Abstract In recent years, smart contract technology has garnered significant attention due to its ability to address trust issues that traditional technologies have long struggled with. However, like any evolving technology, smart contracts are not immune to vulnerabilities, and some remain underexplored, often eluding detection by existing vulnerability assessment tools. In this article, we have performed a systematic literature review of all the scientific research and papers conducted between 2016 and 2021. The main objective of this work is to identify what vulnerabilities and smart contract technologies have not been well studied. In addition, we list all the datasets used by previous researchers that can help researchers in building more efficient machine-learning models in the future. In addition, comparisons are drawn among the smart contract analysis tools by considering various features. Finally, various future directions are also discussed in the field of smart contracts that can help researchers to set the direction for future research in this domain.
Cryptocurrencies are considered relevant assets and they are currently used as an investment or to carry out transactions. However, specific characteristics commonly associated with the cryptocurrencies such as irreversibility, immutability, decentralized architecture, absence of control authority, mobility, and pseudo-anonymity make them appealing for money laundering activities. Thus, the collection and characterization of current cryptocurrency-based methods used for money laundering are paramount to understanding the circulation flows of physical and digital money and preventing this illegal activity. In this paper, a collection of cryptocurrency transaction methods is presented and distributed through the money laundering life cycle. Each method is analyzed and classified according to the phase of money laundering it corresponds to. The result of this article may in the future help design efficient strategies to prevent illegal money laundering activities.
The use of non-fungible tokens (NFTs) in AAA games is a very controversial topic, which leads to negative reactions from the gamer community. The objective of this article is to relate some of these cases that presented visibility in the press and to analyze the reactions this theme generates. To achieve this, we present some cases that had more relevance in the specialized press and, in the sequence, we present a discussion about the main problems pointed out, such as the state of the art of blockchains, energy efficiency, frauds, and currency evasions. Finally, we present some hypotheses to glimpse how NFTs, and their use in games, may happen in the near future.
With the prevalent adoption of blockchain in the financial system, there has been an increase in phishing scams on cryptocurrency platforms such as Ethereum, and an effective anomaly detection method is urgently required. The latest studies have focused on anomaly identification using natural language processing techniques or constructing simple static graphs. However, the existing methods are insufficient to convey the diversity of connectivity patterns in the Ethereum transaction network concerning amount and time. To this end, we proposed a novel transaction network embedding algorithm transE based on the multi-channel random walk to model the detection of Ethereum phishing scam accounts as a multigraph node classification task. Specifically, we first model the Ethereum transaction as a time-amount directed multigraph. Then, the hybrid feature representation of network nodes is learned via transE from their local and global neighbours, which uses the attention mechanism to maximize the probability of preserving node network neighbours. Ultimately, we employ visualization techniques and machine learning models to validate the effectiveness of the algorithms, and the model with the top performance is picked for Ethereum account classification. Experimental results indicate that the embedding vector extracted by transE improves the detection accuracy of Ethereum phishing accounts in the different classification tasks.
Smart contracts based on blockchain are widely used in finance, management, Internet of Things, healthcare, and other fields. However, with the rapid development of smart contracts, the corresponding security vulnerability attack cases occur frequently. Existing Ethereum smart contract vulnerability detection tools based on static analysis techniques rely too much on expert rules, for this reason, this paper proposes an Ethereum smart contract vulnerability detection method SCSVM based on support vector machine technology. A representation of smart contracts is constructed based on the word-to-vector technique, the features of Ethereum smart contracts are extracted based on the support vector machine technique, and these features are combined to identify vulnerabilities. Experiments on Smartbugs and Smartbugs-wild show that SCSVM is significantly effective. It achieves a detection accuracy of 87.51%, outperforming five typical static analysis vulnerability detection tools in terms of F1-score. To alleviate the problems of deep learning methods over-relying on large-scale data to train models and collecting a large number of smart contract attack samples in a short period, this paper proposes a basic learner-meta-learner framework, SCLMF. solc-based acquisition of the bytecode of Ethereum smart contract Solidity, on which smart contract representations are constructed via Python and the use of SCLMF for vulnerability detection. The experiments on WScrawlD show that SCLMF has a certain detection effect. Also, to further verify the effectiveness of SCLMF, experiments were conducted on Omniglot, and the detection accuracy was 96.7% and 98.5% under 5-way 1-shot and 5-way 5-shot conditions, respectively, which exceeded Memory-Augmented Neural Networks and CONVOLUTIONAL SIAMESE NETS. In summary, the experiments proved the effectiveness of SCSVM and SCLMF in Ethereum smart contract vulnerability detection.
Due to the anonymity of blockchain, frequent security incidents and attacks occur through it, among which the Ponzi scheme smart contract is a classic type of fraud resulting in huge economic losses. Machine learning-based me... | Find, read and cite all the research you need on Tech Science Press
Lin William Cong, Kimberly Grauer, Daniel Rabetti, Henry Updegrave
We provide an overview of crypto-related scams, including investment scams, Ponzi schemes, and more recently, rug pulls that are commonly seen in Decentralized Finance (DeFi) projects. We then discuss data sources for studying Initial Coin Offering (ICO) scams, before examining the case of PlusToken, the largest crypto scam, AnubisDAO, the prototypical rug pull, and Luno's anti-scam initiative, a good prototype for other cryptocurrency exchanges and service entities to follow. User protection and education are crucial in preventing scams, despite the fact that they may require efforts from centralized entities and regulators.
Ethereum is a digital asset whose transactions are kept on a decentralized, globally accessible ledger. An Ethereum Blockchain owner's real identity is concealed behind a pseudonym termed an address. Because of this, Ethereum is frequently used in illegal activities like gambling and ransomware attacks because it is popularly believed to offer the highest level of anonymity. As a result, it is necessary to categorize the various malicious cybercriminal users' activities and addresses in the Ethereum Blockchain. The Blockchain's public data enables an in-depth analysis. Using supervised machine learning models including linear, non-linear, and ensemble learning models based on malicious and non-malicious activities, the classification of Ethereum Blockchain addresses is carried out in this paper. In this research work, cross-validation accuracy, recall, precision, and f1-score have been employed for the assessment. Findings indicate that linear and non-linear machine learning approaches are superior to ensemble learning for classifying Ethereum Blockchain addresses. The results also show that it is possible to discover the Ethereum Blockchain addresses of malicious users.
Lars Hornuf, Paul P. Momtaz, Rachel J. Nam, Ye Yuan
We examine how cybercrime impacts victims’ risk-taking and returns. Our difference-indifferences analysis of a sample of victims and matched non-victims is in line with prospect theory and suggests that victims increase their long-term total risk-taking after losing part of their wealth. Victims also earn lower risk-adjusted returns in the post-cybercrime period. Victims’ long-term total risk-taking increases because they increase diversifiable risk in the long term. The increased diversifiable risk correlates with victims’ withdrawal from altcoins after cybercrime. At the same time, the reduction in risk-adjusted returns correlates with increased trading activity and churn, due plausibly to managing cybercrime exposure. In the cross-section of Ethereum addresses, we show that the most affluent victims take a systematic approach to restore their pre-cybercrime wealth level, while the least affluent victims turn into gamblers. Finally, a parsimonious forensic model explains a good part of the addresses’ probability of being involved in cybercrime, on both the victim and the cybercriminal side.
Mohammad Khalid Khawrin, Nooman Zadran, Ahmad Helal
The world is on the brink of rewriting business and monitoring history. It is very crucial to mention academically how Afghan crypto-monitory transactions are taking place. even though it is a soft threat to official government organizations via tax evasion, money laundering, and terrorism financing. The qualitative method with content analysis was applied because the data was in textual form. The data was analyzed through Atlis.ti 9. First of all, the interviews were coded, and then themes were created. The result showed that Bitcoin and Binance had the most users, and there were six types of cryptocurrencies in Afghanistan. Furthermore, the advantages and disadvantages were highlighted. Lastly, it was highly suggested that the Afghan government have specific laws for general protection and to gain the benefits of the new world of high technology.
Decentralized finance (DeFi) has exploded in popularity with a billion-dollar market cap. While uncollateralized lending, known as a flash loan, emerged from DeFi, it has become a primary tool used by attackers to drain investment tokens from DeFi networks. The existing countermeasures seem practical, but no comprehensive quantitative analysis framework was available to test them. This paper proposes the Flash loan Attack Analysis (FAA) framework, which aids security practitioners in understanding the DeFi system’s effects on preventative methods when various factors change. The quantitative predictions can help security professionals in identifying hidden dangers and more efficiently adopting countermeasure strategies. The simulation predicts that the existing strategy, fair reserves, can fully protect the platform in a typical market environment; however, in a highly volatile market where the token price drops by 60% in a single hour, it will be broken, causing more than $8 million in damage.
Blockchain technology has created a new cryptocurrency world and attracted a lot of attention. It also attracts scams, for example, phishing scam, a typical fraud, has been found making a notable amount of money in the blockchain ecosystem, which has a very negative impact. Considering the whole life cycle of a phishing scam, this paper proposes the concept of a phishing gang, that is, a set of accounts that serve for phishing activity and belong to the same entity on the blockchain. As phishers often use multiple accounts to commit phishing scams and money laundering, detecting phishing gangs in the blockchain ecosystem is a real and critical problem. To help deal with this issue, this paper proposes a method of detecting phishing gangs on the Ethereum blockchain. Specifically, we first construct a transaction network with a graph structure by mining the transaction record and the account labels of the Ethereum blockchain. Next, we propose the base and improvement methods of taint analysis, aiming to evaluate the taint score of each account by tracking the fund flow of phishing accounts. Then, with the results of taint analysis and some heuristic means, all accounts in the transaction network are divided into five categories. Based on this, we propose a heuristics algorithm for phishing gang detection. And we also summarize gang patterns and reveal money laundering in phishing activities. Experimental results indicate that the proposed framework can be used to build a uniform platform to monitor every account on the Ethereum blockchain for early warning of phishing scams and detection of the phishers' money laundering and cashing process.
Chencheng Zhou, Liudong Xing, Qisi Liu, Honggang Wang
Selfish mining is a typical malicious attack targeting the blockchain-based bitcoin system, an emerging crypto asset. Because of the non-incentive compatibility of the bitcoin mining protocol, the attackers are able to collect unfair mining rewards by intentionally withholding blocks. The existing works on selfish mining mostly focused on cryptography design, and malicious behavior detection based on different approaches, such as machine learning or timestamp. Most defense strategies show their effectiveness in the perspective of reward reduced. No work has been performed to design a defense strategy that aims to improve bitcoin dependability and provide a framework for quantitively evaluating the improvement. In this paper, we contribute by proposing two network-wide defensive strategies: the dynamic difficulty adjustment algorithm (DDAA) and the acceptance limitation policy (ALP). The DDAA increases the mining difficulty dynamically once a selfish mining behavior is detected, while the ALP incorporates a limitation to the acceptance rate when multiple blocks are broadcast at the same time. Both strategies are designed to disincentivize dishonest selfish miners and increase the system’s resilience to the selfish mining attack. A continuous-time Markov chain model is used to quantify the improvement in bitcoin dependability made by the proposed defense strategies. Statistical analysis is applied to evaluate the feasibility of the proposed strategies. The proposed DDAA and ALP methods are also compared to an existing timestamp-based defense strategy, revealing that the DDAA is the most effective in improving bitcoin’s dependability.
At present, the concept of metaverse has sparked widespread attention from the public to major industries. With the rapid development of blockchain and Web3 technologies, the decentralized metaverse ecology has attracted a large influx of users and capital. Due to the lack of industry standards and regulatory rules, the Web3-empowered metaverse ecosystem has witnessed a variety of financial crimes, such as scams, code exploit, wash trading, money laundering, and illegal services and shops. To this end, it is especially urgent and critical to summarize and classify the financial security threats on the Web3-empowered metaverse in order to maintain the long-term healthy development of its ecology. In this paper, we first outline the background, foundation, and applications of the Web3 metaverse. Then, we provide a comprehensive overview and taxonomy of the security risks and financial crimes that have emerged since the development of the decentralized metaverse. For each financial crime, we focus on three issues: a) existing definitions, b) relevant cases and analysis, and c) existing academic research on this type of crime. Next, from the perspective of academic research and government policy, we summarize the current anti-crime measurements and technologies in the metaverse. Finally, we discuss the opportunities and challenges in behavioral mining and the potential regulation of financial activities in the metaverse. The overview of this paper is expected to help readers better understand the potential security threats in this emerging ecology, and to provide insights and references for financial crime fighting.
In order to reduce the expense of cyberthreats, organisations are considering to outsource their cyber-risk control to insurers. However, a number of barriers have prevented widespread adoption of cyber-insurance. First, it is challenging to determine the insurance premium due to the dearth of valid data used to assess cyber-risks. Second, the legal and administrative barriers that prevent insurers from examining an organization's security posture. Contrasted with, the blockchain technology has gained a lot of popularity because of its capacity to offer security and transparency. Blockchain uses the distributed ledger in order to store transaction details, and instead of keeping the data on a single server, the data is kept across a network of computers. This study suggests a fresh framework to cover a cyber-product utilising blockchain technology in order to enhance the use of cyber-insurance. An insurance request for a cyber-product is first made by a Manager. After then, interested insurers submit their preferred pricing for the insurance system to take part in a sealed-bid auction. The insurers will be chosen from among the auction winners, and in exchange for their responsibilities, they will be given tokens. Among the instance the legitimacy of an indemnity request is verified before calling the claim function to locate the appropriate sum in the money received from the insurers. In addition, we provide a fresh approach for integrating a sealed-bid auction into smart contracts for insurance crowdfunding.
Cryptocurrencies characteristics facilitated ran-somware attacks extorting payments in the form of Bitcoin, Mon-ero, Ethereum and others from individuals and organizations. The open cyber boarders allowed anyone to own cryptocurrency without revealing their identities. This research investigates the role of cryptocurrency in the increase of cyber attacks and creating the new phenomenon of crypto-ransomware and answer two fundamental questions: (1) Is there a correlation between the increase use of cryptocurrency and the spread of cyber attacks? And (2) Would ransomware attacks exist if cryptocurrency did not exist?.
Majd Soud, Ilham Qasse, Grischa Liebel, Mohammad Hamdaqa
Due to the risks associated with vulnerabilities in smart contracts, their security has gained significant attention in recent years. However, there is a lack of open datasets on smart contract vulnerabilities and their fixes that allows for data-driven research. Towards this end, we propose an automated framework for mining and classifying Ethereum’s smart contract vulnerabilities and their corresponding fixes from GitHub and from the Common Vulnerabilities and Exposures (CVE) records in the National Vulnerability Database. We implemented the proposed method in a fully automated framework, which we call AutoMESC. AutoMESC uses seven of the most well-known smart contract security tools to classify and label the collected vulnerabilities based on vulnerability types. Furthermore, it collects metadata that can be used in data-intensive smart contract security research (e.g., vulnerability detection, vulnerability classification, severity prediction, and automated repair). We used AutoMESC to construct a sample dataset and made it publicly available. Currently, the dataset contains 6.7K smart contract vulnerability-fix pairs written in Solidity. We assess the quality of the constructed dataset in terms of accuracy, provenance, and relevance, and compare it with existing datasets. AutoMESC is designed to collect data continuously and keep the corresponding dataset up-to-date with newly discovered smart contract vulnerabilities and their fixes from GitHub and CVE records.