Skip to main content
QUICK REVIEW

[论文解读] Understanding Security Issues in the NFT Ecosystem

Dipanjan Das, Priyanka Bose|arXiv (Cornell University)|Nov 17, 2021
Blockchain Technology Applications and Security被引用 4
一句话总结

本文首次系统性分析了NFT生态系统中的安全与隐私问题,识别出八个顶级NFT市场中的设计缺陷和恶意交易行为。通过大规模数据收集和自动化检测模型,量化了出价屏蔽及其他金融风险,发现66.67%的出价屏蔽项目已通过验证,仅在CryptoVoxels平台上就有24,519.27美元的出价被屏蔽。

ABSTRACT

Non-Fungible Tokens (NFTs) have emerged as a way to collect digital art as well as an investment vehicle. Despite having been popularized only recently, NFT markets have witnessed several high-profile (and high-value) asset sales and a tremendous growth in trading volumes over the last year. Unfortunately, these marketplaces have not yet received much security scrutiny. Instead, most academic research has focused on attacks against decentralized finance (DeFi) protocols and automated techniques to detect smart contract vulnerabilities. To the best of our knowledge, we are the first to study the market dynamics and security issues of the multi-billion dollar NFT ecosystem. In this paper, we first present a systematic overview of how the NFT ecosystem works, and we identify three major actors: marketplaces, external entities, and users. We perform an in-depth analysis of the top 8 marketplaces (ranked by transaction volume) to discover potential issues associated with such marketplaces. Many of these issues can lead to substantial financial losses. We also collected a large amount of asset and event data pertaining to the NFTs being traded in the examined marketplaces. We automatically analyze this data to understand how the entities external to the blockchain are able to interfere with NFT markets, leading to serious consequences, and quantify the malicious trading behaviors carried out by users under the cloak of anonymity.

研究动机与目标

  • 系统性调查快速发展的NFT生态系统中的安全与隐私风险。
  • 识别NFT市场及外部实体中的设计缺陷,这些缺陷导致了财务损失。
  • 检测并量化恶意交易行为,如出价屏蔽和冒名攻击。
  • 分析诈骗行为的普遍性,包括虚假项目、社交工程和“跑路”骗局。
  • 通过大规模数据分析,提供NFT市场中经济操纵的实证证据。

提出的方法

  • 从Ethereum主网及八个顶级NFT市场(OpenSea、Rarible等)收集交易、资产和事件数据。
  • 构建自动化模型,通过分析拍卖结束前的出价序列和取消模式,检测出价屏蔽行为。
  • 对100个被标记的实例进行人工验证,以确认检测准确率并优化模型启发式规则。
  • 通过Discord和社交媒体上的用户投诉,验证发现结果在现实世界中的影响。
  • 通过测量被屏蔽出价的金融价值及在已验证与未验证项目中的频率,量化恶意行为。
  • 应用统计分析评估出价屏蔽的普遍性,结果显示66.67%的被屏蔽项目已通过验证。

实验结果

研究问题

  • RQ1NFT生态系统,尤其是顶级市场中,主要的安全与隐私漏洞是什么?
  • RQ2出价屏蔽的普遍性如何?其在已验证与未验证NFT项目中的财务影响是什么?
  • RQ3冒名和社交工程攻击在多大程度上利用了NFT市场信任机制?
  • RQ4恶意行为者如何通过“拉高出货”或“跑路”策略操纵NFT市场动态?
  • RQ5外部实体和区块链透明性在多大程度上助长了针对NFT的密码经济攻击?

主要发现

  • 66.67%的出价屏蔽项目已通过验证,表明高需求、信誉良好的项目是出价屏蔽的主要目标。
  • 仅在CryptoVoxels项目中,就有35起实例导致24,519.27美元的出价被屏蔽,与用户报告的活动增加情况相符。
  • 人工验证确认100个被标记的出价屏蔽案例中有90个为真正阳性,证明检测准确率较高。
  • 当竞标者在取消前相互出更高价时,检测模型会产生误报,凸显了对更严格行为启发式规则的需求。
  • 出价屏蔽常与出价屏蔽者和拍卖获胜者之间的串通行为结合使用,以人为方式推高价格。
  • 本研究揭示,由于验证和信任机制薄弱,NFT市场易受冒名、伪造项目和社交工程等多种攻击影响。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。