Amit Kumar Tyagi, Bukola Fatimah Balogun, Shrikant Tiwari
Digital forensics plays an important role in investigating cybercrimes, data breaches, and other digital misdeeds in an increasingly connected world. With the proliferation of blockchain technology, a new dimension has emerged in the world of digital forensics. This work presents a comprehensive review of the intersection between blockchain and digital forensics, exploring the various ways blockchain technology influences and challenges the traditional practices of digital forensic investigations. This work begins by elucidating the fundamental concepts of blockchain technology, emphasizing its decentralized and immutable nature, cryptographic underpinnings, and its uses in cryptocurrency transactions. Subsequently, it delves into the potential benefits of blockchain for digital forensics, such as providing transparent and tamper-proof logs of digital activities and transactions. However, this chapter also discusses the unique challenges posed by blockchain in digital forensic investigations.
In the introductory part of the paper, the author briefly explores the emergence of the first cryptocurrency (Bitcoin), which was initially devised for the purpose of securing easier transactions without intermediaries. Criminals soon realised that cryptocurrencies, due to their inherent characteristics, could provide them with anonymity. As other cryptocurrencies (altcoins) emerged, it was necessary to define their conceptual framework. While cryptocurrencies were initially used in illegal sales of narcotics, their application soon spread to a number of other criminal activities. In that context, the author first presents the reasons that led criminals to turn to cryptocurrencies in their financial transactions, and then explains the possible uses of cryptocurrencies in the commission of crime. The central part of the paper provides examples of criminal activities committed by using cryptocurrencies. It is reasonable to expect that, in the future, the use of cryptocurrencies will extend to other criminal activities, which are still unaffected by the trend that has existed for the last ten years.
M.D.M. Shamalka, Banujan Kuhaneswaran, Banage T. G. S. Kumara
Most of the software vendors lost their expected revenue because of the pirated software. Not only economic losses but also they face numerous kinds of problems including reputation damage. Software users are also facing a number of issues because of pirated software including legal issues because of the break of copyright protections. The aim of this research is to introduce blockchain and smart contracts-based approaches to mitigate software piracy. Software piracy remains a pervasive challenge in the digital landscape, prompting the exploration of innovative solutions to protect intellectual property rights. This research proposes a novel approach leveraging blockchain technology and smart contracts to mitigate software piracy. The proposed platform allows users to download and install software securely, with every transaction meticulously recorded on the blockchain. Through the immutability and transparency inherent in blockchain, a tamper-resistant ledger ensures the traceability of software transactions. Smart contracts, embedded in the platform, enforce licensing agreements, providing an automated and decentralized mechanism for software distribution. The integration of blockchain and smart contracts not only fortifies software protection but also introduces a transparent and auditable ecosystem. This research contributes to the discourse on combating software piracy by harnessing the power of blockchain technology, offering a robust and decentralized solution for safeguarding intellectual property in the digital era.
ABSTRACT Bitcoin, launched in 2009, has gone through inconspicuous years, halcyon years, and now, the chaos years. Writers predicted that bitcoin would replace fiat currencies and the underlying technology, blockchain, would significantly reduce the need for auditors. However, there have been numerous major cryptocurrency crimes and related bankruptcies. Called the “heist of the century,” in the 2016 Bitfinex hack, 119,754 bitcoins were illegally transferred from over 2,000 Bitfinex accounts to an external wallet. Starting in January 2017, about 25,118 of those bitcoins were transferred to other exchanges. Several money laundering techniques were employed; however, the perpetrators made mistakes and were arrested in 2022. They were identified through analyzing the bitcoin blockchain, geolocating the IP addresses used for communications, and identifying individuals when bitcoin was used for “real world” transactions. The bitcoin blockchain is publicly available and would be a great resource for Big Data, data analytics, and forensics classes. JEL Classifications: K42.
A smart contract is a computerised transaction agreement that carries out predefined terms without human involvement or third-party intermediaries. It serves as a trust intermediary in several industries, including finance, insurance, and supply chain management, in the blockchain 2.0 era. With the increasing interest in smart contracts, security has become a serious problem. Examining typical vulnerability types and vulnerability detection methodologies is of special importance. In this research, a comprehensive evaluation of common smart contract security vulnerabilities is conducted, and a three-tier threat model is then provided to classify the vulnerabilities. In addition, we examine fourteen existing smart contract analysis tools for finding vulnerabilities and classify them according to the main technique they apply. This article is designed to serve as a reference for people who wish to analyse deployed code and enhance existing detection techniques. At the conclusion, open issues and future research paths regarding smart contract vulnerability detection are presented.
Open access
2 source records
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
The rapid growth in the fintech industry propels financial services into the digital era, bringing unprecedented convenience and efficiency. However, this transformation could be a smoother process; it faces difficulties, primarily in Cybersecurity. This comprehensive study explores the cybersecurity landscape in the fintech industry, including common threats, existing defensive measures, and innovative solutions that shape the future. Significant dangers, such as data breaches, phishing attacks, and malware complications, emphasize the need for strong cybersecurity strategies. Fintech firms address these concerns by employing various defensive measures, including encryption technology, robust multi-factor authentication, and strict compliance with legal frameworks. Examining prospects, the article explores emerging themes such as the mysterious domain of quantum-resistant cryptography, the mysterious frontier of behavioral analytics, and the shift toward decentralized identification solutions. These developments demonstrate a proactive shift in strategy, anticipating and preparing for potential hazards to prevent and minimize their impact. The conclusion presents important findings, drawing out their implications for the future and proposing sensible suggestions for further research and industrial practices. This research provides vital insights for stakeholders in the rapidly changing field of fintech, helping them navigate the complex intersection of finance and technology and guaranteeing a safe journey through unfamiliar areas.
Smart contracts are becoming appealing targets for hackers because of the vast amount of cryptocurrencies under their control. Asset loss due to the exploitation of smart contract codes has increased significantly in recent years. To guarantee that smart contracts are vulnerability-free, there are many works to detect the vulnerabilities of smart contracts, but only a few vulnerability repair works have been proposed. Repairing smart contract vulnerabilities at the source code level is attractive as it is transparent to users, whereas existing repair tools, such as SCRepair and sGuard , suffer from many limitations: (1) ignoring the code of vulnerability prevention; (2) possibly applying the repair to the wrong statements and changing the original business logic of smart contracts; and (3) showing poor performance in terms of time and gas overhead. In this work, we propose machine learning guided rule-based automated vulnerability repair on smart contracts to improve the effectiveness and efficiency of sGuard . To address the limitations mentioned above, we design the features that characterize both the symptoms of vulnerabilities and the methods of vulnerability prevention to learn various vulnerability patterns and reduce false positives. Additionally, a fine-grained localization algorithm is designed by traversing the nodes of the abstract syntax tree, and we refine and extend the repair rules of sGuard to preserve the original business logic of smart contracts and support new vulnerability types. Our tool, named sGuard+ , reduces time overhead based on machine learning models, and reduces gas overhead by fewer code changes and precise patching. In our experiment, we collect a publicly available vulnerability dataset from CVE, SWC, and SmartBugs Curated as a ground truth for evaluations. Overall, sGuard+ repairs more vulnerabilities with less time and gas overhead than state-of-the-art tools. Furthermore, we reproduce about 9,000 historical transactions for regression testing. It is shown that sGuard+ has no impact on the original business logic of smart contracts.
Our daily activities revolve around various technologies, the smart city technologies and the services they offer have all influenced modern living conditions. The purpose of a smart city is to enhance people's quality of life and provide possibilities to address social and environmental issues. As a developing technology, blockchain is beneficial for enhancing smart city services including food tracking, supply-demand matching, the security of connected cars, and regulatory compliance. We propose a new framework for describing how blockchain technology is used in smart contracts to improve security, dependability, and many other positive outcomes in a smart city environment. We propose smarter and resilient smart contracts using blockchain technology to manage real estate information. We propose a framework with tamperproof functionality to store the data and retrieve the data. Smart contract mathematical computations like overhead rate, execution time, mean computational cost, standard deviation, throughput, and resource utilization are evaluated and the results are compared. This paper focuses on real-world rental file management scenarios to demonstrate the benefits of blockchain technology and how it is used to address the issues that currently exist in developing smart contracts and services while exchanging real land and other properties in a smart city environment.
This research introduces innovative features tailored to capture distinctive characteristics of ransomware activity within the cryptocurrency ecosystem. The study employs a multifaceted analysis to delve into ransomware-related data encompassing transaction metadata, ransom analysis, behavioral patterns, and financial aspects. A feature selection algorithm is explored to discern ransomware transactions in Bitcoin (BTC) and the United States Dollar (USD) using the UGRansome dataset. This comprehensive dataset of ransomware-related transactions facilitates the proposal of novel features designed to capture the unique traits of ransomware activity. The correlation matrix and temporal analysis of these features contribute to a nuanced understanding of the dynamic nature of ransomware threats. The research presents the Ransomware Feature Selection Algorithm (RFSA) based on Gini Impurity and Mutual Information (MI) to effectively select crucial ransomware features. Evaluation metrics such as precision, recall, accuracy, and F1 score highlight the effectiveness of the RFSA. The analysis reveals that approximately 68% of ransomware incidents involve BTC transactions ranging from 1.46 to 2.56, with an average of 2.01 BTC transactions per attack. Moreover, ransomware causes financial damages ranging from 4.38 to 172.36 USD, with an average damage of 88.37 USD. The RFSA identifies 17 ransomware types and their associated malware to shed light on their characteristics. The study investigates the pricing of ransomware and reveals that TowerWeb is associated with the highest fee, amounting to 135.26 BTC, while CryptoLocker has the lowest fee, recorded at 10.51 BTC. Additionally, the impact of ransomware duration on financial gains and network flow is investigated, disclosing a correlation between extended duration and higher financial gains. The research achieves outstanding performance metrics, including an MI score of 95%, accuracy of 93%, recall of 92%, and precision of 89%. These results showcase the superiority of the proposed approach over existing studies, emphasizing the dynamic and adaptable nature of ransomware demands. The findings suggest that there is no fixed amount for specific cyberattacks. This underscores the importance of adapting to the evolving landscape of ransomware threats.
Ensuring robust security in the Internet of Things (IoT) landscape is of paramount importance. This research article presents a novel approach to enhance IoT security by leveraging collaborative threat intelligence and integrating blockchain technology with machine learning (ML) models. The iOS application acts as a central control centre, facilitating the reporting and sharing of detected threats. The shared threat data is securely stored on a blockchain network, enabling ML models to access and learn from a diverse range of threat scenarios. The research focuses on implementing Random Forest, Decision Tree classifier, Ensemble, LSTM, and CNN models on the IoT23 dataset within the context of a Collaborative Threat Intelligence Framework for IoT Security. Through an iterative process, the models’ accuracy is improved by reducing false negatives through the collaborative threat intelligence system. The article investigates the implementation details, privacy considerations, and the seamless integration of ML-based techniques for continuous model improvement. Experimental evaluations on the IoT23 dataset demonstrate the effectiveness of the proposed system in enhancing IoT security and mitigating potential threats. The research contributes to the advancement of collaborative threat intelligence and blockchain technology in the context of IoT security, paving the way for more secure and reliable IoT deployments.
Blockchain, as one of the emerging technologies in recent years, is essentially a decentralized distributed ledger. By leveraging blockchain, it provides a new approach to identity authentication. This paper provides an overview of the applications of identity authentication based on blockchain. Firstly, the background knowledge of blockchain is introduced. Then, the technical aspects of identity authentication based on blockchain are discussed and classified from the perspectives of identity authentication techniques and cryptographic algorithms. Subsequently, the applications of identity authentication based on blockchain technology are introduced and classified in various fields. Finally, a summary of the entire paper is presented.
Elohim Fonseca dos Reis, Alexander Teytelboym, Abeer ElBahrawy, Ignacio De Loizaga · 5 authors
Dark web marketplaces have been a significant outlet for illicit trade, serving millions of users worldwide for over a decade. However, not all users are the same. This paper aims to identify the key players in Bitcoin transaction networks linked to dark markets and assess their role by analysing a dataset of 40 million Bitcoin transactions involving the 31 major markets in the period 2011-2021. First, we propose an algorithm that categorizes users either as buyers or sellers, and show that a large fraction of the trading volume is concentrated in a small group of elite market participants. We find that the dominance of markets is reflected in trading properties of buyers and sellers. Then, we investigate both market star-graphs and user-to-user networks, and highlight the importance of a new class of users, namely 'multihomers', who operate on multiple marketplaces concurrently. Specifically, we show how the networks of multihomers and seller-to-seller interactions can shed light on the resilience of the dark market ecosystem against external shocks. Our findings suggest that understanding the behavior of key players in dark web marketplaces is critical to effectively disrupting illegal activities.
With the ever-increasing advancement in blockchain technology, security is a significant concern when substantial investments are involved. This paper explores known smart contract exploits used in previous and current years. The purpose of this research is to provide a point of reference for users interacting with blockchain technology or smart contract developers. The primary research gathered in this paper analyses unique smart contracts deployed on a blockchain by investigating the Solidity code involved and the transactions on the ledger linked to these contracts. A disparity was found in the techniques used in 2021 compared to 2023 after Ethereum moved from a Proof-of-Work blockchain to a Proof-of-Stake one, demonstrating that with the advancement in blockchain technology, there is also a corresponding advancement in the level of effort bad actors exert to steal funds from users. The research concludes that as users become more wary of malicious smart contracts, bad actors continue to develop more sophisticated techniques to defraud users. It is recommended that even though this paper outlines many of the currently used techniques by bad actors, users who continue to interact with smart contracts should consistently stay up to date with emerging exploitations.
Alejandro Valencia-Arías, Juan David González-Ruíz, Lilian Verde Flores, Luis Vega-Mori · 6 authors
Machine learning and blockchain technology are fast-developing fields with implications for multiple sectors. Both have attracted a lot of interest and show promise in security, IoT, 5G/6G networks, artificial intelligence, and more. However, challenges remain in the scientific literature, so the aim is to investigate research trends around the use of machine learning in blockchain. A bibliometric analysis is proposed based on the PRISMA-2020 parameters in the Scopus and Web of Science databases. An objective analysis of the most productive and highly cited authors, journals, and countries is conducted. Additionally, a thorough analysis of keyword validity and importance is performed, along with a review of the most significant topics by year of publication. Co-occurrence networks are generated to identify the most crucial research clusters in the field. Finally, a research agenda is proposed to highlight future topics with great potential. This study reveals a growing interest in machine learning and blockchain. Topics are evolving towards IoT and smart contracts. Emerging keywords include cloud computing, intrusion detection, and distributed learning. The United States, Australia, and India are leading the research. The research proposes an agenda to explore new applications and foster collaboration between researchers and countries in this interdisciplinary field.
Elena Baninemeh, Slikker, Marre, Katsiaryna Labunets, Jansen, Slinger
Distributed ledger technologies have gained significant attention and adoption in recent years. Despite various security features distributed ledger technology provides, they are vulnerable to different and new malicious attacks, such as selfish mining and Sybil attacks. While such vulnerabilities have been investigated, detecting and discovering appropriate countermeasures still need to be reported. Cybersecurity knowledge is limited and fragmented in this domain, while distributed ledger technology usage grows daily. Thus, research focusing on overcoming potential attacks on distributed ledgers is required. This study aims to raise awareness of the cybersecurity of distributed ledger technology by designing a security risk assessment method for distributed ledger technology applications. We have developed a database with possible security threats and known attacks on distributed ledger technologies to accompany the method, including sets of countermeasures. We employed a semi-systematic literature review combined with method engineering to develop a method that organizations can use to assess their cybersecurity risk for distributed ledger applications. The method has subsequently been evaluated in three case studies, which show that the method helps to effectively conduct security risk assessments for distributed ledger applications in these organizations.
Bhupendra Acharya, Muhammad Saad, Antonio Emanuele Ciná, Lea Schönherr · 8 authors
The mainstream adoption of cryptocurrencies has led to a surge in wallet-related issues reported by ordinary users on social media platforms. In parallel, there is an increase in an emerging fraud trend called cryptocurrency-based technical support scam, in which fraudsters offer fake wallet recovery services and target users experiencing wallet-related issues.In this paper, we perform a comprehensive study of cryptocurrency-based technical support scams. We present an analysis apparatus called HoneyTweet to analyze this kind of scam. Through HoneyTweet, we lure over 9K scammers by posting 25K fake wallet support tweets (so-called honey tweets). We then deploy automated systems to interact with scammers to analyze their modus operandi. In our experiments, we observe that scammers use Twitter as a starting point for the scam, after which they pivot to other communication channels (e.g., email, Instagram, or Telegram) to complete the fraud activity. We track scammers across those communication channels and bait them into revealing their payment methods. Based on the modes of payment, we uncover two categories of scammers that either request secret key phrase submissions from their victims or direct payments to their digital wallets. Furthermore, we obtain scam confirmation by deploying honey wallet addresses and validating private key theft. We also collaborate with the prominent payment service provider by sharing scammer data collections. The payment service provider feedback was consistent with our findings, thereby supporting our methodology and results. By consolidating our analysis across various vantage points, we provide an end-to-end scam lifecycle analysis and propose recommendations for scam mitigation.
Anton Wahrstätter, Alfred Taudes, Davor Svetinović
Privacy within the Bitcoin ecosystem has been critical for the operation and propagation of the system since its very first release. While various entities have sought to deanonymize and reveal user identities, the default semi-anonymous approach to privacy was judged as insufficient and the community developed a number of advanced privacy-preservation mechanisms. In this study, we propose an improved variant of the multiple-input clustering approach that incorporates advanced privacy-enhancing techniques. We examine the CoinJoin-adjusted user graph of Bitcoin through quantitative network analysis and draw conclusions on the effectiveness of our proposed clustering method compared to naive multiple-input clustering. Our findings indicate that CoinJoin transactions can significantly distort commonly applied address clustering approaches. Moreover, we demonstrate that Bitcoin's user graph has become less dense in recent years, concurrent with the collapse of several independent user clusters. Our results contribute to a more comprehensive understanding of privacy aspects in the Bitcoin transaction network and lay the groundwork for developing enhanced measures to prevent money laundering and terrorism financing.
Abstract Identifying illicit behavior in the Bitcoin network is a well‐explored topic. The methods proposed over time have generated great insights into the deanonymization of the Bitcoin user base through the clustering of inputs and outputs. With advanced techniques being deployed by Bitcoin users, these heuristics are now being challenged in their ability to aid in the detection of illicit activity. In this paper, we provide a comprehensive list of methods deployed by malicious actors on the network and illicit transaction mining methods. We detail the evolution of the heuristics that are used to deanonymize Bitcoin transactions. We highlight the issues associated with conducting law enforcement investigations and propose recommendations for the research community to address these issues. Our recommendations include the release of public data by exchanges to allow researchers and law enforcement to further protect the network from malicious users. We recommend the enhancement of current heuristics through machine learning methods and discuss how researchers can take the fight head‐on against expert cybercriminals.
Blockchain technology offers a promising way to improve business processes by providing a secure and transparent transaction platform. However, using this technology brings its own set of challenges, especially when trying to balance user privacy with legal and regulatory needs. This article explores the challenges of keeping user information private, adhering to regulatory frameworks, and fulfilling legal requirements on the blockchain. A key point in this research is the challenge of keeping or maintaining confidentiality while being transparent. The article also discusses the issues of applying legal rules to a system not controlled by one central authority, the risks of privacy and security breaches, and the need to follow data protection laws. The article highlights how some blockchain-based companies have tackled these challenges, mainly through smart blockchain management and innovative technology, by looking at real-world examples from major companies like IBM, Bitpay, Ripple, and Coinbase. The systematic literature review (SLR) methodology involved reviewing literature from the past 15 years (2008-2023) from trusted sources like Google Scholar, ACM Digital Library, IEEE, Springer, and Science Direct. The findings indicate that cutting-edge technologies prioritizing privacy, such as zero-knowledge proofs, ring signatures, and encryption methods, would enable Bitcoin (BTC) platform operations to maintain or balance privacy and transparency. Furthermore, the study indicates the importance of clear privacy guidelines, adhering to relevant regulations, working closely with regulators and law enforcement, and educating users. In summary, it is crucial to approach blockchain carefully, prioritizing user privacy while meeting all legal and regulatory requirements.
Purpose The study provides a comprehensive understanding of the issues and illegal activities related to cryptocurrencies and their negative repercussions. This study aims to identify and classify cryptocurrency downsides using grounded theory and in-depth interviews. The study also analysed investors’ reluctance to invest in cryptocurrency. This pioneering qualitative study illuminates a deep and multifaceted criminal aspect of cryptocurrency. Design/methodology/approach The study conducted in-depth interviews with respondents who have experience and knowledge of cryptocurrency investments. The interviews were recorded and transcribed. The analysis was performed using the NVivo 14 software in the study. Findings The study specified two major types of cryptocurrency’s negative aspects: barriers and illegal usage. Barriers to cryptocurrency investment include technological, security, trust, market-related and regulatory reasons. Terrorist funding, money laundering, fraud and ransom payments are all examples of illegal usage. The results of the word cloud analysis are consistent with the overall findings of the survey, which highlighted illegal usage as a prominent negative element of cryptocurrencies. It is a key reason why cryptocurrency is not included in investing portfolios by investors. Originality/value The study’s findings provide useful insights for policymakers to develop better methods for successfully mitigating risks and ensuring responsible and sustainable usage of cryptocurrencies. In addition, the study could serve as a stepping stone for more cryptocurrency-related studies, contributing to the development of a more complete and nuanced comprehension of this emergent technology and its societal effects.
There is a distinct lack of criminological research examining victimisation experiences in emerging cryptocurrency frauds. At the same time, online cryptocurrency communities have become a key part of the social milieu of the cryptocurrency ecosystem where scams are commonplace. Using Reddit forum data from the subreddit r/ CryptoCurrency, this exploratory qualitative study investigates how users in an online cryptocurrency community share knowledge and experiences of cryptocurrency scams. Thematic analysis revealed how online cryptocurrency communities discuss scams by (1) arming the community (e.g. newcomer guides, personal disclosures of scam victimisation, and reflections on the technological affordances in scams); and (2) establishing community norms in response to cryptocurrency scams (e.g. protecting the community, ‘scambaiting’ practices, normalising scams as an outcome of ‘decentralisation’). Gaining a deeper understanding of cryptocurrency scam experiences provides timely insights into the intersections between victims/offenders in digital environments, how we can respond to the recent growth in cryptocurrency scams, and the variegated ways that victims seek assistance following experiences.
Pengcheng Xia, Yu Zhou, Kailong Wang, Kai Ma · 9 authors
The dark web has emerged as the state-of-the-art solution for enhanced anonymity. Just like a double-edged sword, it also inadvertently becomes the safety net and breeding ground for illicit activities. Among them, cryptocurrencies have been prevalently abused to receive illicit income while evading regulations. Despite the continuing efforts to combat illicit activities, there is still a lack of an in-depth understanding regarding the characteristics and dynamics of cryptocurrency abuses on the dark web. In this work, we conduct a multi-dimensional and systematic study to track cryptocurrency-related illicit activities and campaigns on the dark web. We first harvest a dataset of 4,923 cryptocurrency-related onion sites with over 130K pages. Then, we detect and extract the illicit blockchain transactions to characterize the cryptocurrency abuses, targeting features from single/clustered addresses and illicit campaigns. Throughout our study, we have identified 2,564 illicit sites with 1,189 illicit blockchain addresses, which account for 90.8 BTC in revenue. Based on their inner connections, we further identify 66 campaigns behind them. Our exploration suggests that illicit activities on the dark web have strong correlations, which can guide us to identify new illicit blockchain addresses and onions, and raise alarms at the early stage of their deployment.
Money laundering in cryptocurrencies is a significant concern, as it facilitates and conceals crime and can distort markets and the broader financial system. To combat this issue, researchers have turned to techniques to develop effective Anti-Money Laundering (AML) frameworks. The findings contribute to the ongoing efforts to promote social good by reducing the impact of criminal activities on society. By preventing money laundering, we can also help to combat other criminal activities such as drug trafficking, corruption, and terrorism. This paper focuses on the use of Graph Neural Networks (GNNs) to classify cryptocurrencies transactions. Specifically, the study employs Graph Convolutional Networks (GCNs), Graph Attention Networks (GAT), the Chebyshev spatial convolutional neural network (ChebNet), and GraphSAGE network to classify Bitcoin transactions. The study finds that ChebNet, GraphSAGE and a variant of GAT outperform other methods and improve upon the state of the art in terms of recall and F1 scores, thus suggesting that they can be more reliable in identifying illicit transactions.