Abstract The pronounced multi-domain technologicalization specific to the last decades has had a significant impact on all areas of activity, including the financial one. The use of cyberspace to facilitate the actions undertaken in the monetary activity has generated the development of this field to the point where virtual currencies have been created and new technologies have been developed to support their use. Like any emerging domain, the cryptocurrency field and the related technology are in a relatively early stage and exclusively imply operating in cyberspace, thus generating security risks in the event of the involvement of malicious entities in illicit activities. In this context, it is worth analyzing how the improper use of the crypto domain can lead to various risks to national security.
Dec 1, 2021·2021 IEEE 23rd Int Conf on High Performance Computing & Communications; 7th Int Conf on Data Science & Systems; 19th Int Conf on Smart City; 7th Int Conf on Dependability in Sensor, Cloud & Big Data Systems & Application (HPCC/DSS/SmartCity/DependSys)
Bitcoin has become the choice of many illegal transactions due to its anonymity. To fight crime and maintain the order of the financial market, it is necessary to identify illegal transaction activities in the Bitcoin network. On the basis of referring to the relationship between data, information, and knowledge in the DIKW architecture, this article proposes a new method called MP-GAT to convert discrete data in the Bitcoin network into usable information and knowledge to help identify illegal transactions. MP-GAT uses a combination of multi-layer perceptron and graph attention networks to build a model for identifying illegal transactions. Specifically, the concept of artificial intelligence is used to simulate the human reasoning system and learn from the data. Use the MP-GAT model to convert Bitcoin data into information and knowledge. The method of artificial intelligence is used to complete the transformation of data, information, and knowledge in the DIKW system to achieve the purpose of detecting and identifying illegal transactions in the Bitcoin network.
The susceptibility of cryptocurrencies to criminal activity is a vigorously debated issue of high policy relevance. Not only the share of cryptocurrency turnover linked to crime is unknown, also the question which of several cryptocurrencies are prevalent on the darknet, and hence should be prioritized in building analytical capability for law enforcement, calls for empirical research. Using the event study methodology, we estimate the market reaction on cryptocurrency exchanges to news about successful law enforcement actions of systemic relevance for the cybercriminal ecosystem. The events studied include seizures of darknet marketplaces and shutdowns of cybercriminal data centers and mixers. Although the number of relevant events is still small, we observe significant cumulative abnormal returns to such news over the past years. We cautiously interpret the obtained results by cryptocurrency and direction of the effect, and derive implications for future research and policy.
Deepesh Chaudhari, Rachit Agarwal, Sandeep K. Shukla
The temporal aspect of blockchain transactions enables us to study the address's behavior and detect if it is involved in any illicit activity. However, due to the concept of change addresses (used to thwart replay attacks), temporal aspects are not directly applicable in the Bitcoin blockchain. Several pre-processing steps should be performed before such temporal aspects are utilized. We are motivated to study the Bitcoin transaction network and use the temporal features such as burst, attractiveness, and inter-event time along with several graph-based properties such as the degree of node and clustering coefficient to validate the applicability of already existing approaches known for other cryptocurrency blockchains on the Bitcoin blockchain. We generate the temporal and non-temporal feature set and train the Machine Learning (ML) algorithm over different temporal granularities to validate the state-of-the-art methods. We study the behavior of the addresses over different time granularities of the dataset. We identify that after applying change-address clustering, in Bitcoin, existing temporal features can be extracted and ML approaches can be applied. A comparative analysis of results show that the behavior of addresses in Ethereum and Bitcoin is similar with respect to in-degree, out-degree and inter-event time. Further, we identify 3 suspects that showed malicious behavior across different temporal granularities. These suspects are not marked as malicious in Bitcoin.
At present, most smart contract vulnerability detection use manually-defined patterns, which is time-consuming and far from satisfactory. To address this issue, researchers attempt to deploy deep learning techniques for automatic vulnerability detection in smart contracts. Nevertheless, current work mostly relies on a single code representation such as AST (Abstract Syntax Tree) or code tokens to learn vulnerability characteristics, which might lead to incompleteness of learned semantics information. In addition, the number of available vulnerability datasets is also insufficient. To address these limitations, first, we construct a dataset covering most typical types of smart contract vulnerabilities, which can accurately indicate the specific row number where a vulnerability may exist. Second, for each single code representation, we propose a novel way called AFS (AST Fuse program Slicing) to fuse code characteristic information. AFS can fuse the structured information of AST with program slicing information and detect vulnerabilities by learning new vulnerability characteristic information.
In times of exogenous systemic shocks, such as the COVID-19 pandemic, it is important to identify hedge or safe haven assets. Therefore, this paper analyzes changes in the idiosyncratic risk of Bitcoin in a portfolio of commodities and global stocks. For this purpose, the M-GARCH model employed considers the interdependence among all the portfolio assets by using a time-varying asset pricing framework. This framework measures the impact of commodities and global stock prices as sources of systemic risk for Bitcoin returns before and after the COVID-19 pandemic. The evidence suggests that during the COVID-19 pandemic, the effects of changes in commodities and global prices on the idiosyncratic risk of Bitcoin were statistically significant. The idiosyncratic risk of Bitcoin measured as a percentage of total variance not accounted for by the proposed model rose from 86.06% to 95.05% during the pandemic. These results are in line with previous studies regarding the properties of Bitcoin as a hedge or safe haven asset for a portfolio composed of commodities and global stocks.
Purpose This study aims to explore how to deanonymize cryptocurrency money launderers with the help of machine learning (ML). Money is laundered through cryptocurrencies by distributing funds to multiple accounts and then reexchanging the crypto back. This process of exchanging currencies is done through cryptocurrency exchanges. Current preventive efforts are outdated, and ML may provide novel ways to identify illicit currency movements. Hence, this study investigates ML applicability for combatting money laundering activities using cryptocurrency. Design/methodology/approach Four supervised-learning algorithms were compared using the Bitcoin Elliptic Dataset. The method covered a quantitative analysis of the algorithmic performance, capturing differences in three key evaluation metrics of F1-scores, precision and recall. Two complementary qualitative interviews were performed at cryptocurrency exchanges to identify fit and applicability of the algorithms. Findings The study results show that the current implemented ML tools for preventing money laundering at cryptocurrency exchanges are all too slow and need to be optimized for the task. The results also show that while not one single algorithm is most suitable for detecting transactions related to money-laundering, the specific applicability of the decision tree algorithm is most suitable for adoption by cryptocurrency exchanges. Originality/value Given the growth of cryptocurrency use, this study explores the newly developed field of algorithmic tools to combat illicit currency movement, in particular in the growing arena of cryptocurrencies. The study results provide new insights into the applicability of ML as a tool to combat money laundering using cryptocurrency exchanges.
Crime research has repeatedly shown that small proportions of offenders are responsible for large proportions of crimes. While there is a substantial body of evidence for this ‘offending concentration’ in connection to traditional offline crime, there is limited research assessing the concentration of offending for cybercrime. This research analyzes victim reports of Bitcoin-related cybercrimes (blackmail, ransomware, sextortion, darknet market fraud, Bitcoin tumbler fraud) to illuminate the extent of cybercrime offending concentration and to identify groups of offenders involved in online crime. Our results indicate that a large proportion of cybercrimes are associated with a small number of very active Bitcoin addresses. However, Bitcoin addresses associated to high numbers of reports are not necessarily those that generate the largest financial benefits.
Abstract The rise of cryptocurrencies during the last decade has caused growing concerns among national and international regulators. One of the risks identified is that these instruments may constitute an innovative tool for criminals when laundering money. This risk has been confirmed by numerous recent cases which have underlined the criminogenic potential of cryptocurrencies. Through the V antimoney laundering (AML) Directive, the European legislator has first regulated this emerging issue. This legislation extends the AML duties to two players of the cryptocurrencies market: exchangers and wallet providers. This choice, however, does not exploit the opportunities offered by cryptocurrencies and fails to provide a customized regulatory framework. By maintaining a traditional regulatory approach centered on intermediaries it misses the key innovation of blockchain technology: disintermediation. Compared with traditional online money flows, intermediaries are not necessary nor fundamental in the cryptocurrencies environment. Failing to adapt to this reality, the Directive is employing chivalry to fight a trench war. To guarantee the integrity of this market, the policymaker has to abandon the traditional intermediary‐centred approach in favor of a strategy that seizes the new opportunities offered by blockchain. This paper advocates for a shift from an individual‐centered approach to financial crime control to a transaction‐centered one.
Kevin Tjiam, Rui Wang, Huanhuan Chen, Kaitai Liang
Smart contracts on Ethereum enable billions of dollars to be transacted in a decentralized, transparent and trustless environment. However, adversaries lie await in the Dark Forest, waiting to exploit any and all smart contract vulnerabilities in order to extract profits from unsuspecting victims in this new financial system. As the blockchain space moves at a breakneck pace, exploits on smart contract vulnerabilities rapidly evolve, and existing research quickly becomes obsolete. It is imperative that smart contract developers stay up to date on the current most damaging vulnerabilities and countermeasures to ensure the security of users' funds, and to collectively ensure the future of Ethereum as a financial settlement layer. This research work focuses on two smart contract vulnerabilities: transaction-ordering dependency and oracle manipulation. Combined, these two vulnerabilities have been exploited to extract hundreds of millions of dollars from smart contracts in the past year (2020-2021). For each of them, this paper presents: (1) a literary survey from recent (as of 2021) formal and informal sources; (2) a reproducible experiment as code demonstrating the vulnerability and, where applicable, countermeasures to mitigate the vulnerability; and (3) analysis and discussion on proposed countermeasures. To conclude, strengths, weaknesses and trade-offs of these countermeasures are summarised, inspiring directions for future research.
Purpose As decentralized finance (DeFi) has collected substantial promotion, investment and cryptographic development as a new model for numerous financial operations over the last months. As DeFi models and technology are quite unique, authorities have not been engaged much yet. However, these non-regulated financial markets will be overlooked for no long by the regulators. Therefore, the purpose of this paper is to analyse and evaluate the new challenges for financial crime compliance which need to be tackled very soon. Design/methodology/approach The research relied on secondary sources of data, using secondary research to collect archival data in the form of documents. Content and thematic analyses were used to synthesize the collected data Findings DeFi is considered to be one of the major steps towards adopting crypto masses. It is expected that DeFi will play a significant role in future and provide the present banking system with a feasible alternative. Therefore, it is crucial that the DeFi industry must address the main risks to ensure its “user” full compliance. Originality/value This research is the first to analyse the emerging challenges of fighting financial crime in the DeFi ecosystem.
Bitcoins are evolving as a modern class of investment assets and it is crucial for investors to manage their investment risk. This paper examines the impact of macroeconomic-financial indicators on Bitcoin price using symmetric and asymmetric version of autoregressive distributed lag (ARDL) models with structural breaks. The asymmetric long-run association ascertained between Bitcoin prices and the macroeconomic-financial indicators is evident. Our empirical results indicate that the Bitcoin cannot be used to hedge against the inflation, Federal funds rate, stock markets and commodity markets. We further find that Bitcoin can be regarded as a hedging device for the oil prices. Our findings have significant implications for market participants who consider including alternate investment assets in their portfolios.
Blockchain and smart contracts can be used to facilitate almost any financial transaction. Thanks to these smart contracts, the settlement of dividends and coupons could be automated. The blockchain would allow all these transactions to be saved in a single ledger rather than in many databases through many organizations as is currently the case. Smart contracts have become lucrative and profitable targets for attackers because they can hold a large amount of money. This paper takes stock of cryptocurrency crime by assessing attacks due to smart contracts and the cost of losses. These losses are often the result of two types of malicious contracts: vulnerable contracts and criminal smart contracts. Studying the behavior of malicious contracts allows us to understand the root causes and consequences of attacks and the defense capabilities that exist although they do not definitively solve the crime problem. It makes it possible to approach new defense perspectives which will be concretized in future work.
On January 26, 2018, 58 billion yen ($530 million) worth of a cryptocurrency, NEM, was fraudulently accessed, and was then stolen from the Coincheck Exchange, headquartered in Japan. This hacking incident is unprecedented not only because it was one of the world’s largest cryptocurrency heists, but also because the stolen NEM was sold and money laundered on a crypto market. Three years later, the Metropolitan Police Department, Japan, announced that more than 30 people had been charged for allegedly exchanging NEM cryptocurrency, accounting for one third of the stolen value, for other cryptocurrencies. The hackers have not yet been arrested, and how the stolen NEM was money laundered has not yet been investigated. By resolving two challenges in tracking the stolen NEM and its money laundering, this report shows that there were increasingly larger sales of the stolen NEM over time, and on the last two days of market operation, approximately one third of the stolen NEM was money laundered. Furthermore, this study reveals that there was no pattern in the hour of the day of the sales transactions whereas more sales occurred on Sundays and Mondays. This suggests that the laundering was international and that the stolen NEM was purchased by individuals. These findings emphasize the need for cryptocurrency exchanges to verify the identity of a new user when an account is opened.
Raja Wasim Ahmad, Khaled Salah, Raja Jayaraman, Ibrar Yaqoob · 5 authors
Today's systems, approaches, and technologies leveraged for managing oil and gas supply chain operations fall short in providing operational transparency, traceability, audit, security, and trusted data provenance features. Also, a large portion of the existing systems is centralized, manual, and highly disintegrated which make them vulnerable to manipulation and the single point of failure problem. In this survey, we explore the potential opportunities and applications of blockchain technology in managing the exploration, production, and supply chain and logistics operations in the oil and gas industry as it can offer traceability, immutability, transparency, and audit features in a decentralized, trusted, and secure manner. We discuss state-of-the-art blockchain-based schemes, research projects, business initiatives, and case studies to highlight the practicability of blockchain in the oil and gas industry. We present the potential opportunities brought about by blockchain technology in various use cases and application scenarios. We introduce several systems that leverage blockchain-based smart contracts to automate the important services in terms of tracking and tracing of petroleum products, protection of international trade documents, and coordination of purchasing and bidding activities for granting oil exploration rights to petroleum exploration and development companies. Finally, we present open challenges acting as future research directions.
Abstract This study analyzes the impact of a newly emerging type of anti-money laundering regulation that obligates cryptocurrency exchanges to report suspicious transactions to financial authorities. We build a theoretical model for the reporting decision structure of a private bank or cryptocurrency exchange and show that an inferior ability to detect money laundering (ML) increases the ratio of reported transactions to unreported transactions. If a representative money launderer makes an optimal portfolio choice, then this ratio increases further. Our findings suggest that cryptocurrency exchanges will exhibit more excessive reporting behavior under this regulation than private banks. We attribute this result to cryptocurrency exchanges’ inferior ML detection abilities and their proximity to the underground economy.
In this article, the author primarily aims to clarify from a technical and terminological point of view several notions relevant for the blockchain ecosystem. In this context, the analysis is focused on notions such as blockchain, Proof of Work or Proof of Stake consensus mechanism, virtual currency, crypto-asset, digital wallet, centralized or decentralized exchange platform, public address, public and private cryptographic key, seed phrase, etc. Beyond these technical and terminological clarifications, the author aims to analyse the European and national regulatory framework, in an attempt to resolve, among other things, different matters such as the difference between virtual currencies, crypto-assets and electronic money or the regulation of exchange service providers and digital wallet providers. Last but not least, the author analyses both the risks and benefits of blockchain technology from a cyber security perspective, as well as several criminal behaviours in regard to virtual currencies or other crypto-assets. In this context, behaviours such as ransomware, cryptojacking, unauthorized transfer of virtual currencies or other cryptocurrencies, counterfeiting of virtual currencies, cloning or restricting access to digital wallets, etc. are all taken into consideration.
Cryptocurrencies are a subset of virtual currencies that have been devised for anonymous payments made entirely independent of governments and traditional financial institutions. The payment system of cryptocurrencies is expanding at a rapid pace and has reached Ethiopia. This article examines the extent to which cryptocurrencies are regulated under Ethiopia’s national payment system and anti-money laundering legal norms. The study has employed doctrinal research supported by in-depth interviews. During the last decade, Ethiopia has adopted several legal frameworks that govern different aspects of the payments landscape, most notably regarding payment services and electronic money. The country has anti-money laundering legal norms that are embodied in domestic laws and international and regional instruments that it has ratified. However, these legal norms have strategic deficiencies in regulating cryptocurrencies. Thus, the government of Ethiopia should consider enacting a comprehensive law that regulates the payment system of cryptocurrencies.
Xabier Echeberria-Barrio, Francesco Zola, Lander Segurola-Gil, Raúl Orduna-Urrutia
Blockchain technology has gained much relevance in recent years, specifically the smart contract functionality, due to its great potential to decentralize different required scenarios. This technology brings many advantages, in particular, smart contracts provide blockchain with very great versatility. However, these smart contracts can bring some threats to the blockchain. This study has focused on the development of an intrusion detection system (IDS) based on the path study. This IDS defends the smart contracts, monitoring the transactions received by the targeted smart contract and generating the paths where the transactions are coming. These generated paths will have some features that are extracted and analyzed. Our approach suggests implementing an automated IDS on smart contracts to defend them from potential threats.