Achraf Boumhidi, Abdessamad Benlahbib, El Habib Nfaoui
Reputation generation systems are decision-making tools used in different domains including e-commerce, tourism, social media events, etc. Such systems generate a numerical reputation score by analyzing and mining massive amounts of various types of user data, including textual opinions, social interactions, shared images, etc. Over the past few years, users have been sharing millions of tweets related to cryptocurrencies. Yet, no system in the literature was designed to handle the unique features of this domain with the goal of automatically generating reputation and supporting investors’ and users’ decision-making. Therefore, we propose the first financially oriented reputation system that generates a single numerical value from user-generated content on Twitter toward cryptocurrencies. The system processes the textual opinions by applying a sentiment polarity extractor based on the fine-tuned auto-regressive language model named XLNet. Also, the system proposes a technique to enhance sentiment identification by detecting sarcastic opinions through examining the contrast of sentiment between the textual content, images, and emojis. Furthermore, other features are considered, such as the popularity of the opinions based on the social network interactions (likes and shares), the intensity of the entity’s demand within the opinions, and news influence on the entity. A survey experiment has been conducted by gathering numerical scores from 827 Twitter users interested in cryptocurrencies. Each selected user assigns 3 numerical assessment scores toward three cryptocurrencies. The average of those scores is considered ground truth. The experiment results show the efficacy of our model in generating a reliable numerical reputation value compared with the ground truth, which proves that the proposed system may be applied in practice as a trusted decision-making tool.
Abstract With the widespread use of blockchain, more and more smart contracts are being deployed, and their internal logic is getting more and more sophisticated. Due to the large false positive rate and low detection accuracy of most current detection methods, which heavily rely on already established detection criteria, certain smart contracts additionally call for human secondary detection, resulting in low detection efficiency. In this study, we propose HGAT, a hierarchical graph attention network-based detection model, in order to address the aforementioned issues as well as the shortcomings of current smart contract vulnerability detection approaches. First, using Abstract Syntax Tree (AST) and Control Flow Graph, the functions in the smart contract are abstracted into code graphs (CFG). Then abstract each node in the code subgraph, extract the node features, utilize the graph attention mechanism GAT, splice the obtained vectors to form the features of each line of statements and use these features to detect smart contracts. To create test data and assess HGAT, we leverage the open-source smart contract vulnerability sample dataset. The findings of the experiment indicate that this method can identify smart contract vulnerabilities more quickly and precisely than other detection techniques.
This paper presents a comprehensive analysis of the cryptocurrency free giveaway scam disseminated in a new distribution channel, Twitter lists. To collect and detect the scam in this channel, unlike existing scam detection systems that rely on manual effort, this paper develops a fully automated scam detection system, \textit{GiveawayScamHunter}, to continuously collect lists from Twitter and utilize a Nature-Language-Processing (NLP) model to automatically detect the free giveaway scam and extract the scam cryptocurrency address. By running \textit{GiveawayScamHunter} from June 2022 to June 2023, we detected 95,111 free giveaway scam lists on Twitter that were created by thousands of Twitter accounts. Through analyzing the list creator accounts, our work reveals that scammers have combined different strategies to spread the scam, including compromising popular accounts and creating spam accounts on Twitter. Our analysis result shows that 43.9\% of spam accounts still remain active as of this writing. Furthermore, we collected 327 free giveaway domains and 121 new scam cryptocurrency addresses. By tracking the transactions of the scam cryptocurrency addresses, this work uncovers that over 365 victims have been attacked by the scam, resulting in an estimated financial loss of 872K USD. Overall, this work sheds light on the tactics, scale, and impact of free giveaway scams disseminated on Twitter lists, emphasizing the urgent need for effective detection and prevention mechanisms to protect social media users from such fraudulent activity.
Shenqiang Wang, Zhaowei Liu, Haiyang Wang, Jianping Wang
Abstract The rapid development of blockchain technology has garnered increasing attention, particularly in the field of edge computing. It has become a significant subject of research in this area due to its ability to protect the privacy of data. Despite the advantages that blockchain technology offers, there are also security threats that must be addressed. Attackers may manipulate certain nodes in the blockchain network, which can result in tampering with transaction records or other malicious activities. Moreover, the creation of a large number of false nodes can be utilized to gain control and manipulate transaction records of the blockchain network, which can compromise the reliability and security of edge computing. This paper proposes a blockchain node detection method named $$T^2A2vec$$ T 2 A 2 v e c that provides a more secure, credible, and reliable solution to address these challenges. In order to achieve $$T^2A2vec$$ T 2 A 2 v e c , a transaction dataset that is evenly distributed in both space and time was collected. The transaction dataset is constructed as a transaction graph, where nodes represent accounts and edges describe transactions. BP neural network is used to extract account features, and a random walk strategy based on transaction time, type, and amount is used to extract transaction features. The obtained account features and transaction features are fused to obtain account representation. Finally, the obtained node representation is fed into different classifiers to identify malicious nodes.
Ensuring the authenticity and transparency of data along with the prevention of its misuse has become an increasing concern in today’s data-driven economy. The use of blockchain helps in this regard to a certain extent, given its decentralized way of storing data combined with its power of making the data extremely hard to be mutated. This DApp (Decentralised application) being developed enables easy verification of skills and certifications of a particular candidate by storing the captured data on Ethereum Blockchain, thereby making the information stored immutable and secure. The proposed system has been developed in three phases. In the first phase, the institute or an organisation enrols the candidate or student, after which they are required to update their profiles and enter the necessary background information. In the second phase, candidates can raise a request for endorsements and verification of their skills and certifications. And in the third phase, organizations can accept or reject the endorsement requests. This skill-verification system prevents malpractices in the hiring process and ensures the validity of the data provided by an individual.
Since the emergence of the Internet of Things (IoTs), the potential for connecting devices with other devices, to collect and exchange data has been widely becoming an integrated part of human society. The ongoing development and innovation have also reached various other domains. However, there are still some significant security measures and trust issues that need to be resolved to make the Internet of Things more secure and reliable. Blockchain technology emerged as one potential solution for the security-related goals of IoTs. There has been a growing interest in exploring the potential for integrating blockchain technology with the Internet of Things(IoTs). Blockchain provides distributed immutable ledger that keeps track of transactions done by nodes connected to its network. However, security risks remain, such as the potential inclusion of malicious nodes in the blockchain network. To address this, we propose a method that uses TLS certificates to identify and prevent malicious nodes from joining the blockchain network, ensuring the reliability and security of the distributed ledger.
Alexander Shevtsov, Despoina Antonakaki, Ioannis Lamprou, Ioannis Kontogiorgakis · 6 authors
On 24 February 2022, Russia invaded Ukraine, starting what is now known as the Russo-Ukrainian War, initiating an online discourse on social media. Twitter as one of the most popular SNs, with an open and democratic character, enables a transparent discussion among its large user base. Unfortunately, this often leads to Twitter's policy violations, propaganda, abusive actions, civil integrity violation, and consequently to user accounts' suspension and deletion. This study focuses on the Twitter suspension mechanism and the analysis of shared content and features of the user accounts that may lead to this. Toward this goal, we have obtained a dataset containing 107.7M tweets, originating from 9.8 million users, using Twitter API. We extract the categories of shared content of the suspended accounts and explain their characteristics, through the extraction of text embeddings in junction with cosine similarity clustering. Our results reveal scam campaigns taking advantage of trending topics regarding the Russia-Ukrainian conflict for Bitcoin and Ethereum fraud, spam, and advertisement campaigns. Additionally, we apply a machine learning methodology including a SHapley Additive explainability model to understand and explain how user accounts get suspended.
Blockchain is a promising technology that is quickly gaining traction in the realm of security that is regulated by both governmental and commercial organizations. Donors are unable to know whether their donations are being used effectively due to a complete lack of transparency in donation-related transactions, which has prompted many to stop believing in charities. The immutability, traceability, and reliability properties of blockchain technology make it a viable solution for enhancing efficiency and transparency for charity. This research work is based on the Ethereum Blockchain, the decentralized donation tracking system that will permit transparent accountability, openness, and direct communication with the intended targets. The blockchain network would be made up of well-known, reliable, and esteemed companies.
As blockchain technology becomes more and more popular, a typical financial scam, the Ponzi scheme, has also emerged in the blockchain platform Ethereum. This Ponzi scheme deployed through smart contracts, also known as the smart Ponzi scheme, has caused a lot of economic losses and negative impacts. Existing methods for detecting smart Ponzi schemes on Ethereum mainly rely on bytecode features, opcode features, account features, and transaction behavior features of smart contracts, which are unable to truly characterize the behavioral features of Ponzi schemes, and thus generally perform poorly in terms of detection accuracy and false alarm rates. In this paper, we propose SourceP, a method to detect smart Ponzi schemes on the Ethereum platform using pre-trained models and data flow, which only requires using the source code of smart contracts as features. SourceP reduces the difficulty of data acquisition and feature extraction of existing detection methods. Specifically, we first convert the source code of a smart contract into a data flow graph and then introduce a pre-trained model based on learning code representations to build a classification model to identify Ponzi schemes in smart contracts. The experimental results show that SourceP achieves 87.2% recall and 90.7% F-score for detecting smart Ponzi schemes within Ethereum's smart contract dataset, outperforming state-of-the-art methods in terms of performance and sustainability. We also demonstrate through additional experiments that pre-trained models and data flow play an important contribution to SourceP, as well as proving that SourceP has a good generalization ability.
Smart contract vulnerabilities have become a common source of security incidents in the blockchain network in recent years. To mitigate the impact of such vulnerabilities, scholars have been exploring more effective and dependable methods for detecting them. However, existing smart contract vulnerability detection methods suffer from issues like a high rate of false positives and omissions, limited scalability, and reliance on expert knowledge, among others. To address these challenges, this study proposes a hybrid neural network model-based approach to smart contract vulnerability detection that leverages the strengths of different neural networks. By incorporating global context alongside local feature extraction, the method significantly enhances feature extraction rates. Experimental results demonstrate that the proposed method is highly efficient and accurate, making it a suitable solution for detecting smart contract vulnerabilities.
Due to the rapid development of blockchain, security issues caused by smart contract vulnerabilities are receiving increasingly widespread attention. Unfortunately, traditional smart contract vulnerability detection methods rely heavily on expert knowledge and elaborate rules, while neural network-based vulnerability detection methods have not yet achieved satisfactory accuracy either. In this paper, we propose a novel vulnerability detection method for smart contracts called VULDET. We first construct a contract graph based on the structure of the smart contract source code and combine security domain knowledge to attach additional features to nodes in the graph that are closely associated with vulnerabilities to highlight key nodes, and finally use graph attention networks for contract vulnerability detection. We apply VULDET to reentrancy vulnerability as well as timestamp dependency vulnerability detection and conduct extensive experiments, and the results show that our approach has significant advantages over existing methods.
Blockchain has facilitated the growth of cryptocurrencies but has also provided new ideas for illegals to commit fraud. Research on malicious accounts detection shows that the number of malicious accounts is much smaller than that of benign accounts, leading to imbalanced dataset samples. Most researchers adopt the under-sampling method to help deal with this issue, but this method does not correspond to the actual scale. So, we propose an anomaly detection method based on community discovery. Firstly, we use the transaction information in the Ethereum public chain to build a transaction network and use the Louvain algorithm to divide the transaction network into communities. Secondly, we use the LightGBM algorithm to classify the community. Finally, based on the classification results, we use HBOS, LOF, K-Means, KNN and iForest algorithms as benchmark algorithms for anomaly detection and compare the experimental results using the methods in this paper with the results of anomaly detection using the original transaction network. Experimental show that our method can reduce the amount of data by 35.53% and increase the AUC values of the five algorithms by 7.52%, 8.41%, 14.88%, 0.83% and 27.95%.
Roseline Oluwaseun Ogundokun, Micheal Olaolu Arowolo, Robertas Damaševičius, Sanjay Misra
The recent progress in blockchain and wireless communication infrastructures has paved the way for creating blockchain-based systems that protect data integrity and enable secure information sharing. Despite these advancements, concerns regarding security and privacy continue to impede the widespread adoption of blockchain technology, especially when sharing sensitive data. Specific security attacks against blockchains, such as data poisoning attacks, privacy leaks, and a single point of failure, must be addressed to develop efficient blockchain-supported IT infrastructures. This study proposes the use of deep learning methods, including Long Short-Term Memory (LSTM), Bi-directional LSTM (Bi-LSTM), and convolutional neural network LSTM (CNN-LSTM), to detect phishing attacks in a blockchain transaction network. These methods were evaluated on a dataset comprising malicious and benign addresses from the Ethereum blockchain dark list and whitelist dataset, and the results showed an accuracy of 99.72%.
Abstract With the development of blockchain, cryptocurrencies are also showing a boom. However, due to the decentralized and anonymous nature of blockchain, cryptocurrencies have inevitably become a hotbed for fraudulent crimes. For example, phishing scams are frequent, which not only jeopardize the financial security of blockchain, but also hinder the promotion of blockchain technology. To solve this problem, this paper proposes a graph neural network‐based phishing detection method for Ethereum, and validates it using Ethereum datasets. Specifically, this paper proposes a feature learning algorithm named TransWalk, which consists of a random walk strategy for transaction networks and a multi‐scale feature extraction method for Ethereum. Then, an Ethereum phishing fraud detection framework is built based on TransWalk, and conduct extensive experiments on the Ethereum dataset to verify the effectiveness of this scheme in identifying Ethereum phishing detection.
In the world of modern technology, ensuring security is a top priority. To address this issue, blockchain technology has emerged as a promising solution by eliminating intermediaries and enhancing security. Cryptocurrencies are the first type of digital assets that have been successfully managed using blockchain technology. In recent years, financial institutions have been increasingly adding cryptocurrencies to their portfolios, leading to widespread adoption and interest among various stakeholders, including the banking sector, government, and individual investors. Cryptocurrency has the potential to become the future global currency, replacing fiat currency. This research project provides a comprehensive overview of the cryptocurrency market, including its origins, key features, price dynamics, market capitalization, and trading volumes. The project also explores important concepts such as Ethereum, smart contracts, tokens, and consensus algorithms that are critical to the functioning of the cryptocurrency market.
Recently, the birth of non-fungible tokens (NFTs) has attracted great attention. NFTs are capable of representing users’ ownership on the blockchain and have experienced tremendous market sales due to their popularity. Unfortunately, the high value of NFTs also makes them a target for attackers. The defects in NFT smart contracts could be exploited by attackers to harm the security and reliability of the NFT ecosystem. Despite the significance of this issue, there is a lack of systematic work that focuses on analyzing NFT smart contracts, which may raise worries about the security of users’ NFTs. To address this gap, in this paper, we introduce 5 defects in NFT smart contracts. Each defect is defined and illustrated with a code example highlighting its features and consequences, paired with possible solutions to fix it. Furthermore, we propose a tool named NFTGuard to detect our defined defects based on a symbolic execution framework. Specifically, NFTGuard extracts the information of the state variables from the contract abstract syntax tree (AST), which is critical for identifying variable-loading and storing operations during symbolic execution. Furthermore, NFTGuard recovers source-code-level features from the bytecode to effectively locate defects and report them based on predefined detection patterns. We run NFTGuard on 16,527 real-world smart contracts and perform an evaluation based on the manually labeled results. We find that 1,331 contracts contain at least one of the 5 defects, and the overall precision achieved by our tool is 92.6%.
With the epidemic of Covid-19, a realisation has come into effect that the healthcare industry requires a more efficient method of storing non-tamperable vaccination certificates as well as sharing them with the relevant parties when required. As such, the need for efficient and secure vaccination tracking has led to the development of decentralized solutions. This paper aims to bring forth a Ethereum platform-based vaccination blockchain certificate system which supports authenticated consensual vaccination certificate sharing through the use of solidity smart contracts. We analyse the system architecture, implementation and evaluation, which will support the system's ability to resolve some of the security issues associated with centralised database systems such as low availability, integrity of the vaccination information as well as confidentiality and privacy of patient medical records. Vaxina system is a real-world implementation of a decentralized vaccination tracking system based on the Ethereum platform. It focuses more on the practical implementation and addresses some of the limitations of the previous proposed systems. It has been implemented and tested on the Ethereum blockchain and is available on GitHub for public use. The paper provides valuable insights for future work in the field of decentralized healthcare solutions.
Ethereum phishing scams have proven to be highly profitable in recent years, and pose a serious risk to the security of the blockchain ecosystem. Existing techniques for detecting phishing scams mostly model the transaction network at a very coarse-grained level. These methods rarely take into account the heterogeneity of the network, and do not consider multiple transactions over time between pairs of accounts. To this end, we model the Ethereum transaction network as a heterogeneous muiltidigraph and propose a novel graph embedding technique. Specifically, we use a temporal-weighted biased walking method based on the Jump-Stay strategy, which not only captures the properties of the dynamic transaction network more comprehensively, but also elegantly balances the distribution of different types of nodes. The superior performance of our model is shown through classification experiments on a real-world dataset of Ethereum transactions.
Zhen Zhang, Tao He, Kai Chen, Boshen Zhang · 6 authors
As the use of digital currencies, such as cryptocurrencies, increases in popularity, phishing scams and other cybercriminal activities on blockchain platforms (e.g., Ethereum) have also risen. Current methods of detecting phishing in Ethereum focus mainly on the transaction features and local network structure. However, these methods fail to account for the complexity of interactions between edges and the handling of large graphs. Additionally, these methods face significant issues due to the limited number of positive labels available. Given this, we propose a scheme that we refer to as the Bagging Multiedge Graph Convolutional Network to detect phishing scams on Ethereum. First, we extract the features from transactions and transform the complex Ethereum transaction network into three simple inter-node graphs. Then, we use graph convolution to generate node embeddings that leverage the global structural information of the inter-node graphs. Further, we apply the bagging strategy to overcome the issues of data imbalance and the Positive Unlabeled (PU) problem in transaction data. Finally, to evaluate our approach’s effectiveness, we conduct experiments using actual transaction data. The results demonstrate that our Bagging Multiedge Graph Convolutional Network (0.877 AUC) outperforms all of the baseline classification methods in detecting phishing scams on Ethereum.
Phishing is a widespread scam activity on Ethereum, causing huge financial losses to victims. Most existing phishing scam detection methods abstract accounts on Ethereum as nodes and transactions as edges, then use manual statistics of static node features to obtain node embedding and finally identify phishing scams through classification models. However, these methods can not dynamically learn new Ethereum transactions. Since the phishing scams finished in a short time, a method that can detect phishing scams in real-time is needed. In this paper, we propose a streaming phishing scam detection method. To achieve streaming detection and capture the dynamic changes of Ethereum transactions, we first abstract transactions into edge features instead of node features, and then design a broadcast mechanism and a storage module, which integrate historical transaction information and neighbor transaction information to strengthen the node embedding. Finally, the node embedding can be learned from the storage module and the previous node embedding. Experimental results show that our method achieves decent performance on the Ethereum phishing scam detection task.
As one of the most active blockchain platforms at present, Ethereum attracts a great deal of interest, including that of fraudsters. They exploit the anonymity of Ethereum accounts to perpetrate varieties of scams, the most common of which is phishing frauds. However, existing phishing detection work ignores the heterogeneity of Ethereum transaction edges. In fact, the activities on Ethereum include external transactions, internal transactions, and token transactions. Therefore, this paper proposes an Ethereum account phishing fraud detection method named HTSGCN. Based on heterogeneous transaction subnets, our method makes full use of the type and direction information contained in transactions. First, we collect Ethereum transaction data and construct a k-order heterogeneous subnet for each account. To aggregate the neighbor feature, we design a message propagation mechanism based on graph convolution network. Finally, we classify node representation vectors containing neighborhood and its own characteristics. Experimental results show that HTSGCN has a better effect on detecting phishing accounts than previous work which is based on homogeneous networks.
Ethereum, one of the most popular cryptocurrencies, allows for anonymous transactions and is frequently used for money laundering and scams. Although advanced scammers are hard to trace as they use sophisticated coin-mixing techniques, we argue that many generic scams only involve amateurs who manually mix transactions to avoid police detection. To counter this, centralized exchanges require users to go through Know-Your-Customer (KYC) processes before exchanging tokens for fiat currency. This paper extends the anti-money laundering further by proposing An EOA Identity Tracing System (AITS), which traces the flow of crypto tokens from the thief wallet to the exchange and backtracking from the KYC’s identities to the thief’s real identity. The proposed AITS also aids investigators with the token-transferring graph that is useful for off-chain investigation. The experimental results on the 1,045 thieves’ transactions recorded over 290 days reveal behaviors that the scammers used to evade police detection.
Modern technology has created the need for information flow to be fast and effective. we have been able to reach this through the internet; the medium, that is, the internet has expedited every folks, by creating the communication cheap and quick. One such innovative technology is blockchain. Having the properties such as immutability, integrity and decentralized architecture, one of the prospective application of blockchain is e-voting. The objective of e-voting system using blockchain is to facilitate transparent, fair and verifiable approach. But the existing e-voting systems using blockchain take more time to reflect the vote casted by the voters as the number of voters increases and make the system slow. In this paper we propose a system which uses a consensus algorithm called PoA to minimize the time for authentication, mining and verification of casted votes. The Proposed system which replaces the PoW consensus algorithm, in existing system, with PoA consensus algorithm, proved to be faster than existing system by more than 9 seconds. Thus this paper highlights how the existing e-voting system using blockchain is slow and how the proposed system optimizes the time required and makes the system faster.