While blockchain technology triggers new industrial and technological revolutions, it also brings new challenges. Recently, a large number of new scams with a "blockchain" sock-puppet continue to emerge, such as Ponzi schemes, money laundering, etc., seriously threatening financial security. Existing fraud detection methods in blockchain mainly concentrate on manual feature and graph analytics, which first construct a homogeneous transaction graph using partial blockchain data and then use graph analytics to detect anomaly, resulting in a loss of pattern information. In this paper, we mainly focus on Ponzi scheme detection and propose HFAug, a generic Heterogeneous Feature Augmentation module that can capture the heterogeneous information associated with account behavior patterns and can be combined with existing Ponzi detection methods. HFAug learns the metapath-based behavior characteristics in an auxiliary heterogeneous interaction graph, and aggregates the heterogeneous features to corresponding account nodes in the homogeneous one where the Ponzi detection methods are performed. Comprehensive experimental results demonstrate that our HFAug can help existing Ponzi detection methods achieve significant performance improvement on Ethereum datasets, suggesting the effectiveness of heterogeneous information on detecting Ponzi schemes.
ASIC Kings (Company name: Boðeind EHF | Identification number: 6907871569) is based in Reykjavik - Iceland, we are an experienced supplier dedicated to providing our customers with the best cryptocurrency mining equipment.
As one of the most complex types of vulnerabilities, reentrancy poses a significant threat to smart contract development. Indeed, millions of dollars have evaporated due to reentrancy vulnerabilities of smart contracts in past years. In this article, we propose a new approach to detect reentrancy vulnerabilities using fuzz testing and develop a novel tool named ReDefender. Our approach consists of three main steps: 1)preprocess contract to be detected:when a contract is uploaded, its source code will be preprocessed to extract candidate pool for fuzzing and dependency graph which guides the automatic deployment of contracts; 2)fuzzing input generation:fuzzing input is generated to constitute transactions which will be sent to an agent contract to stimulate attacks, where runtime information is collected and recorded in the execution log during each execution; and 3)vulnerability verification:the execution log is analyzed to determine whether a reentrancy process occurs and whether the reentrancy process is malicious. We conduct comparative experiments on 204 tagged smart contracts and 90 injected contracts. The results show higher accuracy and lower false negative rate of ReDefender than that of the other three famous tools. Moreover, we conduct an experiment on 4776 real-world contracts demonstrating the ability of ReDefender to find reentrancy vulnerabilities that really cause economic losses.
Cryptocurrencies have dramatically increased adoption in mainstream applications in various fields such as financial and online services, however, there are still a few amounts of cryptocurrency transactions that involve illicit or criminal activities. It is essential to identify and monitor addresses associated with illegal behaviors to ensure the security and stability of the cryptocurrency ecosystem. In this paper, we propose a framework to build a dataset comprising Bitcoin transactions between 12 July 2019 and 26 May 2021. This dataset (hereafter referred to as BABD-13) contains 13 types of Bitcoin addresses, 5 categories of indicators with 148 features, and 544,462 labeled data, which is the largest labeled Bitcoin address behavior dataset publicly available to our knowledge. We also propose a novel and efficient subgraph generation algorithm called BTC-SubGen to extract a${k}$-hop subgraph from the entire Bitcoin transaction graph constructed by the directed heterogeneous multigraph starting from a specific Bitcoin address node. We then conduct 13-class classification tasks on BABD-13 by five machine learning models namely${k}$-nearest neighbors algorithm, decision tree, random forest, multilayer perceptron, and XGBoost, the results show that the accuracy rates are between 93.24% and 97.13%. In addition, we study the relations and importance of the proposed features and analyze how they affect the effect of machine learning models. Finally, we conduct a preliminary analysis of the behavior patterns of different types of Bitcoin addresses using concrete features and find several meaningful and explainable modes.
Crypto Kitties is one of the most well-known games built on the Ethereum blockchain and has been in operation for a longer time. This paper examines the market’s fairness by focusing on the gene determination algorithm required for breeding two kittens. This method has very little unpredictability, and as a result, players who understand it have a considerable edge over those who do not. Furthermore, this paper demonstrates a methodology that aims to increase randomness in the gene determination algorithm by associating it with a discrete crossover operator. In the end, this paper addresses some of the drawbacks of crypto kitties and countermeasures to overcome them.
Ardeshir Shojaeinasab, Amir Pasha Motamed, Behnam Bahrak
Abstract Cryptocurrencies, particularly Bitcoin, have garnered attention for their potential in anonymous transactions. However, their anonymity has often been compromised by deanonymization attacks. To counter this, mixing services have been introduced. While they enhance privacy, they obscure fund traceability. This study seeks to demystify transactions linked to these services, shedding light on pathways of concealed and laundered money. We propose a method to identify and classify transactions and addresses of major mixing services in Bitcoin. Unlike previous research focusing on older techniques like CoinJoin, we emphasize modern mixing services. We gathered labelled data by transacting with three prominent mixers (MixTum, Blemder, and CryptoMixer) and identified recurring patterns. Using these patterns, an algorithm was created to pinpoint mixing transactions and distinguish mixer‐related addresses. The algorithm achieved a remarkable recall rate of 100%. Given the lack of clear ground truth and the vast number of unlabelled transactions, ensuring accuracy was a challenge. However, by analyzing a set of non‐mixing transactions with our model, it was confirmed that the high recall rate was not misleading. This work provides a significant advancement in monitoring mixing transactions, presenting a valuable tool against fraud and money laundering in cryptocurrency networks.
This paper examines the relationship between events reported in international news via categorical discourses and Bitcoin price. Natural language processing was adopted in this study to model data-driven discourses in the crypto-economy, specifically the Bitcoin market. Using topic modelling, namely Latent Dirichlet Allocation, a text analysis of cryptocurrency articles ( N = 4218) published from 60 countries in international news media identified key topics associated with cryptocurrency in the international news media from 2018 to 2020. This study provides empirical evidence that across the corpora of international news articles, 18 key topics were framed around the following categorical macro discourses: crypto-related crime, financial governance, and economy and markets. Analysis shows that the identified discourses may have had a ‘social signal’ effect on movements in the crypto-financial markets, particularly on Bitcoin's price volatility. Results show these specific discourses proved to have a negative effect on Bitcoin's market price, within 24 h of when the crypto news articles were published. Further, the study found that in some cases, the source of the news may have amplified the volatility effect, particularly in terms of geographical region, relative to broader market conditions.
Jinho Choi, Taehwa LEE, Kwanwoo KIM, Min-Jae Seo · 6 authors
Bitcoin is currently a hot issue worldwide, and it is expected to become a new legal tender that replaces the current currency started with El Salvador. Due to the nature of cryptocurrency, however, difficulties in tracking led to the arising of misuses and abuses. Consequently, the pain of innocent victims by exploiting these bitcoins abuse is also increasing. We propose a way to detect new signatures by applying two-fold NLP-based clustering techniques to text data of Bitcoin abuse reports received from actual victims. By clustering the reports of text data, we were able to cluster the message templates as the same campaigns. The new approach using the abuse massage template representing clustering as a signature for identifying abusers is much efficacious.
Julio Jesús Salas Conde, Manuel Martín Ortiz, Victor Manuel Carneiro Díaz
The Fourth Industrial Revolution has propelled global society into a new era of information and knowledge, transforming the economy and society of many countries. The global digitization process impacts more than half of the world population with internet access and the increase in the incidence of crimes in cyberspace, affecting the population mainly online fraud, crimes that attack vulnerable groups such as girls, boys and adolescents, as well as the diversity of cyberattacks with an impact on the availability, integrity and confidentiality of essential data and information systems of public, private and academic institutions. Most of these antisocial behaviors are published on the Deep Internet due to its anonymity, one of these being the TOR browser project (The Onion Router), in order to address this problem, a methodology was developed that allows the authorities in Mexico have a database that allows correlating data published on this network with the investigations they carry out derived from reports of cybercrimes to obtain lines of investigation based on the identification and classification of cybercrime, and using language engineering techniques and of knowledge as the methods of creation of ontologies of Ding, Y; Foo, S; recovery tool for large information files on websites such as wget, security measures for browsing the Deep Internet such as "Whonix Gateway", "Text Cleaning" techniques, extraction and classification features such as "Jaccard and Cosine Similarity Calculation", among other.
This thesis presents techniques to investigate transactions in uncharted cryptocurrencies and services. Cryptocurrencies are used to securely send payments online. Payments via the first cryptocurrency, Bitcoin, use pseudonymous addresses that have limited privacy and anonymity guarantees. Research has shown that this pseudonymity can be broken, allowing users to be tracked using clustering and tagging heuristics. Such tracking allows crimes to be investigated. If a user has coins stolen, investigators can track addresses to identify the destination of the coins. This, combined with an explosion in the popularity of blockchain, has led to a vast increase in new coins and services. These offer new features ranging from coins focused on increased anonymity to scams shrouded as smart contracts. In this study, we investigated the extent to which transaction privacy has improved and whether users can still be tracked in these new ecosystems. We began by analysing the privacy-focused coin Zcash, a Bitcoin-forked cryptocurrency, that is considered to have strong anonymity properties due to its background in cryptographic research. We revealed that the user anonymity set can be considerably reduced using heuristics based on usage patterns. Next, we analysed cross-chain transactions collected from the exchange ShapeShift, revealing that users can be tracked as they move across different ledgers. Finally, we present a measurement study on the smart-contract pyramid scheme Forsage, a scam that cycled $267 million USD (of Ethereum) within its first year, showing that at least 88% of the participants in the scheme suffered a loss. The significance of this study is the revelation that users can be tracked in newer cryptocurrencies and services by using our new heuristics, which informs those conducting investigations and developing these technologies.
Criminals have become increasingly experienced in using cryptocurrencies, such as Bitcoin, for money laundering. The use of cryptocurrencies can hide criminal identities and transfer hundreds of millions of dollars of dirty funds through their criminal digital wallets. However, this is considered a paradox because cryptocurrencies are goldmines for open-source intelligence, giving law enforcement agencies more power when conducting forensic analyses. This paper proposed Inspection-L, a graph neural network (GNN) framework based on a self-supervised Deep Graph Infomax (DGI) and Graph Isomorphism Network (GIN), with supervised learning algorithms, namely Random Forest (RF), to detect illicit transactions for anti-money laundering (AML). To the best of our knowledge, our proposal is the first to apply self-supervised GNNs to the problem of AML in Bitcoin. The proposed method was evaluated on the Elliptic dataset and shows that our approach outperforms the state-of-the-art in terms of key classification metrics, which demonstrates the potential of self-supervised GNN in the detection of illicit cryptocurrency transactions.
Security issues are increasing day by day all over the world. Cyber issues are one of the major issues that cause cyber-attacks involving Malware, Phishing, and Ransomware attack. Pakistan is also one of the major countries that are facing cybercrime issues. The most important firms are government agencies like NADRA, Law Firm, and Police Firm. Pakistan has still not made a refined structure to ensure its security from advanced risks. By, and by it has transformed into a national security hazard for Pakistan because the individual data of the government is not secured. Multiple attacks on the NADRA server have occurred in the past. The reason is the centralization server, and security flaws. With the coming of Technology in the 21st century, and security worries that happens due to cybercrimes. Individuals are currently pushing toward new advances, the main thing that comes in the mind to keep away from security hazards, is to circulate the information among various individuals, so the idea of decentralization comes in. A technology that recently has gathered a lot of attention is Blockchain technology. Its decentralized nature gives secure, secret, and basic intends to keep up the records without alteration. Blockchain provides immutability, Integrity, helps enhanced security, distributed ledger, and also provides consensuses. So for government organizations like NADRA data is the most important thing, if this data is compromised due to security flaws then it’s happened a national security hazard that causes leakages of the nation's personal information. So this thesis purpose how to secure data using Blockchain technology a private Blockchain technology. An architectural view is presented with the help of use cases for government organizations NADRA, Police Firm, and Law Firm using HLF Blockchain technology. This thesis also presents the design, and architecture of how organizations work, and interact with one another. Using this design, and architecture we will be able to provide forensic to government organization data which makes it more secure from cyber threats.
In the age of virtual currency's prosperity, the privacy of virtual currency cannot be ignored. By comparing the degree of privacy of Monero and Bitcoin and analyzing the technical background of Monero, it is found that the encryption method and privacy of Monero will become a major mainstream trend leading to the digital currency in the future. Through the discussion of the privacy, security, and non-traceability of Monero, we found that the security of Monero is obvious to all. The forecast of future market analysis compares the future development trend, market supply, and profitable rate of return of Monero and Bitcoin, confirming that Monero's market outlook is very impressive. Facing the emergence of digital currencies such as Zcash and Dash, Monero will still become the mainstream currency that will lead the development of digital currencies in the future.
In the same way that personal data provide irrefutable information about individuals, they sometimes reveal the legal identity of contracts as well as other specific information. The data a contract generates could represent a competitive advantage. This study's focus was to develop a template of the factors associated with smart contracts data breaches. This model was based on the following variables: smart contracts, exposure level, security level, and structural inputs. The outcome variable was the binary value for a data breach/no data breach. This study covers more than 6000 smart contracts, operating on Etheurm and imported as tables into the study database, the contracts have been selected randomly from the databases of various safety tools such as OYENTE, MAIAN, GASPER, Securify, Solcove, and SmartCheck, These tools are designed to find code vulnerabilities in the smart contracts. 50% of all samples were selected from one source (Securify). Binary logistic regression was employed to examine the data breach model. The findings demonstrate more than 500 cases of actual breaches, with several factors being significantly associated with smart contract data breaches.
The Internet of Things (IoT) is a concept that is transforming our everyday life. Because of its capacity to change people's lives, it has become a vital element of our lives. IoT devices are being used by an increasing number of businesses because they provide new opportunities for wearable devices, home appliances, and healthcare. With all of these possibilities, the risks associated with IoT security are increasing. One of the most challenging aspects of any IoT application is device identification. Things in the IoT share and process data without the need for human interaction. As a result of their total authority, these entities must authenticate and recognize one another effectively. Failure to legitimately authenticating the IoT devices can make them vulnerable to a number of assaults such as DDoS and replay attacks. It is nearly hard to develop an effective authentication system due to the size and other characteristics of IoT. Although a lot of work has been done on this issue, the majority of these solutions rely on a centralized system. These centralized systems are segregated and incompatible with one another, making information exchange between them impossible. In addition, once a centralized authority is attacked, the user's privacy can be exposed easily. Proof of security, decentralization, and anonymity characteristics of blockchain can help address these issues. With blockchain technology applied to IoT systems, obstacles to IoT architecture development and security can be overcome. This paper, therefore, focuses on covering current advancements made in the application of blockchain for authentication in IoT. There is a lack of survey papers on the use of blockchain for authentication in IoT this paper will serve as an aide. This paper will also add to the knowledge of researchers who are interested in IoT security.
Abstract With the wide application and development of blockchain technology in various fields such as finance, government affairs and medical care, security incidents occur frequently on it, which brings great threats to users’ assets and information. Many researchers have worked on blockchain abnormal behavior awareness in respond to these threats. We summarize respectively the existing public blockchain and consortium blockchain abnormal behavior awareness methods and ideas in detail as the difference between the two types of blockchain. At the same time, we summarize and analyze the existing data sets related to mainstream blockchain security, and finally discuss possible future research directions. Therefore, this work can provide a reference for blockchain security awareness research.
Abstract The COVID-19 pandemic and lockdown pushed several groups of traders to rely on cryptocurrency as one of the chosen tools for commercial transactions. India is no exception. Because of its notorious misuses by criminal gangs, the Reserve Bank of India (RBI) declared cryptocurrency as derecognized. Consequently, the Indian parliament also created a draft bill titled Banning of Cryptocurrency & Regulation of Official Digital Currency Bill, 2019 (the Bill), which not only derecognizes the currency or the use of it for any commercial purposes, it also makes the investors, exchanges and agencies dealing with cryptocurrency criminally liable. Later, the Supreme Court of India in 2020 set aside the above-mentioned RBI guidelines banning cryptocurrency. But this has not nullified or suggested any amendment for the Bill. This article argues that due to this legal confusion, cryptocurrency investors, traders, exchanges and agencies, etc. have become guardian-less victims who may not be eligible to claim basic rights of victims as has been established by the United Nations Declaration of Basic Principles of Justice for Victims of Crime and Abuse of Power. In such a legal tangle, it is necessary to analyse the issues from cyber-victimological perspectives for providing functional suggestions for restitution of justice.
Smart Contracts are general-purpose programs that provide a higher level of security than traditional contracts and reduce other transaction costs associated with the bargaining practice, as they are executed in a Blockchain infrastructure. Developers use smart contracts to build their tokens and set up gambling games, crowd sales, ICO, and many others domains of application. The security of Smart Contracts is also crucial, as SCs at the very core level, move money. In recent years, researchers have provided a set of known vulnerabilities that afflict SCs. This study analyzed the relationship between the SC domain of application, domain category, and known vulnerabilities. We categorized the SC using the topic modeling on a curated dataset of SC annotated with know vulnerabilities. Indeed, we found that a certain category of SC is strongly associated with specific vulnerabilities.
Finans, sağlık, sosyal medya vb ortamlardaki insanların ihtiyacı olan güven problemine blok zinciri teknolojisi, şifreli algoritmalar ile çözümler sunmaktadır. Güven problemini çözen ve verileri dağıtık olarak kayıt altına alan ve her şeyi şeffaf olarak bizlere sunan blok zinciri bir devrim niteliğindedir. Blok zinciri, akıllı sözleşmeler sayesinde kurumsal projelerde de kullanabilmektedir. Kurumların arasında yeni nesil bir ağ olarak da adlandırılan blok zinciri ile bir çok şeyin değişmesi beklenmektedir. İnternetin, mobile cihazların ve sensörlerin yaygınlaşmasıyla birlikte güven problemi her geçen gün daha da önem kazanmaktadır. Farklı amaçlara hizmet eden Ethereum, Cardano, EOS, Cosmos, Hyperledger gibi blok zincir platformları vardır. Altyapılarında Proof of Work (PoW), Proof of Stake (PoS), Delegated Proof of Stake (DPoS) ve Directed Acyclic Graph (DAG) gibi farklı fikir birliği mekanizmalarını kullanmaktadırlar. Bu çalışmada blok zinciri platformları, altyapılarında kullandıkları mutabakat mekanizmaları ve blok zinciri ağının güvenliği araştırılmıştır.
The key issue in the field of smart contract security is efficient and rapid vulnerability detection in smart contracts. Most of the existing detection methods can only detect the presence of vulnerabilities in the contract and can hardly identify their type. Furthermore, they have poor scalability. To resolve these issues, in this study, we developed a smart contract vulnerability detection model based on multi-task learning. By setting auxiliary tasks to learn more directional vulnerability features, the detection capability of the model was improved to realize the detection and recognition of vulnerabilities. The model is based on a hard-sharing design, which consists of two parts. First, the bottom sharing layer is mainly used to learn the semantic information of the input contract. The text representation is first transformed into a new vector by word and positional embedding, and then the neural network, based on an attention mechanism, is used to learn and extract the feature vector of the contract. Second, the task-specific layer is mainly employed to realize the functions of each task. A classical convolutional neural network was used to construct a classification model for each task that learns and extracts features from the shared layer for training to achieve their respective task objectives. The experimental results show that the model can better identify the types of vulnerabilities after adding the auxiliary vulnerability detection task. This model realizes the detection of vulnerabilities and recognizes three types of vulnerabilities. The multi-task model was observed to perform better and is less expensive than a single-task model in terms of time, computation, and storage.
Blockchain is a progression of associated information structures called blocks, which contain or track all that occurs in disseminated frameworks in a distributed organization. Each block is connected to the previous block with an uncommon pointer called a hash pointer, forming a chain and resulting in a framework consisting of annexes: A perpetual and irreversible history that can be utilized as a constant review trail by any member to check the precision of the records by essentially surveying information itself. The chapter will discuss the role of blockchain in digital forensics with an introduction to blockchain technology and its applications and challenges. It also explores the architecture and protocols related to blockchain technology. The chapter also highlights the managing of digital evidence by maintaining the chain of custody with the help of Ethereum and Hyperledger. It will also enlighten readers about the application of blockchain for distributed cloud storage in digital forensics. It will reveal the role of blockchain in digital forensics, which will be helpful for cybercrime investigation, blockchain technology, and digital forensics enthusiasts, students, PhD scholars and researchers.
Abstract Online markets in cryptocurrency represent a sprawling and eclectic alternative financial system, selling cutting edge techno-investment schemes that are complex and high risk. Crime control is almost entirely absent from this new crypto economy, and it is full of scams. This paper draws on an ethnography of crypto trading to review the main types of scam, suggesting that the grey economy of cryptocurrency trading is part of a wider evolution of society towards the technosocial, and beyond that perhaps towards the metaversal.