[论文解读] Demystifying Scam Tokens on Uniswap Decentralized Exchange.
本文提出了一种结合罪责关联启发式方法与机器学习的混合方法,用于检测Uniswap上的欺诈代币,识别出超过10,000个欺诈代币——约占所有上市代币的50%——这些代币通过协调的跑路骗局和恶意智能合约,导致40,165名受害者至少损失1600万美元。
The prosperity of the cryptocurrency ecosystem drives the needs for digital asset trading platforms. Beyond centralized exchanges (CEXs), decentralized exchanges (DEXs) are introduced to allow users to trade cryptocurrency without transferring the custody of their digital assets to the middlemen, thus eliminating the security and privacy issues of CEX. Uniswap, as the most prominent cryptocurrency DEX, is continuing to attract scammers, with fraudulent cryptocurrencies flooding in the ecosystem. In this paper, we take the first step to detect and characterize scam tokens on Uniswap. We first collect all the transactions related to Uniswap exchanges and investigate the landscape of cryptocurrency trading on Uniswap from different perspectives. Then, we propose an accurate approach for flagging scam tokens on Uniswap based on a guilt-by-association heuristic and a machine-learning powered technique. We have identified over 10K scam tokens listed on Uniswap, which suggests that roughly 50% of the tokens listed on Uniswap are scam tokens. All the scam tokens and liquidity pools are created specialized for the rug pull scams, and some scam tokens have embedded tricks and backdoors in the smart contracts. We further observe that thousands of collusion addresses help carry out the scams in league with the scam token/pool creators. The scammers have gained a profit of at least $16 million from 40,165 potential victims. Our observations in this paper suggest the urgency to identify and stop scams in the decentralized finance ecosystem.
研究动机与目标
- 调查Uniswap这一领先的去中心化交易所上欺诈代币的普遍性和特征。
- 应对去中心化金融中因欺诈相关财务损失上升而产生的对自动化检测机制的迫切需求。
- 分析欺诈代币及其相关流动性池的结构和行为模式。
- 揭示欺诈代币创建者与恶意地址之间的共谋网络。
- 量化欺诈代币对Uniswap及整个去中心化金融生态系统造成的财务影响。
提出的方法
- 收集并分析了所有与Uniswap相关的交易,以绘制该平台上加密货币交易的全景图。
- 应用罪责关联启发式方法,标记与已知欺诈活动或可疑交易模式相关的代币。
- 采用基于交易和合约元数据训练的机器学习模型,以提高欺诈代币检测的准确性。
- 在特征如代币创建模式、流动性池行为和地址聚类等方面训练模型。
- 识别并分析恶意智能合约模式,包括后门和内置陷阱。
- 追踪并绘制了涉及协助欺诈代币发行和跑路的地址之间的共谋网络。
实验结果
研究问题
- RQ1在Uniswap上所有上市代币中,欺诈代币的普遍性如何?
- RQ2欺诈代币及其相关流动性池在结构和行为上与合法代币有何不同?
- RQ3地址共谋网络在促进欺诈代币发行和跑路中扮演什么角色?
- RQ4用户因Uniswap上的欺诈代币遭受了多大的财务损失?
- RQ5罪责关联和机器学习技术在多大程度上能够以高准确度检测欺诈代币?
主要发现
- 已在Uniswap上识别出超过10,000个欺诈代币,约占所有上市代币的50%。
- 欺诈代币及其流动性池系统性地用于跑路骗局,恶意智能合约通常包含内置后门。
- 数千个共谋地址积极支持欺诈代币创建者,促进协调退出骗局。
- Uniswap上的欺诈生态系统已从40,165名潜在受害者中获利至少1600万美元。
- 罪责关联与机器学习的结合能够准确检测欺诈代币,揭示了去中心化金融中的系统性漏洞。
- 研究结果凸显了在去中心化金融中亟需主动检测与缓解机制。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。