Cryptocurrencies, like Bitcoin and Ethereum, have garnered global attention in recent years as digital alternatives to traditional fiat currencies. This paper explores the complex landscape of cryptocurrency adoption, consumer behavior, and perceptions. Beginning with the origin of cryptocurrencies and the dominance of Bitcoin with its USD 1.23 trillion market capitalization, the paper highlights popular online platforms facilitating Bitcoin trading. It also examines the varying legal statuses and regulations across different countries, with a notable divide between Eastern and Western nations, attributed to factors like wealth, risk tolerance, and government restrictions. The role of blockchain technology as the foundation of cryptocurrencies is explained, emphasizing its role in ensuring secure and transparent transactions. The paper delves into the processes involved in handling cryptocurrencies, including the blockchain, exchanges, wallets, and mining. Consumer behavior and the factors influencing cryptocurrency usage are analyzed, with a focus on speculation, algorithm trust, spending power, and demographics. Survey findings and case studies from diverse geographical areas reveal patterns of adoption and local consumer perceptions. The paper concludes by discussing the cryptocurrency market’s inherent volatility and sensitivity to regulatory changes, as well as the different types of cryptocurrencies and online exchanges shaping this evolving financial landscape. Overall, it offers insights into the complex dynamics surrounding cryptocurrency adoption and its potential impact on global finance.
Cryptocurrencies, particularly Bitcoin, have gained considerable attention due to their decentralized nature and potential for high returns. However, they are also subject to fraud-ulent activities, posing challenges to security and transparency. In this paper, we aim to detect fraudulent Bitcoin transactions using machine learning models, including traditional models like Logistic Regression, Decision Trees, and Random Forests, in addition to other deep learning models. Our results demonstrate that when trained on the complete transactional dataset, the Random Forest model outperforms other models, suggesting its potential for effectively detecting fraudulent transactions within the Bitcoin network.
Xihan Xiong, Zhipeng Wang, William J. Knottenbelt, Michael Huth
Uniswap is currently the most liquid Decentralized Exchange (DEX) on Ethereum. In May 2021, it upgraded to the third protocol version named Uniswap V3. The key feature update is “concentrated liquidity”, which supports liquidity provision within custom price ranges. However, this design introduces a new type of Miner Extractable Value (MEV) source called Just-in-Time (JIT) liquidity attack, where the adversary mints and burns a liquidity position right before and after a sizable swap. We begin by formally defining the JIT liquidity attack and subsequently conduct empirical measurements on Ethereum. Over a span of 20 months, we identify 36,671 such attacks, which have collectively generated profits of 7,498 ETH. Our analysis suggests that the JIT liquidity attack essentially represents a whales' game, predominantly controlled by a select few bots. The most active bot, identified as 0xa57…6CF, has managed to amass 92% of the total profit. Furthermore, we find that this attack strategy poses significant entry barriers, as it necessitates adversaries to provide liquidity that is, on average, 269 times greater than the swap volume. In addition, our findings reveal that the JIT liquidity attack exhibits relatively poor profitability, with an average Return On Investment (ROI) of merely 0.007%. We also find this type of attack to be detrimental to existing Liquidity Providers (LPs) within the pool, as their shares of liquidity undergo an average dilution of 85%. On the contrary, this attack proves advantageous for liquidity takers, who secure execution prices that are, on average, 0.139% better than before. We further dissect the behaviors of the top MEV bots and evaluate their strategies through local simulation. Our observations reveal that the most active bot, 0xa57…6CF, conducted 27% of non-optimal attacks, thereby failing to capture at least 7,766 ETH (equivalent to 16.1M USD) of the potential attack profit.
The emergence of cryptocurrencies has significantly impacted the global economy and disrupted the established banking structures. However, the decentralised structure of cryptocurrencies and the lack of governmental control have brought about several hazards that require careful analysis and efficient management. This paper presents a comprehensive risk analysis of cryptocurrencies with a focus on the difficulties encountered and potential future options for risk mitigation. This study examines the hazards associated with cryptocurrency, considering elements such as techniques, tools, advantages, and disadvantages of available publications. It assesses how these risks affect a variety of stakeholders, such as investors and companies. This paper also explores the concept and adopts currently used by financial institutions and industry individuals in risk management. It assesses how well these techniques work to reduce the identified risks while highlighting their inherent drawbacks. It emphasizes the value of encouraging interdisciplinary collaboration among academia, industry specialists, and regulatory organizations to address the changing issues and create a future landscape of Bitcoin risk management.
Natural or man-made disasters pose significant challenges for delivering critical relief to affected populations due to disruptions in critical infrastructures and logistics networks. Unmanned aerial vehicles (UAVs)-aided disaster relief networks (UDRNs) leverage UAVs to assist existing ground relief networks by swiftly assessing affected areas and timely delivering lifesaving supplies. To meet the growing demands for collaborative, trust-free, and transparent UDRN services, blockchain-based UDRNs emerge as a promising approach through immutable ledgers and distributed smart contracts. However, several efficiency and security challenges hinder the deployment of blockchain-based UDRNs, including the lack of cooperation between smart contracts, lack of dynamic audit for smart contract vulnerabilities, and low forensics robustness against transaction malleability attacks. Towards efficient and secure blockchain-based UDRNs, this paper presents potential solutions: (i) a series of collaborative smart contracts for coordinated relief management, (ii) a dynamic contract audit mechanism to prevent known/unknown contract vulnerabilities; and (iii) a robust transaction forensics strategy with on/off-chain cooperation to resist transaction malleability attacks. Our prototype implementation and experimental results demonstrate the feasibility and effectiveness of our approach. Lastly, we outline key open research issues crucial to advancing this emerging field.
Pedro Henrique Resende Ribeiro, Pedro Leale, Ivan da Silva Sendin
Over recent decades, the global financial paradigm has experienced significant transformations, notably the emergence and adoption of cryptocurrencies. The escalating prominence of assets like Bitcoin has inadvertently catalysed a surge in illicit activities associated with the currency. Consequently, the forensic examination of transactions within blockchains becomes imperative for the detection and surveillance of malevolent undertakings. This research delineates a preliminary pipeline for a Bitcoin forensic analysis tool. Moving forward, the ambition is to conceptualize and empirically validate this tool utilizing data procured from blockchain and ancillary sources. The methodology will harness Open-Source Intelligence (OSINT), clustering of Bitcoin addresses, and an exhaustive financial analysis. Upon finalizing the pipeline, the implementation of an open-source instrument is envisioned, poised to confer substantial advantages to the broader cryptocurrency milieu.
Catherine Carpentier-Desjardins, Masarah Paquet-Clouston, Stefan Kitzler, Bernhard Haslhofer
*PLEASE REFER TO THE SECOND VERSION UPLOADED IN JANUARY 2025. THIS VERSION CONTAINS A FEW DUPLICATES. VERSION 2 IS AVAILABLE FOR DOWNLOAD HERE: https://zenodo.org/records/14706760 README - Crime Events Dataset This document provides a detailed overview of the structure of the dataset for the paper: "Mapping the DeFi crime landscape: An Evidence-based Picture". The following fields are included, each representing different aspects of the events collected. Data Fields 1. unique_key Description: A unique number assigned to identify each event in the dataset. 2. Agregators Description: The sources where the event is listed. Aggregators include: - De.Fi REKT - SlowMist - CryptoSec (rebranded to ChainSec as of February 2023) 3. DeFi actor involved Description: The name of the DeFi actor involved in the event (target, perpetrator, or intermediary). Sources: - On De.Fi REKT: Found as the "Title" of the event’s listing. - On SlowMist: Found under the “Hacked target” title. - On CryptoSec: Found in the "Title" of the event’s listing with the date. 4. REKT URL Description: The URL to the event's listing on De.Fi REKT. Process: Found by searching for the DeFi actor involved in the REKT Database: https://de.fi/rekt-database 5. SlowMist URL Description: The URL to the event's listing on SlowMist. Process: Available via https://hacked.slowmist.io/search/. Note that searching the actor's name will lead to the event but without an individualized URL. 6. CryptoSec URL Description: The URL to the event's listing on CryptoSec. Process: Found at https://chainsec.io/defi-hacks/. Events are listed on a single page; use traditional keyboard search to locate specific events. 7. Aggregator Summary Description: A summary of the event provided by the aggregator. Sources: - On De.Fi REKT: Found under "Quick Summary" and "Details of the Exploit". - On SlowMist: Under "Description of the event". - On CryptoSec: Below the title in quotation marks. 8. Aggregator sources URL Description: The URLs of references linked by the aggregator in the event’s listing. Sources: - On De.Fi REKT: Found at the bottom by clicking "Source" or "Archived link". - On SlowMist: Found by clicking "View Reference Sources". - On CryptoSec: Available by clicking the source’s name at the end of the summary. 9. Event date Description: The date the event occurred. Sources: - On De.Fi REKT: Listed under the "Date" field. - On SlowMist: At the top right of the listing. - On CryptoSec: Listed in parentheses behind the actor’s name. 10. Event year Description: The year the event occurred, extracted from the Event date. 11. Stolen amount USD Description: The total amount stolen, converted to USD. Sources: - On De.Fi REKT: Found under "Funds lost". - On SlowMist: Under the title “Amount of loss”. - On CryptoSec: Behind the title "Amount stolen". Note: If needed, conversions were manually performed using CoinMarketCap’s historical data as explained in the paper. 12. Implication of actor Description: Indicates whether the DeFi actor was a target, perpetrator, or intermediary in the event. Manually coded after reviewing the aggregator’s summary and linked sources. 13. Strategy Description: The main approach used to steal funds. Six categories are possible: Technical vulnerability, Human risks, Undetermined, Malicious use of contract, Misappropriation of funds, and Imitation. This was manually coded from the event summary and sources. 14. General tactic Description: The common techniques or methods used by malicious actors. Eleven categories are possible, defined in the appendix. Manually coded after reviewing the summary and linked sources. 15. Specific tactic Description: The precise technique used to commit the crime. Thirty-seven categories are possible, defined in the appendix. This was manually coded based on the event summary and sources. 16. Paper category Description: The main area of operation of the involved DeFi actor. Twelve categories are possible: Blockchain, Bridge, DApp, Derivatives, Exchange, Fungible Token (FT), Non-Fungible Token (NFT), Oracle, Yield, Staking, and Others. This was determined by the event summary and research on the actor. 17. Stack category Description: The technical layer of the DeFi Stack Reference (DSR) model corresponding to the paper category. Five categories are possible: DeFi Compositions (CP), DeFi Protocols (P), Cryptoassets (CA), Distributed Ledger Technology (DLT), and Interfaces (INT). --- For more detailed information on the tactics, strategies, or categories used, please refer to the appendix of the dataset or the associated documentation.
B S Anupama, Akash Ranjan Das, Navdeep Rattan, Riya Jaiswal · 5 authors
Nowadays many transactions are being executed by the individuals without bringing it to the notice of the higher authorities. The higher authorities are unaware of what their officials are doing with the funds released to respective departments for the welfare of citizens. To stop such corrupt activities by the officials and bring in transparency in the system so that no manipulation of data or transaction happens at any point of time, a decentralized system needs to be developed for the various departments in which every stake holder is aware of every transaction that happens in the department. We propose to use Blockchain technology for the above problem and the use case considered is the Fund Tracking System. We have developed a Proof of concept on Ethereum platform with suitable smart contracts.
In the aftermath of the 2008 global financial crisis, the foundation was developed for the protocol we know as blockchain. Blockchain is a system through which money can be sent from one person to another without using any financial service providers. It has been argued that the security of blockchain technology could be the answer to people’s mistrust and lost confidence in the financial market. However, blockchain technology and cryptocurrencies go much further than a mere transfer of money. New forms of value exchange have been created, in addition to providing access to financial services in locations where only limited services are offered by traditional banks. As the use of such innovation gains popularity, the legislator is slowly catching up, but how much is covered? This paper studies FinTech and cryptocurrencies in respect of money laundering. It is found that the current regulatory landscape has several weaknesses that can be attractive for those wishing to exploit them.
W. D. Li, Zhun Wang, Chenyu Li, H. F. Chen · 8 authors
The rapid growth and adoption of decentralized finance (DeFi) systems have been accompanied by various threats, notably those emerging from vulnerabilities in their intricate design. In our work, we introduce and define an attack strategy termed as Role-Play Attack, in which the attacker acts as multiple roles concurrently to exploit the DeFi system and cause substantial financial losses. We provide a formal definition of this strategy and demonstrate its potential impacts by revealing the total loss of \$435.1M caused by 14 historical attacks with applying this pattern. Besides, we mathematically analyzed the attacks with top 2 losses and retrofitted the corresponding attack pattern by concrete execution, indicating that this strategy could increase the potential profit for original attacks by \$3.34M (51.4%) and \$3.76M (12.0%), respectively.
Cryptocurrency has been subject to illicit activities probably more often than traditional financial assets due to the pseudo-anonymous nature of its transacting entities. An ideal detection model is expected to achieve all three critical properties of (I) early detection, (II) good interpretability, and (III) versatility for various illicit activities. However, existing solutions cannot meet all these requirements, as most of them heavily rely on deep learning without interpretability and are only available for retrospective analysis of a specific illicit type. To tackle all these challenges, we propose Intention-Monitor for early malice detection in Bitcoin (BTC), where the on-chain record data for a certain address are much scarcer than other cryptocurrency platforms. We first define asset transfer paths with the Decision-Tree based feature Selection and Complement (DT-SC) to build different feature sets for different malice types. Then, the Status/Action Proposal Module (S/A-PM) and the Intention-VAE module generate the status, action, intent-snippet, and hidden intent-snippet embedding. With all these modules, our model is highly interpretable and can detect various illegal activities. Moreover, well-designed loss functions further enhance the prediction speed and model's interpretability. Extensive experiments on three real-world datasets demonstrate that our proposed algorithm outperforms the state-of-the-art methods. Furthermore, additional case studies justify our model can not only explain existing illicit patterns but can also find new suspicious characters.
Decentralized Exchanges (DEXs) are one of the most important infrastructures in the world of Decentralized Finance (DeFi) and are generally considered more reliable than centralized exchanges (CEXs). However, some well-known decentralized exchanges (e.g., Uniswap) allow the deployment of any unaudited ERC20 tokens, resulting in the creation of numerous honeypot traps designed to steal traders' assets: traders can exchange valuable assets (e.g., ETH) for fraudulent tokens in liquidity pools but are unable to exchange them back for the original assets. In this paper, we introduce honeypot traps on decentralized exchanges and provide a taxonomy for these traps according to the attack effect. For different types of traps, we design a detection scheme based on historical data analysis and transaction simulation. We randomly select 10,000 pools from Uniswap V2 & V3, and then utilize our method to check these pools. Finally, we discover 8,443 abnormal pools, which shows that honeypot traps may exist widely in exchanges like Uniswap. Furthermore, we discuss possible mitigation and defense strategies to protect traders' assets.
Duzgun Kucuk, Emre ÇAKAR, Ömer Faruk Yakut, Fatih Ertam
One of the biggest innovations brought by the digitalized world is undoubtedly the invention of crypto money, which is decentralized, anonymous and complex, and connected to blockchain technology. This relatively new technology has attracted the attention of many people with its revolutionary changes in payment systems and great price movements in the market, as well as the economic balances it has changed around the world. In addition to this interest, it also attracted the attention of crime and crime organizations in a short time, and over time it turned into a tool used by illegal organizations such as laundering the proceeds of crime. Although this structure was initially exposed to the reaction of some states at the level of nation states, on the other hand, it managed to get the support of many states. However, although the spread of blockchain-based money laundering methods is an undeniable problem for all states, a significant cooperation has not been achieved by international collaborations and organizations to prevent this situation. On the other hand, it is of great importance for law enforcement and forensic analysts to clarify this situation and to fight against these structures in order to protect national interests. In this study; In this study, an approach that will detect money laundering is tried to be presented through sample scenarios by bringing a broad perspective to crypto money-based money laundering methods, which are very difficult to trace due to their nature. In addition, it is expected that the difficulties in implementation of the proposed approach will be clearly addressed and will shed light and inspire further study.
Abstract Deanonymization is one of the major research challenges in the Bitcoin blockchain, as entities are pseudonymous and cannot be identified from the on-chain data. Various approaches exist to identify multiple addresses of the same entity, i.e., address clustering. But it is known that these approaches tend to find several clusters for the same actor. In this work, we propose to assign a fingerprint to entities based on the dynamic graph of the taint flow of money originating from them, with the idea that we could identify multiple clusters of addresses belonging to the same entity as having similar fingerprints. We experiment with different configurations to generate substructure patterns from taint flows before embedding them using representation learning models. To evaluate our method, we train classification models to identify entities from their fingerprints. Experiments show that our approach can accurately classify entities on three datasets. We compare different fingerprint strategies and show that including the temporality of transactions improves classification accuracy and that following the flow for too long impairs performance. Our work demonstrates that out-flow fingerprinting is a valid approach for recognizing multiple clusters of the same entity.
Phan The Duy, Nghi Hoang Khoa, Nguyen Huu Quyen, Le Cong Trinh · 7 authors
This paper presents VulnSense framework, a comprehensive approach to efficiently detect vulnerabilities in Ethereum smart contracts using a multimodal learning approach on graph-based and natural language processing (NLP) models. Our proposed framework combines three types of features from smart contracts comprising source code, opcode sequences, and control flow graph (CFG) extracted from bytecode. We employ Bidirectional Encoder Representations from Transformers (BERT), Bidirectional Long Short-Term Memory (BiLSTM) and Graph Neural Network (GNN) models to extract and analyze these features. The final layer of our multimodal approach consists of a fully connected layer used to predict vulnerabilities in Ethereum smart contracts. Addressing limitations of existing vulnerability detection methods relying on single-feature or single-model deep learning techniques, our method surpasses accuracy and effectiveness constraints. We assess VulnSense using a collection of 1.769 smart contracts derived from the combination of three datasets: Curated, SolidiFI-Benchmark, and Smartbugs Wild. We then make a comparison with various unimodal and multimodal learning techniques contributed by GNN, BiLSTM and BERT architectures. The experimental outcomes demonstrate the superior performance of our proposed approach, achieving an average accuracy of 77.96\% across all three categories of vulnerable smart contracts.
This article discusses the reasons behind the Chinese government's conservative attitude toward cryptocurrencies, despite the rapid growth of the cryptocurrency market in China. Cryptocurrencies have become popular in finance because of their advantages in privacy, permanence, and scalability. However, they also pose challenges, such as regulatory un-certainties and security risks. China has banned financial institutions from facilitating bitcoin transactions and imposed restrictions on cryptocurrencies. The article suggests that China's attitude towards cryptocurrencies may be due to their defects. Clear regulations and laws are needed to normalize transactions and issuance and mitigate policy risks. The article also provides some possible solutions based on the defects of cryptocurrencies.
Decentralized Finance (DeFi) apps have rapidly proliferated with the development of blockchain and smart contracts, whose maximum total value locked (TVL) has exceeded 100 billion dollars in the past few years. These apps allow users to interact and perform complicated financial activities. However, the vulnerabilities hiding in the smart contracts of DeFi apps have resulted in numerous security incidents, with most of them leading to funds (tokens) leaking and resulting in severe financial loss. In this paper, we summarize Token Leaking vulnerability of DeFi apps, which enable someone to abnormally withdraw funds that far exceed their deposits. Due to the massive amount of funds in DeFi apps, it is crucial to protect DeFi apps from Token Leaking vulnerabilities. Unfortunately, existing tools have limitations in addressing this vulnerability. To address this issue, we propose DeFiWarder, a tool that traces on-chain transactions and protects DeFi apps from Token Leaking vulnerabilities. Specifically, DeFiWarder first records the execution logs (traces) of smart contracts. It then accurately recovers token transfers within transactions to catch the funds flow between users and DeFi apps, as well as the relations between users based on role mining. Finally, DeFiWarder utilizes anomaly detection to reveal Token Leaking vulnerabilities and related attack behaviors. We conducted experiments to demonstrate the effectiveness and efficiency of DeFiWarder. Specifically, DeFi-Warder successfully revealed 25 Token Leaking vulnerabilities from 30 Defi apps. Moreover, its efficiency supports real-time detection of token leaking within on-chain transactions. In addition, we summarize five major reasons for Token Leaking vulnerability to assist DeFi apps in protecting their funds.
Bitcoin has attracted significant attention from academia and industry and has emerged as a new and rapidly growing research field over the past decade. However, there has been no previous bibliometric analysis of Bitcoin-related publications within business, management, finance, and economics. Consequently, the study conducts a bibliometric analysis of 1109 articles written in English language in the Scopus database, published between years 2020 to 2022, focusing on Bitcoin research within the domains of business, management, finance, and economics. This bibliometric analysis was performed using R and VOSviewer. The analysis explores publication trends, influential authors/institutions/countries, and significant articles in the field. The results provide valuable insights into the evolution and trends of Bitcoin research and offer guidance for researchers aiming to publish in reputable journals. The future research agenda includes investigating price volatility and risk analysis, exploring market inefficiency and price discovery mechanisms, understanding acceptance factors, studying governance and regulations, and examining business applications. Addressing these areas will contribute to a better understanding of Bitcoin's dynamics, its impact on financial markets, and its integration into traditional financial systems.
This chapter relates how federal regulators struggled with the issue of determining whether cryptocurrencies are “real” money or are they just another tradable asset. FinCen and state financial services regulators concluded that, while cryptocurrencies are not “real” money, they would be regulated as a “currency” anyway. This meant that crypto dealers are subject to state and FinCen regulation as “money transmitters,” which imposes anti-money laundering and other regulatory requirements on those entities. Federal bank regulators were slow to react to the development of cryptocurrencies but eventually launched a policy initiative to determine whether, and to what extent, banks should be allowed to engage in such activities. In the meantime, federally regulated banks were allowed to engage in some cryptocurrency related business. At the state level, New York and Wyoming created special banking licenses for cryptocurrency dealers.
This Conclusion summarizes governmental efforts seeking to regulate cryptocurrencies that are covered in this Primer. They include the first tentative endeavors to provide consumer protection from widespread fraud in the cryptocurrency market through investor alerts. After that attempt proved unsuccessful, financial service regulators began applying their existing regulations to cryptocurrencies by variously labeling this new asset class as “money” that is subject to money transmitter regulations, then as a “security” regulated under the federal securities laws and as a “commodity” regulated by the Commodity Exchange Act of 1936. None of those labels was a good fit for cryptocurrencies. The validity of those regulatory efforts also remain uncertain in light of the “major questions doctrine” that requires congressional action when the regulatory authority of an agency is not clearly defined. The Primer concludes with an analysis of the legislation that is needed to regulate cryptocurrencies effectively.
Multiple works have leveraged the public Bitcoin ledger to estimate the revenue cybercriminals obtain from their victims. Estimations focusing on the same target often do not agree, due to the use of different methodologies, seed addresses, and time periods. These factors make it challenging to understand the impact of their methodological differences. Furthermore, they underestimate the revenue due to the (lack of) coverage on the target's payment addresses, but how large this impact remains unknown. In this work, we perform the first systematic analysis on the estimation of cybercrime bitcoin revenue. We implement a tool that can replicate the different estimation methodologies. Using our tool we can quantify, in a controlled setting, the impact of the different methodology steps. In contrast to what is widely believed, we show that the revenue is not always underestimated. There exist methodologies that can introduce huge overestimation. We collect 30,424 payment addresses and use them to compare the financial impact of 6 cybercrimes (ransomware, clippers, sextortion, Ponzi schemes, giveaway scams, exchange scams) and of 141 cybercriminal groups. We observe that the popular multi-input clustering fails to discover addresses for 40% of groups. We quantify, for the first time, the impact of the (lack of) coverage on the estimation. For this, we propose two techniques to achieve high coverage, possibly nearly complete, on the DeadBolt server ransomware. Our expanded coverage enables estimating DeadBolt's revenue at $2.47M, 39 times higher than the estimation using two popular Internet scan engines.
Jiachi Chen, Jiang Hu, Xin Xia, David Lo · 7 authors
Decentralized Finance (DeFi) uses blockchain technologies to transform traditional financial activities into\ndecentralized platforms that run without intermediaries and centralized institutions. Smart contracts are\nprograms that run on the blockchain, and by utilizing smart contracts, developers can more easily develop\nDeFi applications. Some key features of smart contracts – self-executed and immutability – ensure the\ntrustworthiness, transparency and efficiency of DeFi applications, and have led to a fast-growing DeFi market.\nHowever, misbehaving developers can add traps or backdoor code snippets to a smart contract, which are\nhard for contract users to discover. We call these code snippets in a DeFi smart contract as “DeFi Contract\nTraps" (DCTs). In this paper, we identify five DeFi contract traps and introduce their behaviors, describe\nhow attackers use them to make unfair profits, and analyse their prevalence in the Ethereum platform. We\npropose a symbolic execution tool, DeFiDefender, to detect such traps and use a manually labeled small-scale\ndataset that consists of 700 smart contracts to evaluate it. Our results show that our tool is not only highly\neffective but also highly efficient. DeFiDefender only needs 0.48s to analyze one DeFi smart contract and\nobtains a high average accuracy (98.17%), precision (99.74%), and recall (89.24%). Among the five DeFi contract\ntraps introduced in this paper, four of them can be detected through contract bytecode without the need for\nsource code. We also apply DeFiDefender to a large-scale dataset that consists of 20,679 real DeFi related\nEthereum smart contracts. We found that 52.13% of these DeFi smart contracts contain at least one contract\ntrap. Although a smart contract that contains contract traps is not necessarily malicious, our finding suggests\nthat DeFi related contracts have many centralized issues in a zero-trust environment and in the absence of a\ntrusted part