This paper investigates extreme risk in cryptocurrency markets by comparing Bitcoin and Ethereum daily returns with those of S&P 500 and SPY ETF. Using the Generalized Tempered Stable (GTS) distribution to model heavy tails and Quantile-Quantile (Q-Q) plots to assess fitness, we find that all assets deviate sharply from normal distribution. Within this framework, Ethereum exhibits a higher frequency of extreme returns than Bitcoin, highlighting differences in risk profiles even among leading cryptocurrencies.
With the rapid expansion of the global cryptocurrency market since the 2018 Bitcoin investment boom, the number of cryptocurrency users has increased significantly. Despite the emergence of various cryptocurrency wallets, issues such as users' inability to properly manage their assets and the growing number of security incidents and crimes continue to undermine trust in digital asset storage. In this context, there is an urgent need for a system that can ensure secure asset protection and address users' anxiety regarding cryptocurrency management. However, the concept of cryptocurrency security remains undefined, relevant laws and regulations are not yet institutionalized, and academic research in this area is still limited. To address these challenges, this paper proposes an Ethereumbased cryptocurrency wallet system that not only enhances the functional and security aspects of existing wallets but also enables cryptocurrency delegation and ownership transfer. We designed and implemented a DApp that allows users to securely store, delegate, and transfer cryptocurrencies through an escrow account implemented via smart contracts on the Ethereum blockchain. By presenting a practical implementation of a transferable and delegatable wallet, this study contributes to improving user trust and asset safety, while laying the foundation for legal and technological innovation in the digital asset ecosystem.
The cryptocurrency market offers significant investment opportunities, but with high levels of financial risk compared to traditional asset classes. This study analyzes the daily returns of Bitcoin and Ethereum, focusing on tail behavior and peakedness to assess risk. Using the flexible Generalized Tempered Stable (GTS) distribution, we capture significant deviations from normality. Results show Bitcoin returns are more concentrated around the mean, with 80 % of returns between$-1.27 \%$and 2.84 %, while Ethereum is more dispersed-only 40 % of its returns fall in that range. Bitcoin's distribution is more sharply peaked; Ethereum has heavier tails and greater exposure to extreme fluctuations. These findings underscore the importance of using advanced models like the GTS for accurate risk management and portfolio optimization in cryptocurrencies.
Abstract Ensuring the security of smart contracts is essential for maintaining the reliability and trustworthiness of decentralized applications, which are deployed across various domains, including industrial applications. In pursuit of this goal, it is imperative to analyze the common errors developers make when crafting smart contracts on the infrastructure that gave birth to them, i.e., the Ethereum blockchain. In this paper, we present a comprehensive analysis of the vulnerabilities in Ethereum smart contracts. Our methodology involves downloading the entire Ethereum blockchain and identifying smart contracts, which we then scan for vulnerabilities using various tools. We have discovered numerous vulnerabilities across many deployed smart contracts, highlighting the need for improved development practices. This analysis provides critical insights into the prevalence of security issues and underscores the urgency of raising development standards. By promoting the adoption of secure-by-design principles, our research seeks to enhance security standards within the Ethereum smart contract ecosystem.
Multi-chain deployment has become a mainstream strategy for U.S.-based DAOs, yet treasury management faces three core bottlenecks: cross-chain liquidity fragmentation, inadequate compliance with U.S. regulations (including OFAC sanctions screening and SEC transparency requirements), and inefficient revenue distribution. Leveraging the incubation practices of over 12 U.S. DAOs (via daos.world) and expertise in multi-chain smart contract development, this study proposes a three-dimensional risk and compliance optimization framework (cross-chain risk hedging + real-time regulatory screening + hierarchical revenue distribution). Empirical testing on 8 U.S. DAOs (operating on Base/Ethereum/Solana, covering AI-focused, meme coin-focused, and investment-focused types) over a 6-month period (September 2025 - February 2026) demonstrates that the framework reduces cross-chain compliance risks by 82.3% (OFAC violation rate drops from 18.0% to 3.2%), increases the annualized treasury return rate by 17.6% (from 4.2% to 5.04%), lowers cross-chain transaction costs by 28.5% (average Gas fee decreases from $12.8 to $9.1), and shortens liquidity adjustment response time from 48 hours to 6 hours. Integrating U.S. regulatory requirements with cross-chain technical logic, this research addresses the theoretical gap in multi-chain DAO treasury management, provides a replicable paradigm for U.S. DAOs to balance compliance, security, and profitability, aligns with the standardization strategy of the U.S. Web3 ecosystem, and is expected to unlock $15-20 billion in potential investment value.
Термин сферы децентрализованных финансов анализируется в рамках когнитивной парадигмы. Целью исследования является определение роли когнитивно-матричного анализа в контексте изучения терминов рассматриваемой области знания. Объектом исследования выступает термин “decentralized finance”. Предметом является применение когнитивно-матричного анализа как метода изучения терминолексики сферы децентрализованных финансов. Научная новизна исследования заключается в том, что впервые в отечественном терминоведении проводится изучение англоязычных терминов указанной сферы с когнитивной позиции. В частности, приводится пример использования когнитивно-матричного анализа для определения концептуальной структуры термина изучаемой области знания. В статье рассматривается несколько подходов к определению понятия «термин»: субстанциональный, функциональный и когнитивный. Проводится когнитивно-матричный анализ на материале термина “decentralized finance” и его определений, закрепленных в глоссариях децентрализованных платформ, приложений и новостных англоязычных интернет-ресурсов, таких как Binance Academy, Consensys, Ethereum Website, Ethereum Glossary и Tastycrypto. В результате анализа определено, что наибольшую компонентную представленность в структуре концепта DECENTRALIZED FINANCE демонстрируют «техническая и технологическая» и «социальная» области, в то время как «финансовая» и «правовая» репрезентированы менее широко, что обусловлено смещением акцента в определениях термина с базовых характеристик на инновационные и дифференцирующие. Когнитивно-матричный анализ позволяет выявлять периферийные области и концептуальные компоненты когнитивной структуры терминов сферы децентрализованных финансов, подчеркивая их междисциплинарный характер. The term “decentralized finance” is analyzed within the framework of the cognitive paradigm. The article examinesthe application of cognitive-matrix analysis as a method for studying the terminological vocabulary of the specified domain. The object of the research is the term “decentralized finance”, while the subject is the application of cognitive matrix analysis as a method for studying the terminological vocabulary of decentralized finance. The novelty of the research lies in the fact that, for the first time in Russian terminology studies, English-language terms of the specified field are examined from a cognitive perspective. An example is provided of how cognitive matrix analysis can be used to identify the conceptual structure of decentralized finance terms. The article considers several approaches to defining the concept of the term: the substantial, functional, and cognitive. A cognitive matrix analysis is conducted on the material of the term “decentralized finance”, as represented in the glossaries of decentralized platforms, applications, and English-language news resources such as Binance Academy, Consensys, Ethereum Website, Ethereum Glossary, and Tastycrypto. The analysis reveals that the “technical and technological” and “social” peripheral domains are most prominently represented in the structure of the concept DECENTRALIZED FINANCE, whereas the “financial” and “legal” domains are less explicitly present. This is due to the shift in focus from basic characteristics of the concept to innovative and differentiating features in the term’s definitions. Cognitive matrix analysis makes it possible to identify peripheral domains and conceptual components of the cognitive structure of DeFi terminological vocabulary, highlighting its interdisciplinary nature.
Tipwadee Leala, Krist Thamniyom, Thawatchai Chomsiri
Cryptocurrency investments have grown exponentially, but the rapid expansion of decentralized finance (DeFi) ecosystems has been accompanied by the rise of sophisticated fraud schemes, particularly Rug Pulls. These scams occur when developers deliberately withdraw liquidity or sell large amounts of tokens, leaving investors with worthless assets. This research presents a machine learning-based framework for detecting rug-pull-prone projectson the Binance Smart Chain (BSC). A comprehensive dataset was constructed by aggregating transactional and smart contract features from reliable sources such as BscScan, TokenSniffer, DEXTools, and PeckShield Alerts. Data preprocessing included handling missing values, removing duplicates, detecting and mitigating outliers, and addressing severe class imbalance using Synthetic Minority Oversampling Technique (SMOTE). Seven machine learning algorithms were compared: Decision Tree (DT), Random Forest (RF), Gradient Boosting (GB), Extreme Gradient Boosting (XGB), K-Nearest Neighbors (KNN), Support Vector Machine (SVM), and Multi-Layer Perceptron (MLP). The top-performing models, Random Forest and XGBoost, were further validated using stratified holdout testing. Results demonstrate that XGBoost achieved the highest overall performance$(\mathrm{F1} = 0.82,\ \text{ROC-AUC} = 0.90,\ \text{PR-AUC} = 0.994)$confirming the model's robustness in identifying fraudulent patterns. This approach offers a scalable framework for blockchain fraud detection on BSC, with potential applicability to other networks such as Ethereum and Polygon.
Aqsa Rashid, Raja Wasim Ahmad, Mirna Nachouki, Atta Ur Rehman Khan
Ensuring food safety and traceability in fruit supply chains (FSC) remains a critical concern, as traditional centralized methods often suffer from data manipulation, lack of transparency, and delayed responses during contamination events. These challenges lead to reduced consumer trust and inefficiencies in monitoring product integrity throughout the supply network. To address these limitations, this paper presents a blockchain-based framework that leverages cryptographic protocols and smart contracts to secure, automate, and validate traceability processes across all stages of the fruit supply chain. The proposed FSC_SDG system enforces trusted data recording, real-time provenance verification, and autonomous policy execution, while aligning with the United Nations Sustainable Development Goals (UN-SDGs). A proof-of-concept prototype was implemented on the Ethereum blockchain to assess performance. Experimental evaluations demonstrate reduced latency in traceability verification, improved data integrity, and enhanced resistance to tampering compared with existing approaches. These results confirm the effectiveness of the proposed framework in strengthening food safety, transparency, and trust within fruit supply chains.
Block space on the blockchain is scarce and must be allocated efficiently through block building. However, Ethereum's current block-building ecosystem, MEV-Boost, has become highly centralized due to integration, which distorts competition, reduces blockspace efficiency, and obscures MEV flow transparency. To guarantee equitability and economic efficiency in block building, we propose $\mathrm{Boost+}$, a system that decouples the process into collecting and ordering transactions, and ensures equal access to all collected transactions. The core of $\mathrm{Boost+}$ is the mechanism $\mathit{M}_{\mathrm{Boost+}}$, built around a default algorithm. $\mathit{M}_{\mathrm{Boost+}}$ aligns incentives for both searchers (intermediaries that generate or route transactions) and builders: Truthful bidding is a dominant strategy for all builders. For searchers, truthful reporting is dominant whenever the default algorithm dominates competing builders, and it remains dominant for all conflict-free transactions, even when builders may win. We further show that even if a searcher can technically integrate with a builder, non-integration combined with truthful bidding still dominates any deviation for conflict-free transactions. We also implement a concrete default algorithm informed by empirical analysis of real-world transactions and evaluate its efficacy using historical transaction data.
Arivarasan Karmegam, Lucianna Kiffer, Antonio Fernández Anta
Blockchain validators can reduce block processing time by exploiting multi-core CPUs, but deterministic execution must preserve a given total order while respecting transaction conflicts and per-block runtime limits. This paper systematically examines how validators can exploit multi-core parallelism during both block construction and execution without violating blockchain semantics. We formalize two validator-side optimization problems: (i) executing an already ordered block on \(p\) cores to minimize makespan while ensuring equivalence to sequential execution; and (ii) selecting and scheduling a subset of mempool transactions under a runtime limit \(B\) to maximize validator reward. For both, we develop exact Mixed-Integer Linear Programming (MILP) formulations that capture conflict, order, and capacity constraints, and propose fast deterministic heuristics that scale to realistic workloads. Using Ethereum mainnet traces and including a Solana-inspired declared-access baseline (Sol) for ordered-block scheduling and a simple reward-greedy baseline (RG) for block construction, we empirically quantify the trade-offs between optimality and runtime.
Penelitian ini bertujuan untuk menganalisis pengaruh harga Bitcoin, Ethereum, indeks S&P 500, dan emas terhadap volatilitas harga Xrp. Xrp sebagai salah satu aset kripto dengan kapitalisasi pasar besar menunjukkan tingkat volatilitas yang tinggi, sehingga penting untuk memahami faktor-faktor eksternal yang memengaruhi pergerakan volatilitasnya. Penelitian ini menggunakan pendekatan kuantitatif dengan data sekunder berbentuk time series. Data yang digunakan meliputi harga Bitcoin, Ethereum, S&P 500, emas, serta harga Xrp yang diperoleh dari sumber terpercaya seperti Investing.com dan Coinglass selama periode pengamatan tertentu. Volatilitas harga Xrp dianalisis menggunakan model Multivariate Generalized Autoregressive Conditional Heteroskedasticity untuk menangkap karakteristik volatilitas yang bersifat time-varying, clustering, serta keterkaitan volatilitas antar aset. Hasil penelitian menunjukkan bahwa harga Bitcoin berpengaruh signifikan terhadap volatilitas harga Xrp, yang mengindikasikan adanya keterkaitan volatilitas yang kuat antara kedua aset kripto tersebut. Sementara itu, harga Ethereum, indeks S&P 500, dan emas tidak menunjukkan pengaruh signifikan terhadap volatilitas harga Xrp. Temuan ini mengindikasikan bahwa volatilitas Xrp lebih sensitif terhadap dinamika pergerakan Bitcoin dibandingkan dengan aset kripto lainnya maupun aset keuangan tradisional. Penelitian ini memberikan implikasi penting bagi investor dan pelaku pasar dalam pengambilan keputusan investasi, khususnya dalam mengelola risiko pada aset kripto. Selain itu, hasil penelitian ini diharapkan dapat menjadi referensi bagi penelitian selanjutnya terkait keterkaitan volatilitas antar aset kripto dan integrasinya dengan pasar keuangan global
Personal Health Records (PHRs) enable personalized and continuous healthcare services, but contain highly sensitive information, requiring strong security and privacy safeguards. Self-sovereign architectures, where individuals retain full control over their data, represent a promising model for secure PHR sharing. In our prior work, we implemented a blockchain-based system using Non-Fungible Tokens (NFTs) to represent data ownership and usage rights. While NFTs provide tamper resistance, NFT-only access control is vulnerable to wallet compromise and requires explicit user consent, making it unsuitable for emergency access when patients are unconscious or otherwise unable to consent. To address these limitations, we newly propose a hybrid PHR-sharing framework combining NFTs with Attribute-Based Encryption (ABE). Our new approach enforces cryptographic access policies beyond NFT possession and enables emergency access to predefined medical information without explicit user consent. We analyze representative attack scenarios and show that the scheme provides secure access control and rights management. We implement a prototype and evaluate its performance. For 1 MB of data, used as a practical upper bound for text-based PHR records based on wearable-device measurements, retrieval takes approximately 1 second, while registration and access granting take approximately 12 and 6 seconds on the Base testnet, a high-speed Ethereum-compatible test network. These results demonstrate practical feasibility, with further optimization possible through faster blockchain networks or reduced blockchain transactions.
Smart contracts are autonomous programs executed on blockchain platforms such as Ethereum. They facilitate the development of decentralized applications but also introduce significant risks. Since the code of a deployed smart contract is immutable and often controls valuable digital assets, any security vulnerability can lead to severe and irreversible consequences. This paper presents a comprehensive survey of smart-contract vulnerability detection systems, synthesizing findings from over 108 tools across static analysis, formal verification, dynamic fuzzing, machine learning, symbolic execution, and runtime monitoring. A vulnerability taxonomy is organized spanning coding, design, and environmental weaknesses (e.g., reentrancy, arithmetic errors, access-control faults, timestamp dependence, and misuse of pseudo-randomness). Rather than conducting new empirical evaluations, this survey synthesizes performance metrics reported in the literature and proposes a KPI-based framework for comparing tools. However, direct quantitative comparisons are limited by heterogeneous evaluation contexts, datasets, and tool versions across studies. Techniques are contextualized with real attack exemplars, tool capabilities are summarized, and trade-offs among accuracy, scalability, and coverage are highlighted. Open challenges are identified—including compositional reasoning for multi-contract interactions, uncovering businesslogic errors, and balancing precision with throughput—and design guidance is distilled for practitioners. Overall, while detection capabilities have improved substantially, securing smart contracts remains an active frontier that calls for hybrid, multilayer defenses and continuous innovation.
R. N. V. Jagan Mohan, Pravallika Sree Rayanoothala, R. Praneetha Sree
Agriculture faces multifaceted challenges including climate variability, soil degradation, and supply chain inefficiencies, particularly for smallholder farmers practicing multicropping. This study systematically integrates blockchain technology for secure, transparent transactions with reinforcement learning (RL)-optimized Neutrosophic multi-regression for precise crop loss prediction in multicropping systems. Using real-world data from six crops (rice, banana, turmeric, elephant foot yam, coconut, cocoa), Neutrosophic multi-regression estimated losses with RL hyperparameter tuning, achieving superior prediction accuracy. A blockchain framework was developed for farmer validation, transaction security, and smart contract execution using Ethereum/Ganache. Results demonstrate 25%–35% reduction in predicted crop losses and enhanced supply chain traceability. This Smart Agriculture 5.0 framework advances Agriculture 4.0 through human-AI symbiosis and uncertainty modeling, addressing single-point failures, data privacy, and trust deficits for scalable sustainable farming Through this multidimensional approach, the study endeavors to not only enhance the productivity and sustainability of agricultural practices but also to foster resilience in the face of evolving challenges.
Yaroslava Yakovenko, Zavodovska D., Reichling Peter
Over the past decade, cryptocurrencies have evolved from a niche technological innovation into a global financial phenomenon. Bitcoin, Ethereum, and other digital assets have attracted massive attention from investors, policymakers, and the general public. The central debate surrounding cryptocurrencies centres on whether they represent a financial bubble destined to burst or the foundation of a new, decentralized financial future.
Do online narratives leave a measurable imprint on prices in markets for digital or cultural goods? This paper evaluates how community attention and sentiment relate to valuation in major Ethereum NFT collections after accounting for time effects, market-wide conditions, and persistent visual heterogeneity. Transaction data for large generative collections are merged with Reddit-based discourse measures available for 25 collections, covering 87{,}696 secondary-market sales from January 2021 through March 2025. Visual differences are absorbed by a transparent, within-collection standardized index built from explicit image traits and aggregated via PCA. Discourse is summarized at the collection-by-bin level using discussion intensity and lexicon-based tone measures, with smoothing to reduce noise when text volume is sparse. A mixed-effects specification with a Mundlak within--between decomposition separates persistent cross-collection differences from within-collection fluctuations. Valuations align most strongly with sustained collection-level attention and sentiment environments; within collections, short-horizon negativity is consistently associated with higher prices, and attention is most informative when measured as cumulative engagement over multiple prior windows.
Open access
3 source records
econ.GN
Consumer Behavior in Brand Consumption and Identification
Front-running attacks have become a threat to blockchain security. By exploiting transaction ordering, attackers use front-running to gain profits on Ethereum-based blockchains. Existing heuristics and ML approaches fail to capture the complex relational dependencies in these attacks. We propose a novel framework by leveraging instruction-tuned large language models, Llama-3.2-3B and Gemma-2-2B, for multi-class front-running detection on Ethereum. Through parameter-efficient fine-tuning with LoRA and an enriched dataset augmented with blockchain metadata from Alchemy and Chainstack, our models achieve up to 96.4 % macro accuracy, surpassing the baseline approach by 8.7 %. We further identify that 256 tokens is the optimal input length while discussing the trade-offs between runtime efficiency and performance. Our findings demonstrate that LLMs are a powerful tool for learning complex transactional patterns, which is crucial for blockchain security.
Using the Crypto Fear & Greed Index and Bitcoin daily data, sentiment extremity predicts excess uncertainty beyond realized volatility. Extreme fear and extreme greed regimes exhibit significantly higher spreads than neutral periods -- the "extremity premium." Extended validation on the full Fear & Greed history (2018--2026, N = 2,896) confirms the finding: within-volatility-quintile comparisons show a premium ($p < 0.001$, pooled volatility-demeaned Cohen's $d = 0.21$ -- a post-hoc, exploratory test, as the pre-specified within-quintile endpoint does not survive multiple-testing correction; raw pooled extreme-vs-neutral $d = 0.40$), Granger causality runs from uncertainty to spreads (primary-sample $F = 12.79$; the extended-sample $F = 211$ is partly mechanical, sharing a high-low input with the spread measure), and placebo tests reject the null ($p < 0.0001$). The effect replicates on Ethereum and across 6 of 7 market cycles. However, the premium is sensitive to functional form: regression controls absorb regime effects, while nonparametric stratification preserves them. We interpret this as evidence that sentiment extremity captures volatility-regime interactions not fully represented by parametric controls -- consistent with, but not conclusively separable from, the F&G Index's embedded volatility component. An agent-based model is included as an illustrative device that reproduces the pattern qualitatively; because its spread-uncertainty link is coded rather than emergent, it does no inferential work (the reported moment-matching test validates a separate simplified model, not the full agent specification), and the inferential weight rests entirely on the empirical analysis. The results suggest that intensity, not direction, drives uncertainty-linked liquidity withdrawal in cryptocurrency markets, though identifying "pure" sentiment effects from volatility remains open.
Verifiable and transparent voting must protect democratic process from being interfered or falsified in any form, but traditionally implemented voting systems in electronics aren’t transparent, vulnerable to cheating attacks, and centralized in control. To overcome these problems, an election voting system based on blockchain, embedding cryptography security as well as distributed transparency, was conceptualized. With Ethereum-based smart contracts, Advanced Encryption Standard – Galois/Counter Mode (AES-GCM) encryption maintains secrecy of ballots intact, and integrity and tamper protection through hashing by Keccak-256. The voter registration involved Elliptic Curve Cryptography (ECC) based key generation, and an election time commit reveal scheme to maintain privacy intact and allow for non repudiation. Backend was implemented in Flask and MySQL as database management, and frontend in Streamlit to keep it user friendly and easily accessible during voting hours. Every and each voting in blockchain transactions traceable and checkable to maintain voter privacy intact, thereby providing for auditability and transparency. The architecture also offers for security features to withstand replay attacks, instances of double voting, and data breach, thereby making it dependable and scalable in future polls in democracies.
Abdullah Ayub Khan, Abdullah M. Baqasah, Majed Alsafyani, Hamed Alsufyani · 6 authors
The revolution in Blockchain Distributed Ledger Technology (BDLT) is changing conventional structures and creating previously unattainable opportunities across a variety of industrial fields. This study explores new developments, opportunities, and trends while tackling important issues that highlight the revolutionary potential of BDLT. For secure, automated, and dependable ecosystem management, it focuses on innovations like Denaturalized Finance (Defi), chaincode, and BDLT interface with the Internet of Things (IoT). The investigation of hybrid blockchain models, which combine the benefits of private and public blockchains, is a novel component of this research. It provides a customized strategy to guarantee improved scalability, privacy, and performance. Conversely, this study highlighted the critical function of Hyperledger, a modular framework that makes enterprise-level blockchain solutions possible. Thus, Ethereum is a flexible platform with strong chaincode capabilities that facilitate the creation of Distributed Applications (DApps). Such opportunities for advancements are evaluated closely in order to demonstrate how they contribute to practical uses and innovations unique to a given sector. To improve worldwide acceptance, the paper also presents Systematic Literature Review (SLR) in order to demonstrate the existing innovative frameworks, especially Hyperledger Technology (HT) for resolving constraints such as consensus protocols for energy efficiency and adaptive regulatory models. For technological experts, industrial developers, and third-party policymakers seeking to harness BDLT's disruptive capabilities while navigating its complexity, this paper offers new viewpoints and practical insights to help close the gap between theoretical innovation and real-world applications.
Ethereum-Smart Contracts verwalten häufig erhebliche finanzielle Werte. Da sie praktisch unveränderlich sind und häufig böswilligen Akteuren ausgesetzt sind, die durch finanziellen Gewinn motiviert sind, stellt die semantische Korrektheit eine zentrale Sicherheitsanforderung dar. Etablierte Testmethoden reichen oft nicht aus, um die Korrektheit über alle möglichen Ausführungspfade hinweg zu gewährleisten. Daher stellt die formale Verifikation ein wesentliches Mittel dar, um solche Sicherheitsgarantien zu stärken. Diese Arbeit untersucht die auf symbolischer Ausführung basierende Verifikation von Ethereum-Smart-Contracts unter Verwendung des KEVM-Frameworks sowie zweier darauf aufbauender Werkzeuge auf höherer Abstraktionsebene: ACT und Kontrol. Diese Arbeit behandelt Fragestellungen hinsichtlich der Ausdrucksstärke und Konstruktion von Beweisen sowie der Nutzbarkeit und Interpretierbarkeit sowohl von Beweisdefinitionen als auch von generierten Beweisartefakten. Es wird untersucht, ob und welche praktischen Herausforderungen bei der Verwendung von KEVM und zugehörigen Werkzeugen auftreten, einschließlich der Syntax, der verfügbaren Debugging-Werkzeuge sowie der Analyse von Beweisen und Gegenbeweisen. Anschließend erfolgt eine Evaluierung, wie semantische Eigenschaften über alle Werkzeuge hinweg spezifiziert werden können und wie präzise diese spezifiziert werden, wobei insbesondere die Zielkonflikte zwischen unterschiedlichen Abstraktionsebenen hervorgehoben werden. Darüber hinaus verifizieren wir semantische Eigenschaften von ERC20-Token-Smart-Contracts mit besonderem Fokus darauf, ob bestimmte Einträge in der Common Vulnerabilities and Exposures (CVE)-Datenbank tatsächlich korrekt sind oder mithilfe von KEVM widerlegt werden können. Zu diesem Zweck analysieren wir die gemeldete Schwachstelle, formulieren ein formales Argument gegen die behauptete Verletzung und konstruieren darauf aufbauend einen Beweis unter Verwendung von Kontrol. Dabei zeigen wir, wie semantische Eigenschaften innerhalb des Frameworks formuliert und verifiziert werden können. Abschließend untersuchen wir die Community-Aktivität rund um KEVM und dessen Ökosystem. Dazu werden GitHub-Repository-Metriken sowie Kommunikationsdaten aus Discord ausgewertet, um Entwicklungsaktivität, Dynamiken der Beitragenden sowie Muster im Nutzer-Support zu analysieren. Diese kombinierte Perspektive aus technischer und empirischer Sicht liefert eine ganzheitliche Betrachtung von KEVM sowohl als formales Verifikationsframework als auch als Entwickler-Ökosystem.
Pooja Raut, Mayuresh Shinde, Simran Tiwari, A. L. Pereira · 5 authors
Most traditional carpooling schemes rely on centralized agents, with potential issues regarding trust, transparency, and additional commission fees. This paper introduces "Smart Contracts for Carpooling: A Blockchain-Based Approach", a decentralized application (dApp) that tackles these limitations. Building on the Ethereum blockchain and using smart contracts implemented in Solidity, our system offers secure, peer-to-peer transactions between drivers and passengers without relying on third-party authority. The platform enables users to sign up, post or request rides, match desired rides, and make payments—under laws by peer-to-peer transparent and tamperevident smart contracts. HTML, CSS, and JavaScript are used for frontend code, while Web3.js serves to integrate dApp with the Ethereum network via MetaMask. Development and testing were performed utilizing Ganache to mimic a local blockchain environment. This implementation demonstrates a functional, trustless carpooling system within a controlled setting, emphasizing block-chain’s potential to improve security, reduce operational costs, and eliminate reliance on intermediaries in the ride-sharing ecosystem. Although not yet deployed on a public network, the prototype showcases the feasibility and advantages of applying decentralized technologies to create efficient, user-centric transportation solutions.
Weihong Wang, Yana Dimova, Victor Vansteenkiste, Tom Van Goethem · 5 authors
Cryptocurrency wallets are the primary interface for managing pseudonymous blockchain addresses, viewing balances, and interacting with Web3 applications. Although users typically assume that their addresses remain independent of each other unless intentionally revealed, modern wallets routinely communicate with both blockchain infrastructure and decentralized applications (dApps), generating network-side and web-side signals that may undermine this assumption. In this paper, we identify and formalize five privacy threats that arise directly from wallets interacting with the network and the web browser. Using large-scale dynamic measurements of 85 of the most popular Chrome Web Store browser-extension wallets (representing 35.16 million users), we observe that routine remote procedure call (RPC) operations leak structural links between a user's addresses; that the majority of Ethereum wallets implement permission revocation inconsistently and continue to expose previously revoked addresses across sessions; and that many wallets inject their provider interfaces into cross-origin iframes, enabling passive cross-site tracking beyond dApps and potentially real-world identity deanonymization without user interaction. Taken together, our results show that these wallet behaviors leak sensitive information that can be used to link multiple addresses to the same user, track wallet users across sessions and sites, and connect their browsing activity to their on-chain wealth. We discuss practical mitigations and show that many of these threats can be substantially reduced through improved wallet implementation, stronger privacy considerations in ecosystem standards, and stricter controls over provider exposure. Our results highlight the need for standardized, privacy-preserving wallet architectures and provide actionable guidance for strengthening user privacy in the emerging Web3 ecosystem.