Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

1,615 papersLast indexed Aug 31, 2026
Search papers

Paper index

1,615 results · page 52 of 68

Clear filters
Jul 30, 2020·Balkan Journal of Electrical and Computer Engineering
11 cites
Blockchain Based Information Sharing Mechanism for Cyber Threat Intelligence

Ebubekir Buber, Özgür Koray Şahingöz

In recent years, networked computers are extensively used in every aspect of our daily lives. Besides, the anonymous structure of the Internet results in an increase in the number of attacks not only for individual users but also for local area networks. Current attacks are more sophisticated, and they are developed by experienced intruders with the use of automated malware production methods. These organized intrusions can go over the defense lines of the systems due to the weakness of the detection/prevention mechanisms or carelessness of individual users. After sneaking into the system, these attacks can work until they are detected, and they can access many critical resources of the company. Earlier detection of these attacks is very trivial issue for the security admins. This can be accomplished by acquiring the signature (critical information) of the newest attacks as early as possible. One suggested solution is the use of a Threat Information Sharing system, which is set up between security firms and authorities. This approach enables the distribution of the marks of the recent (zero-day) attacks and the development of some proactive prevention mechanisms for them. The use of both peer to peer and centralized sharing mechanisms have some inherited deficiencies. Therefore, in this paper, a pure decentralized cyber security information sharing system is proposed with the use of blockchain technology. A controlled decision-making mechanism, authorization termination, and rule-sets maintenance are proposed to make distributed decisions within the system. For making a decision, two smart contracts should be used in the blockchain. One holds the positive votes while the other holds the negative ones. Members of the system are able to access cyber threat data by using company-related queries. The system can facilitate the integration of many data sources into cyber security management system. Additionally, it enables to collect in a single repository that can be accessed for implementing real-time cyber security applications.

Open access
Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
Cybercrime and Law Enforcement Studies
Original source
Jul 30, 2020·The Information Society
46 cites
Cryptocurrencies and the emergence of blockocracy

Donncha Kavanagh, Paul J. Ennis

Blockocracies are a coherent, distinctive and novel organizational form bound by a collective ledger and a cryptocurrency. We frame our analysis of blockocracies against Weber’s enduring description of bureaucracy, identifying those features of Weberian bureaucracies that are present, absent or marginalized in blockocracies. In contrast to bureaucracy’s monocratic authority structure, authority in blockocracies is centered on four distinct layers. In each layer, there is governance of the code and governance by the code, and in the latter we distinguish between endogenous and exogenous rules. We also compare the “blockocrat” with Weber’s depiction of the bureaucrat.

Blockchain Technology Applications and Security
Crime, Illicit Activities, and Governance
Cybercrime and Law Enforcement Studies
Original source
Jul 28, 2020·New Journal of European Criminal Law
22 cites
Cooperation between Financial Intelligence Units in the European Union: Stuck in the middle between the General Data Protection Regulation and the Police Data Protection Directive

Foivi Mouzakiti

Financial Intelligence Units (FIUs) hold a central position in the chain of actors responsible for the monitoring of money movements in the European Union. In support of their role, which is to receive, analyse and disseminate suspicious transaction reports, they have been furnished with significant information processing powers. At present, FIUs feature prominently in the EU’s anti-money laundering and counterterrorist financing agendas and plans to further enhance their powers of information exchange are underway. At the same time, however, the legal challenges that arise from their constant empowerment, particularly for the protection of personal data, are being overlooked. This article focuses on the cooperation between FIUs in the EU and argues that the latter takes place under a complex legal framework, which raises significant challenges for data protection. In particular, it highlights the present-day uncertainty over the data protection framework that governs their operations and discusses whether FIUs should be subject to the General Data Protection Regulation or to its law enforcement counterpart, the Police Data Protection Directive. The remaining of the article focuses on the ‘ FIU.net ’ – the decentralized network for information exchanges between EU FIUs – and on the data protection challenges that emerged from the recent integration of this network into Europol.

Open access
Crime, Illicit Activities, and Governance
European Criminal Justice and Data Protection
Cybercrime and Law Enforcement Studies
Original source
Jul 26, 2020·Journal of Medical Internet Research
68 cites
Combating Health Care Fraud and Abuse: Conceptualization and Prototyping Study of a Blockchain Antifraud Framework

Tim K. Mackey, Ken Miyachi, Danny Fung, Samson Qian · 5 authors

BACKGROUND: An estimated US $2.6 billion loss is attributed to health care fraud and abuse. With traditional health care claims verification and reimbursement, the health care provider submits a claim after rendering services to a patient, which is then verified and reimbursed by the payer. However, this process leaves out a critical stakeholder: the patient for whom the services are actually rendered. This lack of patient participation introduces a risk of fraud and abuse. Blockchain technology enables secure data management with transparency, which could mitigate this risk of health care fraud and abuse. OBJECTIVE: The aim of this study is to develop a framework using blockchain to record claims data and transactions in an immutable format and to enable the patient to act as a validating node to help detect and prevent health care fraud and abuse. METHODS: We developed a health care fraud and abuse blockchain technical framework and prototype using key blockchain tools and application layers including consensus algorithms, smart contracts, tokens, and governance based on digital identity on the Ethereum platform (Ethereum Foundation). RESULTS: Our technical framework maps to the claims adjudication process and focuses on Medicare claims, with the US Centers for Medicare and Medicaid Services (CMS) as the central authority. A prototype of the framework system was developed using the blockchain platform Ethereum (Ethereum Foundation), with its design features, workflow, smart contract functions, system architecture, and software implementation outlined. The software stack used to build the system consisted of a front-end user interface framework, a back-end processing server, and a blockchain network. React was used for the user interface framework, and NodeJS and an Express server were used for the back-end processing server; Solidity was the smart contract language used to interact with a local Ethereum blockchain network. CONCLUSIONS: The proposed framework and the initial prototype have the potential to improve the health care claims process by using blockchain technology for secure data storage and consensus mechanisms, which make the claims adjudication process more patient-centric for the purposes of identifying and preventing health care fraud and abuse. Future work will focus on the use of synthetic or historic CMS claims data to assess the real-world viability of the framework.

Open access
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Organizational and Employee Performance
Original source
Jul 17, 2020·IEEE Network
121 cites
Smart Contract Vulnerability Analysis and Security Audit

Daojing He, Zhi Wen Deng, Yuxing Zhang, Sammy Chan · 6 authors

Ethereum started the blockchain-based smart contract technology that due to its scalability more and more decentralized applications are now based on. On the downside this has led to the exposure of more and more security issues and challenges, which has gained widespread attention in terms of research in the field of Ethereum smart contract vulnerabilities in both academia and industry. This article presents a survey of the Ethereum smart contract's various vulnerabilities and the corresponding defense mechanisms that have been applied to combat them. In particular, we focus on the random number vulnerability in the Fomo3d-like game contracts, as well as that attack and defense methods applied. Finally, we summarize the existing Ethereum smart contract security audit methods and compare several mainstream audit tools from various perspectives.

Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
Cybercrime and Law Enforcement Studies
Original source
Jul 16, 2020
6 cites
Applications of Blockchain in Digital Forensics and Forensics Readiness

M. Suresh Kumar

The advancement in information technology has changed our life significantly. No doubt, the Internet, smartphones, and social media have connected people and society. It has contributed to various aspects of our daily life. However, there is also a dark side of cyberspace, that is, cybercrime. It is becoming a global threat and needs technological solutions to combat. Whenever there is a crime, there is a law to curb the crime. The role of digital forensics is to understand the ‘Who, What, Where and Why’ of the incident. Digital forensics is a scientific process to collect, analyze, and present the evidence in a court of law. As it is used to link the person with criminal activities, it is crucial that the entire process of investigation be trustworthy. Managing the digital evidence and maintaining the chain of custody and integrity of digital evidence are utmost important. This chapter discusses the applications of blockchain technology to address the challenging issues faced by the digital investigation process and forensic readiness. The chapter also discusses the legal issues and admissibility of blockchain-based evidence in a court of law.

Digital and Cyber Forensics
Law, AI, and Intellectual Property
Cybercrime and Law Enforcement Studies
Original source
Jul 10, 2020·Journal of Money Laundering Control
11 cites
The implications of the Brexit from EU and bitcoin

Tareq Na’el Al-Tawil, Hassan Younies

Purpose The purpose of this paper is to tackle the most pressing issues confronting global anti-money laundering (AML) efforts, particularly, the implications of the Brexit from EU and the increasing association of bitcoin and cryptocurrencies with crimes. Design/methodology/approach This paper will evaluate the implications of Brexit to AML efforts and the threat that cryptocurrencies like bitcoin pose to the financial system. Findings Instead of banning trade and other transactions using BTC and other cryptocurrencies, financial experts, with the able assistance of IT and mining experts, from all over the world need to convene and tailor an effective regulatory framework. Solid cooperation among the international community, supported by unitary standards and procedures, will help boost the worlds AML/combatting the financing of terrorism (CFT) efforts. As an added bonus, effective regulation, monitoring and control can facilitate more efficient tax collection. Originality/value Recommendations were advanced about the future of AML/CFT efforts and the need for internationally holistic approaches in combatting these twin scourges on all economies.

Crime, Illicit Activities, and Governance
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Original source
Jul 9, 2020·European Journal of Crime Criminal Law and Criminal Justice
35 cites
Laundering the Profits of Ransomware

Bart Custers, J.J. Oerlemans, Ronald Pool

Ransomware is malicious software (malware) that blocks access to someone’s computer system or files on the system and subsequently demands a ransom to be paid for unlocking the computer or files. Ransomware is considered one of the main threats in cybercrime today. Cryptoware is a specific type of ransomware, which encrypts files on computer systems. The ransom is often demanded in bitcoins. Based on desk research, a series of interviews, and the investigation of several police files, this paper investigates the modi operandi in which cybercriminals use ransomware and cryptoware to make profits and how they launder these profits. Two models, based on the payment of the ransom via vouchers and via bitcoins respectively, are identified and described. These methods allow criminals to launder profits in relative anonymity and prevent the seizure of the illegally obtained money.

Open access
Advanced Malware Detection Techniques
Spam and Phishing Detection
Cybercrime and Law Enforcement Studies
Original source
Jul 9, 2020·Arabian Journal for Science and Engineering
248 cites
Blockchain for COVID-19: Review, Opportunities, and a Trusted Tracking System

Dounia Marbouh, Tayaba Abbasi, Fatema Maasmi, Ilhaam A. Omar · 8 authors

<p>The sudden development of the COVID-19 pandemic exposed the limitations in modern healthcare systems to handle public health emergencies. It is evident that adopting innovative technologies such as blockchain can help in effective planning operations and resource deployments. Blockchain technology can play an important role in the healthcare sector such as improved clinical trial data management by reducing delays in regulatory approvals, streamline the communication between diverse stakeholders of the supply chain etc. Moreover, the spread of misinformation has intensely increased during the outbreak and existing platforms lack the ability to validate the authenticity of data, causing people to panic and act irrationally. Thus, developing a blockchain-based tracking system is important to ensure that the information received by the public and government agencies are reliable and trustworthy. In this paper, we focus on blockchain abilities to track the COVID-19 data collected from various sources including news, healthcare professionals, researchers etc, verify and append them in a secure and trusted distributed ledger. Thus, we propose a generic framework using Ethereum smart contracts and oracles to track real-time data related to the number of new cases, deaths and recovered cases obtained from trusted sources. We present detailed algorithms that capture the interactions between stakeholders in the network. The smart contract code was developed and tested in Remix environment. We present the cost and security analysis incurred by the stakeholders and highlight the challenges and future directions of our work. Our work demonstrates that the proposed solution is economically feasible and ensures data integrity, security, transparency, data traceability among stakeholders. </p>

Open access
3 source records
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Retinal Imaging and Analysis
Original source
Jul 5, 2020·Journal of Money Laundering Control
31 cites
Discerning payment patterns in Bitcoin from ransomware attacks

Adam Turner, Stephen McCombie, Allon J. Uhlmann

Purpose The purpose of this paper is to investigate available forensic data on the Bitcoin blockchain to identify typical transaction patterns of ransomware attacks. Specifically, the authors explore how distinct these patterns are and their potential value for intelligence exploitation in support of countering ransomware attacks. Design/methodology/approach The authors created an analytic framework – the Ransomware–Bitcoin Intelligence–Forensic Continuum framework – to search for transaction patterns in the blockchain records from actual ransomware attacks. Data of a number of different ransomware Bitcoin addresses was extracted to populate the framework, via the WalletExplorer.com programming interface. This data was then assembled in a representation of the target network for pattern analysis on the input (cash-in) and output (cash-out) side of the ransomware seed addresses. Different graph algorithms were applied to these networks. The results were compared to a “control” network derived from a Bitcoin charity. Findings The findings show discernible patterns in the network relating to the input and output side of the ransomware graphs. However, these patterns are not easily distinguishable from those associated with the charity Bitcoin address on the input side. Nonetheless, the collection profile over time is more volatile than with the charity Bitcoin address. On the other hand, ransomware output patterns differ from those associated charity addresses, as the attacker cash-out tactics are quite different from the way charities mobilise their donations. We further argue that an application of graph machine learning provides a basis for future analysis and data refinement possibilities. Research limitations/implications Limitations are evident in the sample size of data taken on ransomware campaigns and the “control” subject. Further analysis of additional ransomware campaigns and “control” subjects over time would help refine and validate the preliminary observations in this paper. Future research will also benefit from the application of more powerful computing resources and analytics platforms that scale with the amount of data being collected. Originality/value This research contributes to the maturity of the field by analysing ransomware-Bitcoin behaviour using the Ransomware–Bitcoin Intelligence–Forensic Continuum. By combining several different techniques to discerning patterns of ransomware activity on the Bitcoin network, it provides insight into whether a ransomware attack is occurring and could be used to trigger alerts to seek additional evidence of attack, or could corroborate other information in the system.

Cybercrime and Law Enforcement Studies
Advanced Malware Detection Techniques
Crime, Illicit Activities, and Governance
Original source
Jul 1, 2020·2020 Second International Conference on Inventive Research in Computing Applications (ICIRCA)
18 cites
Video Fraud Detection using Blockchain

Aditya Dhiran, D. Dinesh Kumar, Abhishek, Anshul Arora

This paper has considered the problem of Video Fraudulence, i.e., attackers can tamper with the original video and can create a fake video of their own. This problem is of great practical importance given the massive volume of online videos available through the World Wide Web, Internet news feeds, electronic mail, corporate databases, and digital libraries. To the best of our knowledge, no such video fraud detection algorithm has been proposed in the literature that can detect, using Blockchain, whether the video has been tampered with. This paper is a comparative study and provides a prototype of how it applies Blockchain to detect video fraudulence. The focus is on the usability of Blockchain and how to implement it to get the desired result. Three features of Blockchain that are Decentralization, Data transparency, and Security and privacy are being used to provide a reliable solution. Some cryptographic algorithms are used to find unique feature in all of the videos that can act as the hash value of the video because, in Blockchains, every node stores the data in the form of the hash value. If the video is tampered with, then the hash value changes and hence any fraud in the video can be detected.

Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Cybercrime and Law Enforcement Studies
Original source
Jul 1, 2020·arXiv
0 cites
The Bisq DAO: On the Privacy Cost of Participation

Liam Hickey, Martin Harrigan

The Bisq DAO is a core component of Bisq, a decentralized cryptocurrency exchange. The purpose of the Bisq DAO is to decentralize the governance and finance functions of the exchange. However, by interacting with the Bisq DAO, participants necessarily publish data to the Bitcoin blockchain and broadcast additional data to the Bisq peer-to-peer network. We examine the privacy cost to participants in sharing this data. Specifically, we use a novel address clustering heuristic to construct the one-to-many mappings from participants to addresses on the Bitcoin blockchain and augment the address clusters with data stored within the Bisq peer-to-peer network. We show that this technique aggregates activity performed by each participant: trading, voting, transfers, etc. We identify instances where participants are operating under multiple aliases, some of which are real-world names. We identify the dominant transactors and their role in a two-sided market. We conclude with suggestions to better protect the privacy of participants in the future.

Open access
2 source records
cs.CR
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Original source
Jul 1, 2020·2020 IEEE Fifth International Conference on Data Science in Cyberspace (DSC)
11 cites
A Study of Bitcoin De-Anonymization: Graph and Multidimensional Data Analysis

Xingyu Lv, Zhong Ye, Qingfeng Tan

Bitcoin was designed to be a decentralized global electronic payment system that does not require verification by a third-party intermediary platform and can be used by anyone originally. Due to its anonymity and globalization, bitcoin has achieved great success and attracted the attention of various illegal traders. In recent years, the number of illegal transactions of bitcoin has been increasing. Although bitcoin can support a certain amount of privacy, the bitcoin users and entity information can be linked by tracking the on-chain information of bitcoin users and combining the public off-chain information. Through bitcoin users de-anonymization, we can obtain some valuable intelligence information, which plays an important role in combating bitcoin-related crimes. In this paper, we build a visual analysis system for bitcoin transactions based on a graph database and use real-world multi-dimensional data sources to analyze the entity information of bitcoin transactions on the chain to achieve the effect of de-anonymization. Besides, we adopt a supervised learning method in our system to predict the legitimacy of unknown bitcoin transactions. Experiments and analyses show that our system can achieve good correlation analysis and de-anonymization. Finally, we put forward the future research direction of the bitcoin de-anonymization field.

Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Crime, Illicit Activities, and Governance
Original source
Jul 1, 2020·Proceedings of the Twenty-Ninth International Joint Conference on Artificial Intelligence
192 cites
Phishing Scam Detection on Ethereum: Towards Financial Security for Blockchain Ecosystem

Weili Chen, Xiongfeng Guo, Zhiguang Chen, Zibin Zheng · 5 authors

In recent years, blockchain technology has created a new cryptocurrency world and has attracted a lot of attention. It also is rampant with various scams. For example, phishing scams have grabbed a lot of money and has become an important threat to users' financial security in the blockchain ecosystem. To help deal with this issue, this paper proposes a systematic approach to detect phishing accounts based on blockchain transactions and take Ethereum as an example to verify its effectiveness. Specifically, we propose a graph-based cascade feature extraction method based on transaction records and a lightGBM-based Dual-sampling Ensemble algorithm to build the identification model. Extensive experiments show that the proposed algorithm can effectively identify phishing scams.

Open access
2 source records
Blockchain Technology Applications and Security
Spam and Phishing Detection
Cybercrime and Law Enforcement Studies
Original source
Jun 27, 2020·Journal of Money Laundering Control
63 cites
Cryptocurrencies and financial crime: solutions from Liechtenstein

Fabian Teichmann, Marie-Christin Falker

Purpose The purpose of this paper is to illustrate how cryptocurrencies are being used as a vehicle for financial crime (such as money laundering, terrorist financing and corruption) and propose a more effective international standard for regulation that uses the Liechtenstein blockchain act as a benchmark. Design/methodology/approach This paper investigates how cryptocurrencies facilitate financial crime through a qualitative study consisting of interviews with 10 presumed providers of illegal financial services and 18 international compliance experts. Findings This study shows that cryptocurrencies are a highly suitable vehicle for money laundering, terrorist financing and corruption and that current compliance efforts in the cryptocurrency sector are ineffective. Research limitations/implications The presented findings illustrate that for a more effective combat of financial crime via cryptocurrency, an international standard for blockchain and cryptocurrency regulation must be created. This paper suggests that Liechtenstein’s innovative and comprehensive blockchain act could be used as a basis for said standard. Practitioners should also consider cooperating transnationally when prosecuting financial crime via cryptocurrency. Originality/value The fact that cryptocurrencies facilitate financial crime is widely known. However, this study combines the perspectives of both compliance experts and presumed criminals to gain a comprehensive understanding of the techniques that money launderers, terrorist financiers and corrupt public officials use. This paper examines the potential for the innovative Liechtenstein blockchain act, which has, thus, far not received empirical attention, to set the benchmark for international regulations.

Crime, Illicit Activities, and Governance
Cybercrime and Law Enforcement Studies
Blockchain Technology Applications and Security
Original source
Jun 19, 2020·Proceedings of the 2020 5th International Conference on Machine Learning Technologies
73 cites
Comparative Analysis Using Supervised Learning Methods for Anti-Money Laundering in Bitcoin

Ismail Alarab, Simant Prakoonwit, Mohamed Ikbal Nacer

With the advance of Bitcoin technology, money laundering has been incentivised as a den of Bitcoin blockchain, in which the user's identity is hidden behind a pseudonym known as address. Although this trait permits concealing in the plain sight, the public ledger of Bitcoin blockchain provides more power for investigators and allows collective intelligence for anti-money laundering and forensic analysis. This fascinating paradox arises in the strength of Bitcoin technology. Machine learning techniques have attained promising results in forensic analysis, in order to spot suspicious behaviour in Bitcoin blockchain. This paper presents a comparative analysis of the performance of classical supervised learning methods using a recently published data set derived from Bitcoin blockchain, to predict licit and illicit transactions in the network. Besides, an ensemble learning method is utilised using a combination of the given supervised learning models, which outperforms the given classical methods. This experiment is performed using a newly published data set derived from Bitcoin blockchain. Our main contribution points out that using ensemble learning approach outperforms the performance of the classical learning models used in the original paper, using Elliptic data set, a time series of Bitcoin transaction graph with node transactions and directed payments flow edges. Using the same data set, we show that we are able to predict licit/illicit transactions with an accuracy of 98.13% and F1 score equals to 83.36% using the proposed method. We discuss the variety of supervised learning methods, and their capabilities of assisting forensic analysis, and propose future work directions.

2 source records
Blockchain Technology Applications and Security
Crime, Illicit Activities, and Governance
Cybercrime and Law Enforcement Studies
Original source
Jun 16, 2020·Utrecht University Repository (Utrecht University)
1 cites
Laundering the Profits of Ransomware: Money Laundering Methods for Vouchers and Cryptocurrencies

Bart Custers, J.J. Oerlemans, Ronald Pool

Ransomware is malicious software (malware) that blocks access to someone’s computer system or files on the system and subsequently demands a ransom to be paid for unlocking the computer or files. Ransomware is considered one of the main threats in cybercrime today. Cryptoware is a specific type of ransomware, which encrypts files on computer systems. The ransom is often demanded in bitcoins. Based on desk research, a series of interviews, and the investigation of several police files, this paper investigates the modi operandi in which cybercriminals use ransomware and cryptoware to make profits and how they launder these profits. Two models, based on the payment of the ransom via vouchers and via bitcoins respectively, are identified and described. These methods allow criminals to launder profits in relative anonymity and prevent the seizure of the illegally obtained money.

Open access
Cybercrime and Law Enforcement Studies
Crime, Illicit Activities, and Governance
Spam and Phishing Detection
Original source
May 1, 2020·2020 IEEE International Conference on Blockchain and Cryptocurrency (ICBC)
10 cites
Wallet Contracts on Ethereum

Monika di Angelo, Gernot Salzer

On the blockchain, cryptocurrencies play a role similar to cash, while cryptographic tokens are a universal tool for handling rights and assets. Software wallets interact with blockchains in general and with smart contracts (on-chain programs) in particular. Some wallets are realized (partly) as smart contracts with the intent to increase trust and security by being transparent and by offering features like daily limits, approvals, multiple signatures, and recovery mechanisms. Ethereum is the most prominent platform for both, tokens and smart contracts, and thus also for wallet contracts. We discuss several methods for identifying wallet contracts in a semi-automatic manner by looking at the deployed bytecodes and their interaction patterns. Furthermore, we differentiate characteristics of wallets in use, and group them into six types.

Open access
Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
Cybercrime and Law Enforcement Studies
Original source
May 1, 2020·2020 IEEE International Conference on Blockchain and Cryptocurrency (ICBC)
27 cites
Mining blocks in a row: A statistical study of fairness in Bitcoin mining

Shengnan Li, Yang Zhao, Claudio J. Tessone

The Bitcoin system keeps its ledger consistent in a blockchain by solving cryptographic problems, in a method called "Proof-of-Work". The conventional wisdom asserts that the mining protocol is incentive-compatible. However, Eyal and Sirer in 2014 have discovered a mining attack strategy called selfish mining (SM), in which a miner (or a mining pool) publishes the blocks it mines selectively instead of immediately. SM strategy would have the impact of wasting resources of honest miners. Scholars proposed various extensions of the SM strategy and approaches to defense the SM attack. Whether selfish mining occurs in practice or not, has been subject of extensive debate. For the first time, in this paper we propose a method to identify selfish miners by detecting anomalies in the properties of consecutive blocks' statistics. Furthermore, we extend our method to detect the mining cartels, in which miners secretly get together and share timely information. Our results provide evidence that these strategic behaviors take place in practice.

Open access
Blockchain Technology Applications and Security
Crime, Illicit Activities, and Governance
Cybercrime and Law Enforcement Studies
Original source
May 1, 2020·2020 IEEE International Conference on Blockchain and Cryptocurrency (ICBC)
39 cites
From Hodl to Heist: Analysis of Cyber Security Threats to Bitcoin Exchanges

Kris Oosthoek, Christian Doerr

Bitcoin is gaining traction as an alternative store of value. Its market capitalization transcends all other cryptocurrencies in the market. But its high monetary value also makes it an attractive target to cyber criminal actors. Hacking campaigns usually target the weakest points in an ecosystem. In Bitcoin, these are currently the exchange platforms. As each exchange breach potentially decreases Bitcoin's market value by billions, it is a threat not only to direct victims, but to everyone owning Bitcoin. Based on an extensive analysis of 36 breaches of Bitcoin exchanges, we show the attack patterns used to exploit Bitcoin exchange platforms using an industry standard for reporting intelligence on cyber security breaches. Based on this we are able to provide an overview of the most common attack vectors, showing that all except three hacks were possible due to relatively lax security. We also show that while the security regimen of Bitcoin exchanges is not on par with other financial service providers, the use of stolen credentials, which does not require any hacking, is decreasing. We also show that the amount of BTC taken during a breach is decreasing, as well as the exchanges that terminate after being breached. With exchanges being targeted by nation-state hacking groups, security needs to be a first concern.

Blockchain Technology Applications and Security
Crime, Illicit Activities, and Governance
Cybercrime and Law Enforcement Studies
Original source
May 1, 2020·arXiv (Cornell University)
58 cites
Tracing Cryptocurrency Scams: Clustering Replicated Advance-Fee and Phishing Websites

Ross C. Phillips, Heidi Wilder

Over the past few years, there has been a growth in activity, public knowledge, and awareness of cryptocurrencies and related blockchain technology. As the industry has grown, there has also been an increase in scams looking to steal unsuspecting individuals' cryptocurrency. Many of the scams operate on visually similar but seemingly unconnected websites, advertised by malicious social media accounts, which either attempt an advance-fee scam or operate as phishing websites. This paper analyses public online and blockchain-based data to provide a deeper understanding of these cryptocurrency scams. The clustering technique DBSCAN is applied to the content of scam websites to discover a typology of advance-fee and phishing scams. It is found that the same entities are running multiple instances of similar scams, revealed by their online infrastructure and blockchain activity. The entities also manufacture public blockchain activity to create the appearance that their scams are genuine. Through source and destination of funds analysis, it is observed that victims usually send funds from fiat-accepting exchanges. The entities running these scams cash-out or launder their proceeds using a variety of avenues including exchanges, gambling sites, and mixers.

Open access
3 source records
Spam and Phishing Detection
Blockchain Technology Applications and Security
Cybercrime and Law Enforcement Studies
Original source