Interface Illusions: Uncovering the Rise of Visual Scams in Cryptocurrency Wallets
Guoyi Ye, Geng Hong, Yuan Zhang, Min Yang
摘要
Cryptocurrencies, while revolutionary, have become a magnet for malicious actors. With numerous reports underscoring cyberattacks and scams in this domain, our paper takes the lead in characterizing visual scams associated with cryptocurrency wallets---a fundamental component of Web3. Specifically, scammers capitalize on the omission of vital wallet interface details, such as token symbols, wallet addresses, and smart contract function names, to mislead users, potentially resulting in unintended financial losses. Analyzing Ethereum blockchain transactions from July 2022 to June 2023, we uncovered a total of 24,901,115 visual scam incidents, which include 3,585,493 counterfeit token attacks, 21,281,749 zero-transfer attacks, and 33,873 function name attacks, orchestrated by 6,768 distinct attackers. Shockingly, over 28,414 victims fell prey to these scams, with losses surpassing 27 million USD. This alarming data underscores the pressing need for robust protective measures. By profiling the typical victims and attackers, we are able to propose mitigation strategies informed by our findings.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- Insecurity Through Obscurity: Veiled Vulnerabilities in Closed-Source ContractsSen Yang, Kaihua Qin, Aviv Yaish, Fan ZhangCCS 2026 · 被引用 3 次
- CtPhishCapture: Uncovering Credential-Theft-Based Phishing Scams Targeting Cryptocurrency WalletsHui Jiang, Zhenrui Zhang, Xiang Li, Yan Li 等NDSS 2026 · 被引用 1 次
- Meme Coin Factories: Uncovering Large-Scale Manipulations on pump.funNicolas Szwajcok, Taro Tsuchiya, Enze Liu, Kyle Soska 等CCS 2026
- Lost in Blockchain Address Misuse: Hidden Cross-Platform Risks and Their Security ImpactZhenzhe Shao, Jiashuo Zhang, Zihao Li, Daoyuan Wu 等USENIX Security 2026
- Blockchain Address PoisoningTaro Tsuchiya, Jin-Dong Dong, Kyle Soska, Nicolas ChristinUSENIX Security 2025
它引用的顶会 Paper4
- Hiding in Plain Sight: A Longitudinal Study of Combosquatting AbusePanagiotis Kintis, Najmeh Miramirkhani, Charles Lever, Yizheng Chen 等CCS 2017 · 被引用 166 次
- Phishpedia: A Hybrid Deep Learning Based Approach to Visually Identify Phishing WebpagesYun Lin, Ruofan Liu, Dinil Mon Divakaran, Jun Yang Ng 等USENIX Security 2021 · 被引用 164 次
- "Johnny, you are fired!" - Spoofing OpenPGP and S/MIME Signatures in EmailsJens Müller, Marcus Brinkmann, Damian Poddebniak, Hanno Böck 等USENIX Security 2019 · 被引用 34 次
- Double and Nothing: Understanding and Detecting Cryptocurrency Giveaway ScamsXigao Li, Anurag Yepuri, Nick NikiforakisNDSS 2023
相关 Paper
- WalleTruth: Visual-Oriented Software Testing for Web3 Wallet Browser ExtensionsXiaohui Hu, Ningyu He, Haoyu WangFSE 2026
- Characterizing Ethereum Address Poisoning AttackShixuan Guan, Kai LiCCS 2024 · 被引用 4 次
- Pulling Off The Mask: Forensic Analysis of the Deceptive Creator Wallets Behind Smart Contract FraudMingxuan Yao, Runze Zhang, Haichuan Xu, Shih-Huan Chou 等S&P 2024 · 被引用 10 次
- Large-Scale Study of Vulnerability Scanners for Ethereum Smart ContractsChristoph Sendner, Lukas Petzi, Jasper Stang, Alexandra DmitrienkoS&P 2024 · 被引用 19 次
- SoK: Decentralized Finance (DeFi) AttacksLiyi Zhou, Xihan Xiong, Jens Ernstberger, Stefanos Chaliasos 等S&P 2023
