Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

1,615 papersLast indexed Aug 31, 2026
Search papers

Paper index

1,615 results ¡ page 28 of 68

Clear filters
Oct 7, 2023¡International Journal on Cybernetics & Informatics
0 cites
A Proposal for an Open-Source Bitcoin Forensics Tool

Pedro Henrique Resende Ribeiro, Pedro Leale, Ivan da Silva Sendin

Over recent decades, the global financial paradigm has experienced significant transformations, notably the emergence and adoption of cryptocurrencies. The escalating prominence of assets like Bitcoin has inadvertently catalysed a surge in illicit activities associated with the currency. Consequently, the forensic examination of transactions within blockchains becomes imperative for the detection and surveillance of malevolent undertakings. This research delineates a preliminary pipeline for a Bitcoin forensic analysis tool. Moving forward, the ambition is to conceptualize and empirically validate this tool utilizing data procured from blockchain and ancillary sources. The methodology will harness Open-Source Intelligence (OSINT), clustering of Bitcoin addresses, and an exhaustive financial analysis. Upon finalizing the pipeline, the implementation of an open-source instrument is envisioned, poised to confer substantial advantages to the broader cryptocurrency milieu.

Open access
Blockchain Technology Applications and Security
Crime, Illicit Activities, and Governance
Cybercrime and Law Enforcement Studies
Original source
Oct 6, 2023¡2023 4th IEEE Global Conference for Advancement in Technology (GCAT)
4 cites
An Evidence Collection Using Blockchain for Cybercrime Detection

Vinod Balmiki

Inspections into cybercrime rely heavily on the use of digital evidence because of its ability to connect individuals to specific illegal activity. During a probe into a computer crime, it is essential that the integrity, authenticity, and auditability of digital evidence be maintained at all times when it is being transferred through the chain of custody from the beginning to the finish. The digitalization of banking is paralleled by an equally digitalization of the environment for financial crime. Because laws, rules, and forensic techniques are unable to keep up with the fast development of new technologies, investigations into embezzlement schemes might benefit from the standardization of processes and recording of the related approach. The applicability and adaptability of our method may be extended to include a wide variety of fraud investigations as well as routine internal audits. We offer a working Ethereum-based solution, and we incorporate standardised forensic processes and chain of custody preservation techniques. In conclusion, we investigate the challenges surrounding the mutually beneficial link between blockchain technology and financial investigations, as well as the managerial effect and potential avenues for further study. r wicked actors. In this sense, the characteristics afforded by blockchain technology, such as immutability, verifiability, and authentication, contribute to an increase in the degree of rigor that may be achieved in financial forensics. In this article, we describe not only the current status of blockchain-based digital forensic procedures but also a taxonomy of the most popular methodologies used in financial investigations. Our solution makes it possible for consumers to trace the history of their data by making use of smart contracts (CS). In conclusion, the development of an Artificial Neural Network (ANN) for blockchain makes the collection of evidence more easier. Java, which is used for clouds and blockchains, and network simulator-3.26, which is used for software-defined networking (SDN), are both used inside a single testing environment. Response time, Evidence input time, Evidence verification time, All aspects of the suggested forensic architecture, including communication overhead, hash calculation time, key generation time, encryption time, decryption time, and overall change rate, show potential.

Anomaly Detection Techniques and Applications
Cybercrime and Law Enforcement Studies
Digital Media Forensic Detection
Original source
Oct 6, 2023¡Journal of Cybersecurity
14 cites
Mapping the DeFi crime landscape: an evidence-based picture

Catherine Carpentier-Desjardins, Masarah Paquet-Clouston, Stefan Kitzler, Bernhard Haslhofer

*PLEASE REFER TO THE SECOND VERSION UPLOADED IN JANUARY 2025. THIS VERSION CONTAINS A FEW DUPLICATES. VERSION 2 IS AVAILABLE FOR DOWNLOAD HERE: https://zenodo.org/records/14706760 README - Crime Events Dataset This document provides a detailed overview of the structure of the dataset for the paper: "Mapping the DeFi crime landscape: An Evidence-based Picture". The following fields are included, each representing different aspects of the events collected. Data Fields 1. unique_key Description: A unique number assigned to identify each event in the dataset. 2. Agregators Description: The sources where the event is listed. Aggregators include: - De.Fi REKT - SlowMist - CryptoSec (rebranded to ChainSec as of February 2023) 3. DeFi actor involved Description: The name of the DeFi actor involved in the event (target, perpetrator, or intermediary). Sources: - On De.Fi REKT: Found as the "Title" of the event’s listing. - On SlowMist: Found under the “Hacked target” title. - On CryptoSec: Found in the "Title" of the event’s listing with the date. 4. REKT URL Description: The URL to the event's listing on De.Fi REKT. Process: Found by searching for the DeFi actor involved in the REKT Database: https://de.fi/rekt-database 5. SlowMist URL Description: The URL to the event's listing on SlowMist. Process: Available via https://hacked.slowmist.io/search/. Note that searching the actor's name will lead to the event but without an individualized URL. 6. CryptoSec URL Description: The URL to the event's listing on CryptoSec. Process: Found at https://chainsec.io/defi-hacks/. Events are listed on a single page; use traditional keyboard search to locate specific events. 7. Aggregator Summary Description: A summary of the event provided by the aggregator. Sources: - On De.Fi REKT: Found under "Quick Summary" and "Details of the Exploit". - On SlowMist: Under "Description of the event". - On CryptoSec: Below the title in quotation marks. 8. Aggregator sources URL Description: The URLs of references linked by the aggregator in the event’s listing. Sources: - On De.Fi REKT: Found at the bottom by clicking "Source" or "Archived link". - On SlowMist: Found by clicking "View Reference Sources". - On CryptoSec: Available by clicking the source’s name at the end of the summary. 9. Event date Description: The date the event occurred. Sources: - On De.Fi REKT: Listed under the "Date" field. - On SlowMist: At the top right of the listing. - On CryptoSec: Listed in parentheses behind the actor’s name. 10. Event year Description: The year the event occurred, extracted from the Event date. 11. Stolen amount USD Description: The total amount stolen, converted to USD. Sources: - On De.Fi REKT: Found under "Funds lost". - On SlowMist: Under the title “Amount of loss”. - On CryptoSec: Behind the title "Amount stolen". Note: If needed, conversions were manually performed using CoinMarketCap’s historical data as explained in the paper. 12. Implication of actor Description: Indicates whether the DeFi actor was a target, perpetrator, or intermediary in the event. Manually coded after reviewing the aggregator’s summary and linked sources. 13. Strategy Description: The main approach used to steal funds. Six categories are possible: Technical vulnerability, Human risks, Undetermined, Malicious use of contract, Misappropriation of funds, and Imitation. This was manually coded from the event summary and sources. 14. General tactic Description: The common techniques or methods used by malicious actors. Eleven categories are possible, defined in the appendix. Manually coded after reviewing the summary and linked sources. 15. Specific tactic Description: The precise technique used to commit the crime. Thirty-seven categories are possible, defined in the appendix. This was manually coded based on the event summary and sources. 16. Paper category Description: The main area of operation of the involved DeFi actor. Twelve categories are possible: Blockchain, Bridge, DApp, Derivatives, Exchange, Fungible Token (FT), Non-Fungible Token (NFT), Oracle, Yield, Staking, and Others. This was determined by the event summary and research on the actor. 17. Stack category Description: The technical layer of the DeFi Stack Reference (DSR) model corresponding to the paper category. Five categories are possible: DeFi Compositions (CP), DeFi Protocols (P), Cryptoassets (CA), Distributed Ledger Technology (DLT), and Interfaces (INT). --- For more detailed information on the tactics, strategies, or categories used, please refer to the appendix of the dataset or the associated documentation.

Open access
3 source records
Blockchain Technology Applications and Security
Crime, Illicit Activities, and Governance
Cybercrime and Law Enforcement Studies
Original source
Oct 6, 2023¡Cybersecurity
2 cites
Aparecium: understanding and detecting scam behaviors on Ethereum via biased random walk

Chuyi Yan, Chen Zhang, Meng Shen, Ning Li ¡ 8 authors

Abstract Ethereum’s high attention, rich business, certain anonymity, and untraceability have attracted a group of attackers. Cybercrime on it has become increasingly rampant, among which scam behavior is convenient, cryptic, antagonistic and resulting in large economic losses. So we consider the scam behavior on Ethereum and investigate it at the node interaction level. Based on the life cycle and risk identification points we found, we propose an automatic detection model named Aparecium . First, a graph generation method which focus on the scam life cycle is adopted to mitigate the sparsity of the scam behaviors. Second, the life cycle patterns are delicate modeled because of the crypticity and antagonism of Ethereum scam behaviors. Conducting experiments in the wild Ethereum datasets, we prove Aparecium is effective which the precision, recall and F1-score achieve at 0.977, 0.957 and 0.967 respectively.

Open access
Network Security and Intrusion Detection
Cybercrime and Law Enforcement Studies
Spam and Phishing Detection
Original source
Oct 5, 2023¡2023 International Conference Automatics and Informatics (ICAI)
1 cites
An Evaluation of Web3 Concepts and Technologies and Relation with Digital Forensics

Blerim Krasniqi, Eliza Stefanova

The World is experiencing a significant shift in how technology is being used and how new strategies are being developed to streamline and get around bureaucratic processes. Cannot continue without mentioning blockchain as a revolutionary decentralization concept that also serves as a foundational notion for Web 3. One must admit that this is a struggle we are going through and that will continue into this new period as we add more approaches and technologies. In this study, the Web3 principles (like decentralization, trust and security, privacy and data protection), methodologies, and technologies are evaluated, along with their connections to digital forensics. Various viewpoints emphasizing the difficulties and current condition of these issues are offered. Authors discuss their viewpoints while highlighting their extensive background in digital forensics, keeping in mind that digital forensics is a relatively new profession. Based on their viewpoint's conclusions are being set. This work is currently being done by the authors as part of their research in the field of digital forensics and Web3.

Digital and Cyber Forensics
Cybercrime and Law Enforcement Studies
Advanced Malware Detection Techniques
Original source
Oct 2, 2023¡2023 IEEE International Conference on Intelligence and Security Informatics (ISI)
5 cites
Disrupting Ransomware Actors on the Bitcoin Blockchain: A Graph Embedding Approach

Benjamin Ampel, Kaeli Otto, Sagar Samtani, Hsinchun Chen

Ransomware is a growing problem and significant threat to cybersecurity in the United States. One primary vector for ransomware payments is the Bitcoin network. Network science techniques are a potential approach to analyze ransomware payment networks to discover salient ransomware actors. In this study, we propose a design framework for labeling nodes in a ransomware payment network and identifying key ransomware Bitcoin addresses that can be targeted for disruption. By leveraging semi-supervised graph embedding methodology and updating the loss function of a prevailing algorithm, GraphSAGE, to manage dataset imbalance, we identify key wallets in our ransomware network. We demonstrate the utility of our approach with a case study identifying a Bitcoin wallet that has been reported as a ransomware actor as recently as December 2021 and has transferred over $450 million in Bitcoin.

Advanced Malware Detection Techniques
Cybercrime and Law Enforcement Studies
Network Security and Intrusion Detection
Original source
Oct 2, 2023¡arXiv (Cornell University)
1 cites
Multi-triplet Feature Augmentation for Ponzi Scheme Detection in Ethereum

Chengxiang Jin, Jiajun Zhou, Shengbo Gong, Chenxuan Xie ¡ 5 authors

Blockchain technology revolutionizes the Internet, but also poses increasing risks, particularly in cryptocurrency finance. On the Ethereum platform, Ponzi schemes, phishing scams, and a variety of other frauds emerge. Existing Ponzi scheme detection approaches based on heterogeneous transaction graph modeling leverages semantic information between node (account) pairs to establish connections, overlooking the semantic attributes inherent to the edges (interactions). To overcome this, we construct heterogeneous Ethereum interaction graphs with multiple triplet interaction patterns to better depict the real Ethereum environment. Based on this, we design a new framework named multi-triplet augmented heterogeneous graph neural network (MAHGNN) for Ponzi scheme detection. We introduce the Conditional Variational Auto Encoder (CVAE) to capture the semantic information of different triplet interaction patterns, which facilitates the characterization on account features. Extensive experiments demonstrate that MAHGNN is capable of addressing the problem of multi-edge interactions in heterogeneous Ethereum interaction graphs and achieving state-of-the-art performance in Ponzi scheme detection.

Open access
3 source records
Spam and Phishing Detection
Network Security and Intrusion Detection
Misinformation and Its Impacts
Original source
Oct 2, 2023¡arXiv (Cornell University)
4 cites
Unmasking Role-Play Attack Strategies in Exploiting Decentralized Finance (DeFi) Systems

W. D. Li, Zhun Wang, Chenyu Li, H. F. Chen ¡ 8 authors

The rapid growth and adoption of decentralized finance (DeFi) systems have been accompanied by various threats, notably those emerging from vulnerabilities in their intricate design. In our work, we introduce and define an attack strategy termed as Role-Play Attack, in which the attacker acts as multiple roles concurrently to exploit the DeFi system and cause substantial financial losses. We provide a formal definition of this strategy and demonstrate its potential impacts by revealing the total loss of \$435.1M caused by 14 historical attacks with applying this pattern. Besides, we mathematically analyzed the attacks with top 2 losses and retrofitted the corresponding attack pattern by concrete execution, indicating that this strategy could increase the potential profit for original attacks by \$3.34M (51.4%) and \$3.76M (12.0%), respectively.

Open access
3 source records
Blockchain Technology Applications and Security
Crime, Illicit Activities, and Governance
Cybercrime and Law Enforcement Studies
Original source
Oct 2, 2023¡arXiv (Cornell University)
73 cites
Large Language Model-Powered Smart Contract Vulnerability Detection: New Perspectives

Sihao Hu, Tiansheng Huang, Fatih İlhan, Selim Furkan Tekin ¡ 5 authors

This paper provides a systematic analysis of the opportunities, challenges, and potential solutions of harnessing Large Language Models (LLMs) such as GPT-4 to dig out vulnerabilities within smart contracts based on our ongoing research. For the task of smart contract vulnerability detection, achieving practical usability hinges on identifying as many true vulnerabilities as possible while minimizing the number of false positives. Nonetheless, our empirical study reveals contradictory yet interesting findings: generating more answers with higher randomness largely boosts the likelihood of producing a correct answer but inevitably leads to a higher number of false positives. To mitigate this tension, we propose an adversarial framework dubbed GPTLens that breaks the conventional one-stage detection into two synergistic stages $-$ generation and discrimination, for progressive detection and refinement, wherein the LLM plays dual roles, i.e., auditor and critic, respectively. The goal of auditor is to yield a broad spectrum of vulnerabilities with the hope of encompassing the correct answer, whereas the goal of critic that evaluates the validity of identified vulnerabilities is to minimize the number of false positives. Experimental results and illustrative examples demonstrate that auditor and critic work together harmoniously to yield pronounced improvements over the conventional one-stage detection. GPTLens is intuitive, strategic, and entirely LLM-driven without relying on specialist expertise in smart contracts, showcasing its methodical generality and potential to detect a broad spectrum of vulnerabilities. Our code is available at: https://github.com/git-disl/GPTLens.

Open access
4 source records
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Artificial Intelligence in Law
Original source
Sep 29, 2023¡2023 IEEE 2nd International Conference on Industrial Electronics: Developments & Applications (ICIDeA)
5 cites
Blockchain Security and Challenges: A Review

Pawan Golait, Deepak Singh Tomar, R. K. Pateriya, Yogesh Kumar Sharma

Blockchain technology has emerged as a ground-breaking innovation with the potential to revolutionize various industries and transform transactions. Its decentralized platform allows for storing and trading digital assets without intermediaries. Robust security features such as immutability and cryptographic security deter data tampering or fraudulent activities through unique key codes. However, for successful widespread implementation across all industries, stakeholders must thoroughly understand its vulnerabilities. They need to consider specific security issues carefully and propose suitable solutions to enhance network protection. This review paper aims to critically examine the security aspects and challenges surrounding blockchain technology. By synthesizing existing literature and research findings, it offers comprehensive analysis insights into the inherent security concerns in blockchain implementations. Researchers can benefit from this consolidated resource by enriching their understanding of blockchain security, identifying knowledge gaps, and contributing to further advancements in the field. Additionally, practitioners and industry professionals can leverage the findings presented in this paper to gain a deeper comprehension of potential risks and vulnerabilities associated with blockchain technology. This empowers them to develop robust security strategies effectively mitigate threats.

Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Original source
Sep 27, 2023¡2023 6th World Symposium on Communication Engineering (WSCE)
8 cites
A Comparative Analysis of Ethereum Solidity and Sui Move Smart Contract Languages: Advantages and Trade-Offs

Antonios Giatzis, Christos K. Georgiadis, Γεώργιος Δίγκας

This article offers an extensive comparison between Ethereum Solidity and Sui Move, two prominent smart contract languages. As blockchain technology gains momentum, choosing the right smart contract language becomes paramount for building resilient decentralized applications. The study delves into the unique features, strengths, and limitations of both languages, assisting developers in making well-informed decisions. Ethereum Solidity, widely adopted due to its versatility, has been integrated into numerous blockchain projects. Conversely, Move, introduced by the Libra blockchain, prioritizes security and safety through a distinct approach, advantages that the Sui network has incorporated into the Sui Move language. The analysis covers various key elements of each language while at the same time, examines their support for overall security mechanisms, formal verification, and ease of use. By providing an evaluation of Ethereum Solidity and Sui Move, the article aims to empower developers with valuable insights during the process of creating robust and secure decentralized applications.

Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
FinTech, Crowdfunding, Digital Finance
Original source
Sep 26, 2023¡ACM Transactions on Knowledge Discovery from Data
3 cites
From Asset Flow to Status, Action and Intention Discovery: Early Malice Detection in Cryptocurrency

Ling Cheng, Feida Zhu, Yong Wang, Ruicheng Liang ¡ 5 authors

Cryptocurrency has been subject to illicit activities probably more often than traditional financial assets due to the pseudo-anonymous nature of its transacting entities. An ideal detection model is expected to achieve all three critical properties of (I) early detection, (II) good interpretability, and (III) versatility for various illicit activities. However, existing solutions cannot meet all these requirements, as most of them heavily rely on deep learning without interpretability and are only available for retrospective analysis of a specific illicit type. To tackle all these challenges, we propose Intention-Monitor for early malice detection in Bitcoin (BTC), where the on-chain record data for a certain address are much scarcer than other cryptocurrency platforms. We first define asset transfer paths with the Decision-Tree based feature Selection and Complement (DT-SC) to build different feature sets for different malice types. Then, the Status/Action Proposal Module (S/A-PM) and the Intention-VAE module generate the status, action, intent-snippet, and hidden intent-snippet embedding. With all these modules, our model is highly interpretable and can detect various illegal activities. Moreover, well-designed loss functions further enhance the prediction speed and model's interpretability. Extensive experiments on three real-world datasets demonstrate that our proposed algorithm outperforms the state-of-the-art methods. Furthermore, additional case studies justify our model can not only explain existing illicit patterns but can also find new suspicious characters.

Open access
3 source records
cs.LG
cs.AI
Blockchain Technology Applications and Security
Original source
Sep 22, 2023¡International Journal of Advances in Engineering and Pure Sciences
1 cites
Investigation of Cryptocurrency-Centered Money Laundering Scenarios in terms of Digital Forensics

Duzgun Kucuk, Emre ÇAKAR, Ömer Faruk Yakut, Fatih Ertam

One of the biggest innovations brought by the digitalized world is undoubtedly the invention of crypto money, which is decentralized, anonymous and complex, and connected to blockchain technology. This relatively new technology has attracted the attention of many people with its revolutionary changes in payment systems and great price movements in the market, as well as the economic balances it has changed around the world. In addition to this interest, it also attracted the attention of crime and crime organizations in a short time, and over time it turned into a tool used by illegal organizations such as laundering the proceeds of crime. Although this structure was initially exposed to the reaction of some states at the level of nation states, on the other hand, it managed to get the support of many states. However, although the spread of blockchain-based money laundering methods is an undeniable problem for all states, a significant cooperation has not been achieved by international collaborations and organizations to prevent this situation. On the other hand, it is of great importance for law enforcement and forensic analysts to clarify this situation and to fight against these structures in order to protect national interests. In this study; In this study, an approach that will detect money laundering is tried to be presented through sample scenarios by bringing a broad perspective to crypto money-based money laundering methods, which are very difficult to trace due to their nature. In addition, it is expected that the difficulties in implementation of the proposed approach will be clearly addressed and will shed light and inspire further study.

Open access
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Crime, Illicit Activities, and Governance
Original source
Sep 18, 2023¡2023 Eighth International Conference on Fog and Mobile Edge Computing (FMEC)
0 cites
Modelling And Simulation For Detecting Vulnerabilities And Security Threats Of Smart Contracts Using Machine Learning

Ala Mughaid, Ibrahim Obeidat, Andaleeb Shdaifat, Razan Alhayjna ¡ 5 authors

Recently, the use and development of a blockchain systems such as Ethereum has increased rapidly, and many systems have relied on a third party as an intermediary between the sender and the receiver. Despite the attempts of developers to protect smart contracts, smart contracts contain many vulner-abilities that hackers resort to exploiting and using due to the attack that caused many financial and economic losses, and with the increase of errors in smart contracts, there are many tools and methods. For the analysis of smart contracts, machine learning models have appeared that facilitate their discovery instead of extracting them manually. In this paper, We have built a model that attempts to cancel the third party and we used machine learning to identify valid and invalid smart contracts. We have used several models and compared them with previous results of previous work in the same field. The result of this research was as expected of height accuracy achieved with approximately.99%.

Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Original source
Sep 17, 2023¡arXiv (Cornell University)
0 cites
How NFT Collectors Experience Online NFT Communities: A Case Study of Bored Ape

Allison Sinnott, Kyrie Zhixuan Zhou

Non-fungible tokens (NFTs) are unique cryptographic assets representing the ownership of digital media. NFTs have soared in popularity and trading prices. However, there exists a large gap in the literature regarding NFTs, especially regarding the stakeholders and online communities that have formed around NFT projects. Bored Ape Yacht Club (BAYC) is one of the most influential NFT projects. Through an observational study of online BAYC communities across social media platforms and semi-structured interviews with four participants who owned BAYC NFTs, we explored the experiences of NFT collectors within the online NFT community. Positive community experiences, i.e., personal expression and identity, mutual support among BAYC holders, and exclusive access to online and offline events, were expressed. Encountered challenges included scams and "cash grab" NFT projects as well as trolling. The results of this study point towards the welcoming, positive nature of the NFT community, which is a possible causation factor of the initial rise in popularity of NFTs. Demotivators, on the other hand, countered the established trustworthiness of NFT technology among its consumers.

Open access
2 source records
cs.HC
cs.CR
cs.CY
Original source
Sep 15, 2023¡International Journal of Information Security
30 cites
Vulnsense: efficient vulnerability detection in ethereum smart contracts by multimodal learning with graph neural network and language model

Phan The Duy, Nghi Hoang Khoa, Nguyen Huu Quyen, Le Cong Trinh ¡ 7 authors

This paper presents VulnSense framework, a comprehensive approach to efficiently detect vulnerabilities in Ethereum smart contracts using a multimodal learning approach on graph-based and natural language processing (NLP) models. Our proposed framework combines three types of features from smart contracts comprising source code, opcode sequences, and control flow graph (CFG) extracted from bytecode. We employ Bidirectional Encoder Representations from Transformers (BERT), Bidirectional Long Short-Term Memory (BiLSTM) and Graph Neural Network (GNN) models to extract and analyze these features. The final layer of our multimodal approach consists of a fully connected layer used to predict vulnerabilities in Ethereum smart contracts. Addressing limitations of existing vulnerability detection methods relying on single-feature or single-model deep learning techniques, our method surpasses accuracy and effectiveness constraints. We assess VulnSense using a collection of 1.769 smart contracts derived from the combination of three datasets: Curated, SolidiFI-Benchmark, and Smartbugs Wild. We then make a comparison with various unimodal and multimodal learning techniques contributed by GNN, BiLSTM and BERT architectures. The experimental outcomes demonstrate the superior performance of our proposed approach, achieving an average accuracy of 77.96\% across all three categories of vulnerable smart contracts.

Open access
4 source records
Blockchain Technology Applications and Security
Crime, Illicit Activities, and Governance
Cybercrime and Law Enforcement Studies
Original source
Sep 11, 2023¡2023 38th IEEE/ACM International Conference on Automated Software Engineering (ASE)
20 cites
DeFiWarder: Protecting DeFi Apps from Token Leaking Vulnerabilities

Jianzhong Su, Xingwei Lin, Zhiyuan Fang, Zhirong Zhu ¡ 8 authors

Decentralized Finance (DeFi) apps have rapidly proliferated with the development of blockchain and smart contracts, whose maximum total value locked (TVL) has exceeded 100 billion dollars in the past few years. These apps allow users to interact and perform complicated financial activities. However, the vulnerabilities hiding in the smart contracts of DeFi apps have resulted in numerous security incidents, with most of them leading to funds (tokens) leaking and resulting in severe financial loss. In this paper, we summarize Token Leaking vulnerability of DeFi apps, which enable someone to abnormally withdraw funds that far exceed their deposits. Due to the massive amount of funds in DeFi apps, it is crucial to protect DeFi apps from Token Leaking vulnerabilities. Unfortunately, existing tools have limitations in addressing this vulnerability. To address this issue, we propose DeFiWarder, a tool that traces on-chain transactions and protects DeFi apps from Token Leaking vulnerabilities. Specifically, DeFiWarder first records the execution logs (traces) of smart contracts. It then accurately recovers token transfers within transactions to catch the funds flow between users and DeFi apps, as well as the relations between users based on role mining. Finally, DeFiWarder utilizes anomaly detection to reveal Token Leaking vulnerabilities and related attack behaviors. We conducted experiments to demonstrate the effectiveness and efficiency of DeFiWarder. Specifically, DeFi-Warder successfully revealed 25 Token Leaking vulnerabilities from 30 Defi apps. Moreover, its efficiency supports real-time detection of token leaking within on-chain transactions. In addition, we summarize five major reasons for Token Leaking vulnerability to assist DeFi apps in protecting their funds.

Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Crime, Illicit Activities, and Governance
Original source
Sep 8, 2023¡Healthcare
18 cites
Blockchain Revolutionizing in Emergency Medicine: A Scoping Review of Patient Journey through the ED

Tzu-Chi Wu, Chien‐Ta Bruce Ho

BACKGROUND: Blockchain technology has revolutionized the healthcare sector, including emergency medicine, by integrating AI, machine learning, and big data, thereby transforming traditional healthcare practices. The increasing utilization and accumulation of personal health data also raises concerns about security and privacy, particularly within emergency medical settings. METHOD: Our review focused on articles published in databases such as Web of Science, PubMed, and Medline, discussing the revolutionary impact of blockchain technology within the context of the patient journey through the ED. RESULTS: A total of 33 publications met our inclusion criteria. The findings emphasize that blockchain technology primarily finds its applications in data sharing and documentation. The pre-hospital and post-discharge applications stand out as distinctive features compared to other disciplines. Among various platforms, Ethereum and Hyperledger Fabric emerge as the most frequently utilized options, while Proof of Work (PoW) and Proof of Authority (PoA) stand out as the most commonly employed consensus algorithms in this emergency care domain. The ED journey map and two scenarios are presented, exemplifying the most distinctive applications of emergency medicine, and illustrating the potential of blockchain. Challenges such as interoperability, scalability, security, access control, and cost could potentially arise in emergency medical contexts, depending on the specific scenarios. CONCLUSION: Our study examines the ongoing research on blockchain technology, highlighting its current influence and potential future advancements in optimizing emergency medical services. This approach empowers frontline medical professionals to validate their practices and recognize the transformative potential of blockchain in emergency medical care, ultimately benefiting both patients and healthcare providers.

Open access
Blockchain Technology Applications and Security
Organizational and Employee Performance
Cybercrime and Law Enforcement Studies
Original source
Sep 8, 2023¡2023 International Conference on Intelligent Management and Software Engineering (IMSE)
2 cites
Smart Contract Vulnerability Detection Based on TextCNN and Attention Mechanism

Yang Zhou, Chuangming Zhou, Qian Xiang, Wei Huang ¡ 5 authors

To address the problems of low detection accuracy of traditional smart contract vulnerability detection schemes and single vulnerability type detection of deep learning-based schemes, this paper proposes a smart contract vulnerability detection scheme based on TextCNN and attention mechanism. Firstly, word embedding is used to obtain the word vector representation of operation codes, and then the word vectors are input into TextCNN to extract sequential features. An attention mechanism is used to assign different weights to different features to highlight key features. Finally, normalization processing is carried out through activation functions to implement detection and recognition of smart contract vulnerabilities. The paper collected and screened 3735 valid smart contracts and used these contracts for model experiments and evaluation. The experimental results show that compared with deep learning models and traditional tools, the scheme proposed in the paper has certain improvements in terms of accuracy, precision, recall and Fl score, and can accurately identify 5 types of smart contract vulnerabilities with an accuracy of 99.20%.

Law, AI, and Intellectual Property
Artificial Intelligence in Law
Cybercrime and Law Enforcement Studies
Original source
Sep 7, 2023¡Sustainability
42 cites
Blockchain Technology and Related Security Risks: Towards a Seven-Layer Perspective and Taxonomy

Sepideh Mollajafari, Kamal Bechkoum

Blockchain technology can be a useful tool to address issues related to sustainability. From its initial foundation based on cryptocurrency to the development of smart contracts, blockchain technology promises significant business benefits for various industry sectors, including the potential to offer more trustworthy modes of governance, reducing the risks for environmental and economic crises. Notwithstanding its known benefits, and despite having some protective measures and security features, this emerging technology still faces significant security challenges within its different abstract layers. This paper classifies the critical cybersecurity threats and vulnerabilities inherent in smart contracts based on an in-depth literature review and analysis. From the perspective of architectural layering, each layer of the blockchain has its own corresponding security issues. In order to have a detailed look at the source of security vulnerabilities within the blockchain, a seven-layer architecture is used, whereby the various components of each layer are set out, highlighting the related security risks and corresponding countermeasures. This is followed by a taxonomy that establishes the inter-relationships between the vulnerabilities and attacks in a smart contract. A specific emphasis is placed on the issues caused by centralisation within smart contracts, whereby a “one-owner” controls access, thus threatening the very decentralised nature that blockchain is based upon. This work offers two main contributions: firstly, a general taxonomy that compiles the different vulnerabilities, types of attacks, and related countermeasures within each of the seven layers of the blockchain; secondly, a specific focus on one layer of the blockchain namely, the contract layer. A model application is developed that depicts, in more detail, the security risks within the contract layer, while enlisting the best practices and tools to use to mitigate against these risks. The findings point to future research on developing countermeasures to alleviate the security risks and vulnerabilities inherent to one-owner control in smart contracts.

Open access
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Original source
Sep 7, 2023¡Journal of Information Technology
8 cites
Competing stakeholder narratives on crypto-assets: Miracle or mirage?

Wendy L. Currie, Jonathan J. M. Seddon

Academic and practitioner interest in crypto-assets is gaining momentum. Different values and agendas influence regulatory policy. Competing ideologies and social norms about the efficacy of regulatory regimes, the influence of innovation philosophies, and the need to foster ethical principles and practices underpin debates on crypto-assets. Semi-structured interviews were carried out in the USA and UK with regulators, tech firms, institutional and retail investors, and crypto social media influencers. Stakeholder groups were classified as interventionists, innovators, influencers, and investors. The research builds a data structure from extant literature and empirical research. Aggregate dimensions of inchoate technology, regulatory intervention, and innovation social norms reflect complex and competing stakeholder positions on crypto assets. Findings show crypto-assets are not homogenous, but highly differentiated with potential effects and outcomes determined by algorithmic code. However, competing stakeholder agendas obfuscate policy development for decentralized finance.

Open access
FinTech, Crowdfunding, Digital Finance
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Original source
Sep 7, 2023¡arXiv (Cornell University)
10 cites
Cybercrime Bitcoin Revenue Estimations: Quantifying the Impact of Methodology and Coverage

Gibran GĂłmez, Kevin van Liebergen, Juan Caballero

Multiple works have leveraged the public Bitcoin ledger to estimate the revenue cybercriminals obtain from their victims. Estimations focusing on the same target often do not agree, due to the use of different methodologies, seed addresses, and time periods. These factors make it challenging to understand the impact of their methodological differences. Furthermore, they underestimate the revenue due to the (lack of) coverage on the target's payment addresses, but how large this impact remains unknown. In this work, we perform the first systematic analysis on the estimation of cybercrime bitcoin revenue. We implement a tool that can replicate the different estimation methodologies. Using our tool we can quantify, in a controlled setting, the impact of the different methodology steps. In contrast to what is widely believed, we show that the revenue is not always underestimated. There exist methodologies that can introduce huge overestimation. We collect 30,424 payment addresses and use them to compare the financial impact of 6 cybercrimes (ransomware, clippers, sextortion, Ponzi schemes, giveaway scams, exchange scams) and of 141 cybercriminal groups. We observe that the popular multi-input clustering fails to discover addresses for 40% of groups. We quantify, for the first time, the impact of the (lack of) coverage on the estimation. For this, we propose two techniques to achieve high coverage, possibly nearly complete, on the DeadBolt server ransomware. Our expanded coverage enables estimating DeadBolt's revenue at $2.47M, 39 times higher than the estimation using two popular Internet scan engines.

Open access
3 source records
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Crime, Illicit Activities, and Governance
Original source