Who Stole My NFT? Investigating Web3 NFT Phishing Scams on Ethereum

被引:0
|
作者
Yang, Jingjing [1 ]
Liu, Jieli [2 ]
Lin, Dan [2 ]
Wu, Jiajing [2 ]
Huang, Baoying [1 ]
Li, Quanzhong [1 ]
Zheng, Zibin [2 ]
机构
[1] Sun Yat Sen Univ, Sch Comp Sci & Engn, Guangzhou 510006, Peoples R China
[2] Sun Yat Sen Univ, Sch Software Engn, Zhuhai 519082, Peoples R China
基金
中国国家自然科学基金;
关键词
Nonfungible tokens; Phishing; Smart contracts; Cryptocurrency; Open source software; Feature extraction; Security; Web3; non-fungible tokens; ethereum; phishing scams; security;
D O I
10.1109/TIFS.2024.3463541
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
With the popularity of Non-Fungible Tokens (NFTs), the high value of NFTs makes them a target for phishing scammers, which harms the security and reliability of the Web3 NFT ecosystem. Despite the significance of this issue, there is a lack of systematic research in the area of emerging NFT phishing scams. To address this gap, we are the first to conduct a case retrospective analysis and empirical measurement study of real-world historical NFT phishing scams on Ethereum. We collect and publicly release the first NFT phishing dataset which includes 1,625 NFT phishing accounts and transaction records as of August 2023. We further categorize the existing scams into four phishing patterns and investigate their distinguishable behaviors. Then, we reveal the modus operandi preferences and economic impacts to characterize NFT phishing scams. We find that NFT phishers stole 67,188 NFTs, with a total direct selling profit of ${\$}$ 20.92 million. We also observe that scammers favor certain categories and collections of NFTs, coupled with signs of gang theft. Furthermore, we design a variety of account features for the classification task of NFT phishers based on empirical conclusions. Experimental results on real-world NFT transaction data demonstrate the effectiveness of these features in detecting NFT phishing accounts, and outperform traditional phishing detection methods with 41% average Precision and 44% average Recall.
引用
收藏
页码:9301 / 9314
页数:14
相关论文
共 6 条
  • [1] Unraveling the Deception of Web3 Phishing Scams: Dynamic Multiperspective Cascade Graph Approach for Ethereum Phishing Detection
    Zhang, Lejun
    Zhang, Xucan
    Xiao, Siyi
    Li, Zexin
    Su, Shen
    Qiu, Jing
    Tian, Zhihong
    IEEE TRANSACTIONS ON COMPUTATIONAL SOCIAL SYSTEMS, 2024,
  • [2] Web3, metaverses and NFT applied to tourism
    Pons, Jimmy
    REVISTA DE OCCIDENTE, 2022, (491) : 55 - 67
  • [3] Predicting NFT Classification with GNN: A Recommender System for Web3 Assets
    Yu, Guangsheng
    Wang, Qin
    Altaf, Tanzeela
    Wang, Xu
    Xu, Xiwei
    Chen, Shiping
    2023 IEEE INTERNATIONAL CONFERENCE ON BLOCKCHAIN AND CRYPTOCURRENCY, ICBC, 2023,
  • [4] Demystifying Web3 Centralization: The Case of Off-Chain NFT Hijacking
    Stoger, Felix
    Zhou, Anxin
    Duan, Huayi
    Perrig, Adrian
    FINANCIAL CRYPTOGRAPHY AND DATA SECURITY, FC 2023, PT II, 2024, 13951 : 182 - 199
  • [5] Design of a Secured Medical Data Access Management using Ethereum Smart Contracts, Truffle Suite and Web3
    Niranga, G. D. Heshan
    Nair, Vidya S.
    Shibu, Sai N. B.
    PROCEEDINGS OF THE TWENTIETH ACM CONFERENCE ON EMBEDDED NETWORKED SENSOR SYSTEMS, SENSYS 2022, 2022, : 1215 - 1221
  • [6] My Holistic Data Share: A WEB3 Data Share Application: Extending Beyond Finance to Privacy-Protected Decentralised Share of Multi-Dimensional Data to Enhance Global Healthcare
    ChainAim, Newington
    CT, United States
    Blockchain. Healthc. Today., 2024, 2