[论文解读] Tracking Counterfeit Cryptocurrency End-to-end
本文首次系统性地测量了以太坊上的伪造ERC-20代币,识别出2,117个针对100种最受欢迎加密货币中94种的虚假代币。通过分析交易模式、广告渠道和诈骗行为,作者识别出两种主要诈骗类型——空投诈骗和套利诈骗,涉及至少7,104名受害者,造成超过1,700万美元的损失。
The production of counterfeit money has a long history. It refers to the creation of imitation currency that is produced without the legal sanction of government. With the growth of the cryptocurrency ecosystem, there is expanding evidence that counterfeit cryptocurrency has also appeared. In this paper, we empirically explore the presence of counterfeit cryptocurrencies on Ethereum and measure their impact. By analyzing over 190K ERC-20 tokens (or cryptocurrencies) on Ethereum, we have identified 2, 117 counterfeit tokens that target 94 of the 100 most popular cryptocurrencies. We perform an end-to-end characterization of the counterfeit token ecosystem, including their popularity, creators and holders, fraudulent behaviors and advertising channels. Through this, we have identified two types of scams related to counterfeit tokens and devised techniques to identify such scams. We observe that over 7,104 victims were deceived in these scams, and the overall financial loss sums to a minimum of $ 17 million (74,271.7 ETH). Our findings demonstrate the urgency to identify counterfeit cryptocurrencies and mitigate this threat.
研究动机与目标
- 调查以太坊生态系统中伪造加密货币的普遍程度及其特征。
- 识别参与伪造代币创建与分发的实体,包括创建者、持有者和广告平台。
- 分析与伪造代币相关的欺诈行为,如空投诈骗和套利诈骗。
- 衡量这些诈骗的财务影响和受害人数,以凸显检测与缓解的紧迫性。
- 通过交易和网络分析开发识别伪造代币诈骗的检测技术。
提出的方法
- 使用Etherscan和区块链探索工具的数据,收集并分析了2020年3月前以太坊上的超过190,000个ERC-20代币。
- 通过匹配前100种热门代币(如USDT、BTC)的名称和符号,在不同合约地址下识别出伪造代币。
- 追踪交易流程和智能合约交互,以描述伪造代币创建者和持有者的活动特征。
- 通过挖掘社交媒体和论坛帖子,映射广告渠道,识别用于推广伪造代币的平台。
- 为两种诈骗类型开发检测启发式规则:空投诈骗(受害者向指定地址转账以获取虚假代币)和套利诈骗(利用不同交易所间的价格差异进行欺诈)。
- 应用基于图的分析方法,建立代币合约、钱包和交易所活动之间的关系模型,以揭示诈骗模式。
实验结果
研究问题
- RQ1伪造ERC-20代币在以太坊上有多普遍?有多少目标指向最热门的加密货币?
- RQ2伪造代币生态系统中的关键参与者是谁——创建者、持有者和分发者?他们的行为模式是什么?
- RQ3与伪造代币相关的欺诈行为有哪些类型?它们在实际中如何运作?
- RQ4哪些在线平台被用于广告和传播伪造代币?这些渠道的有效性如何?
- RQ5我们能否基于交易和网络特征,开发可靠的检测技术来识别伪造代币诈骗?
主要发现
- 本研究识别出2,117个针对以太坊上100种最热门加密货币中94种的伪造ERC-20代币。
- 超过7,104名受害者在伪造代币诈骗中受骗,导致最低1,735万美元的财务损失(74,271.7 ETH)。
- 共有103个在线平台,包括社交媒体和论坛,被用于传播关于伪造代币的欺诈信息。
- 识别出两种主要诈骗类型:空投诈骗(受害者向指定地址转账以获取虚假代币)和套利诈骗(利用不同交易所间的价格差异进行欺诈)。
- 大多数伪造代币使用与合法代币完全相同的名称和符号(例如,多个‘Tether USD’代币),利用用户混淆。
- 分析显示,许多伪造代币仅通过极低的技术投入创建,通常使用标准ERC-20模板,凸显攻击者进入门槛极低。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。