In the era of big data, there is an urgent need to establish data trading markets for effectively releasing the tremendous value of the drastically explosive data. Data security and data pricing, however, are still widely regarded as major challenges in this respect, which motivate this research on the novel multi-blockchain based framework for data trading markets and their associated pricing mechanisms. In this context, data recording and trading are conducted separately within two separate blockchains: the data blockchain (DChain) and the value blockchain (VChain). This enables the establishment of two-layer data trading markets to manage initial data trading in the primary market and subsequent data resales in the secondary market. Moreover, pricing mechanisms are then proposed to protect these markets against strategic trading behaviors and balance the payoffs of both suppliers and users. Specifically, in regular data trading on VChain-S2D, two auction models are employed according to the demand scale, for dealing with users' strategic bidding. The incentive-compatible Vickrey-Clarke-Groves (VCG) model is deployed to the low-demand trading scenario, while the nearly incentive-compatible monopolistic price (MP) model is utilized for the high-demand trading scenario. With temporary data trading on VChain-D2S, a reverse auction mechanism namely two-stage obscure selection (TSOS) is designed to regulate both suppliers' quoting and users' valuation strategies. Furthermore, experiments are carried out to demonstrate the strength of this research in enhancing data security and trading efficiency.
Delegated-Proof-of-Stake (DPoS) blockchains, such as EOSIO, Steem and TRON, are governed by a committee of block producers elected via a coin-based voting system. We recently witnessed the first de facto blockchain takeover that happened between Steem and TRON. Within one hour of this incident, TRON founder took over the entire Steem committee, forcing the original Steem community to leave the blockchain that they maintained for years. This is a historical event in the evolution of blockchains and Web 3.0. Despite its significant disruptive impact, little is known about how vulnerable DPoS blockchains are in general to takeovers and the ways in which we can improve their resistance to takeovers. In this paper, we demonstrate that the resistance of a DPoS blockchain to takeovers is governed by both the theoretical design and the actual use of its underlying coin-based voting governance system. When voters actively cooperate to resist potential takeovers, our theoretical analysis reveals that the current active resistance of DPoS blockchains is far below the theoretical upper bound. However in practice, voter preferences could be significantly different. This paper presents the first large-scale empirical study of the passive takeover resistance of EOSIO, Steem and TRON. Our study identifies the diversity in voter preferences and characterizes the impact of this diversity on takeover resistance. Through both theoretical and empirical analyses, our study provides novel insights into the security of coin-based voting governance and suggests potential ways to improve the takeover resistance of any blockchain that implements this governance model.
Smart contracts are rapidly applied in many fields, with their varied types and increasing complexity. A sharp increase in the method development demands seems to be certain. However, this type of development has its unique programming language and security requirements, making it difficult for regular software personnel to adapt quickly. It is important to realize that the development efficiency is application specific and that getting this application issue solved is critical for its further development. To this end, we proposes a new, automatic, and intelligent contract-generation method, based on code annotation. First of all, combined with the semantic annotation information of smart contract code association ,a clustering analysis model is built to realize fast and accurate clustering with functions similar to smart contract. Then, based on Char-RNN network, a multi-level and automatic generation method of intelligent contract knowledge base is built to realize the automatic generation at different levels, such as contract layer, function layer and interface layer. Finally,by using text matching technology and by calculating the semantic similarity of the user text demands as well as the smart contract knowledge base annotation, the relevant contract code is automatically extracted for users to choose, with the aims to improve the method efficiency and to meet the needs of different users. To test the effectiveness of the method, with the aid of bilingual quality assessment BLEU and Mythril, VaaS and other code security tools for evaluation are used and results are compared with the existing method. The generated code BLEU average score was increased by 27% and the average accuracy was increased by 11.5%.Therefore, the smart contract generated by our method is relatively accurate and reliable.
The rapid progression of Decentralized Finance (DeFi) has established Decentralized Exchanges (DEX) as critical elements in the financial landscape. Nevertheless, the open and transparent nature of DEX makes them susceptible to strategic manipulations, especially the sandwich attack. During such maneuvers, ill-intentioned actors exploit price slippage by positioning their transactions strategically around a target’s order to reap unfair profits. This paper introduces a ground-breaking framework rooted in mechanism design game theory to lessen the impact of sandwich attacks. The framework delineates the precise strategy of the sandwich attack and its repercussions, shedding light on the tactical aspects and utility functions pertinent to both the attackers and the ordinary traders, subsequently referred to as workers. The discussion extends to defining utility functions for both the market and the workers, emphasizing the benefits of liquidity provision for the market and the potential profits and losses for the workers. The proposal encourages adopting a market-centric mechanism design grounded in game theory, wherein the market, operating as the designer, creates rules to maximize its utility while considering the workers’ utility. Through a meticulous analysis of this game-theoretic approach, the study identifies optimum strategies for all the involved parties, demonstrating that these strategies can reach a balanced state. Further, this study presents a comparative view against existing research, highlighting the limitations of contemporary solutions and asserting the effectiveness of the proposed model in protecting the interests of both the market and the workers. Ultimately, this research furnishes stakeholders with new perspectives and instruments to thwart sandwich attacks and lays a foundation for creating resilient and fair decentralized trading infrastructures.
Smart Contract (SC) Programming Languages (PL) are inspired by Non-SC PLs. Many, like Solidity, use an object-oriented approach with interfaces and inheritance-based sub-typing. However, the main focus of these concepts is on abstraction and extend-ability, whereas for SC Systems, robust, secure and composable SCs are of higher importance. Further, despite supporting inheritance, Solidity and other SC PLs fail to leverage the full benefits of the object-oriented paradigm when multiple SCs are involved. This work presents an approach to SC composability that enables highly composable and secure SCs by encapsulating logic in small traits that serve as interfaces.
Norah M. Alshahrani, Miss Laiha Mat Kiah, B. B. Zaidan
Smart contracts have received increasing attention in recent years for their potential to enable decentralized and automated transactions in various fields, including finance, supply chain management, and real estate. However, selecting and evaluating the appropriate smart contract for a specific application remains challenging due to the large number of available options and various criteria that need to be considered. This paper discusses the challenges and open issues in selecting and evaluating appropriate smart contracts for various applications. It proposes multi-criteria analysis (MCA) to evaluate and compare different options based on multiple criteria. The study aims to provide a comprehensive review of the current state-of-the-art in the field by considering various criteria used in the selection process, such as security, scalability, and performance. The review covers the challenges associated with critical criteria for smart contract selection, including security, privacy, efficiency, scalability, and regulatory concerns. Additionally, the paper presents various criteria used in different domains/groups to carry out various blockchain- related tasks, such as operational function, asset management, mitigation, analysis, communications, planning, and others. The criteria vary from one person to another and from application to application, and the importance level of the criteria is subjective. The paper highlights the need for more research on smart contract platforms' long-term performance and scalability and more comprehensive and objective evaluation methods for MCA of smart contract selection.
Purpose The smart contract provides an opportunity to improve existing contract management practices in the construction projects by replacing traditional contracts. However, translating the contracts into computer languages is considered a major challenge which has not been investigated. Thus, it is necessary to: (1) identify the obstructing clauses in real-world contracts; and (2) analyze the replacement's technical and economic feasibility. This paper aims to discuss the aforementioned objectives. Design/methodology/approach This study identified the flexibility clauses of traditional contracts and their corresponding functions through inductive content analysis with representative standard contracts as materials. Through a speculative analysis in accordance to design science paradigm and new institutional economics, the economic and technical feasibility of existing approaches, including enumeration method, fuzzy algorithm, rough sets theory, machine learning and artificial intelligence, to transform respective clauses (functions) into executable codes are analyzed. Findings The clauses of semantic flexibility and structural flexibility are identified from the contracts. The transformation of semantic flexibility is economically and/or technically infeasible with existing methods and materials. But with more data as materials and methods of rough sets or machine learning, the transformation can be feasible. The transformation of structural flexibility is technically possible however economically unacceptable. Practical implications Given smart contracts' inability to provide the required flexibility for construction projects, smart contracts will be more effective in less relational contracts. For construction contracts, the combination of smart contracts and traditional contracts is recommended. In the long run, with the sharing or trading of data in the industry level and the integration of machine learning or artificial intelligence reducing relevant costs, the automation of contract management can be achieved. Originality/value This study contributes to the understanding of the smart contract's limitations in industry scenarios and its role in construction project management.
Although the prices of cryptocurrencies remained volatile for the past decade, the factors that impact the price dynamics of the new type of investment instrument have not been fully identified yet. In this study, we recognize the dual nature of cryptocurrencies, that is, being a software program and a financial instrument, and examine the impact of software advancement on the price dynamics of cryptocurrencies. The open-source software (OSS) platform functionality enables social behaviors that we use as signals. Using data from the largest OSS platform, we establish the connection between open-source activities and the price movement of cryptocurrency. In particular, as project popularity (forks and watches) and users’ feedback (issues) increase, the market price increases by 4.3 percent, 2.4 percent, and 4.4 percent per annum, respectively. On the contrary, the number of code corrections (pull requests) is negatively related to prices leading to a 5 percent annual price decrease. Our results suggest that OSS contributions create a perfect selection mechanism, where higher quality projects receive more developers’ attention and user feedback, whereas lower quality projects do not, thus creating the separating equilibrium.
The rapid rise in blockchain-based Decentralized Autonomous Organizations (DAOs) offers policy-makers and decision-makers new opportunities to automatically execute decisions and processes that help enhance transparency, accountability, participation and trust.Yet, many DAOs have a limited lifespan.There is little empirical evidence of the effect of governance elements on the viability of DAOs.Using 220 on-chain governed DAOs, this paper analyses how governance elements (accountability, decision/voting, and incentives) influence the viability of DAOs in the longterm.The findings show that DAOs without weighted decisionmaking and without incentive structures are more viable than those with weighted decision power and incentive mechanisms.This suggests that financial and share-like DAO governance elements do not or may even negatively contribute to the long-term viability of DAOs.Also, voting power distribution is found to have a statistically significant influence on DAOs' viability.We further propose a preliminary theory that relates governance elements to the long-term viability of DAOs.These insights will help policymakers in designing more viable DAOs.Future research should investigate how DAO objectives, the chosen deployment infrastructure and the type of users can impact the long-term viability of DAOs.
Stefan Kitzler, Stefano Balietti, Pietro Saggese, Bernhard Haslhofer · 5 authors
We present a study analyzing the voting behavior of contributors, or vested users, in Decentralized Autonomous Organizations (DAOs). We evaluate their involvement in decision-making processes, discovering that in at least 7.54% of all DAOs, contributors, on average, held the necessary majority to control governance decisions. Furthermore, contributors have singularly decided at least one proposal in 20.41% of DAOs. Notably, contributors tend to be centrally positioned within the DAO governance ecosystem, suggesting the presence of inner power circles. Additionally, we observed a tendency for shifts in governance token ownership shortly before governance polls take place in 1202 (14.81%) of 8116 evaluated proposals. Our findings highlight the central role of contributors across a spectrum of DAOs, including Decentralized Finance protocols. Our research also offers important empirical insights pertinent to ongoing regulatory activities aimed at increasing transparency to DAO governance frameworks.
Jedna od popularnijih primjena blockchain tehnologije su NFT-ovi ili nezamjenjivi tokeni. Ti tokeni predstavljaju vlasništvo nad nekim resursom. NFT-ovi se programiraju koristeći pametne ugovore koji se postavljaju na Ethereum mrežu. Za pisanje pametnih ugovora je korišten programski jezik Solidity. U radu je pokazan proces kreiranja produkcijskog NFT pametnog ugovora koji ima razne funkcionalnosti kao što su cijena tokena i ograničenje ukupnog broja tokena. Također, objašnjen je mehanizam tantijema i kako ispravno postaviti metapodatke za tokene. Od naprednijih tehnika pokazano je kako implementirati listu korisnika s posebnim privilegijama unutar pametnog ugovora.
We develop a general and practical framework to address the problem of the optimal design of dynamic fee mechanisms for multiple blockchain resources. Our framework allows to compute policies that optimally trade-off between adjusting resource prices to handle persistent demand shifts versus being robust to local noise in the observed block demand. In the general case with more than one resource, our optimal policies correctly handle cross-effects (complementarity and substitutability) in resource demands. We also show how these cross-effects can be used to inform resource design, i.e. combining resources into bundles that have low demand-side cross-effects can yield simpler and more efficient price-update rules. Our framework is also practical, we demonstrate how it can be used to refine or inform the design of heuristic fee update rules such as EIP-1559 or EIP-4844 with two case studies. We then estimate a uni-dimensional version of our model using real market data from the Ethereum blockchain and empirically compare the performance of our optimal policies to EIP-1559.
Immanni Bhanu Prakash, Adarsh Kr Tiwari, U. Hariharan
Decentralized autonomous organization (DAO) utilizes blockchain technology and smart contracts to invest in Non-Fungible Tokens (NFTs). The proposed DAO is entirely on-chain, where members can join to pool their funds transparently and securely. The structure of this decentralized platform will be distributed, allowing its members to propose and vote on investment decisions. The DAO's predefined investment strategy will focus on NFTs with a proven track record of successful growth or high potential for future. Additionally, before making any investments, extensive research investigations will be performed. Another potential feature of the proposed DAO platform is the ability to promote stakeholder participation through pre-defined NFTs, assuring active participation from members of the platform. The proposed DAO has the potential to transform NFT investing by promoting a more democratic and inclusive approach. Small investors who would otherwise be unable to participate in the NFT market might do so through this platform by pooling the financial resources. This proposed system incorporates blockchain technology to increase transparency and security, reduce the risk of fraudulent behavior or bad decision-making. This research work articulates the proposed DAO's technological and governance features by providing a road map for its effective development and implementation.
In recent years the adoption of smart contracts, in blockchain platforms, has increased substantially. One of the main applications of smart contracts are the so called Decentralized Autonomous Organizations (DAO), which originated from an idea envisaged by Buterin, in his Ethereum white paper. Indeed, DAOs are decentralized organizations, where the members implement their decisions using smart contracts. In the article, we introduce a simple framework for a DAO, and then we discuss some governance issues. In particular, we focus on how DAO members could be induced to dedicate sufficient time to voting sessions, for a proper functioning of the organization. Indeed, recent empirical research suggests how the members’ participation rate, to voting activities, has a meaningful positive correlation with to a DAO's performance. More specifically, we formalize the notion of attention time and propose a simple model for the so-called Holographic Consensus, a protocol introduced by the DAOStack platform to solve the issue of limited time dedicated to governance, discussing under what conditions DAO members may choose the so-called boosting voting procedure.
The use of smart contracts is transforming traditional industry and business practices. It enables the automatic enforcement of contractual terms without the need for a trusted third party. Smart contracts can automate a variety of transactions on Blockchain. Despite their numerous benefits, some challenges, such as security vulnerabilities, still need to be addressed before smart contracts can be widely adopted.This paper introduces two models of smart contracts – one simple and one more complex – using the interactive theorem prover Agda. This is a step towards converting the previous work of verifying Bitcoin smart contracts using weakest preconditions [1], [2] to Ethereum’s Solidity-style [3] smart contracts. Since Ethereum’s contracts are object-oriented, this model is substantially more complex than Bitcoin’s. We provide models supporting simple and complex executions, the calling of other contracts, and functions referring to addresses and messages. Furthermore, these models also support transferring money to other contracts and updating specific contracts, and the more complex model includes gas cost and pure functions.
We present an implementation of a Web3 platform that leverages the Groth16 Zero-Knowledge Proof schema to verify the validity of questionnaire results within Smart Contracts. Our approach ensures that the answer key of the questionnaire remains undisclosed throughout the verification process, while ensuring that the evaluation is done fairly. To accomplish this, users respond to a series of questions, and their answers are encoded and securely transmitted to a hidden backend. The backend then performs an evaluation of the user's answers, generating the overall result of the questionnaire. Additionally, it generates a Zero-Knowledge Proof, attesting that the answers were appropriately evaluated against a valid set of constraints. Next, the user submits their result along with the proof to a Smart Contract, which verifies their validity and issues a non-fungible token (NFT) as an attestation of the user's test result. In this research, we implemented the Zero-Knowledge functionality using Circom 2 and deployed the Smart Contract using Solidity, thereby showcasing a practical and secure solution for questionnaire validity verification in the context of Smart Contracts.
Phuong Duy Huynh, Thisal De Silva, Son Hoang Dau, Xiaodong Li · 6 authors
We investigate in this work a recently emerged type of scam ERC-20 token called Trapdoor, which has cost investors billions of US dollars on Uniswap, the largest decentralised exchange on Ethereum, from 2020 to 2023. In essence, Trapdoor tokens allow users to buy but preventing them from selling by embedding logical bugs and/or owner-only features in their smart contracts. By manually inspecting a number of Trapdoor samples, we established the first systematic classification of Trapdoor tokens and a comprehensive list of techniques that scammers used to embed and conceal malicious codes, accompanied by a detailed analysis of representative scam contracts. In particular, we developed TrapdoorAnalyser, a fine-grained detection tool that generates and crosschecks the error-log of a buy-and-sell test and the list of embedded Trapdoor indicators from a contract-semantic check to reliably identify a Trapdoor token. TrapdoorAnalyser not only outperforms the state-of-the-art commercial tool GoPlus in accuracy, but also provides traces of malicious code with a full explanation, which most of the existing tools lack. Using TrapdoorAnalyser, we constructed the very first dataset of about 30,000 Trapdoor and non-Trapdoor tokens on UniswapV2, which allows us to train several machine learning algorithms that can detect with very high accuracy even Trapdoor tokens with no available Solidity source codes.
Jiachi Chen, Jiang Hu, Xin Xia, David Lo · 7 authors
Decentralized Finance (DeFi) uses blockchain technologies to transform traditional financial activities into\ndecentralized platforms that run without intermediaries and centralized institutions. Smart contracts are\nprograms that run on the blockchain, and by utilizing smart contracts, developers can more easily develop\nDeFi applications. Some key features of smart contracts – self-executed and immutability – ensure the\ntrustworthiness, transparency and efficiency of DeFi applications, and have led to a fast-growing DeFi market.\nHowever, misbehaving developers can add traps or backdoor code snippets to a smart contract, which are\nhard for contract users to discover. We call these code snippets in a DeFi smart contract as “DeFi Contract\nTraps" (DCTs). In this paper, we identify five DeFi contract traps and introduce their behaviors, describe\nhow attackers use them to make unfair profits, and analyse their prevalence in the Ethereum platform. We\npropose a symbolic execution tool, DeFiDefender, to detect such traps and use a manually labeled small-scale\ndataset that consists of 700 smart contracts to evaluate it. Our results show that our tool is not only highly\neffective but also highly efficient. DeFiDefender only needs 0.48s to analyze one DeFi smart contract and\nobtains a high average accuracy (98.17%), precision (99.74%), and recall (89.24%). Among the five DeFi contract\ntraps introduced in this paper, four of them can be detected through contract bytecode without the need for\nsource code. We also apply DeFiDefender to a large-scale dataset that consists of 20,679 real DeFi related\nEthereum smart contracts. We found that 52.13% of these DeFi smart contracts contain at least one contract\ntrap. Although a smart contract that contains contract traps is not necessarily malicious, our finding suggests\nthat DeFi related contracts have many centralized issues in a zero-trust environment and in the absence of a\ntrusted part
We provide a game-theoretic analysis of the problem of front-running attacks. We use it to distinguish attacks from legitimate competition among honest users for having their transactions included earlier in the block. We also use it to introduce an intuitive notion of the severity of front-running attacks. We then study a simple commit-reveal protocol and discuss its properties. This protocol has costs because it requires two messages and imposes a delay. However, we show that it prevents the most severe front-running attacks while preserving legitimate competition between users, guaranteeing that the earliest transaction in a block belongs to the honest user who values it the most. When the protocol does not fully eliminate attacks, it nonetheless benefits honest users because it reduces competition among attackers (and overall expenditure by attackers). This paper was accepted by Joshua Gans, business strategy. Funding: The authors gratefully acknowledge the financial support of the Ethereum Foundation [Grant FY22-0840].