace, Justice, and Strong Institutions) has the highest number of publications and citations but has an inverse relationship with Darkweb, as the latter undermines the former. This study highlights the need for further research in bitcoin, blockchain, IoT, NLP, cryptocurrencies, phishing and cybercrime, botnets and malware, digital forensics, and electronic crime countermeasures about the Darkweb. The study further elucidates the multi-dimensional nature of the Darkweb, emphasizing the intricate relationship between technology, psychology, and geopolitics. This comprehensive understanding serves as a cornerstone for evolving effective countermeasures and calls for an interdisciplinary research approach. The study also delves into the psychological motivations driving individuals towards illegal activities on the Darkweb, highlighting the urgency for targeted interventions to promote pro-social online behavior.
As blockchain technology continues to advance, the secure deployment of smart contracts has become increasingly prevalent, underscoring the critical need for robust security measures. This surge in usage has led to a rise in security breaches, often resulting in substantial financial losses for users. This article presents a comprehensive survey of smart contract quality assurance, from understanding vulnerabilities to evaluating the effectiveness of detection tools. Our work is notable for its innovative classification of 40 smart contract vulnerabilities, mapping them to established attack patterns. We further examine nine defense mechanisms, assessing their efficacy in mitigating smart contract attacks. Furthermore, we develop a labeled dataset as a benchmark encompassing 10 common vulnerability types, which serves as a critical resource for future research. We also conduct comprehensive experiments to evaluate 14 vulnerability detection tools, providing a comparative analysis that highlights their strengths and limitations. In summary, this survey synthesizes state-of-the-art knowledge in smart contract security, offering practical recommendations to guide future research and foster the development of robust security practices in the field.
Blockchain technology is leading a revolutionary transformation across diverse industries, with effective governance standing as a critical determinant for the success and sustainability of blockchain projects. Community forums, pivotal in engaging decentralized autonomous organizations (DAOs), wield a substantial impact on blockchain governance decisions. Concurrently, Natural Language Processing (NLP), particularly sentiment analysis, provides powerful insights from textual data. While prior research has explored the potential of NLP tools in social media sentiment analysis, a gap persists in understanding the sentiment landscape of blockchain governance communities. The evolving discourse and sentiment dynamics on the forums of top DAOs remain largely unknown. This paper delves deep into the evolving discourse and sentiment dynamics on the public forums of leading DeFi projects—Aave, Uniswap, Curve Dao, Aragon, Yearn.finance, Merit Circle, and Balancer—placing a primary focus on discussions related to governance issues. Despite differing activity patterns, participants across these decentralized communities consistently express positive sentiments in their Discord discussions, indicating optimism towards governance decisions. Additionally, our research suggests a potential interplay between discussion intensity and sentiment dynamics, indicating that higher discussion volumes may contribute to more stable and positive emotions. The insights gained from this study are valuable for decision-makers in blockchain governance, underscoring the pivotal role of sentiment analysis in interpreting community emotions and its evolving impact on the landscape of blockchain governance. This research significantly contributes to the interdisciplinary exploration of the intersection of blockchain and society, with a specific emphasis on the decentralized blockchain governance ecosystem. We provide our data and code for replicability as open access on GitHub.
Identity documentation for refugees is a complex process and crucial for host nations. A secured identity management system ensures both security and the efficient provision of services for the host nation and the donor organizations. Realizing the benefits, a handful of studies enriched the blockchain-based security identification for refugees. The research studies presented the introductory, conceptual, and practical solution related to the blockchain-based smart contract. There is a common agreement in the studies that blockchain-based smart contract not only streamlines refugee identity verification but also safeguards against unauthorized entries. Since it is a technology as well, it has been essential to know the present status of the technology in the social context. In such a situation it becomes essential to review the existing research studies to provide insight for future studies. In this study, we reviewed current studies using a thematic approach. Our findings suggest researchers are more inclined to provide conceptual models as the models are important in advancing technology; however, the models need to be implemented for practical advances. However, the main contribution of this study is that this study gathers current efforts in smart contract-based refugee identity management. This study is important for the refugee host nations as well as for stakeholders. Knowledge gained from the study is expected to provide insight into how the technology can be developed using existing theory and implementation frameworks.
In recent years, blockchain technology has witnessed rapid development and received considerable attention. However, its decentralized and pseudonymous nature has also attracted many criminal activities. Among them, Ponzi schemes, a classic form of financial fraud, also hide their true face in smart contracts, causing huge losses to blockchain users. Although numerous methods have been proposed to detect Ponzi contracts, these methods still have limitations in terms of generalization and feature learning. To address this issue, we conduct research on Ethereum, the currently largest blockchain platform enabling smart contracts, and propose a novel contrastive learning-based smart Ponzi scheme detection method named ContraPonzi. This method first extracts control flow graph information from bytecodes and models it as attribute graphs that preserve both semantic and structural information. Next, by augmenting the bytecode data of multi-version compilers and maximizing the graph representation similarity of multi-version bytecodes of the same contract, a pre-training graph encoder is obtained and then can be used in Ponzi contract detection. Experimental results on real-world data demonstrate that ContraPonzi is significantly superior to the state-of-the-art in Ethereum Ponzi scheme detection.
Abstract Security threats posed by Ponzi schemes present a considerably higher risk compared to many other online crimes. These fraudulent online businesses, including Ponzi schemes, have witnessed rapid growth and emerged as major threats in societies like Nigeria, particularly due to the high poverty rate. Many individuals have fallen victim to these scams, resulting in significant financial losses. Despite efforts to detect Ponzi schemes using various methods, including machine learning (ML), current techniques still face challenges, such as deficient datasets, reliance on transaction records, and limited accuracy. To address the negative impact of Ponzi schemes, this paper proposes a novel approach focusing on detecting Ponzi schemes on Ethereum using ML algorithms like random forest (RF), neural network (NN), and K-nearest neighbor (KNN). Over 20,000 datasets related to Ethereum transaction networks were gathered from Kaggle and preprocessed for training the ML models. After evaluating and comparing the three models, RF demonstrated the best performance with an accuracy of 0.94, a class-score of 0.8833, and an overall-score of 0.96667. Comparative evaluations with previous models indicate that our model achieves high accuracy. Moreover, this innovative work successfully detects key fraud features within the Ponzi scheme dataset, reducing the number of features from 70 to only 10 while maintaining a high level of accuracy. The main strength of this proposed method lies in its ability to detect clever Ponzi schemes from their inception, offering valuable insights to combat these financial threats effectively.
The phishing scams pose a serious threat to the ecosystem of Ethereum which is one of the largest blockchains in the world. Such a type of cyberattack recently has caused losses of millions of dollars. In this paper, we propose a Self-supervised IncrEmental deep Graph lEarning (SIEGE) model, for the phishing scam detection problem on Ethereum. To overcome the data scalability challenge, we propose splitting the original Ethereum transaction data and constructing transaction graphs for each split. Confronted with the minimal labeled data available, we resort to graph-based self-supervised learning. We design a spatial pretext task to learn high-quality node embeddings inside a single graph split, as well as an incremental learning paradigm and a temporal pretext task to facilitate information flow between different graph splits. To evaluate the effectiveness of SIEGE, we gather a real-world dataset consisting of six-month Ethereum transaction records. The results demonstrate that our model consistently outperforms baseline approaches in both transductive and inductive settings.
Eder J. Scheid, Sebastian Küng, Muriel Figueredo Franco, Burkhard Stiller
Since the proposal of Bitcoin in 2009 and with the inclusion of the first transaction in its genesis block, Blockchains (BC) have been used to store arbitrary data, including texts, images, and documents. However, such data is often not easily discoverable in BCs and is embedded within their binary data structures. Thus, this paper presents the design and implementation of a solution to analyze BC transactions searching for “media” content. This solution, called blockchain-parser, is capable of detecting ASCII strings and files (e.g., PDF, GIF, and SVG) embedded in BC's transactions. To evaluate such a solution, Bitcoin, Monero, and Ethereum cryptocurrencies were examined to find commonalities and differences between different BCs regarding their arbitrary data storage usage. Conclusions from such an evaluation indicate that Ethereum has been the most used BC for media data storage compared to Bitcoin and Monero.
Blockchain technology has generated an influx of transaction data and complex interactions, posing significant challenges for traditional machine learning methods, which struggle to capture high-dimensional patterns in transaction networks. In this paper, we present the disentangled prototypical graph convolutional network (DP-GCN), an innovative approach to account classification in Ethereum transaction records. Our method employs a unique disentanglement mechanism that isolates relevant features, enhancing pattern recognition within the network. Additionally, we apply prototyping to disentangled representations, to classify scam nodes robustly, despite extreme class imbalances. We further employ a joint learning strategy, combining triplet loss and prototypical loss with a gamma coefficient, achieving an effective balance between the two. Experiments on real Ethereum data showcase the success of our approach, as the DP-GCN attained an F1 score improvement of 32.54%p over the previous best-performing GCN model and an area under the ROC curve (AUC) improvement of 4.28%p by incorporating our novel disentangled prototyping concept. Our research highlights the importance of advanced techniques in detecting malicious activities within large-scale real-world cryptocurrency transactions.
Smart contracts are computer programs that run on blockchain networks, enabling secure, transparent, and decentralized transactions. However, the security of smart contracts has always been a critical issue in the blockchain community. One major concern in recent years is the proliferation of honeypots - malicious contracts that deceive users into depositing funds, only to discover that they cannot withdraw their money and have lost their original deposit. In this research, we present a novel classification of honeypots and introduce a new type of contract that allows for the development of a future-proof method for detecting honeypots based on the contract owner and cash flow. We implement this method in a detection tool called HoneyVader, which uses symbolic execution to identify real-world honeypot contracts. Our tool analyzes over 2 million contracts deployed on the Ethereum network, detecting 139 honeypots. By using HoneyVader, we are able to uncover previously unknown zero-day honeypots and new techniques used by attackers, in addition to the ones identified in previous works.
Håkon I. FrØland, Edward Palm, Katina Kralevska, Danilo Gligoroski
This paper presents a proof-of-concept (PoC) that leverages Web3 technology, specifically blockchain and Non-Fungible Tokens (NFTs), to create a secure, transparent, and fair reseller market without the need for a trusted third party. The PoC demonstrates that NFTs can be used to authenticate items, build trust between parties and establish verifiable product own-ership. By paralleling NFT transfers with the sale of items, the practicality of selling counterfeit goods is reduced. Furthermore, the blockchain-based storage of product information enables verification of origin, history, and authenticity by any involved party, fostering transparency and equal access to information for buyers and sellers. We demonstrate that Web3 technology can effectively address critical issues in traditional reseller markets, offering substantial benefits to all parties involved.
With the rapid progress of technology, Web 3.0 has emerged as a transformative force in the digital realm. It is characterized by decentralization, user-centric data ownership, and the implementation of cryptographic techniques. Smart contracts, as a core component of Web 3.0, play a pivotal role in driving its evolution by enabling novel functionalities and various application. However, given the substantial financial significance of smart contracts and their inherent transparency, the accessibility of their source code to all opens potential avenues for attackers to identify and exploit vulnerabilities. Therefore, the detection of security vulnerabilities in smart contracts has become significantly important. Existing smart contract vulnerability detection tools mostly rely on expert-defined rules, leading to high false positive rates. To address this problem, this paper proposes an efficient and automated framework that combines Graph and Attention for detecting smart contract vulnerabilities. This framework takes into account the code structure of smart contracts, extracts nodes, and constructs a contract graph, utilizing dataflow to represent the different semantics of variable nodes at different locations. Additionally, a bidirectional multilayer Transformer framework is constructed and trained with our dataset, utilizing the information from the nodes. The framework achieves state-of-the-art levels of$Accuracy$92.72%,$Recall$82.81%, and$F1_{score}$87.54%, respectively. These results show that our framework can effectively detect security vulnerabilities in smart contracts and has the potential to improve their security.
Zsofia Baruwa, Sanjay Bhattacherjee, Sahil Rey Chandnani, Zhen Zhu
This work is the first study on the effects of attacks on cryptocurrencies as expressed in the sentiments and emotions of social media users. Our goals are to design the methodologies for the study including data collection, conduct volumetric and temporal analyses of the data, and profile the sentiments and emotions that emerge from the data. As a first step, we have created a first-of-its-kind comprehensive list of 31 events of 51% attacks on various PoW cryptocurrencies, showing that these events are quite common contrary to the general perception. We have gathered Twitter data on the events as well as benchmark data during normal times for comparison. We have defined parameters for profiling the datasets based on their sentiments and emotions. We have studied the variation of these sentiment and emotion profiles when a cryptocurrency is under attack and the benchmark otherwise, between multiple attack events of the same cryptocurrency, and between different cryptocurrencies. Our results confirm some expected overall behaviour and reactions while providing nuanced insights that may not be obvious or may even be considered surprising. Our code and datasets are publicly accessible.
Due to the decentralized and transparent characteristics of the blockchain ecosystem, malicious activities such as phishing scams on the Ethereum platform result in significant financial losses for users. The current methods for detecting phishing largely rely on analyzing original transactions, which makes uncovering hidden transaction patterns challenging. To tackle this limitation, we introduce the Spatio-Temporal Fusion Network (STFN) designed to identify phishing scams on the Ethereum network. Specifically, STFN incorporates two key components: the transactions subgraph encoder for formalizing spatial features, and the transaction sequence BERT encoder for capturing temporal features. By fusing these spatio-temporal features, we facilitate their integration into a machine learning algorithm for classifying phishing accounts. The experimental outcomes underscore the effectiveness of the STFN, achieving an AUC of 93.26% and a Recall of 94.53%, outperforming previous methods for Ethereum phishing detection.
This paper presents the first comprehensive analysis of an emerging cryptocurrency scam named "arbitrage bot" disseminated on online social networks. The scam revolves around Decentralized Exchanges (DEX) arbitrage and aims to lure victims into executing a so-called "bot contract" to steal funds from them. To entice victims and convince them of this scheme, we found that scammers have flocked to publish YouTube videos to demonstrate plausible profits and provide detailed instructions and links to the bot contract. To collect the scam at a large scale, we developed a fully automated scam detection system namedCryptoScamHunter, which continuously collects YouTube videos and automatically detects scams. Meanwhile,CryptoScamHunter can download the source code of the bot contract from the provided links and extract the associated scam cryptocurrency address. Through deployingCryptoScamHunter from Jun. 2022 to Jun. 2023, we have detected 10,442 arbitrage bot scam videos published from thousands of YouTube accounts. Our analysis reveals that different strategies have been utilized in spreading the scam, including crafting popular accounts, registering spam accounts, and using obfuscation tricks to hide the real scam address in the bot contracts. Moreover, from the scam videos we have collected over 800 malicious bot contracts with source code and extracted 354 scam addresses. By further expanding the scam addresses with a similar contract matching technique, we have obtained a total of 1,697 scam addresses. Through tracing the transactions of all scam addresses on the Ethereum mainnet and Binance Smart Chain, we reveal that over 25,000 victims have fallen prey to this scam, resulting in a financial loss of up to 15 million USD. Overall, our work sheds light on the dissemination tactics and censorship evasion strategies adopted in the arbitrage bot scam, as well as on the scale and impact of such a scam on online social networks and blockchain platforms, emphasizing the urgent need for effective detection and prevention mechanisms against such fraudulent activity.
Duong Vu, Tuan Hoang Nguyen, Van Tong, Sami Souihil
Smart contracts are decentralized applications that play an important role in blockchain-based applications. Smart contracts are written by programming languages (e.g., Solidity, Python, etc.), so it is error-prone and suffers from vulnerabilities, leading to a huge amount of economic loss for the blockchain ecosystem. In the past, there were many existing vulnerability detection tools such as MythX, Oyente, Slither, and so on. However, these tools contain several limitations related to low accuracy and high execution time. Therefore, many studies focus on vulnerability detection mechanisms using Deep Learning which takes into account the bytecode of smart contracts to detect its vulnerabilities. Despite achieving good accuracy, these studies make an assumption that there is only one vulnerability in a smart contract. When there is more than one vulnerability in a smart contract, these studies can not obtain good performance. Therefore, in this paper, we propose a multi-label vulnerability detection of smart contracts using a language model. Concretely, the proposal takes into account the bytecode by using the SecBERT pre-trained model to extract the implicit features and analyzes it using the Multi-Layer Perceptron algorithm to identify multiple vulnerabilities in a smart contract. The experimental results show that the proposal outperforms benchmarks and obtains 92.55 percent accuracy.
Buzhen He, Tao Feng, Junli Fang, Chunyan Liu · 5 authors
With the flourishing development of philanthropy, more and more people are actively involved in charitable activities. However, traditional charitable systems face several challenges, including low levels of information, lack of transparency in the flow of funds, lack of accountability and vulnerability to tampering. To address these issues, Ethereum provides a distributed platform that can execute smart contracts, ensuring adherence to predefined rules and mitigating the possibility of fraud and third-party interference. Blockchain, as a decentralized distributed ledger technology, stores data records across multiple computer nodes and employs cryptographic methods to ensure data security and reliability. Its main features include decentralization, immutability, transparency and traceability. However, in the construction of a secure, reliable, and third-party-independent charitable donation system, challenges associated with privacy protection and search efficiency need to be addressed. To tackle these issues, this paper proposes a solution based on the Ethereum blockchain, highlighting the role of searchable encryption methods. This solution employs searchable encryption methods, enabling search operations to perform without decrypting the ciphertext, effectively safeguarding participants’ privacy information, and enhancing search efficiency. This system is more secure, trustworthy, and efficient compared to traditional charitable donation systems.In the implementation of the proposed solution, we conduct a detailed analysis of the security of the searchable encryption scheme. We successfully counter key guessing attacks and multi-keyword selection attacks. Furthermore, we perform a security analysis of the smart contract to verify the system’s feasibility and security. Additionally, we comprehensively compare the proposed solution with existing alternatives and evaluate its performance. By introducing Ethereum blockchain technology and searchable encryption methods, we provide a secure and reliable solution for the charitable donation field, significantly enhancing transparency and efficiency in charitable endeavors. This initiative not only safeguards the interests of donors and recipients but also makes a positive contribution to the development of social public welfare activities.