Bitcoin remains the most widely used cryptocurrency. It has attracted users from tech enthusiasts to commercial investors to criminals, in no small part due to its reputation for anonymity. While not designed primarily for privacy, Bitcoin's architecture contains several provisions that can be exploited by criminals to conduct illegal activity including money laundering and collecting payments from ransomware and scams. Since Bitcoin's creation in 2008, various groups such as law enforcement, lawyers, criminals and privacy-focused Bitcoin users have been locked in a struggle between attempts to reveal hidden Bitcoin users' identities and attempts to keep those identities concealed. We present a survey of the techniques used within Bitcoin to reveal or conceal users' identities. We provide an easy to understand explanations of how these techniques work and provide a cross reference of which revealing techniques are effective for specific concealing techniques.
Charla GriffyโBrown, Karen Johnson, Howard Miller, Mark Chun
Blockchain, or distributed ledger, continues to be deployed in the healthcare, energy, manufacturing, financial services sectors, and retail. Blockchain advocates argue that this technology constitutes a new architectural foundation for building trust based on its unique technological characteristics (Glaser 2017). However, cybersecurity is not a function of technological architecture but, in fact, is critically bound by human elements, processes, and actors. Therefore, all emerging technologies have cyber risk. Given the disruptive nature of this technology, there is a strong business need to understand cyber risk associated with blockchain. With this in mind, this investigation posed the following research questions: What are the risks associated with blockchain? Can a risk-based approach be validated or extended by exploring cases of blockchain deployment and highlighting risk? Multiple qualitative methods were used to analyze the data and to identify trends. This analysis identified cyber risk, in the context of blockchain, using the simple and generally accepted definition of cyber security as confidentiality, integrity, and availability (CIA). Based on the results, a cyber-physical risk-based approach was developed and blockchain deployment was examined in specific cases to identify and analyze the breaches according to this framework. The results demonstrate that beyond technological and data architecture there a strong need to further identify and analyze the cybercriminal actors and behavior in order to address cyber risk.
Bitcoin uses blockchain technology to maintain transactions order and provides probabilistic guarantees to prevent double-spending, assuming that an attackerโs computational power does not exceed 50% of the network power. In this article, we design a novel bribery attack and show that this guarantee can be hugely undermined. Miners are assumed to be rational in this setup, and they are given incentives that are dynamically calculated. In this attack, the adversary misuses the Bitcoin protocol to bribe miners and maximize their gained advantage. We will reformulate the bribery attack to propose a general mathematical foundation upon which we build multiple strategies. We show that, unlike Whale Attack, these strategies are practical, especially in the future when halvings lower the mining rewards. In the so-called โguaranteed variable-rate bribing with commitmentโ strategy, through optimization by Differential Evolution (DE), we show how double-spending is possible in the Bitcoin ecosystem for any transaction whose value is above 218.9BTC, and this comes with 100% success rate. A slight reduction in the success probability, e.g., by 10%, brings the threshold down to 165BTC. If the rationality assumption holds, then this shows how vulnerable blockchain-based systems like Bitcoin are. We suggest a soft fork on Bitcoin to fix this issue at the end.
Mohammad Raihanul Hasan, Shiming Deng, Neegar Sultana, Muhammed Zakir Hossain
Purpose Blockchain technology, a key feature of the fourth industrial revolution, is receiving widespread attention and exploration around the world. Taking the coronavirus pandemic as an example, the purpose of this study to examine the application of blockchain technology from the perspective of epidemic prevention and control. Design/methodology/approach Exploring multiple case studies in the Chinese context at various stages of deployment, this study documents a framework about how some of the major challenges associated with COVID-19 can be alleviated by leveraging blockchain technology. Findings The case studies and framework presented herein show that utilization of blockchain acts as an enabler to facilitate the containment of several COVID-19 challenges. These challenges include the following: complications associated with medical data sharing; breaches of patients' data privacy; absence of real-time monitoring tools; counterfeit medical products and non-credible suppliers; fallacious insurance claims; overly long insurance claim processes; misappropriations of funds; and misinformation, rumors and fake news. Originality/value Blockchain is ushering in a new era of innovation that will lay the foundation for a new paradigm in health care. As there are currently insufficient studies pertaining to real-life case studies of blockchain and COVID-19 interaction, this study adds to the literature on the role of blockchain technology in epidemic control and prevention.
Smart contracts have been plagued by security incidents, which resulted in substantial financial losses. Given numerous research efforts in addressing the security issues of smart contracts, we wondered how software practitioners build security into smart contracts in practice. We performed a mixture of qualitative and quantitative studies with 13 interviewees and 156 survey respondents from 35 countries across six continents to understand practitioners' perceptions and practices on smart contract security. Our study uncovers practitioners' motivations and deterrents of smart contract security, as well as how security efforts and strategies fit into the development lifecycle. We also find that blockchain platforms have astatistically significant impact on practitioners' security perceptions and practices of smart contract development. Based on our findings, we highlight future research directions and provide recommendations for practitioners.
Giacomo Ibba, Giuseppe Antonio Pierro, Marco Di Francesco
Ethereum is one of the most popular platforms for exchanging cryptocurrencies as well as the most established for peer to peer programming and smart contracts publishing [3]. The versatility of the Solidity language allows developers to program general-purpose smart contracts. Among the various smart contracts, there may be some fraudulent ones, whose purpose is to steal Ether from the network participants. A notorious example of such cases are Ponzi schemes, i.e. a financial frauds that require investors to be repaid through the investments of others who have just entered the scheme. Within the Ethereum blockchain, several contracts have been identified as being Ponzi schemes. The paper proposes a machine learning model that uses textual classification techniques to recognize contracts emulating the behavior of a Ponzi scheme. Starting from a contracts dataset containing exclusively Ponzi schemes uploaded between 2016 and 2018, we built models able to properly classify Ponzi schemes contracts. We tested several models, some of which returned an overall accuracy of 99% on classification. The best model turned out to be the linear Support Vector Machine and the Multinomial Naive Bayes model, which provides the best results in terms of metrics evaluation.
The rapid growth of Decentralized Finance (DeFi) boosts the Ethereum ecosystem. At the same time, attacks towards DeFi applications (apps) are increasing. However, to the best of our knowledge, existing smart contract vulnerability detection tools cannot be directly used to detect DeFi attacks. That's because they lack the capability to recover and understand high-level DeFi semantics, e.g., a user trades a token pair X and Y in a Decentralized EXchange (DEX). In this work, we focus on the detection of two types of new attacks on DeFi apps, including direct and indirect price manipulation attacks. The former one means that an attacker directly manipulates the token price in DEX by performing an unwanted trade in the same DEX by attacking the vulnerable DeFi app. The latter one means that an attacker indirectly manipulates the token price of the vulnerable DeFi app (e.g., a lending app). To this end, we propose a platform-independent way to recover high-level DeFi semantics by first constructing the cash flow tree from raw Ethereum transactions and then lifting the low-level semantics to high-level ones, including token trade, liquidity mining, and liquidity cancel. Finally, we detect price manipulation attacks using the patterns expressed with the recovered DeFi semantics. We have implemented a prototype named \tool{} and applied it to more than 350 million transactions. It successfully detected 432 real-world attacks in the wild. We confirm that they belong to four known security incidents and five zero-day ones. We reported our findings. Two CVEs have been assigned. We further performed an attack analysis to reveal the root cause of the vulnerability, the attack footprint, and the impact of the attack. Our work urges the need to secure the DeFi ecosystem.
The bitcoin, one of the most discussed topics in recent years, is a virtual currency with enormous potential and can be used almost immediately with no intervention from financial institutions. It has spread rapidly over the last few years, and all financial and governmental institutions have warned of the risk of its use for money laundering. The paper focuses on this aspect in order to understand if any purchases of bitcoins, using illicit money, can come under the anti-money laundering criminal law. Keywords: Bitcoin; Money laundering; Italian law; Cryptocurrency.
Evidence destruction and tempering is a time-tested tactic to protect the powerful perpetrators, criminals, and corrupt officials. Countries where law enforcing institutions and judicial system can be comprised, and evidence destroyed or tampered, ordinary citizens feel disengaged with the investigation or prosecution process, and in some instances, intimidated due to the vulnerability to exposure and retribution. Using Distributed Ledger Technologies (DLT), such as blockchain, as the underpinning technology, here we propose a conceptual model - 'EvidenceChain', through which citizens can anonymously upload digital evidence, having assurance that the integrity of the evidence will be preserved in an immutable and indestructible manner. Person uploading the evidence can anonymously share it with investigating authorities or openly with public, if coerced by the perpetrators or authorities. Transferring the ownership of evidence from authority to ordinary citizen, and custodianship of evidence from susceptible centralized repository to an immutable and indestructible distributed repository, can cause a paradigm shift of power that not only can minimize spoliation of evidence but human rights abuse too. Here the conceptual model was theoretically tested against some high-profile spoliation of evidence cases from four South Asian developing countries that often rank high in global corruption index and low in human rights index.
Antonio Lรณpez Vivar, Ana Lucila Sandoval Orozco, Luis Javier Garcรญa Villalba
The use of blockchain and smart contracts have not stopped growing in recent years. Like all software that begins to expand its use, it is also beginning to be targeted by hackers who will try to exploit vulnerabilities in both the underlying technology and the smart contract code itself. While many tools already exist for analyzing vulnerabilities in smart contracts, the heterogeneity and variety of approaches and differences in providing the analysis data makes the learning curve for the smart contract developer steep. In this article the authors present ESAF (Ethereum Security Analysis Framework), a framework for analysis of smart contracts that aims to unify and facilitate the task of analyzing smart contract vulnerabilities which can be used as a persistent security monitoring tool for a set of target contracts as well as a classic vulnerability analysis tool among other uses.
The analysis of separate tools for the visualization of movement of cryptocurrency values, and also identification of users who carried out the corresponding transactions has been carried out. The advantages and disadvantages of cryptocurrency from the point of view of offenders and law enforcement agencies have been studied. The main directions of using cryptocurrency in a criminal environment have been determined. The current state and perspectives of normative and legal regulation of cryptocurrency in Ukraine have been analyzed. Theoretical principles of cryptocurrency functioning have been studied. The basic concepts used in this area have been revealed. The properties of cryptocurrency have been described. The mechanism of its issuance of guaranteeing pseudo-anonymity while working with cryptocurrency has been outlined. Some features of blockchain technology and formation of cryptocurrency addresses have been revealed. It has been noted that one of the first and most well-known cryptocurrency is bitcoin. The format of bitcoin address presentation has been described. It has been emphasized that bitcoin wallet software can operate with any number of addresses or each address can be served by a separate wallet. The technology of mixing transactions and the method of increasing the anonymity of CoinJoin have been described. The authors have revealed the possibilities of separate services intended for the analysis of cryptocurrency transactions (Maltego, Bitconeview, Bitiodine, OpReturnTool, Blockchain.info, Anyblockanalytics.com, Chainalysis, Elliptic, Ciphertrace, Blockchain Inspector). The process of risk assessment and construction of visual chains of cryptocurrency transactions has been demonstrated on the example of the โCrystal Expertโ service. Different types of bitcoin addressesโ holders and risk levels have been described. The main and additional investigation tools used on the โCrystal Expertโ platform have been revealed. Based on the conducted analysis, the authors have defined the main tasks for law enforcement agencies at the current stage of development of cryptocurrency. The basic requirements for tools designed for cryptocurrency analysis have been outlined. The authors have suggested some measures of law enforcement agenciesโ respond to threats related to cryptocurrency.
Guglielmo Maria Caporale, Woo-Young Kang, Fabio Spagnolo, Nicola Spagnolo
This paper provides comprehensive evidence on the effects of cyber-attacks (cyber-crime, cyber espionage, cyber warfare and hacktivism) and cyber security on the risk-adjusted returns, realised volatilities and trading volumes of the three main cryptocurrencies (Bitcoin, Ethereum and Litecoin).We find that stronger cyber security is generally effective in increasing the riskadjusted returns of cryptocurrencies and trading activity even in the presence of cyber-attacks.Hacktivism appears to be the most significant threat to cryptocurrency investors.Further, cyberattackers hitting the cryptocurrency exchanges are most likely to attack other sectors (government, industry and finance) as well.In addition, in the case of the US they target the government and industry sectors in preference to the cryptocurrency exchanges given the corresponding potential benefits and costs.In all cases appropriate strategies should be designed to enhance cyber security.
Evidence management is crucial in the field of forensic science. Evidences obtained from a crime scene are important in solving the case and delivering justice to the parties involved. Hence, protecting these evidences from any form of alteration is of utmost important. Chain of Custody is the process which maintains the integrity of evidence. Inability to maintain the chain of custody will make the evidence inadmissible in court, eventually leading to the case dismissal. Digitalization of forensic evidence management system is a need of time as it is an environment friendly model. Blockchains are digitally distributed ledgers of transactions signed cryptographically in chronological order that are sorted into blocks and is completely open to anyone in the blockchain network. Hyperledger Fabric is a consortium blockchain framework created by the Linux foundation and is mainly used for enterprise use. Based on the concept of Hyperledger Fabric, present study aimed to create a framework and further propose an algorithm to implement Blockchain Technology to digitalize forensic evidence management system and maintain Chain of Custody.
Abstract Ethereum attracts extensive attention due to its distinctive function of smart contract and decentralized applications (Dapps). Since the number of contracts on blockchain has increased vigorously, various security vulnerabilities come up. Researchers rely on static symbolic analysis method at first, and it seems to perform well in the accuracy of vulnerability detection. However, this method requires manual analysis in advance and it needs to traverse all the possible execution paths to find out the vulnerable ones. The deeper the path goes, the more time it costs to detect the contracts. This paper proposes an approach to detect smart contracts vulnerability on blockchain by using machine learning(ML) methods. This approach aims to build a general benchmark for new vulnerability detection in order to reduce the demand of expert manpower. Moreover, the high-speed-performance ML algorithm makes quick detection comes true. As long as we adjust the threshold of the model, it can work as a fast prefilter for the traditional symbolic analysis tools in further improvement of accuracy.
The focus on cryptocurrencies in the finance and banking sectors is gaining momentum. In this paper, we investigate the role of cryptocurrencies in modern finance. We apply a narrative literature review method to synthesize prior research and draw insights into the opportunities and challenges of leveraging cryptocurrencies. The results indicate that cryptocurrencies offer businesses and individualsโ lower transaction costs, higher efficiencies, increased security and privacy, meaningful diversification benefits, alternative financing solutions, and financial inclusion.Challenges exist related to the integration of cryptocurrencies in modern finance. These include the lack of regulatory standards, the risk of criminal activity, high energy and environmental costs, regulatory bans and usage restrictions, security and privacy concerns, and the high volatility of cryptocurrencies.The current review is useful for scholars and managers, including those seeking to have a more balanced understanding of these emerging financial instruments.JEL Classification: E42, F30, F65, G21, G23How to Cite:Rejeb, A., Rejeb, K., & Keogh, J. G. (2021). Cryptocurrencies in Modern Finance: a Literature Review. Etikonomi, 20(1), 93 โ 118. https://doi.org/10.15408/etk.v20i1.16911.
Ayman Alkhalifah, Alex Ng, Paul Watters, A. S. M. Kayes
In Ethereum blockchain, smart contracts are immutable, public, and distributed. However, they are subject to many vulnerabilities stemming from coding errors made by developers. Seven cybersecurity incidents occurred in Ethereum smart contracts between 2016 and 2018, which led to financial losses estimated to be over US$ 289 million. Reentrancy vulnerability was the cause of two of these incidents, and the impacts went far beyond financial loss. Several reentrancy countermeasures are available, which are based on predefined patterns that are used to prevent vulnerability exploitation before the deployment of a smart contract; however, several limitations have been identified in these countermeasures. Motivated by all these issues, the objective of this article is to help developers improve the cybersecurity of smart contracts by proposing a solution that calculates the difference between the contract balance and the total balance of all participants in a smart contract before and after any operation in a transaction that changes its state. Proof-of-concept implementations show that this solution can provide a detection and prevention mechanism against reentrancy attacks during the execution of any smart contract.
In this work we propose Dynamit, a monitoring framework to detect reentrancy vulnerabilities in Ethereum smart contracts. The novelty of our framework is that it relies only on transaction metadata and balance data from the blockchain system; our approach requires no domain knowledge, code instrumentation, or special execution environment. Dynamit extracts features from transaction data and uses a machine learning model to classify transactions as benign or harmful. Therefore, not only can we find the contracts that are vulnerable to reentrancy attacks, but we also get an execution trace that reproduces the attack. Using a random forest classifier, our model achieved more than 90 percent accuracy on 105 transactions, showing the potential of our technique.
In today's digital era, data is most important in every phase of work. The storage and processing on data with security is the need of each and every application field. Data need to be tamper resistant due to possibility of alteration. Data can be represented and stored in heterogeneous format. There are chances of attack on information which is vital for particular organization. With rapid increase in cyber crime, attackers behave maliciously to alter those data. But it is having great impact on forensic evidences which is required for provenance. Therefore, it is required to maintain the reliability and provenance of digital evidences as it travels through various stages during forensic investigation. In this approach, there is a forensic chain in which generated report passes through various levels or intermediaries such as pathology laboratory, doctor, police department etc. To build the transparent system with immutability of forensic evidences, blockchain technology is more suitable. Blockchain technology provides the transfer of assets or evidence reports in transparent environment without central authority. In this paper blockchain based secure system for forensic evidences is proposed. The proposed system is implemented on Ethereum platform. The tampering of forensic evidence can be easily traced at any stage by anyone in the forensic chain. The security enhancement of forensic evidences is achieved through implementation on Ethereum platform with high integrity, traceability and immutability.
Discusses the growing trend for criminals to burgle the homes of bitcoin holders and force them to disclose the password to their cryptocurrency. Reviews the operation of crypto asset systems, and considers, with reference to three hypothetical scenarios, how such "rubber hose" attacks might be prosecuted, including whether they constitute "property" offences for the purposes of theft and burglary convictions under the Theft Act 1968.