Pulling Off The Mask: Forensic Analysis of the Deceptive Creator Wallets Behind Smart Contract Fraud
Mingxuan Yao, Runze Zhang, Haichuan Xu, Shih-Huan Chou, Varun Chowdhary Paturi, Amit Kumar Sikder, Brendan Saltaformaggio
摘要
Criminals, using crypto wallets referred to as Deceptive Creator Wallets (DCWs), have orchestrated fraudulent activities by luring victims to transfer funds to fraud smart contracts. Since it is almost impossible to reverse the transactions or pinpoint the true identity of the criminals, the industry has turned to flagging such contracts as user warnings. However, current mitigation efforts focus on individual contracts, overlooking the DCWs behind the scenes. Consequently, our research found that this oversight allows fraud to thrive. To address this, we developed CoCo, an automated forensic analysis pipeline that processes a single fraud contract and generates evidence that the legal authorities need to mitigate the fraud. Applying CoCo to 157 confirmed fraud contracts, our research uncovered 1,283,198 associated contracts linked to 91 DCWs, responsible for 2,638,752 ETH ($2,089,504,682) in illicit profits. More alarmingly, CoCo traces the fraudulent activities back to September 2017. In response, we are closely collaborating with Etherscan and the FBI to combat the fraud identified in our study.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- DVa: Extracting Victims and Abuse Vectors from Android Accessibility MalwareHaichuan Xu, Mingxuan Yao, Runze Zhang, Mohamed Moustafa Dawoud 等USENIX Security 2024 · 被引用 10 次
- Phishing in Wonderland: Evaluating Learning-Based Ethereum Phishing Transaction Detection and PitfallsAhod Alghuried, David MohaisenNDSS 2026 · 被引用 4 次
- Lock the Door But Keep the Window Open: Extracting App-Protected Accessibility Information from Browser-Rendered WebsitesHaichuan Xu, Runze Zhang, Mingxuan Yao, David Oygenblik 等CCS 2025
- Identifying Incoherent Search Sessions: Search Click Fraud Remediation Under Real-World ConstraintsRunze Zhang, Ranjita Pai Sridhar, Mingxuan Yao, Zheng Yang 等S&P 2025
- Enhanced Web Application Security Through Proactive Dead Drop Resolver RemediationJonathan Fuller, Mingxuan Yao, Saumya Agarwal, Srimanta Barua 等CCS 2025
它引用的顶会 Paper14
- Making Smart Contracts SmarterLoi Luu, Duc-Hiep Chu, Hrishi Olickel, Prateek Saxena 等CCS 2016 · 被引用 2,306 次
- SOK: (State of) The Art of War: Offensive Techniques in Binary AnalysisYan Shoshitaishvili, Ruoyu Wang, Christopher Salls, Nick Stephens 等S&P 2016 · 被引用 1,085 次
- ZEUS: Analyzing Safety of Smart ContractsSukrit Kalra, Seep Goel, Mohan Dhawan, Subodh SharmaNDSS 2018 · 被引用 595 次
- teEther: Gnawing at Ethereum to Automatically Exploit Smart ContractsJohannes Krupp, Christian RossowUSENIX Security 2018 · 被引用 345 次
- TTAGN: Temporal Transaction Aggregation Graph Network for Ethereum Phishing Scams DetectionSijia Li, Gaopeng Gou, Chang Liu, Chengshang Hou 等WWW 2022 · 被引用 156 次
相关 Paper
- Interface Illusions: Uncovering the Rise of Visual Scams in Cryptocurrency WalletsGuoyi Ye, Geng Hong, Yuan Zhang, Min YangWWW 2024 · 被引用 7 次
- Blockchain Address PoisoningTaro Tsuchiya, Jin-Dong Dong, Kyle Soska, Nicolas ChristinUSENIX Security 2025
- Characterizing Ethereum Address Poisoning AttackShixuan Guan, Kai LiCCS 2024 · 被引用 4 次
- SmartCoCo: Checking Comment-Code Inconsistency in Smart Contracts via Constraint Propagation and BindingSicheng Hao, Yuhong Nan, Zibin Zheng, Xiaohui LiuASE 2023 · 被引用 7 次
- Smart Contract and DeFi Security Tools: Do They Meet the Needs of Practitioners?Stefanos Chaliasos, Marcos Antonios Charalambous, Liyi Zhou, Rafaila Galanopoulou 等ICSE 2024 · 被引用 49 次
