Majd Soud, Ilham Qasse, Grischa Liebel, Mohammad Hamdaqa
Due to the risks associated with vulnerabilities in smart contracts, their security has gained significant attention in recent years. However, there is a lack of open datasets on smart contract vulnerabilities and their fixes that allows for data-driven research. Towards this end, we propose an automated framework for mining and classifying Ethereum’s smart contract vulnerabilities and their corresponding fixes from GitHub and from the Common Vulnerabilities and Exposures (CVE) records in the National Vulnerability Database. We implemented the proposed method in a fully automated framework, which we call AutoMESC. AutoMESC uses seven of the most well-known smart contract security tools to classify and label the collected vulnerabilities based on vulnerability types. Furthermore, it collects metadata that can be used in data-intensive smart contract security research (e.g., vulnerability detection, vulnerability classification, severity prediction, and automated repair). We used AutoMESC to construct a sample dataset and made it publicly available. Currently, the dataset contains 6.7K smart contract vulnerability-fix pairs written in Solidity. We assess the quality of the constructed dataset in terms of accuracy, provenance, and relevance, and compare it with existing datasets. AutoMESC is designed to collect data continuously and keep the corresponding dataset up-to-date with newly discovered smart contract vulnerabilities and their fixes from GitHub and CVE records.
Bei der illegalen Nutzung von Kryptowährungen liefern sich Straftäter:innen, die versuchen, neue Technologie auszunutzen, Ermittler:innen, die versuchen, Straftaten aufzudecken oder zu unterbinden und Gesetzgeber, die versuchen, die Nutzung zu regulieren, ein Wettrennen. Den Strafverfolgungsbehörden stellen sich zahlreiche Herausforderungen, etwa die Ermittlung von Straftäter:innen, das Fehlen eines rechtlichen Rahmens für die Strafverfolgung sowie von Instrumenten und Ausbildung um Straftaten vorzubeugen oder sie zu unterbinden. Um die Beziehung zwischen Kryptowährungsdelikten und Ermittlungs- und Präventionsmethoden zur digitalen Disruption besser zu verstehen, wird der Forschungsstand analysiert. Ziel ist es, die Praxis, z. B. die Polizei, bei Prävention, Störung und Reduzierung von Delikten zu unterstützen. Die Ergebnisse informieren über Kategorien und Umfang illegaler Aktivitäten sowie den Einfluss von Kryptowährungsmärkten auf Kriminalität, beides wichtige Aspekte für Strafverfolgungsbehörden. Außerdem wurden Ermittlungs- und Präventionsmethoden für digitale Disruption aus der Sicherheitsforschung identifiziert; diese werden hinsichtlich Empfehlungen für weitere Forschung diskutiert. Ebenso wird der Einfluss illegaler Aktivitäten als Treiber des Kryptowährungsmarktes diskutiert. Es wird angenommen, dass die illegale Nutzung von Kryptowährungen zwar zahlenmäßig zunimmt, das Volumen im Verhältnis zum gesamten Markt jedoch abnimmt. Allerdings ist der Kenntnisstand über Umfang, Ausmaß und Veränderungsrate in den verschiedenen Deliktsbereichen uneinheitlich, und es besteht noch kein Konsens über ein einheitliches Berechnungsmodell. Der Text schließt mit einer Reihe von Empfehlungen.
The growing acceptance and popularity of cryptocurrencies have boosted the digital financial markets, which have also increased crime risk due to their anonymity and decentralization. Appropriately monitoring decentralized cryptocurrency, particularly Bitcoin, can prevent participants from financial loss and benefit the community. Therefore, in this paper, we build the first Bitcoin address subgraph dataset called BASD-8, which contains 3,830 labeled Bitcoin address subgraphs, and we study the structural characteristics of these subgraphs, aiming at identifying eight common types of Bitcoin addresses to distinguish between normal and abnormal addresses. Three methods are utilized to exploit subgraph patterns: complex network, machine learning, and empirical analysis. Specifically, we calculate ten vital metrics of subgraphs as features to train address classifiers using basic machine learning models. Also, a graph neural network model is trained as a graph-level classifier, and the experimental results with the best f1-score of 91.35% illustrate the effectiveness of our dataset and study methods. Furthermore, we conduct a detailed empirical pattern analysis combining the subgraph structures and the definitions of each category of Bitcoin addresses.
M. Mazhar Rathore, Sushil S. Chaurasia, Dhirendra Shukla
Anonymity is one of major factors that is causing the rise of bitcoin crypto-currency. There are several attacks (positive or negative) to de-anonymize the bitcoin addresses, in order to link the bitcoin entity to a physical entity or person. Bitcoin mixing service (called mixer) is one of the approaches to keep the user’s crpto-anonymity in the transparent ledger of bitcoin network. Mixers breaks the link between the sender and the receiver by mixing up coins received from multiple sources, while creating a mess to make it impossible to identify the actual sender of bitcoins. On the other hand, mixing services are being vastly exploited by criminals for laundering the illegal money, taken from frauds, ransom, scams, or other illegal activities. Detecting mixing services or mixer’s involvement in a transaction can help in discovering money laundering activities in the bitcoin blockchain. Existing mixer’s detection approaches either have a low accuracy-rate due to the changing nature of the mixing process or they are not efficient enough to be implemented in a real-time environment. In this paper, we developed a highly accurate decision-tree based model using C4.5 machine learning approach to identify addresses providing mixing services. To make this detection process efficient and be able to work in a real environment, we reduced overall feature-set to only eight features, minimizing overall computation time. Further, we shrink the decision-tree using reduced error-pruning to make the detection process faster. With the short decision-tree-size of 55 nodes, we achieved the accuracy of more than 97%, which is quite higher.
Mahafuja Khatun, Ridwan Arefin Islam, Salekul Islam
In recent years, blockchain technology has been successfully used in many distributed environments where different stakeholders, who do not have any trust between them, interact with each other through a secured and transparent platform. The use of blockchain in healthcare insurance industry has not been studied methodically. In this study, we develop a blockchain based Secured and Automated Health Insurance Claim (B-SAHIC) processing system. First, we design an Entity-Relationship (ER) diagram identifying all actors with their respective data and relations between them. We also develop the business model and algorithms for all necessary steps. We implement the system in Hyperledger Fabric and deploy a smart contract to implement these algorithms. We introduce CouchDB to store the OffChain data where we store World-State Database. B-SAHIC provides a web-based portal for all actors who interact with the blockchain. Privacy of clients’ claim-related data is ensured by encrypting treatment-related data with a new key that is derived uniquely for each new submission done of clients’ personal documents. We have also deployed Hyperledger Explorer, a user-friendly web application tool for monitoring the health state of each node participating on the blockchain network. We have studied the performance of B-SAHIC for two to six peer nodes. Moreover, our performance study shows that B-SAHIC is fast and scalable. In our study, the average query latency is decreased from 0.07 second (for two peer nodes) to 0.02 second (for six peer nodes) in case of 1300 queries per second while the average transaction latency remains unchanged (around 3.5 seconds) for 300 transactions per second. Moreover, B-SAHIC consumes minimum resources, around 350MB only for two peer nodes. We believe that the development process of this blockchain based platform can be applicable for the automation of other insurance industry too.
Cryptocurrency is the technological development of currency into the digital form which is considered for sustainable development. There are large numbers of investors, who have started investing on cryptocurrency and it is the emerging financial market across the globe. But the cryptocurrency poses various threats to the investor safety and security and it is hazardous to the environmental condition. There is still no consensus on cryptocurrency whether it is a better option to invest or not. Hence this studies to shed light on to the path of investment opinion about cryptocurrency. This paper will give the perspective of the current trends in the crypto market. This concept will be discussed through three steps: the good cryptocurrency and how the financial market has evolved into the digital technology and secondly now it could emerge as a sustainable development in the field of finance. Hence the technology encourages the development of investor and green cryptocurrency. There are various individual issues, related to bad cryptocurrency like money laundering, scam, crypto whale and viruses. Finally, the ugly cryptocurrency in the financial sector affects the environmental condition and how it could affect the ecosystem of the planet due to crypto mining. This study suggested the token offering organization to adopt the proof-of-authority process than the proof-of-work, to avoid carbon emission and more volume of energy consumption. This study also suggests the investor to invest on the green cryptocurrency than the hazardous cryptocurrency (bitcoin), which affects the environmental condition.
Esta tese oferece uma análise dos fundamentos da Decentralized Finance, particularmente das tokens não fungíveis e dos desafios que estas inovações representam para o arcabouço legal da União Europeia contra o branqueamento de capitais e financiamento do terrorismo. Por um lado, a tese irá analisar as mudanças que estas inovações podem trazer ao mercado da arte e à indústria criativa. Por outro lado, centrarse-á nos riscos de crime financeiro que advêm da maior facilidade em ocultar os produtos do crime na blockchain.
With the rapid growth of Blockchain, Bitcoin, a key Blockchain application, has received a lot of attention. Bitcoin trading has made transactions more convenient. However, because of the anonymity, complexity, and lack of third parties, criminal activity against Blockchain Bitcoin applications is frequent. Individuals and society have suffered enormous losses as a result of money laundering, fraud, airdrop, ransom, and other peculiar abnormal transactions. We propose the GRU-GAT based model to detect abnormal transactions in Blockchain and reduce the loss and harm caused by abnormal transactions. Our proposed model employs a bidirectional recurrent neural network to extract the features of Blockchain Bitcoin transactions, graph attention networks for feature weighting, and the spatio-temporal aspects of transactions to integrate the features of Bitcoin transactions for anomaly identification. We conduct experiment through the publicly available elliptic dataset. The results reveal that the suggested method outperforms the comparison model in terms of accuracy and enhances the accuracy of detecting anomalous transactions in Blockchain digital currency.
Nosipho Mthembu, Kazeem Abimbola Sanusi, Joel Hinaunye Eita
The study investigates the effects of stock market volatility and cybercrime on cryptocurrency returns in the South African economy. Daily time series data on four different types of cryptocurrencies (Bitcoin, Ethereum, Tether, and BMB) were employed. The data covers the period from 1 January 2019–31 December 2021. The study employed the dynamic conditional correlation (DCC GARCH) and Bayesian liner regression model to investigate time-varying correlations among the variables. Empirical findings suggest that stock market volatility has a positive impact on the returns of BNB, Bitcoin, and Ethereum. However, it has a negative impact on Tether. Expectedly, cybercrime poses negative impacts on the returns of BNB, Bitcoin, and Ethereum but could be said to have no impact on the returns of Tether. The study concludes that ongoing efforts to reduce cybercrime activities need to be strengthened to further the use of digital currencies.
Zheng Yang, Chao Yin, Junming Ke, Tien Tuan Anh Dinh · 5 authors
Pooled mining has become the most popular mining approach in the Bitcoin system, which can effectively reduce the variance of the block generation reward of participants. The security of pooled mining depends on whether it is incentive compatible, that is, an honest participant will get a reward proportional to his work. Recent attacks on mining pools, for example, Block Withholding, Fork After Withholding, and Power Adjusting Withholding (PAW) attacks, show that malicious participants may undermine the revenue of the honest pools and receive an unfair share of the mining reward. This paper shows that the security of Bitcoin is even worse than what the recent attacks demonstrated. We describe an attack called Fork Withholding Attack under a Protection Racket (FWAP), in which the mining pool pays the attacker for withholding a fork. Our insight is that the mining pools under forking attacks have incentives to pay in exchange for not being forked. The attacker and the paying pool negotiate how much to be paid, and we show that it is possible for both the attacker and the paying pool to earn higher rewards at the expense of the other pools. In particular, our formal analysis and simulation demonstrate that the payer and the FWAP attacker can get up to 1.8 × and 3.8 × of extra reward as in PAW, respectively. Furthermore, FWAP can escape from the “miners’ dilemma’’ when two FWAP attackers attack each other under some circumstances. We also propose simple approaches that serve as the first step towards preventing the FWAP attack.
Abstract Money laundering is one of the most important criminal offences today, perceived in the context of economic operation. Nevertheless, money laundering is a constantly changing phenomenon that is also influenced by the latest technological advancements. In this study, our aim is, after briefly outlining the phenomenon of money laundering, to review the new statutory definition(s) and those assessment criteria that may also be of significance for legal practice in this context from 2021 onwards in Hungary. Subsequently, we will describe the current challenges of cryptocurrencies regarding the new Hungarian and EU legislation on money laundering. The method we use is criminal law-dogmatic and retrospective analysis. The analysis concluded that the Hungarian legislator has significantly broadened the scope of money laundering, and a much wider spread of this offence is predicted for the future.
Open access
Hungarian Social, Economic and Educational Studies
Abstract Summary The COVID-19 pandemic experience has driven us to rely on technology so much on the development and expansion of technology, including cashless transactions. Criminal groups may become more interested in electronic payments and virtual currencies because of increased traffic in these areas. When comparing the second half of the 2019 to the first half of the 2020, the number of fraudulent card transactions increased by 11.4%. New developments in virtual currency trading regulations, including the digital finance package, which includes, among other things, a draught regulation from the European Parliament and an amended act to combat money laundering and terrorist financing, among others. For the reasons stated above, these regulations may lead to a virtual currency market collapse and the withdrawal of investors and the siphoning of money into Asian markets as a result. The current regulations are a manifestation of total regulation and do not encourage technological advancement.
Smart contracts are commonly used to build finance-related decentralized applications. If a smart contract vulnerability is exploited by an attacker, the contract owner may suffer financial losses. We focus on a particular class of smart contract vulnerabilities that require a specific sequence of multiple transactions to trigger, which we call multi-transaction sequence vulnerabilities. Due to the combinatorial explosion problem caused by the huge number of possible transaction sequences, the efficiency and scalability for existing security analyzers to detect multi-transaction sequence vulnerabilities are limited. To alleviate the problem, we propose a vulnerability detection approach based on symbolic execution and inter-path data dependency. In the approach, we first traverse paths in a contract, and record read and write operations of each path. Then, we selectively execute paths which are conducive to discovering vulnerabilities during the subsequent detection process according to inter-path data dependencies. By pruning out most paths that are not relevant to vulnerabilities, we improve the efficiency and scalability of detecting multi-transaction sequence vulnerabilities. We evaluate our approach on 442 contracts collected from CVE reports and 104 contracts with Ether leakage and suicide defects. The experimental results show that our approach reaches an average 2x speedup comparing to Mythril.
Exchanges serve an essential role in the cryptocurrency ecosystem. It is through exchanges that most people acquire Bitcoin and other cryptocurrencies, often avoiding the blockchain entirely. Because so many customers put their trust and financial resources in exchanges, it is no surprise that they have long been targets of cybercriminal actors. This paper examines 822 cryptocurrency exchanges operational from 2010–2022. We find that 40% of these exchanges subsequently shut down. Using regression and survival analysis, we investigate the factors that could precipitate the closure of exchanges. Consistent with prior work, we find some evidence that experiencing security breaches are associated with closure. However, we find that the strongest effects are connected to how the exchange operates. Exchanges that only trade cryptocurrencies and not fiat face approximately 60% greater odds of shutting down than those that trade both. Trading more coins is negatively associated with failure. Meanwhile, exchanges that permit US customers shut down more quickly, which suggests that the regulatory environment may affect exchange lifetimes.
Ian W. Gray, Jack Cable, Benjamin P. Brown, Vlad Cuiujuclu · 5 authors
Ransomware operations have evolved from relatively unsophisticated threat actors into highly coordinated cybercrime syndicates that regularly extort millions of dollars in a single attack. Despite dominating headlines and crippling businesses across the globe, there is relatively little in-depth research into the modern structure and economics of ransomware operations.In this paper, we leverage leaked chat messages to provide an in-depth empirical analysis of Conti, one of the largest ransomware groups. By analyzing these chat messages, we construct a picture of Conti’s operations as a highly-profitable business, from profit structures to employee recruitment and roles. We present novel methodologies to trace ransom payments, identifying over $80 million in likely ransom payments to Conti and its predecessor – over five times as much as in previous public datasets. As part of our work, we will publish a dataset of 666 labeled Bitcoin addresses related to Conti and an additional 75 Bitcoin addresses of likely ransom payments. Future work can leverage this case study to more effectively trace – and ultimately counteract – ransomware activity.
Purpose Money laundering is the process of concealing unlawfully obtained funds by presenting them as coming from a legitimate source. Criminals use crypto money laundering to hide the illicit origin of funds using a variety of methods. The most simplified form of bitcoin money laundering leans hard on the fact that transactions made in cryptocurrencies are pseudonymous, but open data gives more power to investigators and enables the crowdsourcing of forensic analysis. With the motive to curb these illegal activities, there exist various rules, policies and technologies collectively known as anti-money laundering (AML) tools. When properly implemented, AML restrictions reduce the negative effects of illegal economic activity while also promoting financial market integrity and stability, but these bear high costs for institutions. The purpose of this work is to motivate the opportunity to reconcile the cause of safety with that of financial inclusion, bearing in mind the limitations of the available data. The authors use the Elliptic dataset; to the best of the authors' knowledge, this is the largest labelled transaction dataset publicly available in any cryptocurrency. Design/methodology/approach AML in bitcoin can be modelled as a node classification task in dynamic networks. In this work, graph convolutional decision forest will be introduced, which combines the potentialities of evolving graph convolutional network and deep neural decision forest (DNDF). This model will be used to classify the unknown transactions in the Elliptic dataset. Additionally, the application of knowledge distillation (KD) over the proposed approach gives finest results compared to all the other experimented techniques. Findings The importance of utilising a concatenation between dynamic graph learning and ensemble feature learning is demonstrated in this work. The results show the superiority of the proposed model to classify the illicit transactions in the Elliptic dataset. Experiments also show that the results can be further improved when the system is fine-tuned using a KD framework. Originality/value Existing works used either ensemble learning or dynamic graph learning to tackle the problem of AML in bitcoin. The proposed model provides a novel view to combine the power of random forest with dynamic graph learning methods. Furthermore, the work also demonstrates the advantage of KD in improving the performance of the whole system.
Bitcoin is one of the decentralized cryptocurrencies powered by a peer-to-peer blockchain network. Parties who trade in the bitcoin network are not required to disclose any personal information. Such property of anonymity, however, precipitates potential malicious transactions to a certain extent. Indeed, various illegal activities such as money laundering, dark network trading, and gambling in the bitcoin network are nothing new now. While a proliferation of work has been developed to identify malicious bitcoin transactions, the behavior analysis and classification of bitcoin addresses are largely overlooked by existing tools. In this paper, we propose BAClassifier, a tool that can automatically classify bitcoin addresses based on their behaviors. Technically, we come up with the following three key designs. First, we consider casting the transactions of the bitcoin address into an address graph structure, of which we introduce a graph node compression technique and a graph structure augmentation method to characterize a unified graph representation. Furthermore, we leverage a graph feature network to learn the graph representations of each address and generate the graph embeddings. Finally, we aggregate all graph embeddings of an address into the address-level representation, and engage in a classification model to give the address behavior classification. As a side contribution, we construct and release a large-scale annotated dataset that consists of over 2 million real-world bitcoin addresses and concerns 4 types of address behaviors. Experimental results demonstrate that our proposed framework outperforms state-of-the-art bitcoin address classifiers and existing classification models, where the precision and F1-score are 96% and 95%, respectively. Our implementation and dataset are released, hoping to inspire others.
Advances in technology, easy access to the internet, inconsistent rules and regulations, inadequate police training on cybercrime, and the complexity of international or multiorganizational collaboration in police operations have created new forms of cybercrime. Illegal cryptomarkets/darknet marketplaces transactions on the hidden web use cryptocurrency as a payment method, which makes it difficult to trace the identity of sellers and buyers. The internet and Dark Web browsers have also provided tools for criminals to conduct cyberattacks on businesses, infrastructure, education, health care, government, and even individual citizens with little impunity. The cross-border nature of cybercrimes, lack of uniformity in regulations, difficulties in collecting digital evidence, and identifying the physical location of the perpetrators have proven to be challenging tasks for police. Lack of public awareness of police jurisdiction of cybercrimes and limited police training on cyber technology and digital evidence gathering are some critical gaps identified in this chapter.
Mariam Alnaqbi, Mariam Mohamed Al-Ali, Mahra Alremeithi, Maryam Yaqoub Al Ali · 5 authors
The emergence of Bitcoin has continued to grow both in value and fame, as it was introduced as the first decentralized cryptocurrency. Many studies have shown that criminals are exploiting bitcoin by using it to launder their money, which originates from illegal activities or cybercrime. This paper aims at providing a comparison of detection techniques for preventing money laundering in bitcoin through various methods including graph theory, prevention of mixing services, and machine learning techniques including Random Forest, Shallow Neural Networks, optimizable Decision Trees, Bagging, Boosting algorithms, and Ensemble learning combining Random Forest, Bagging and Extra Tree.
Stručni konsultant rane biznis faze (startap faze) u IT industriji, Ivan Ivljanin
What led to the meteoric growth and popularity of cryptocurrencies, primarily Bitcoin? What concepts preceded the development of modern cryptocurrencies? What is blockchain and what is the architecture of different distributed public ledgers? What is the use value of digital money in everyday transactions and what is the use value in international trade exchange? This paper tries to answer the above questions and decipher the highly complex technical jargon that usually accompanies the topic of digital money.
With the popularity of cryptocurrencies and the remarkable development of blockchain technology, decentralized applications emerged as a revolutionary force for the Internet. Meanwhile, decentralized applications have also attracted intense attention from the online gambling community, with more and more decentralized gambling platforms created through the help of smart contracts. Compared with conventional gambling platforms, decentralized gambling have transparent rules and a low participation threshold, attracting a substantial number of gamblers. In order to discover gambling behaviors and identify the contracts and addresses involved in gambling, we propose a tool termed ETHGamDet. The tool is able to automatically detect the smart contracts and addresses involved in gambling by scrutinizing the smart contract code and address transaction records. Interestingly, we present a novel LightGBM model with memory components, which possesses the ability to learn from its own misclassifications. As a side contribution, we construct and release a large-scale gambling dataset at https://github.com/AwesomeHuang/Bitcoin-Gambling-Dataset to facilitate future research in this field. Empirically, ETHGamDet achieves a F1-score of 0.72 and 0.89 in address classification and contract classification respectively, and offers novel and interesting insights.
Gibran Gómez, Pedro Moreno-Sánchez, Juan Caballero
Cybercriminals often leverage Bitcoin for their illicit activities. In this work, we propose back-and-forth exploration, a novel automated Bitcoin transaction tracing technique to identify cybercrime financial relationships. Given seed addresses belonging to a cybercrime campaign, it outputs a transaction graph, and identifies paths corresponding to relationships between the campaign under study and external services and other cybercrime campaigns. Back-and-forth exploration provides two key contributions. First, it explores both forward and backwards, instead of only forward as done by prior work, enabling the discovery of relationships that cannot be found by only exploring forward (e.g., deposits from clients of a mixer). Second, it prevents graph explosion by combining a tagging database with a machine learning classifier for identifying addresses belonging to exchanges.