Abstract Stratum, the de-facto mining communication protocol used by blockchain based cryptocurrency systems, enables miners to reliably and efficiently fetch jobs from mining pool servers. In this paper we exploit Stratumâs lack of encryption to develop passive and active attacks on Bitcoinâs mining protocol, with important implications on the privacy, security and even safety of mining equipment owners. We introduce StraTap and ISP Log attacks, that infer miner earnings if given access to miner communications, or even their logs. We develop BiteCoin, an active attack that hijacks shares submitted by miners, and their associated payouts. We build BiteCoin on WireGhost, a tool we developed to hijack and surreptitiously maintain Stratum connections. Our attacks reveal that securing Stratum through pervasive encryption is not only undesirable (due to large overheads), but also ineffective: an adversary can predict miner earnings even when given access to only packet timestamps. Instead, we devise Bedrock, a minimalistic Stratum extension that protects the privacy and security of mining participants. We introduce and leverage the mining cookie concept, a secret that each miner shares with the pool and includes in its puzzle computations, and that prevents attackers from reconstructing or hijacking the puzzles. We have implemented our attacks and collected 138MB of Stratum protocol traffic from mining equipment in the US and Venezuela. We show that Bedrock is resilient to active attacks even when an adversary breaks the crypto constructs it uses. Bedrock imposes a daily overhead of 12.03s on a single pool server that handles mining traffic from 16,000 miners.
Ponzi schemes are financial frauds which lure users under the promise of high profits. Actually, users are repaid only with the investments of new users joining the scheme: consequently, a Ponzi scheme implodes soon after users stop joining it. Originated in the offline world 150 years ago, Ponzi schemes have since then migrated to the digital world, approaching first the Web, and more recently hanging over cryptocurrencies like Bitcoin. Smart contract platforms like Ethereum have provided a new opportunity for scammers, who have now the possibility of creating "trustworthy" frauds that still make users lose money, but at least are guaranteed to execute "correctly". We present a comprehensive survey of Ponzi schemes on Ethereum, analysing their behaviour and their impact from various viewpoints.
Increasingly in e-commerce, smart contracts have relied on the code as the contract. But code can be hacked and fail, leaving multiple parties potentially exposed to legal gray areas, great financial loss, and little recourse. Here, Kieron O'Hara considers the ramifications of such contracts by exploring what happened when the Ethereum platform was hacked in the summer of 2016.
In December 2013 the People's Bank of China announced the restriction of Bitcoin from being involved in any services offered by financial institutions in China, fearing that the speculative risks inherent in Bitcoin is too new for Chinese investors and may endanger the national financial system. This article reviews the Bitcoin's evolvement both as currency and as investment asset around the world. Also, the regulatory treatment for Bitcoin in America is discussed. Then I used detrended ratios to compare the volatility of Bitcoin market and China's stock market, concluding that the risks inherent in Bitcoin are not unacceptable for Chinese investors. Moreover, I searched into the relationship between Bitcoin return and some fundamental economic variables, finding that Bitcoin doesn't have enough correlation with the national economic system to depress investors further during an economic downturn and that Bitcoin actually has excellent diversification benefit as portfolio component.
We review seminal social science theories of Trust & Control to consider how their application to Blockchain and Cryptocurrency (DLT, e.g., Bitcoin, Ethereum, Ripple) provide the potential for fresh criminal and information security challenges to traditional mechanisms of criminal detection and law enforcement. The social science theories of trust and control provide an accessible matrix to evaluate malicious behavior related to these new forms of money and currency. This foreshadows the ability for DLTs to become the ĂąÂÂpoison of choiceù for crime and security objectives or perhaps be avoided altogether by criminals. We argue that an understanding of DLTs is incomplete without a social science underpinning and framework which trust and control provide. The continued use of these technologies will require public and private institutions to rethink their approaches to crime prevention and information security for purely digital threats.
Incidents of ransomware have been escalating, which could be fueled in part by the diffusion of crypto-currencies. Without crypto-currencies, the creation of ransomware is less desirable because other forms of payment are more traceable. The risk from ransomware can be considerable, and some companies hold supplies of bitcoins in reserve to pay extortionists if necessary. Here, the authors examine crypto-currenciesâ effects on ransomware and look at what might influence a victimâs decision to pay.
The purpose of this paper is to provide a brief explanation regarding the authorsâ current research in the field of the possible uses of smart contracts in cybercrime, focusing in particular on how the technology could provide a substitute for trust both in client-criminal transactions and in transactions taking place within criminal organizations. The authors share the conviction put forward by Alharby and Moorsel [1] in their 2017 analysis of blockchainbased smart contracts that there is a âlack of studies on criminal activities in smart contractsâ: while quality research does exist, including a paper by Juels et al. [2] detailing three types of such activities that can be facilitated by the technology, it is evident that the subject deserves a more widespread attention. Quality research, in fact, could play an important role in aiding authorities and regulators to understand the issue and react accordingly.
Part I of this Article describes how the healthcare industry has arrived in this place of vulnerability, including (1) the history of the movement toward EHRs through HIPAA, (2) HIPAAâs meaningful use regulations and the background of current ransomware attacks, and (3) the distinctions between these attacks and other security breaches that have plagued large insurers and health systems within the last five years. Next, Part II will examine current industry culture when it comes to cybersecurity and review current legal and business approaches to address this growing threat. Then, Part III will argue that, while the current lawsâincluding HIPAA and HITECHâare a good start, they do not go far enough to curb the current ransomware attacks and thus, should be amended. It will further argue that such amendments cannot be the only solution. Rather, the healthcare industry has to spur its own movement toward better and tighter security over its healthcare technology. Lastly, this Article will conclude with some suggestions and recommendations for how industry and government regulators can work together to assure that hospitals and health systems are not faced with the dilemma of having to choose between patient safety and the payment of a bitcoin ransom.
The purpose of this paper is to provide a brief explanation regarding the authors' current research in the field of the possible uses of smart contracts in cybercrime, focusing in particular on how the technology could provide a substitute for trust both in client-criminal transactions and in transactions taking place within criminal organizations. The authors share the conviction put forward by Alharby and Moorsel [1] in their 2017 analysis of blockchain- based smart contracts that there is a âlack of studies on criminal activities in smart contractsâ: while quality research does exist, including a paper by Juels et al. [2] detailing three types of such activities that can be facilitated by the technology, it is evident that the subject deserves a more widespread attention. Quality research, in fact, could play an important role in aiding authorities and regulators to understand the issue and react accordingly.
While public and private entities question the utility of privacy preserving means of electronic payments for individuals other than criminals, discussions are primarily based on anecdotal evidence. Thus, we address the overall research question of whether pseudonymous cryptocurrencies are primarily used by criminals. Based on Rational Choice Theory and darknet market design, we build a dynamic research model. Utilizing panel data of 296,875 unique product and service listings that were available on 19 darknet markets from June 2014 to July 2015 as well as Bitcoin blockchain transactions, we provide evidence for the co-evolution of Bitcoin and darknet markets. We find that transactions within the Bitcoin blockchain and the usage of transaction obfuscation services can be related to previous sales on darknet markets. The temporal lag can be attributed to escrow mechanisms. We contribute to the research stream of cryptocurrency usage behavior and discussions of regulators, governments and financial services firms.
Bharanidharan Shanmugam, Sami Azam, Kheng Cher Yeo, Jithin Jose · 5 authors
Bitcoin is a new form of global digital currency based on peer-to-peer network, enabling a new payment system, and also a completely decentralised cryptocurrency. The P2P network consists of a digital file listing transactions like a ledger, a copy of which is also maintained on every computer on the network, and the transactions are also broadcasted in the public ledger of the Bitcoin network. Anonymity is the core feature that makes Bitcoin popular among people around the world. This feature is attained through the Bitcoin addresses in the public ledger, which represents the users in the Bitcoin network. Because of the illicit use of Bitcoins, the level of anonymity has reduced even though the users are still using the anonymizers like TOR to keep the anonymity stronger to connect to the Bitcoin network. In this paper, we analyse the complete process of transaction of Bitcoins and the anonymity thatlies in that process. The study also focuses on finding the forensic artefacts and the investigative way of approach towards the Bitcoin using forensic tools. The forensic tools are used to analyse the web browser activities, local drive, hard disk image, cookies, downloads and session data related to Bitcoins. The attacker can relate the transaction of the users and can control the Bitcoin blocks by even delaying the transactions. This research will focus on the methods in which the memory and even mobile devices involved in the transaction could be captured and analysed.
Blockchain Technology Applications and Security
Advanced Steganography and Watermarking Techniques
Services known as Cryptocurrency âTumblersâ obfuscate the provenance, possession, and movement of cryptocurrencies through a process of âmixingâ . While this speaks to the cryptoanarchist philosophical roots of cryptocurrencies, it poses various forms of risks, particularly those subsumed by the anti-money laundering (AML) category. This discussion paper examines that dichotomy, between cryptoanarchism and oversight, through the Tumbler lens, so as to consider the regulation, oversight, and legality of Tumblers themselves.
Selfish mining is a well-known mining attack strategy discovered by Eyal and Sirer in 2014. After that, the attackers' strategy has been further discussed by many other works, which analyze the strategy and behavior of a single attacker. The extension of the strategy research is greatly restricted by the assumption that there is only one attacker in the blockchain network, since, in many cases, a proof of work blockchain has multiple attackers. The attackers can be independent of others instead of sharing information and attacking the blockchain as a whole. In this paper, we will establish a new model to analyze the miners' behavior in a proof of work blockchain with multiple attackers. Based on our model, we extend the attackers' strategy by proposing a new strategy set publish-n. Meanwhile, we will also review other attacking strategies such as selfish mining and stubborn mining in our model to explore whether these strategies work or not when there are multiple attackers. The performances of different strategies are compared using relative stale block rate of the attackers. In a proof of work blockchain model with two attackers, strategy publish-n can beat selfish mining by up to 26.3%.
The first global cryptocurrency benchmarking study presents a systematic and comprehensive picture of a rapidly evolving industry, illustrating how cryptocurrencies are being used, stored, transacted and mined. The study gathered non-public data from more than 100 cryptocurrency companies and over 30 individual cryptocurrency miners in 38 countries around the world via secure web-based questionnaires, capturing an estimated 75 per cent of the cryptocurrency industry. The study breaks down the cryptocurrency industry into four key sectors â exchanges, wallets, payments and mining. Key findings and highlights from the study include our estimate that over three million unique individuals are actively using cryptocurrency today, data on regulation and compliance practices and costs at firms, and a global map of cryptocurrency mining.
Ponzi schemes are financial frauds which lure users under the promise of high\nprofits. Actually, users are repaid only with the investments of new users\njoining the scheme: consequently, a Ponzi scheme implodes soon after users stop\njoining it. Originated in the offline world 150 years ago, Ponzi schemes have\nsince then migrated to the digital world, approaching first the Web, and more\nrecently hanging over cryptocurrencies like Bitcoin. Smart contract platforms\nlike Ethereum have provided a new opportunity for scammers, who have now the\npossibility of creating "trustworthy" frauds that still make users lose money,\nbut at least are guaranteed to execute "correctly". We present a comprehensive\nsurvey of Ponzi schemes on Ethereum, analysing their behaviour and their impact\nfrom various viewpoints.\n
Introduction
In 1989, the digital world was introduced to the PC Cyborg trojan horse (also
known as the âAIDSâ trojan), an impending game-changer in the cybercrime landscape. What later became known as a class of malware called ransomware, PC
Cyborg was created by a biologist, Dr. Joseph Popp, who provided HIV/AIDS
patients with infected floppy disks labeled âAIDS Information â Introductory Diskettesâ (Kassner, 2010; Smith, 2002). Whenever PC Cyborg entered a system, it
tracked the number of system boots until a threshold was met (typically 90 times),
at which point it would hide and encrypt the names of all files and directories in
the local drive of the infected system. PC Cyborg then prompted victims, whose
computers were no longer operational, to send $189 to the PC Cyborg Corporation in order for the files to be decrypted and the computer to be reverted back to
its working state.
Andres Baravalle, Mauro Sanchez Lopez, Sin Wee Lee
In the last years, governmental bodies have been futilely trying to fight against dark web marketplaces. Shortly after the closing of "The Silk Road" by the FBI and Europol in 2013, new successors have been established. Through the combination of cryptocurrencies and nonstandard communication protocols and tools, agents can anonymously trade in a marketplace for illegal items without leaving any record. This paper presents a research carried out to gain insights on the products and services sold within one of the larger marketplaces for drugs, fake ids and weapons on the Internet, Agora. Our work sheds a light on the nature of the market, there is a clear preponderance of drugs, which accounts for nearly 80% of the total items on sale. The ready availability of counterfeit documents, while they make up for a much smaller percentage of the market, raises worries. Finally, the role of organized crime within Agora is discussed and presented.
In recent years, blockchain technology has attracted considerable attention. It records cryptographic transactions in a public ledger that is difficult to alter and compromise because of the distributed consensus. As a result, blockchain is believed to resist fraud and hacking. This work explores the types of fraud and malicious activities that can be prevented by blockchain technology and identifies attacks to which blockchain remains vulnerable. This study recommends appropriate defensive measures and calls for further research into the techniques for fighting malicious activities related to blockchains.