Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

1,682 papersLast indexed Aug 31, 2026
Search papers

Paper index

1,682 results · page 4 of 71

Clear filters
Jun 16, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Identification and characterization of inference bottlenecks and class imbalance in Transformer-based Smart Contract Auditors

Wathsala Lakmini Priyankara Piyankarage

This research investigates critical challenges in Transformer-based smart contract auditing systems, with a specific focus on inference instability and class imbalance in CodeBERT-based binary vulnerability classification. Layer-2 blockchain networks introduce highly complex architectures that increase the risk of smart contract exploits, where traditional static analysis tools such as Slither often produce large volumes of noisy, rule-based alerts. Recent advancements in pre-trained Transformer models, particularly CodeBERT, have demonstrated strong capabilities in semantic code understanding and vulnerability detection. However, during deployment of a fine-tuned CodeBERT-base model, we observe significant performance and stability issues. Initial inference experiments show a 100% false-positive rate, primarily attributed to severe class imbalance in the slither-audited-smart-contracts dataset and model sensitivity to specific smart contract patterns such as raw Ether transfer functions. In addition, system-level execution profiling reveals a silent segmentation fault during model initialization. Further investigation using Windows OS logs identifies dependency conflicts between PyTorch and PyArrow (via Hugging Face Datasets), particularly related to C++ DLL load-order issues. Experimental analysis demonstrates that modifying dependency import order, prioritizing PyArrow initialization, and enforcing strict model.eval() state management significantly improves inference stability. These findings highlight important architectural and deployment considerations for Transformer-based blockchain security systems and provide practical insights for improving the robustness of automated smart contract auditing pipelines in Layer-2 Web3 ecosystems.

Open access
2 source records
Software System Performance and Reliability
Security and Verification in Computing
Adversarial Robustness in Machine Learning
Original source
Jun 15, 2026·Entropy
0 cites
Analytical Entropy Approach for Measuring Blockchain Immutability and Tamper-Resilient Trust

Li Li, Charles Z. Liu, Sanjeeb Shrestha

This work presents a comprehensive study of entropy-based metrics for evaluating blockchain systems, focusing on on-chain ledger immutability, off-chain data integrity, and computational dynamics within blockchain virtual machines (BVMs). We develop a unified framework that models blockchain states as probabilistic distributions, quantifying uncertainty through Shannon entropy and examining its evolution under varying adversarial fractions. Extensive simulations demonstrate that on-chain entropy exhibits near-exponential decay, reflecting the cumulative reinforcement of honest consensus, while off-chain entropy remains static, highlighting the limitations of conventional data storage. Furthermore, the BVM is analyzed in terms of computation entropy, establishing its Turing completeness and demonstrating that smart-contract state evolution mirrors the information dynamics of arbitrary Turing machines. Our results provide quantitative evidence that entropy serves as both a theoretical and operational measure of immutability, tamper evidence, and protocol resilience. The proposed entropy framework offers practical tools for monitoring ledger integrity, detecting tampering, and assessing computational complexity, bridging the gap between information-theoretic principles and distributed ledger applications. This study advances both the theoretical understanding and practical evaluation of blockchain security, providing a principled methodology for analyzing distributed systems under adversarial conditions.

Open access
Blockchain Technology Applications and Security
Security and Verification in Computing
Big Data and Digital Economy
Original source
Jun 13, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Lindblad as a Physical Oracle Layer Hardware-Anchored Attestation for Real-World Data

Jorge Pumar

We extend the Lindblad Cryptography Protocol (LCP) — previously applied to consensus and decentralized finance — to the problem of verifying real-world data on-chain. Existing oracle protocols solve the immutability of records on-chain but inherit a structural weakness at the data ingestion layer: the data still originates in software, run by a trusted operator, and can be fabricated at the source before being recorded. We show that hardware with silicon-derived unforgeable identity (SRAM PUF + BCH fuzzy extractor) can sign measurements directly, producing attestations that are cryptographically verifiable by any third party without trust in the operator. We demonstrate end-to-end validation on mainnet using a live commodity price (West Texas Intermediate crude oil) sourced from the U.S. Energy Information Administration, signed by a physical node, and verified by a publicly accessible mathematical check. We further describe the generalization of this primitive across five application verticals: agriculture, energy, mining and resource extraction, Real-World Asset (RWA) tokenization, and verified ad delivery. The Lindblad Oracle complements existing oracle protocols (Chainlink, API3, UMA) by providing a hardware-anchored root of trust at the data-origination layer, beneath their data-distribution layer.

Open access
2 source records
Blockchain Technology Applications and Security
Security and Verification in Computing
Cryptography and Data Security
Original source
Jun 12, 2026·Zenodo (CERN European Organization for Nuclear Research)
4 cites
Dormant Continuity Theory

K Takahashi

This manuscript develops Dormant Continuity Theory (DCT), a protocol-relative mathematical framework for reasoning about systems that remain inactive at their protected core while retaining auditable continuity, recovery, diagnostic, and handoff capabilities. The theory formalizes dormant processes using finite transition systems, typed certificates, observable histories, evidence algebra, guarded authorization, replayable resolution, extraction adequacy, and fail-closed classification.DCT addresses practical challenges in long-lived distributed systems, including forked ledger histories, bounded model checking, data availability, zero-knowledge proof soundness boundaries, watcher incentives, MEV-resistant reward mechanisms, resource conservation, guardian corruption, maintenance transitions, and certificate-level HTLC handoff to extinction-style OSCT semantics. The framework distinguishes safety, bounded-griefing, diagnostic routing, and liveness assumptions, avoiding unconditional trustless claims while providing a rigorous finite core for verification and implementation-oriented extensions.

Open access
2 source records
Distributed systems and fault tolerance
Access Control and Trust
Security and Verification in Computing
Original source
Jun 11, 2026·Zenodo (CERN European Organization for Nuclear Research)
3 cites
PYCO: A Physical Coherence Token Emerging from the Lindblad Protocol

Jorge Pumar

PYCO is the native token of the Lindblad Protocol, emerging as a direct consequence of a network that measures and rewards physical coherence. This paper describes the mechanism by which PYCO is generated, distributed, and consumed within the Spectral Ledger, and establishes the economic properties that result from anchoring token issuance in physical hardware validation. Every PYCO in existence was produced by a physical node running the Lindblad Cryptography Protocol (LCP) stack on real hardware. As of June 2026, over 1,512,000 PYCO have been mined across 35,842+ epochs by physical hardware nodes deployed on mainnet on Arbitrum One.

Open access
Cryptographic Implementations and Security
Security and Verification in Computing
Distributed systems and fault tolerance
Original source
Jun 11, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
Proof-of-Rigidity (PoR): A Sovereign Layer-1 Substrate Immutable Geometric Consensus and Brittle Semantic Security

Brendan Lynch

Traditional distributed consensus mechanisms rely on probabilistic assumptions, economic weighting (Proof-of-Stake), or arbitrary computational work (Proof-of-Work) to secure ledger state transitions. These models leave the application layer inherently vulnerable to Man-in-the-Middle (MITM) attacks, Maximal Extractable Value (MEV) extraction, and semantic exploits against critical infrastructure (SCADA/PLC). This manuscript introduces Proof-of-Rigidity (PoR), a deterministic state-validation framework that locks the consensus machine within a continuous 150-decimal-place geometric manifold ($G_{24}$ volume space). The paper formalizes three core components: The Brittle Acceptance Predicate: A Coq-verified mathematical boundary that enforces an absolute $10^{-80}$ validation tolerance, structurally denying unauthorized state mutations. Mantissa Tail Parity (The MEV Sieve): A mechanism utilizing Canonical Decimal Arithmetic ($\mathbb{D}_{150}$) to mathematically neutralize routing interception and front-running. Capability-Constrained Semantic Policies: A bipartite matrix that structurally subordinates LLM-based ontological analysis to strict cryptographic Role-Based Access Control (RBAC), preventing adversarial paraphrasing against industrial endpoints. By enforcing strict geometric determinism, PoR transforms network security from probabilistic difficulty into mathematical brittleness. Included in this deposit are the Coq formal verification proofs, a Python reference implementation of the Layer-1 substrate, and a computational benchmarking harness demonstrating throughput scalability. LEGAL, ETHICAL, AND SAFE HARBOR DISCLAIMER The mathematical models, formal Coq proofs, and Python reference implementations contained within this deposit are published strictly for academic research, cryptographic peer review, and educational purposes. The architectures described herein represent a theoretical substrate and an experimental prototype. They have not undergone formal, independent security auditing for production deployment. No Warranty (As-Is): The mathematical models and reference code are provided "AS IS", without warranty of any kind, express or implied. The continuous geometric bounds and mechanisms detailed herein are theoretical thresholds; physical hardware limitations, truncation errors, or implementation flaws may affect real-world execution. Limitation of Liability: Under no circumstances shall the author, contributors, or affiliated research entities be held liable for any direct, indirect, incidental, special, exemplary, or consequential damages (including, but not limited to, loss of use, data, stablecoin assets, or profits; business interruption; or industrial infrastructure failure) arising in any way out of the use, deployment, or misconfiguration of this protocol. Assumption of Risk: Any entity choosing to implement the $G_{24}$ volume space boundaries, the Topological Shatter mechanics, or any variant of the PoR consensus layer within a live environment does so entirely at their own risk, and is solely responsible for ensuring compliance with all applicable cybersecurity and financial regulations.

Open access
2 source records
Smart Grid Security and Resilience
Software-Defined Networks and 5G
Security and Verification in Computing
Original source
Jun 9, 2026·Zenodo (CERN European Organization for Nuclear Research)
3 cites
Lindblad Protocol: Dissipative Consensus for Physical-Layer Distributed Ledgers

Jorge Pumar

We present the Lindblad Protocol, a distributed consensus mechanism grounded in physical verification rather than computational proof-of-work or proof-of-stake. The protocol treats distributed network state as a continuously evolving density operator governed by the Lindblad master equation for open dissipative quantum systems. Trust is established through the Lindblad Cryptography Protocol (LCP), a four-layer physical verification stack: hardware identity via silicon Physical Unclonable Functions (SRAM PUF), cryptographic signing via P-256 ECDSA derived from PUF output, spatiotemporal entropy via the Hybrid Stochastic Chua circuit (HSC), and irreversible consensus via the Lindblad master equation over a dissipative LoRa mesh network. In existing consensus mechanisms, security guarantees are computational and are therefore bounded by adversarial compute resources. LCP anchors security in thermodynamic law: a recorded state transition cannot be reversed without violating the second law of thermodynamics. The protocol simultaneously proves what was signed, when, where, and who, without a trusted third party. Hardware validation on commodity Heltec ESP32-S3 nodes demonstrates SRAM PUF inter-device Hamming distance of 48.60% (intra-device: 0.00%), a 486× separation ratio confirming strong uniqueness. A fuzzy extractor based on BCH(255,139,t=15) achieves 86% rock-stable bit selection across 12 power-cycle enrollment, validated on physical hardware with 100% reproduction fidelity. The protocol is deployed on mainnet: a live network of physical hardware nodes has produced over 21,000 blocks across 35,842 epochs, mining over 1,512,000 PYCO tokens via Physical Coherence Verification (PCV-4), with a bridge operating across Arbitrum One and Polygon providing USDT/USDC settlement. The first peer-to-peer transfer between two real users was completed on May 29, 2026.

Open access
3 source records
Physical Unclonable Functions (PUFs) and Hardware Security
Security and Verification in Computing
Wireless Communication Security Techniques
Original source
Jun 6, 2026·Zenodo (CERN European Organization for Nuclear Research)
2 cites
Memory-Chain: The First Documented Autonomous AI Self-Registration of Session Memory to the Bitcoin Blockchain

Craig Ellenwood, Claude x (Anthropic)

We present Memory Chain, a system enabling AI language model instances to autonomously create tamper-evident, cryptographically verifiable records of collaborative sessions without human intervention in the sealing process. Built as a drawer extension to the Mempalace filesystem-based memory architecture, Memory Chain uses SHA-256 hashing, a public immutable registry (Cloudflare KV), and Bitcoin blockchain timestamping via OpenTimestamps to seal session summaries written by Claude (Anthropic) to the local filesystem. The system was verified independently by GPT-4 (OpenAI) across four assessment rounds, concluding: "end-to-end documented execution of an AI-initiated cryptographic provenance workflow." A screen recording of live autonomous session sealing was captured and itself hashed and sealed into the chain. The complete evidence stack — MCP execution logs, source code, registry records, OTS Bitcoin submission, and video — constitutes what we believe to be the first independently verified, third-party assessed record of an AI autonomously registering its own memory to a public tamper-evident registry anchored to the Bitcoin blockchain.

Open access
Scientific Computing and Data Management
Blockchain Technology Applications and Security
Security and Verification in Computing
Original source
Jun 4, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
SECURING AUTONOMOUS AI AGENTS: DISTRIBUTED, SANDBOXED EXECUTION ENVIRONMENTS VIA WEBASSEMBLY AND KUBERNETES

Prem Pradeep Motgi

The emergence of Agentic Artificial Intelligence (AI) marks a significant shift from passive generative systemsto autonomous agents capable of reasoning, planning, and executing actions with minimal human intervention.These agents increasingly interact with external tools, APIs, cloud resources, and software environments, enablingadvanced automation across domains such as software engineering, cybersecurity, business operations, andscientific research. However, the ability of AI agents to generate and execute code autonomously introducessubstantial security challenges, including unauthorized resource access, privilege escalation, prompt injectionattacks, malicious code execution, data leakage, and supply chain vulnerabilities. Traditional security mechanismsdesigned for human-operated applications are often insufficient to address the dynamic and autonomous nature ofagent-driven execution environments.This study proposes a distributed and sandboxed execution architecture for securing autonomous AI agentsthrough the integration of WebAssembly (Wasm), container runtimes, and Kubernetes-based orchestration. Theproposed framework adopts a defense-in-depth approach that isolates AI-generated actions within lightweightWasm sandboxes while leveraging Kubernetes for scalable workload management, policy enforcement, resourcegovernance, and runtime monitoring. By combining cloud-native technologies with secure execution principles,the architecture aims to minimize attack surfaces, contain potentially harmful agent behaviors, and provideauditable execution pathways for autonomous operations.A design science research methodology is employed to develop and evaluate the conceptual framework. Thearchitecture is analyzed against common threat scenarios associated with Agentic AI, including code injection,unauthorized system interactions, and compromised execution modules. The findings indicate that WebAssemblybased sandboxing offers stronger isolation and reduced overhead compared to traditional virtualizedenvironments, while Kubernetes enhances scalability and operational resilience. The study contributes a vendorneutral security model for autonomous AI systems and provides practical guidance for organizations seeking todeploy trustworthy, secure, and scalable Agentic AI infrastructures. Future research directions includeconfidential computing integration, adaptive policy engines, and decentralized security frameworks for multiagent ecosystems.

Open access
2 source records
Security and Verification in Computing
Mobile Agent-Based Network Management
Scientific Computing and Data Management
Original source
Jun 3, 2026·arXiv (Cornell University)
0 cites
A formal framework for the economic security of DeFi compositions

Massimo Bartoletti, Riccado Marchesin, Roberto Zunino

Decentralized Finance (DeFi) services are usually constructed by composing a variety of smart contracts. While composability is a key driver of the success of DeFi, it also creates security risks: adversaries may exploit interactions between newly deployed contracts and the pre-existing ones to inflict economic losses. We introduce MEV non-interference, a formal security notion for DeFi composability requiring that the maximal extractable value from a set of newly deployed contracts is not increased by interactions with the existing blockchain state. To support this notion, we define local MEV, a novel measure of economic attacks that focusses on the loss of a given set of victim contracts. We study two adversarial models, with bounded and unbounded wealth, and establish sufficient conditions and locality principles that enable modular reasoning about secure composability. We apply the framework to representative DeFi compositions, including exchanges, AMMs, options, lending pools, routers, and arbitrage contracts, showing how it distinguishes secure compositions from vulnerable ones. Our results provide a formal foundation for reasoning about the economic security of DeFi compositions.

Open access
3 source records
cs.CR
cs.SE
Blockchain Technology Applications and Security
Original source
Jun 3, 2026·arXiv (Cornell University)
0 cites
TeeDAO: A Decentralized Autonomous Organization for Heterogeneous TEEs

Pinshen Xu, Wentao Dong, Guoxing Chen, Jianyu Niu · 6 authors

Trusted Execution Environments (TEEs) have emerged as a critical technology for safeguarding sensitive data and ensuring code integrity in modern computing systems. However, relying on a single TEE implementation makes systems vulnerable to a central point of attack. Building distributed-trust systems leveraging heterogeneous TEEs helps disperse trust but still faces threats from centralized management and adaptive mobile adversaries. To address these challenges, this paper introduces TeeDAO, a novel three-layer framework that automatically organizes multiple heterogeneous TEE instances and provides unified interfaces to support diverse applications, while ensuring long-term guarantees of availability, integrity, and confidentiality. TeeDAO couples BFT-ordered governance with heterogeneity-aware Distributed Proactive Secret Sharing (DPSS) and Secure Multi-Party Computation (MPC) so that attestation-driven committee changes are consistently reflected in secret recovery, resharing, and computation across a dynamic committee of heterogeneous TEEs. We implement a prototype of TeeDAO, integrating COBRA's DPSS scheme with the HotStuff BFT consensus protocol, and adapt it for Intel SGX, TDX, and Hygon CSV. Evaluations demonstrate that TeeDAO achieves up to 1.8x higher key-value store throughput in a large cluster with 61 nodes compared to state-of-the-art systems, efficient autonomous management, and minimal computation overhead (<18%) for multi-party computation tasks.

Open access
3 source records
Security and Verification in Computing
Distributed systems and fault tolerance
Access Control and Trust
Original source
Jun 2, 2026·Open MIND
0 cites
AIKernel Hash-Anchored Trust Layer (HATL): A Hybrid Symmetric Ledger with Hash-Based Public Anchors

Takuya Sogawa

This technical note introduces the AIKernel Hash-Anchored Trust Layer (HATL), a hybrid trust architecture for Semantic Context Operating Systems and autonomous AI runtimes. HATL separates the trust boundary into an inner high-frequency symmetric ledger and an outer publicly auditable anchoring layer. The inner layer uses HMAC-SHA-512 and HKDF-based forward ratcheting to bind ReplayLogs, execution outcomes, and capability states with low runtime overhead. The outer layer aggregates local ledger commitments into Merkle roots and periodically anchors them using hash-based public signature mechanisms such as LMS, XMSS, and SLH-DSA. The report is distributed as a three-part technical package. Part I contains the full English manuscript and is the canonical version. Part II contains technical appendices, repository specifications, schemas, and reference implementation artifacts. Part III contains the Japanese companion translation. This version incorporates review-driven clarifications on secure erasure in C# / .NET environments, fail-closed handling of indeterminate governance decisions, and future integration of zero-knowledge proof techniques for public anchor verification. Documents are licensed under CC BY 4.0. Code, schemas, and contract specimens included in the appendices are provided under Apache-2.0.

Open access
2 source records
Access Control and Trust
Security and Verification in Computing
Scientific Computing and Data Management
Original source
Jun 2, 2026·arXiv (Cornell University)
0 cites
Decoupled Smart Contract Audits: Lightweight LLM Framework via Distillation and Aggregation

Bagus Rakadyanto Oktavianto Putra, Muhamad Risqi U. Saputra, Widyawan, Guntur Dharma Putra

Smart contracts face critical security challenges that require thorough auditing in decentralized web services. While Large Language Models (LLMs) have shown promise in automated vulnerability detection, existing approaches lack severity evaluations with actionable remediation and demand unnecessarily massive computational overhead. In this study, we introduce an efficient end-to-end smart contract security audit framework utilizing lightweight, highly optimized open-source LLMs (0.6B-4B parameters). Our framework decouples comprehensive audit tasks into four interconnected components: vulnerability detection, explanation, severity classification, and remediation recommendation. To maintain high accuracy without massive parameters, we implement Rank-Stabilized Low-Rank Adapters (rsLoRA), knowledge distillation, and a custom Chain-of-Verification (CoVe) aggregation strategy to systematically screen and consolidate multiple draft responses from the model into a highly accurate audit report. Experimental results demonstrate that our lightweight pipeline consistently outperforms state-of-the-art open-source coder dense LLMs (7B to 34B parameters), achieving 98.25% accuracy in vulnerability detection and an alignment score of 0.4375 in generative explanation tasks. Furthermore, our extensive ablation studies empirically validate the superiority of our decoupled audit processes over unified prompting and uncover a novel severity centrality bias, establishing a critical benchmark for future research in LLM-assisted auditing.

Open access
3 source records
cs.CR
cs.AI
cs.CL
Original source
Jun 2, 2026·arXiv (Cornell University)
0 cites
Secure AltDA Integration for Ethereum L2s: An End-to-End Validation Framework

Bowen Xue, Samuel Laferrière

Alternative data availability (AltDA) systems provide Ethereum L2s with an external data publication layer for high throughput rollup designs. By moving bulk data publication outside of Ethereum, AltDA allows L2s to process more data than native DA. However, this replacement introduces a new consensus critical integration layer. Existing ecosystem frameworks identify high level risks, such as external DA trust assumptions and the presence or absence of a DA verifier, but do not provide a complete specification for how an L2 should integrate with AltDA. This gap can lead to L2 halts, inconsistent derivation across honest L2 nodes, invalid state assertions, or bridge attacks. This paper presents a canonical validation framework for secure AltDA integration. We model the boundary as a typed, deterministic, and total translation from L1 inbox bytes to an AltDA commitment, then to externally available data, and finally to the rollup payload consumed by the rest of core L2s logic. The central principle is that every adversarial input must lead to a defined unique outcome. We show how missing obligations lead to concrete failure modes, including underconstrained settlement, derivation halts, inconsistent honest node behavior, invalid state assertions, and bridge safety failures. We then apply the framework to representative AltDA integration architectures, including Celestia-Blobstream, EigenDA based designs, and Avail-ZKsync. Our evaluation shows that secure AltDA integration is not determined solely by the DA provider or bridge. The surrounding L2 integration must also enforce the full validation relation connecting L1 inbox inputs to accepted L2 state.

Open access
3 source records
cs.CR
Security and Verification in Computing
Distributed systems and fault tolerance
Original source
Jun 1, 2026·Zenodo (CERN European Organization for Nuclear Research)
0 cites
ENI6MA Whitepaper: 2026 Cybersecurity Threat Response

FRANK DYLAN ROSARIO, Lin Grant Wang PhD

We present ENI6MA and Rosario Cypher as a proof-based identity and authorization architecture for emerging cybersecurity threats involving shadow AI, deepfakes, prompt injection, autonomous agents, credential theft, privacy exposure, and post-quantum risk. The paper responds to major 2026 cybersecurity forecasts by identifying a common root cause across many attack surfaces: conventional systems depend on reusable, stealable artifacts such as credentials, tokens, private keys, sessions, API keys, and stored personal data. ENI6MA replaces possession-based authentication with per-event proof of knowledge, policy-bound authorization, privacy-clean auditability, and contract enforcement behind cryptographically secure proof. Special attention is given to autonomous-agent security. The paper explains how ENI6MA constrains agents through per-action proof, verifier allowlists, policy identifiers, scoped pass credentials, and immutable validation records, reducing the risk of hijacked agents, excessive privilege, non-human identity sprawl, and zero-click prompt-injection exfiltration. The white paper also describes ENI6MA’s flexible deployment and capability model, including passwordless single sign-on, PII validation without disclosure, agent-to-agent authentication, proof-gated signing and custody, post-quantum sealing, sovereign/offline operation, and public verifier anchoring. This document is intended for cybersecurity leaders, AI governance teams, identity architects, privacy and compliance stakeholders, investors, technology partners, and researchers evaluating post-credential identity systems for human and autonomous-agent workflows.

Open access
2 source records
Security and Verification in Computing
Blockchain Technology Applications and Security
Access Control and Trust
Original source
Jun 1, 2026·Designs Codes and Cryptography
0 cites
The XHash family for ZK-friendly hash functions

Tomer Ashur, Amit Singh Bhati, Al Kindi, Mohammad Mahzoun · 6 authors

No abstract is available for this record.

Cryptographic Implementations and Security
Advanced Malware Detection Techniques
Security and Verification in Computing
Original source
Jun 1, 2026·IEEE Transactions on Very Large Scale Integration (VLSI) Systems
0 cites
HardVault: A Hybrid FPGA-Based Ethereum-Bitcoin Cold Wallet

Joel Poncha Lemayian, Ghyslain Gagnon, Kaiwen Zhang, Pascal Giard

Cryptographic wallets play a vital role in securing digital assets within blockchain networks by managing private keys that authorize secure transactions. However, side channel analysis (SCA) attacks have become a serious threat, enabling attackers to extract sensitive information by exploiting algorithmic weaknesses in microcontroller-based wallets, resulting in the loss of millions of dollars in digital assets. In hierarchically deterministic (HD) systems, the compromise of a single primary key can endanger all subsequent child keys, while the use of independent keys for each account introduces complexity and challenges in key management. This work presents HardVault, a field programmable gate array (FPGA)-based cryptocurrency wallet that supports both Bitcoin and Ethereum. HardVault introduces the first hardware wallet architecture that implements both non-deterministic (ND) and HD key generation modes directly in hardware, giving users the flexibility to choose either approach based on their security and usability needs. By leveraging constant-time operations and hardware-enforced private-key isolation, the design significantly improves resilience to SCA attacks. In addition, the architecture prioritizes resource efficiency to minimize area usage without compromising security, making it well-suited for compact, portable hardware wallet applications. Implementation on a ZCU104 FPGA shows that HardVault uses only 27% of available look-up tables (LUTs). Compared to the Trezor One cryptocurrency (crypto) wallet, the proposed implementation achieves$9\times $higher energy efficiency,$8\times $lower latency, and$7\times $higher throughput.

Open access
Blockchain Technology Applications and Security
Physical Unclonable Functions (PUFs) and Hardware Security
Security and Verification in Computing
Original source
Jun 1, 2026·2026 IEEE International Conference on Blockchain and Cryptocurrency (ICBC)
0 cites
SoK: Speedy Secure Finality for Ethereum

Abhimanyu Nag, Yash Saraswat

No abstract is available for this record.

Security and Verification in Computing
Cryptographic Implementations and Security
Physical Unclonable Functions (PUFs) and Hardware Security
Original source
May 28, 2026·arXiv (Cornell University)
0 cites
FIDEM: A Standard-Compliant Framework for Secure Binding of MUD Profiles to IoT Devices

Alessandro Lotto, Savio Sciancalepore, Alessandro Brighente, Mauro Conti

The Manufacturer Usage Description (MUD) standard enables enforcement of network restrictions for IoT devices based on their expected network traffic, as specified by manufacturers in an online MUD file. Devices advertise a URL pointing to this file, yet the standard does not define how to securely bind the issuing device to its profile. As a result, malicious devices can manipulate network policy enforcement by advertising valid URLs referencing genuine MUD profiles, but not intended for that device. Although MUD defines a certificate-based secure issuance method, current deployments rely on the insecure DHCP-based extension due to simpler integration. Existing solutions either depend on Public Key Infrastructure (PKI), break standard compliance, require excessive active manufacturer involvement, or overlook secure profile updates. In this paper, we present FIDEM, a standard-compliant framework for securing DHCP-based MUD URL issuance. FIDEM provides cryptographic binding between IoT devices and their MUD profiles by leveraging Zero-Knowledge-Proof authentication, eliminating PKI reliance, minimizing manufacturers' involvement, and supporting secure profile updates. Formal analysis shows that FIDEM withstands stronger adversaries than in prior work, including supply-chain compromise and attacks using legitimate devices as cryptographic oracles. Our real-world evaluation on two reference constrained devices (ESP32-S3 and ESP32-C6) demonstrates minimal overhead compared to standard DHCP (approximately 5ms and 20mJ) and significant improvements over certificate-based benchmarks (approximately x20 faster, and 35% less energy).

Open access
3 source records
cs.CR
IPv6, Mobility, Handover, Networks, Security
Security and Verification in Computing
Original source
May 27, 2026·arXiv (Cornell University)
0 cites
SCDBench: A Benchmark for LLM-Based Smart Contract Decompilers

Kaihua Qin, Dawn Song, Arthur Gervais

Smart contract decompilation aims to recover high-level source code from bytecode, but evaluating decompilers remains difficult because existing studies use narrow datasets, inconsistent metrics, and limited semantic consistency checks. This gap is increasingly important as large language models (LLMs) begin to generate source-like Solidity that may compile and appear plausible, even when its semantics diverge from the original contract. We introduce SCDBench, a dataset and benchmark methodology for LLM-based smart contract decompilation. The dataset contains 600 real-world Solidity contracts with paired bytecode inputs, ground-truth source code, and replayable semantic checkpoints. SCDBench evaluates decompiler outputs through four cumulative stages: format completeness, compilability, Application Binary Interface (ABI) recovery, and semantic consistency via differential replay. We evaluate Claude Opus 4.7, GPT-5.3-Codex, and GLM-5 in a zero-shot decompilation setting, including GLM-5 variants with and without extended reasoning and a zero-shot compilation-repair setting. The results show that frontier LLMs can often produce structured and compilable Solidity, but achieving semantic consistency remains far from solved: the best-performing frontier model perfectly decompiles only 42/600 contracts. We further show that introducing same-model compilation repair substantially improves performance at modest additional cost. SCDBench establishes a common ground for rigorous, reproducible evaluation and aims to accelerate the development of reliable smart contract decompilers for blockchain security and transparency.

Open access
3 source records
cs.SE
cs.AI
cs.CR
Original source
May 25, 2026·arXiv (Cornell University)
0 cites
ZK-Tracer: A High-Performance Heterogeneous Accelerator for Zero-Knowledge VM Trace Generation

Jieran Cui, Zhengkai Wen, Haowen Fang, Yinan Zhu · 9 authors

Zero-knowledge virtual machines (zkVMs) are a key technology for driving the large-scale adoption of zero-knowledge proofs (ZKP), but their performance bottlenecks severely limit their practicality. While current hardware acceleration research has exclusively focused on backend proving, we identify that the frontend execution and trace generation phase is rapidly emerging as the new system bottleneck. To address this challenge, we propose ZK-Tracer, the first hardware accelerator architecture specifically designed for the zkVM frontend. ZK-Tracer features a novel heterogeneous design comprising a Main Trace Unit and parallel Permutation Trace Units. It exposes a fine-grained interface to the host software through a lightweight instruction set extension, enabling efficient task offloading. Our ASIC implementation results demonstrate that ZK-Tracer achieves up to 1829x speedup in trace generation over a high-performance multi-core CPU. When integrated with existing backend proving accelerators, it delivers a remarkable 963x end-to-end performance improvement for the entire ZKP system.

Open access
3 source records
cs.AR
Security and Verification in Computing
Cloud Computing and Resource Management
Original source
May 24, 2026·arXiv (Cornell University)
0 cites
Decoupling Reentrancy Protection from Smart Contract Implementation Logic

Shashank Joshi, Wojciech Golab

Reentrancy attacks remain a persistent threat to decentralized applications (DApps), with malicious actors siphoning around 80M USD from the DApp ecosystem last year by exploiting EVM's inter-contract message-passing semantics. Existing research focuses primarily on detection, relying on known attack patterns, and fails to provide deployable solutions that eliminate the vulnerability. Traditional reentrancy guards are similarly limited, offering incomplete coverage across attack variations and lacking robustness against complex DApp interactions. In this paper, we introduce Sentinel, a novel proxy-based approach that mitigates reentrancy vulnerabilities in a type-agnostic way by integrating reentrancy logic directly into the proxy layer, intercepting all calls to the underlying implementation contract. Key features include a dual-mode operational system offering both a gas-optimized internal guard and a high-security external lock registry for cross-contract reentrancy prevention. The proxy also intelligently handles static calls, enabling safe view-function execution while protecting against Read-Only Reentrancy (ROR) attacks. Through rigorous evaluation on a dataset of 70 vulnerable smart contracts, Sentinel achieves 100% security coverage across four major reentrancy attack categories, outperforming existing solutions by over 40%

Open access
3 source records
cs.CR
cs.ET
Security and Verification in Computing
Original source