To execute transactional operations in the financial trading industry, cryptocurrencies like as bitcoin make use of decentralization, traceability, and anonymity properties. These digital currencies, which are based on new blockchain technology, are serving as the foundation for some of the world's biggest unregulated marketplaces. A variety of regulatory difficulties arise as a result, including the illegal acquisition of narcotics and weapons, money laundering, and the support of terrorist operations, among others. This chapter examines a variety of legal and ethical implications, as well as their consequences and potential solutions to the fundamental problems that policymakers and regulators are today confronted with on a daily basis. The authors present the findings of an analysis of 30 recently published peer-reviewed scientific publications, and they propose a number of mechanisms that can aid in the detection and prevention of illegal activities, which currently account for a significant portion of cryptocurrency trading at this time. These researchers propose methodologies and apps that may be used to detect dark markets in the future, should the need arise.
Carlos Eduardo Carvalho, Desirée Almeida Pires, Marcel Artioli, Giuliano Contento de Oliveira
Abstract This paper analyses the impacts of the innovation known as distributed ledger technology (DLT) on the monetary system and on financial activities. Private cryptocurrencies, such as Bitcoin, are permissionless means of payment, based on blockchain, a form of DLT. Evaluations suggested that these private cryptocurrencies could compete with the banks payment systems and even supplant state currency. The development of these technologies has the potential to modify profoundly monetary and financial practices, but there are no indications that they may threaten the centrality of state money and the banking system in the contemporary monetary order. Major international banks have developed cryptocurrencies for settlement systems and for interbank transactions, including the so-called stablecoins, issued by highly technological companies with on par conversion into state money. Some central banks are studying the launch of state cryptocurrencies that could coexist with their fiduciary state currency and even replace their paper currency. The use of this technology results in new challenges for regulation, including the fact that cryptocurrencies can be used for money laundering and by organized crime.
In recent years, as blockchain adoption has been expanding across a wide range of domains, e.g., digital asset, supply chain finance, etc., the confidentiality of smart contracts is now a fundamental demand for practical applications. However, while new privacy protection techniques keep coming out, how existing ones can best fit development settings is little studied. Suffering from limited architectural support in terms of programming interfaces, state-of-the-art solutions can hardly reach general developers. In this paper, we proposed the CLOAK framework for developing confidential smart contracts. The key capability of CLOAK is allowing developers to implement and deploy practical solutions to multi-party transaction (MPT) problems, i.e., transact with secret inputs and states owned by different parties by simply specifying it. To this end, CLOAK introduced a domain-specific annotation language for declaring privacy specifications and further automatically generating confidential smart contracts to be deployed with trusted execution environment (TEE) on blockchain. In our evaluation on both simple and real-world applications, developers managed to deploy business services on blockchain in a concise manner by only developing CLOAK smart contracts whose size is less than 30% of the deployed ones.
Md. Zahurul Haq, Zainal Amin Ayub, Zuryati Mohamed Yusoff, Md Abdul Awal Khan
Purpose This paper aims to critically explore the factors influencing the regulation of gambling and cryptocurrencies as part of anti-money laundering (AML) initiatives in Bangladesh. As a member of the Asia/Pacific Group on money laundering, Bangladesh must adopt a risk-based approach to regulate these entities. Design/methodology/approach This study applied an exploratory design and investigated the real nature of the challenge Bangladesh facing in adopting a risk-based approach to regulate gambling and cryptocurrencies. Findings This study demonstrates that current regulatory responses towards gambling and cryptocurrencies in Bangladesh are largely influenced by passive wait-and-see policy instead of a proactive risk-based approach, a measure mandated by the Financial Action Task Force (FATF). It demonstrates that these financial entities, which are poorly regulated because of their unclear legal status in Bangladesh and the regulator’s apparent lack of understanding of the type of threats they pose, may facilitate money laundering. Effective risk-based regulation is required to control potential risks. Research limitations/implications This paper focuses on two specific areas –gambling and cryptocurrencies – which are linked to two specific FATF Recommendations: designated non-financial businesses and professions (DNFBPs) and new technologies. Further research is required to investigate the concern from the perspective of other entities. Practical implications The results of this study will help inform policymakers about ways in which current regulatory approaches may need to be modified to better combat money laundering and financing of terrorism. Originality/value According to the authors’ knowledge, this is the first study aiming to explore challenges Bangladesh confronts in implementing a risk-based approach for DNFBPs and new technologies. Therefore, it provides important insights into the dilemma regulators facing in implementing global AML standards within their traditional legislative and regulatory framework.
Bitcoin is currently the cryptocurrency with the largest market share. Many previous studies have explored the security of Bitcoin from the perspective of blockchain mining. Especially on the double-spending attacks (DSA), some state-of-the-art studies have proposed various analytical models, aiming to understand the insights behind the double-spending attacks. However, we believe that advanced versions of DSA can be developed to create new threats for the Bitcoin ecosystem. To this end, this paper mainly presents a new type of double-spending attack named Adaptive DSA in the context of the Bitcoin blockchain, and discloses the associated insights. In our analytical model, the double-spending attack is converted into a Markov Decision Process. We then exploit the Stochastic Dynamic Programming (SDP) approach to obtain the optimal attack strategies towards Adaptive DSA. Through the proposed analytical model and the disclosed insights behind Adaptive DSA, we aim to alert the Bitcoin ecosystem that the threat of double-spending attacks is still at a dangerous level.
Decentralized Finance (DeFi) took shape in 2020. An unprecedented amount of over 14 billion USD moved into DeFi projects offering trading, loans and insurance. But its growth has also drawn the attention of malicious actors. Many projects were exploited as quickly as they launched and millions of USD were lost. While many developers understand integer overflows and reentrancy attacks, security threats to the DeFi ecosystem are more complex and still poorly understood. In this paper we provide the first overview of in-the-wild DeFi security incidents. We observe that many of these exploits are market attacks, weaponizing weakly implemented business logic in one protocol with credit provided by another to inflate appropriations. Rather than misusing individual protocols, attackers increasingly use DeFi's strength of permissionless composability against itself. By providing the first holistic analysis of real-world security incidents within the nascent financial ecosystem DeFi is, we hope to inform threat modeling in decentralized cryptoeconomic initiatives in the years ahead.
The research designs a new integrated system for the security enhancement of a decentralized network by preventing damages from attackers, particularly for the 51 percent attack. The concept of multiple layered design based on Blockchain Governance Games frameworks could handle multiple number of networks analytically. The Multi-Layered Blockchain Governance Game is an innovative analytical model to find the best strategies for executing a safety operation to protect whole multiple layered network systems from attackers. This research fully analyzes a complex network with the compact mathematical forms and theoretically tractable results for predicting the moment of a safety operation execution are fully obtained. Additionally, simulation results are demonstrated to obtain the optimal values of configuring parameters of a blockchain-based security network. The Matlab codes for the simulations are publicly available to help those whom are constructing an enhanced decentralized security network architecture through this proposed integrated theoretical framework.
Background: In the world of the latest technologies, the blockchain is one of the popular techniques for stopping fraudulent activities. Non-Government Organization (NGO) is increasingly being used to support all the needy people across the globe to shape the world’s responsibility towards society for sustainable development. The existing method of donating money and its monitoring is facing a major corruption problem in several world-renowned NGOs. A Blockchain can transform the way the current business of money transaction is being done in NGOs. The blockchain-based application works on the concept of a decentralized system. Methods: This article presents a blockchain-based transaction system to prevent corruption and money laundering in NGOs and government fundraising organizations. A smart contract has been designed to stop any illegitimate block changes during a financial transaction. Since every node has a copy of the ledger, so it is very difficult to perform malicious activity. Furthermore, the donator can watch how the money flows in the different transactions and everyone can browse the account history. An evaluative judgment, comparing with various consensus algorithms, has also been presented along with their complex nature. The decentralized approach has eliminated the chance of a single point of failure which in turn makes the system robust. Results: The developed framework for the financial transaction using blockchain has been tested using the Rinkeby Test Network. The generators and campaign contracts have been developed and deployed in the Rinkeby testing network. The results indicate that the computing is much more secure and free from the scam in comparison to the traditional client-server financial transaction system. Conclusion: Finally, the proposed approach suggests scenarios such as in NGOs where the introduced security approach should prove to be adequate.
Purpose The aim of this paper is to assess the relevance of cryptocurrencies with regard to the money laundering risk on the market and to present widespread money laundering techniques and recognizable patterns of abuse. In addition, this paper aims to find an answer to the question to what extent the measures of the fifth EU Anti-Money Laundering Directive (AMLD) as well as other appropriate preventive measures are sufficient to reduce the money laundering risk in the area of virtual currencies (VC). Design/methodology/approach Firstly, the analysis requires a consideration of the theoretical foundations of money laundering methods, as well as a presentation of the technical foundations of cryptocurrencies and their ecosystem. Secondly, it is discussed to what extent VC are suitable for money laundering, which characteristics enable them to launder money and which new money laundering techniques result from this. In addition, a comparison of different money laundering risk classification is done in relation to VC from the perspective of different actors in the financial market. Findings Owing to their simple electronic storage and transferability, crypto assets pose a concrete risk of money laundering. Their inclusion in the fifth AMLD was therefore a necessary step by the European legislator. However, the question arises to whether the directive and the further preventive measures presented in this paper sufficiently fulfil the objective of reducing the money laundering risk in relation to VC. One positive aspect is the inclusion of the crypto custody business as a financial service in the German Banking Act. According to the definition in Section 1 (1a) sentence 2 no. 6, the offering of wallets is subject to authorization and the offering party becomes an obligated party within the meaning of the Germany Money Laundering Act. From a supervisory point of view, the new licensing requirement is very much welcomed, as the custody of private cryptographic keys entails considerable risks. However, non-custodian wallet providers who do not store the private keys of their users, are not covered. A closer analysis of the amending directive to the fourth EU AMLD reveals that other relevant players in the crypto market, such as mixer and tumbler services, are also not covered. Originality/value It is quite clear that cryptocurrencies and the blockchain technology will continue to accompany one in the coming years. Further credit institutions arising in the market exposed to the described risks will be seen. The paper will therefore present and evaluate possible risk reduction/options for anti-money laundering for new and existing financial institutions.
Dado el creciente uso de las criptomonedas a nivel mundial, y dentro de estas el bitcoin (BTC), resulta necesario analizar el marco jurídico aplicable con el fin de detectar posibles cambios o actualizaciones. Uno de los aspectos incluidos en dicho análisis refiere a la posibilidad de efectuar el pago del salario de los trabajadores en bitcoins. En este artículo se busca, desde un abordaje principalmente jurídico y económico, conceptualizar jurídicamente al bitcoin para luego evaluar si la normativa vigente en Uruguay habilita el pago de salarios con esta criptomoneda. Se concluye que en Uruguay existen limitaciones legales para que los salarios mínimos se paguen con otros medios distintos de la moneda nacional, aunque podría establecerse un pago parcial con BTC mediante el mecanismo de los Consejos de Salarios. Para la parte del salario que supere el mínimo no habría inconvenientes, tanto se considere al BTC como dinero privado o como un bien incorporal “común”.
Mohammad Rasheed Ahmed, Kandala Meenakshi, Mohammad S. Obaidat, Ruhul Amin · 5 authors
With the evolution of Internet Technology, payment methods have undergone drastic changes from entity exchange to Internet banking. Almost every sector has gone through the transformation from conventional technologies to digital technologies. With the arrival of online payment and digital wallet system, making payments has become easier than ever and with the increasing demand for such services, the number of users using instant money transfer systems are growing rapidly. However, the existing online payment system has issues like a single point of failure, transparency, and insider problem. Also, security in such online payments is crucial to mitigate risks and financial inefficiencies. In this paper, a private and permissioned Blockchain-based Payment System for the financial sector in India is proposed. The proposed architecture is based on Istanbul Byzantine Fault Tolerance (IBFT) consensus and it also discusses the integration of banks with the system.
Ponzi schemes are financial scams that lure users under the promise of high profits. With the prosperity of Bitcoin and blockchain technologies, there has been growing anecdotal evidence that this classic fraud has emerged in the blockchain ecosystem. Existing studies have proposed machine-learning based approaches for detecting Ponzi schemes, i.e., either based on the operation codes (opcodes) of the smart contract binaries or the transaction patterns of addresses. However, state-of-the-art approaches face several major limitations, including lacking interpretability and high false positive rates. Moreover, machine-learning based methods are susceptible to evasion techniques, and transaction-based techniques do not work on smart contracts that have a small number of transactions. These limitations render existing methods for detecting Ponzi schemes ineffective. In this paper, we propose SADPonzi, a semantic-aware detection approach for identifying Ponzi schemes in Ethereum smart contracts. Specifically, by strictly following the definition of Ponzi schemes, we propose a heuristic-guided symbolic execution technique to first generate the semantic information for each feasible path in smart contracts and then identify investor-related transfer behaviors and the distribution strategies adopted. Experimental result on a well-labelled benchmark suggests that SADPonzi can achieve 100% precision and recall, outperforming all existing machine-learning based techniques. We further apply SADPonzi to all 3.4 million smart contracts deployed by EOAs in Ethereum and identify 835 Ponzi scheme contracts, with over 17 million US Dollars invested by victims. Our observations confirm the urgency of identifying and mitigating Ponzi schemes in the blockchain ecosystem.
3 source records
Blockchain Technology Applications and Security
Spam and Phishing Detection
Advanced Steganography and Watermarking Techniques
Bitcoin is extremely easy to be used in corruption cases due to its pseudonym, easy circulation, easy cross-border and other characteristics. As a decentralized electronic account book, the circulation of regulatory funds is jointly confirmed by each node in the bitcoin network, which can ensure the authenticity of the criminal evidence and is not easy to be lost or damaged. It provides great convenience for evidence collection in bitcoin corruption cases. However, there are also shackles in criminal governance, such as how to prove the subjective intent of the bribe takers, the impact of fluctuations in market value on the identification of the case and, most importantly, how to effectively recover stolen goods across borders. Therefore, the difficulty of bitcoin-related cases does not lie in the “anonymity” that some scholars believe, but lies in the determination of subjective intent, the determination of the amount of the crime and the international judicial assistance in recovering the stolen money.
Bitcoin uses blockchain technology to maintain transactions order and provides probabilistic guarantees to prevent double-spending, assuming that an attacker’s computational power does not exceed 50% of the network power. In this article, we design a novel bribery attack and show that this guarantee can be hugely undermined. Miners are assumed to be rational in this setup, and they are given incentives that are dynamically calculated. In this attack, the adversary misuses the Bitcoin protocol to bribe miners and maximize their gained advantage. We will reformulate the bribery attack to propose a general mathematical foundation upon which we build multiple strategies. We show that, unlike Whale Attack, these strategies are practical, especially in the future when halvings lower the mining rewards. In the so-called “guaranteed variable-rate bribing with commitment” strategy, through optimization by Differential Evolution (DE), we show how double-spending is possible in the Bitcoin ecosystem for any transaction whose value is above 218.9BTC, and this comes with 100% success rate. A slight reduction in the success probability, e.g., by 10%, brings the threshold down to 165BTC. If the rationality assumption holds, then this shows how vulnerable blockchain-based systems like Bitcoin are. We suggest a soft fork on Bitcoin to fix this issue at the end.
Massimo La Morgia, Alessandro Mei, Francesco Sassi, Julinda Stefa
Cryptocurrencies are increasingly popular. Even people who are not experts have started to invest in these assets, and nowadays, cryptocurrency exchanges process transactions for over 100 billion US dollars per month. Despite this, many cryptocurrencies have low liquidity and are highly prone to market manipulation. This paper performs an in-depth analysis of two market manipulations organized by communities over the Internet: The pump and dump and the crowd pump. The pump and dump scheme is a fraud as old as the stock market. Now, it has new vitality in the loosely regulated market of cryptocurrencies. Groups of highly coordinated people systematically arrange this scam, usually on Telegram and Discord. We monitored these groups for more than 3 years, detecting around 900 individual events. We report on three case studies related to pump and dump groups. We leverage our unique dataset of the verified pump and dumps to build a machine learning model able to detect a pump and dump in 25 seconds from the moment it starts, achieving the results of 94.5% of F1-score. Then, we move on to the crowd pump, a new phenomenon that hit the news in the first months of 2021, when a Reddit community inflated the price of the GameStop stocks (GME) by over 1,900% on Wall Street, the world’s largest stock exchange. Later, other Reddit communities replicated the operation on the cryptocurrency markets. The targets were DogeCoin (DOGE) and Ripple (XRP). We reconstruct how these operations developed and discuss differences and analogies with the standard pump and dump. We believe this study helps understand a widespread phenomenon affecting cryptocurrency markets. The detection algorithms we develop effectively detect these events in real-time and helps investors stay out of the market when these frauds are in action.
Natkamon Tovanich, Nicolas Soulié, Nicolas Heulot, Petra Isenberg
We provide an empirical analysis of pool hopping behavior among 15 mining pools throughout Bitcoin's history. Mining pools have emerged as major players to ensure that the Bitcoin system stays secure, valid, and stable. Individual miners join mining pools to benefit from a more predictable income. Many questions remain open regarding how mining pools have evolved throughout Bitcoin's history and when and why miners join or leave mining pools. We propose a heuristic algorithm to extract the payout flow from mining pools and detect the pools' migration of miners. Our results showed that payout schemes and pool fees influence miners' decisions to join, change, or exit from a mining pool, thus affecting the dynamics of mining pool market shares. Our analysis provides evidence that mining activity becomes an industry as miners' decisions follow classical economic rationale.
The rapid growth of Decentralized Finance (DeFi) boosts the Ethereum ecosystem. At the same time, attacks towards DeFi applications (apps) are increasing. However, to the best of our knowledge, existing smart contract vulnerability detection tools cannot be directly used to detect DeFi attacks. That's because they lack the capability to recover and understand high-level DeFi semantics, e.g., a user trades a token pair X and Y in a Decentralized EXchange (DEX). In this work, we focus on the detection of two types of new attacks on DeFi apps, including direct and indirect price manipulation attacks. The former one means that an attacker directly manipulates the token price in DEX by performing an unwanted trade in the same DEX by attacking the vulnerable DeFi app. The latter one means that an attacker indirectly manipulates the token price of the vulnerable DeFi app (e.g., a lending app). To this end, we propose a platform-independent way to recover high-level DeFi semantics by first constructing the cash flow tree from raw Ethereum transactions and then lifting the low-level semantics to high-level ones, including token trade, liquidity mining, and liquidity cancel. Finally, we detect price manipulation attacks using the patterns expressed with the recovered DeFi semantics. We have implemented a prototype named \tool{} and applied it to more than 350 million transactions. It successfully detected 432 real-world attacks in the wild. We confirm that they belong to four known security incidents and five zero-day ones. We reported our findings. Two CVEs have been assigned. We further performed an attack analysis to reveal the root cause of the vulnerability, the attack footprint, and the impact of the attack. Our work urges the need to secure the DeFi ecosystem.
Cryptocurrencies are often thought to operate out of the reach of national regulation, but in fact their valuations, transaction volumes and user bases react substantially to news about regulatory actions. The impact depends on the specific regulatory category to which the news relates: events related to general bans on cryptocurrencies or to their treatment under securities law have the greatest adverse effect, followed by news on combating money laundering and the financing of terrorism, and on restricting the interoperability of cryptocurrencies with regulated markets. News pointing to the establishment of specific legal frameworks tailored to cryptocurrencies and initial coin offerings coincides with strong market gains. These results suggest that cryptocurrency markets rely on regulated financial institutions to operate and that these markets are segmented across jurisdictions.
Marco Antonio Castillo Medina, César Vega Zárate, Leticia Murcia López
México se está enfrentando a una nueva era digitalizada, donde nuevos conceptos como economía digital o criptomoneda son cada vez más utilizados entre la población actual mexicana, sin embargo, la legislación de México se encuentra aún rezagada por lo menos en el tema de criptomoneda, caso concreto Bitcoin.Dado lo anterior este trabajo en cuestión es una recopilación de información sobre la criptomoneda llamada Bitcoin y todos los ámbitos que lo rodean. Con la finalidad de esclarecer a fondo el tema del Bitcoin.En sus inicios se explica que es el dinero y su evolución, para dar contexto al tema, posteriormente se habla sobre la criptomoneda y Bitcoin en general en todo lo que le atañe y por último se describe un panorama general del entorno jurídico mexicano para comprender como es que la criptomoneda se contabiliza y fiscaliza en el territorio mexicano con las nuevas reformas creadas.
We present our work on visual analytics tools to support the analysis of Bitcoin mining pool evolution. Mining blocks are a critical component of the Bitcoin ecosystem, helping to keep the system secure, valid, and stable. At the same time, mining is a resource-intensive activity that continues to get more and more difficult. Mining pools have emerged to address this issue and to ensure a more stable and predictable income by sharing computing power. Yet, increased centralization of the mining power is also not without dangers (e. g., the 51% attack), and, thus, it is important to better understand and analyze mining pool activities in Bitcoin. Here, we report three contributions: our extensive data collection on Bitcoin mining pools, our development of two custom visualizations, and our first exploratory data analysis leading to hypotheses and documented activities about pools' main features such as market share, reward rules, or location.
Abstract Oil and gas operators have a multitude of tasks to perform for smooth business operations. In addition to various engineering, technical, and operational decisions, there are back-office operations that should be efficient to keep business running smoothly, including production royalty management (PRM). The current system for PRM is extremely complex and costly, and involvesmultiple parties/contracts and often causes disputes. A blockchain-based solution allows the organizations to better navigate complex laws, courtrulings, and legal jargon that determine how billions of dollars are distributed every year. There are two aspects to PRM —royalties owed and royalties received—and the proposed solution caters to both operators and independent mineral owners. The operator should compile production and revenue data monthly and distribute it to all owners as per their individual lease. The expenses and marketing costs should be entered into the accounting system before revenue is distributed. Owners may be skeptical about data shared; therefore, the entire process can take up to two or more months. Furthermore, privacy is of utmost importance because theoperator can neither share data between owners nor disclose proprietary information. This paper proposes the entire royalty management system be hosted on a permissioned blockchain. Given their intrinsic nature of trustworthiness and transparent execution of transactions involving multiple parties, blockchain can streamline the royalty distribution process. The design and implementation of a smart contract for consent-driven and double-blind data sharingon a blockchain platform is presented. The system is designed for both inter- and intra-organizational transaction—a local peer interacts with an associated anchor peer within the globalnetwork. In addition to transparency and efficiency, this method provides important features ofprivacy and auditability while limiting ledger size. Further, peer identities are hiddenfrom each other while they collectively agree on transaction outcomes, and data will never be shared among the peers of the blockchain without explicit consent from the owners to ensure that the conflicting objectives of privacy and transparency are met. Blockchain is peer-to-peer decentralized digital ledger technology with promising potential. Even after all the recent innovations, the owner-relations department still operates using old methods. An innovative blockchain-based solution to reduce time and money spent on disbursing revenue for the operator and to increase the time value of information and trust in the system for the owner is presented.