Z. Li, Hao Xu, Yang Fang, Boyuan Zhao · 5 authors
No abstract is available for this record.
Follow blockchain research across journals, conferences, and preprint repositories.
1,615 results · page 9 of 68
Z. Li, Hao Xu, Yang Fang, Boyuan Zhao · 5 authors
No abstract is available for this record.
V. V. Belous, Ivan Tarkhanov
No abstract is available for this record.
Ben Wang, Yanxiang Tong, Shunhui Ji, Hai Dong · 6 authors
With the rapid development of blockchain technology, smart contract applications have become increasingly widespread. However, vulnerabilities in contracts may be exploited by attackers, causing serious financial losses. In recent years, learning-based approaches have gained prominence for their accuracy and efficiency by automatically extracting explicit syntactic or semantic features from a large number of smart contracts with minimal manual intervention. In this article, we conduct a comprehensive analysis and ultimately select 61 scientific publications to provide researchers, especially beginners, with a comprehensive understanding of the learning-based detection process and guidance on selecting appropriate code representations. We first introduce common types of vulnerabilities, detail uncovered vulnerabilities, and summarize datasets used in learning-based methods. Then, we elaborate on the general process of learning-based detection and classify existing publications based on code representations, including sequence, tree, graph, and mixed features. Finally, we summarize the progress of existing work and explore future research directions in this field.
Zhenxiang He, Yanling Liu, Xiaohui Sun
Driven by blockchain technology, numerous industries are increasingly adopting smart contracts to enhance efficiency, reduce costs, and improve transparency. As a result, ensuring the security of smart contracts has become critical. Traditional detection methods often suffer from low efficiency, are prone to missing complex vulnerabilities, and have limited accuracy. Although deep learning approaches address some of these challenges, issues with both accuracy and efficiency remain in current solutions. To overcome these limitations, this paper proposes a symmetry-inspired solution that harmonizes bidirectional and generative semantic patterns. First, we generate distinct feature extraction segments for different vulnerabilities. We then use the Bidirectional Encoder Representations from Transformers (BERT) module to extract original semantic features from these segments and the Generative Pre-trained Transformer (GPT) module to extract generative semantic features. Finally, the two sets of semantic features are fused using a multi-attention mechanism and input into a classifier for result prediction. Our method was tested on three datasets, achieving F1 scores of 93.33%, 93.65%, and 92.31%, respectively. The results demonstrate that our approach outperforms most existing methods in smart contract detection.
Sasha Shilina
Proposes are offered Decentralized Ledger Journalism (DLJ) as a distinct and timely subfield within data journalism, emerging at the intersection of technological innovation and investigative practice. Drawing on the unique affordances of blockchain and other distributed ledger technologies (DLT), this approach positions public, immutable records not merely as supplementary datasets, but as primary sources for journalistic inquiry. From financial transactions and smart contract events to decentralized governance and identity systems, distributed ledgers offer a new evidentiary terrain - structured, transparent, and resistant to alteration. Beyond their utility as data sources, these systems provide native mechanisms for content authentication, including cryptographic timestamping, verifiable provenance, and censorship-resistant publication infrastructures. Such tools enable new methods of verification and preservation, allowing journalists to secure both the integrity of their sources and the durability of their outputs. By exploring the methodological and epistemological implications of blockchain-based journalism, this study outlines how decentralized ledgers can serve both as subject and substrate of inquiry. DLJ, we argue, offers a novel framework for enhancing journalistic integrity in a digital environment increasingly shaped by opacity, manipulation, and central control.
Kostiantyn Orobets, V. I. Shkolnikov, Tetiana Batrachenko, Тетяна Василівна Барановська · 5 authors
Introduction: The legal regime of cryptocurrency in different countries of the world is heterogeneous. In some, it is not defined at all, which leads to legal conflicts, including when qualifying crimes committed with cryptocurrency use. The situation is further complicated because such crimes can occur in the territories of several states where cryptocurrency has a different legal regime. Traditional legislation and mechanisms for combating money laundering and terrorist financing are practically ineffective in the landscape of crimes involving the use of cryptocurrency.Objectives: The aim of the study is to systematise the main patterns of crimes related to the use of cryptocurrency, as well as analyse existing vectors of their legal assessment, appropriate design and application of effective methods of combating these crimes.Methods: Based on the methods of analysis and synthesis, qualitative data analysis, using content analysis as the primary research tool, it is shown that the main problem in preventing the use of cryptocurrency in predicate crimes lies in the technical difficulty of identifying a person or group of persons who carry out cryptocurrency transactions for illegal purposes. Such goals may be aimed at legalising funds, i.e., concealing their illegal origin, making payments in a hidden network, organising various fraudulent schemes, financing terrorism, and other crimes.Results: The article argues that given the technical specifics of cryptocurrency transactions and the technical capabilities of "masking" the origin of cryptocurrency funds, it is necessary to develop methods for studying trace formation and develop an algorithm for establishing and consolidating forensically significant information for this type of crime. The results indicate that the future of law enforcement in the fight against cryptocurrency-related crime will require a multifaceted approach. Agencies must adopt a proactive approach by foreseeing emerging criminal strategies. To protect the public from crimes using digital assets, law enforcement must be flexible, progressive, and technologically savvy as cryptocurrencies continue to develop. The development of provisions on cryptocurrency also determines the theoretical significance of the work as an object and means of committing crimes, a surrogate means of payment during the commission of certain crimes.Conclusions: The practical significance of the work lies in the possibility of using its results to solve problems arising in the law-making activities of state authorities and law enforcement activities, as well as in developing recommendations for improving criminal legislation in the field of cryptocurrency-related crimes.
Sabri Hisham
No abstract is available for this record.
Alfred Tanaka Kudiwahove, Monika Gondo
The rapid digital transformation being currently experienced the developing economies such as Zimbabwe has underlined the inefficiencies and vulnerabilities in security of traditional Know Your Customer (KYC) processes. These KYC processes and procedures are predominantly manual, slow and are prone to data breaches. This paper proposes a privacy preserving authentication model for KYC optimization using Zero-Knowledge Proof (ZKP) cryptography. This model addresses critical challenges which include prolonged customer onboarding times, high operational costs and data compliance risks. By means of leveraging ZKP the model enables secure identity verification without exposing sensitive data which ensures compliance with Zimbabwe Data Protection Act. A mixed-methods approach was adopted, combining qualitative and quantitative techniques to design, develop and evaluate the model. Experimental results have demonstrate significant improvements in data privacy and onboarding efficiency which has seen reduced onboarding time from 3 days to under 10 minutes. The model scalability and adaptability potential makes it suitable for diverse sectors which covers education, healthcare, e-commerce and government services therefore positioning Zimbabwe as a leader in secure digital transformation.
Karthik Meduri, Elyson De La Cruz, Renjith Kathalikkattil Ravindran, Vedaprada Ragunath · 8 authors
No abstract is available for this record.
C. V. Suresh Babu, M. Bhavesh, J. Janani, C. Mythili Rani
This chapter explores the impact of AI-powered solutions on cybersecurity within the context of cryptocurrency transactions in e-commerce. The primary objective is to investigate how AI can mitigate the growing cybersecurity risks associated with cryptocurrency fraud, enhancing the safety of e-commerce platforms. Targeting researchers, AI engineers, and e-commerce professionals, this study employs a mixed-method approach, combining case studies, expert interviews, and comparative analysis of AI-based tools and traditional security systems. The findings highlight the significant potential of AI, particularly in predictive analytics and real-time fraud detection, to combat cryptocurrency-related cybercrimes. The chapter also addresses the challenges of integrating AI with existing e-commerce frameworks and discusses ethical concerns related to privacy and surveillance. The conclusion emphasizes the need for further research into real-time AI solutions and the development of international regulatory standards for AI in cryptocurrency security.
Ramy El-Kady
The chapter aims to illuminate the digital forensics of cryptocurrencies and the dark web by reviewing the role of the elements and tools involved in their formation, such as blockchain, computers, and mobile phones, and learning evidence. It will focus on its methods and review the extent to which artificial intelligence and machine language can be relied upon in forensics on the dark web. The chapter identified the need to address several areas of digital cryptocurrency forensics, in which gaps can be filled by developing advanced solutions for cryptocurrency forensics. Further investigation is required in digital forensics concerning significant cryptocurrencies like Monero, Ethereum, Verge, Dogecoin, and others. This is necessary because these currencies are becoming increasingly popular among both legitimate users and evil individuals. The survey highlighted another research gap: the limited amount of substantial research on host-based cryptocurrency forensics, particularly in mobile-based cryptocurrency forensics.
Dr. Anjaiah Adepu
The fact that blockchain technology is decentralized, transparent, and immutable is transforming the face of such industries as finance, healthcare, and logistics. It is nonetheless, difficult in regulatory compliance, data privacy, and law enforcement, specifically blockchain forensics. Blockchain forensics is an activity of tracking transactions and members of illegal organizations like money laundering and cybercrime. Whereas the traceability of the blockchain technology with the transparency it possesses raises no more concerns on the legal issues, the pseudonymity of its participants, on the other hand, makes it quite difficult to identify them, respectively, creating issues within the scope of the data protection, as well as financial regulations. The paper will touch on the practice today of forensics, the regulation and morality of the balance that is there between privacy and criminal investigation. It ends with suggestions of a joint effort in creation of efficient legal frameworks to govern the same, and promotion of innovation.
Chunhong Liu, Zihang Sang, Li Duan, Jingxiong Wang · 6 authors
Security vulnerabilities in smart contracts can have severe economic consequences. Existing smart contract vulnerability detection methods rely primarily on rigid rules defined by experts and have difficulty in detecting unknown vulnerabilities. This article proposes a new Anomalous Smart Contract Detector, named ASCD, to effectively detect known and unknown vulnerabilities in smart contracts. This is achieved by interpreting unknown vulnerabilities as code anomalies and detecting them with an anomaly detection technique named DeepSVDD. This is also attributed to a new design of feature extraction, in which we compile smart contract source codes into opcodes, extract semantic features from opcode sequences, and control flow features from control flow graphs. By joining LSTM and GIN, the semantic and control flow features are fused to offer a comprehensive representation of smart contracts suitable for anomaly detection. Extensive experiments were conducted to verify the ASCD model, and more than 30,000 smart contracts were tested. The new model offers a significantly better F1-score than existing methods in detecting known vulnerabilities and achieves a high accuracy of 77% in detecting unknown vulnerabilities.
Dianxiang Sun, Wei Ma, Liming Nie, Yang Liu
Rug pulls present a critical threat in Decentralized Finance (DeFi), causing substantial financial losses and eroding ecosystem trust. Despite research advances, effective detection remains hampered by fragmented taxonomies, limited datasets, and inadequate tool evaluations. Through systematic analysis of academic and industry sources, we develop a comprehensive taxonomy of 35 distinct rug pull types, including 9 previously undocumented variants. Our analysis reveals significant detection gaps: existing datasets cover only 20% of known types, leading us to create an enhanced dataset of 2,391 instances that increases coverage to 82.9%. Evaluation of 13 detection tools shows substantial capability variation (25.7% to 62.9%), with 9 types completely undetectable. Most critically, tool performance degrades significantly when facing complex attacks, with maximum detection rates dropping from 55.6% for single-vector cases to 31.3% for compound scenarios. These findings provide essential insights for developing more robust security testing approaches for smart contract vulnerabilities in decentralized systems.
Chi Jiang, Shenao Wang, Fan Wu, Yin Zhang⋆
Due to the immutable nature of blockchain, vulnerability detection in on-chain smart contracts is imperative to ensure the security of blockchain transaction. As smart contracts automate significant financial and operational transactions, detecting vulnerabilities before they are exploited is critical. Recently, the application of machine learning techniques to this domain has increased, primarily due to their powerful feature extraction capabilities and operational efficiency in detecting anomalies. Considerable efforts in past research have focused on mining semantic and syntactic features from off-chain source code of smart contracts, typically written in high-level languages like Solidity. However, on-chain smart contracts, which are represented in the form of opcodes, lack these high-level semantic features. This absence necessitates different approaches for effective vulnerability detection. Although on-chain smart contracts lack high-level semantic features, the limited number of characters in opcodes results in more distinct frequency patterns of code. Therefore, in this paper, we explore a multi-class vulnerability detection approach based on the frequency features of smart contract opcodes. This paper provides a simple yet effective feature embedding method for on-chain opcode contract. Experiments on both binary and multi-class vulnerability detection tasks have been conducted to validate its scalability and effectiveness.
Sameeruddin Shaik
The current centralized model of Public Key Infrastructure (PKI) relies heavily on trusted Certificate Authorities (CAs) to authenticate digital identities. Still, this system faces significant security risks, including fraudulent certificate issuance and CA compromises. This thesis explores the potential of blockchain technology as a decentralized solution to these issues, proposing a distributed PKI framework that removes the single point of failure inherent in traditional systems. By leveraging blockchain’s immutability, consensus protocols, and transparency, this approach aims to enhance digital identity security and offer a more resilient infrastructure for managing certificates. A novel design is presented, incorporating a twophase Proof of Stake consensus mechanism, an account tree for domain owners’ public keys, and advanced certificate extensions for verifying identities within the blockchain network. The proposed framework not only improves the security of certificate issuance but also ensures tamper-proof logging and decentralized control, reducing the risks associated with CA vulnerabilities. This research lays the foundation for a more robust, scalable, and censorship-resistant PKI, providing an innovative solution to the challenges facing modern digital communications.
G. Saranya, Velayudham Narendhran, D Karthi, Anand G. Mehul · 5 authors
Securing forensic evidence integrity and security is fundamental to avoid tampering, loss, and illegal access. Classic centralized evidence management systems are easy to manipulate and breach. The current paper advocates for a blockchain-based forensic evidence management system that uses the Ethereum ERC-721 token standard to tokenize each bit of evidence as a non-fungible token (NFT) to promote immutable ownership and verifiable access.The system uses wallet-based authentication and role-based access control (RBAC) to limit evidence handling to authorized users. Key metadata, such as timestamps, digital hashes, and access logs, are recorded immutably on the blockchain. Smart contracts perform verification, logging, and auditing automatically, minimizing human errors and improving operational efficiency. A hybrid storage model stores ownership records on-chain while keeping large forensic files off-chain.
Chenyang Peng, Haijun Wang, Wu Yin, Hao Wu · 7 authors
With the advance application of blockchain technology in various fields, ensuring the security and stability of smart contracts has emerged as a critical challenge. Current security analysis methodologies in vulnerability detection can be categorized into static analysis and dynamic analysis methods.However, these existing traditional vulnerability detection methods predominantly rely on analyzing original contract code, not all smart contracts provide accessible code.We present ETrace, a novel event-driven vulnerability detection framework for smart contracts, which uniquely identifies potential vulnerabilities through LLM-powered trace analysis without requiring source code access. By extracting fine-grained event sequences from transaction logs, the framework leverages Large Language Models (LLMs) as adaptive semantic interpreters to reconstruct event analysis through chain-of-thought reasoning. ETrace implements pattern-matching to establish causal links between transaction behavior patterns and known attack behaviors. Furthermore, we validate the effectiveness of ETrace through preliminary experimental results.
Rajesh Vayyala
In the interconnected world of finance today, fighting money laundering is a paramount issue for institutions globally. This paper presents a new graph-based data architecture to enable multi-institutional pattern identification in anti-money laundering (AML) activities using the capabilities of distributed ledger analytics. With a real-world dataset of transaction records and suspicious activity reports, our solution builds complex networks that uncover hidden connections among distant financial institutions. The architecture facilitates dynamic visualization and anomaly detection on intricate transaction graphs but also leverages the intrinsic security and transparency of distributed ledger technology to provide data integrity and collaborative insights. Through intensive testing, the framework demonstrates improved detection accuracy and reduced false positives, offering an efficient and scalable way for regulators and financial institutions striving to detect and prevent financial crime threats in real time.
Zhihong Liang, Wenhan Zhang, Huan Xu, Siliang Suo
Smart contracts have become a foundational component in blockchain ecosystems, yet their vulnerabilities continue to pose significant security risks and financial losses. Traditional vulnerability detection approaches, such as symbolic execution and rule-based static analysis, often suffer from high computational cost. Recent deep learning methods attempt to learn patterns from smart contract bytecode but typically encode the entire opcode sequence without filtering, introducing noise among opcodes. To address these limitations, this paper proposes a semantics-compressed and attention-guided (SCAG) framework for smart contract vulnerability detection. SCAG introduces an Opcode Semantic Compression (OSC) mechanism to extract a compact set of semantically significant opcodes, thereby reducing noise from redundant or irrelevant instructions. These filtered opcodes are then processed by a self-attention module to capture contextual dependencies that are critical to vulnerability identification. Experiments on the SmartBugs dataset demonstrate that SCAG achieves an F1-score of 0.88 and an AUC of 0.93, outperforming Transformer-based models by approximately 5% and 4.5%, respectively, while also reducing training and inference times by over 50% and maintaining the smallest model size among all deep learning baselines.
Suryam Srivastava, Rajendra B. Singh
We introduce a hybrid system for detecting suspicious blockchain transactions, blending explainable machine learning (like Random Forest) with neural networks to analyze both raw transaction details and network patterns. Our approach achieves industry-leading accuracy (92% F1-score), solving two critical flaws in existing tools: 1) It cuts redundant data noise by 64% using smart feature filtering, and 2) uncovers hidden money trails through transaction graph analysis. While effective, current limitations include reliance on historical data—making it vulnerable to evolving scams like manipulated transaction networks in DeFi schemes—and slower processing times (32 training cycles) that challenge real-time monitoring on high-speed networks like Ethereum. Planned upgrades include dynamic AI models that adapt to live transaction flows and efficient detection systems for time-sensitive environments. We’re also developing stress tests using simulated cyberattack patterns and privacy-focused collaborative training across blockchain nodes. By merging technical precision with clear audit trails, this framework helps financial investigators spot risks like dark market ties while meeting strict compliance standards, offering a practical solution to balance speed and detection accuracy in crypto markets.
Federico Cernera, Massimo La Morgia, Alessandro Mei, Alberto Maria Mongardini · 5 authors
In the world of cryptocurrencies, the public listing of a new token often generates significant hype. In many cases, the price of the token skyrockets in a few seconds, and timing is crucial to determine the success or failure of an investment opportunity. In this work, we present an in-depth analysis of sniper bots, automated tools designed to buy tokens as soon as they are listed on the market. We leverage GitHub open-source repositories of sniper bots to analyze their features and how they are implemented. Then, we build a dataset of Ethereum and BNB Smart Chain (BSC) liquidity pools to identify operations performed using sniper bots. Our findings reveal 352,413 sniping operations on Ethereum and 1,716,917 on BSC for a total turnaround of $155,630,184 and $137,548,859, respectively. We find that Ethereum operations have a higher success rate but require a larger investment. Finally, we analyze possible countermeasures and mechanisms used in token smart contracts that can reduce the negative impact of sniper bots.
Nikos Papatheodorou, George Hatzivasilis, Nikos Papadakis
Self-sovereign identity (SSI) is an emerging model for digital identity management that empowers individuals to control their credentials without reliance on centralized authorities. This work presents YouGovern, a blockchain-based SSI system deployed on Binance Smart Chain (BSC) and compliant with W3C Decentralized Identifier (DID) standards. The architecture includes smart contracts for access control, decentralized storage using the Inter Planetary File System (IPFS), and long-term persistence via Web3.Storage. YouGovern enables users to register, share, and revoke identities while preserving privacy and auditability. The system supports role-based permissions, verifiable claims, and cryptographic key rotation. Performance was evaluated using Ganache and Hardhat under controlled stress tests, measuring transaction latency, throughput, and gas efficiency. Results indicate an average DID registration latency of 0.94 s and a peak throughput of 12.5 transactions per second. Compared to existing SSI systems like Sovrin and uPort, YouGovern offers improved revocation handling, lower operational costs, and seamless integration with decentralized storage. The system is designed for portability and real-world deployment in academic, municipal, or governmental settings.
Fadul Sikder, Yu Lei, Yuede Ji
Smart contracts underpin decentralized applications but face significant security risks from vulnerabilities, while traditional analysis methods have limitations. Large Language Models (LLMs) offer promise for vulnerability detection, yet adapting these powerful models efficiently, particularly generative ones, remains challenging. This paper investigates two key strategies for the efficient adaptation of LLMs for Solidity smart contract vulnerability detection: (1) replacing token-level generation with a dedicated classification head during fine-tuning, and (2) selectively freezing lower transformer layers using Low-Rank Adaptation (LoRA). Our empirical evaluation demonstrates that the classification head approach enables models like Llama 3.2 3B to achieve high accuracy (77.5%), rivaling the performance of significantly larger models such as the fine-tuned GPT-3.5. Furthermore, we show that selectively freezing bottom layers reduces training time and memory usage by approximately 10-20% with minimal impact on accuracy. Notably, larger models (3B vs. 1B parameters) exhibit greater resilience to layer freezing, maintaining high accuracy even with a large proportion of layers frozen, suggesting a localization of general code understanding in lower layers versus task-specific vulnerability patterns in upper layers. These findings present practical insights for developing and deploying performant LLM-based vulnerability detection systems efficiently, particularly in resource-constrained settings.