# VERITAS PROTOCOL

The world of blockchain technology is rapidly growing, and smart contracts are at the forefront, enabling trustless agreements and automated transactions. But with this power comes a dark side: vulnerabilities that have led to billions lost and a tarnished reputation for blockchain technology. Our team, a group of passionate blockchain veterans and AI specialists, is on a mission to change that.&#x20;

Blockchain Security, or blocksec, is a new security field with the mission of securing and defending the cryptocurrency ecosystem and we're building a revolutionary AI-powered platform that significantly boosts Web3 security with automated scam detection, auditing, and forensics of smart contracts across various blockchain networks. By leveraging the power of artificial intelligence, we offer a holistic solution that goes beyond just identifying vulnerabilities. Our platform proactively mitigates risks and ensures adherence to regulatory standards, fostering a more secure and trustworthy blockchain ecosystem for everyone.

<figure><img src="/files/RcObcRtN4IfrsFU38zTV" alt=""><figcaption></figcaption></figure>

### What sets us apart?&#x20;

Our approach is comprehensive, adaptable, and proactive. We're not just meeting the current standards, we're setting a new benchmark for Web3 security. As the blockchain landscape continues to evolve, we remain steadfast in our commitment to innovation. We'll continuously enhance our platform to address the ever-changing needs of users and the exciting opportunities presented by this dynamic technology.

Our platform is built upon the cutting-edge research and best practices outlined in our [own research](/thesis/automated-audits) and other sources. We encourage stakeholders, including developers, auditors, and regulatory bodies, to explore [these resources](/research). Gaining a deeper understanding of Web3 security complexities and the innovative solutions offered by our platform will be mutually beneficial as we navigate the future of blockchain technology together.

{% hint style="info" %}
[Veritas Protocol](https://www.veritasprotocol.com/) safeguards Web3 users and investors by providing AI-powered scam detection and prevention tools, alongside real-time incident response and asset recovery in the event of exploitation. Veritas goes beyond these core functionalities by equipping projects with automated audit tools, real-time threat monitoring, and crucially, insurance coverage against potential exploits.
{% endhint %}

### 🔗 Stay Connected

* Website: <https://www.veritasprotocol.com/>&#x20;
* X: [@veritas\_web3](https://twitter.com/veritas_web3)
* Telegram: <https://t.me/veritasprotocolverify>&#x20;

{% file src="/files/Ye5428n5qrVOM4YS5kP1" %}


# WHITE PAPER

10X Faster, 90% More Affordable Blockchain Security for Users, Investors and Projects

{% hint style="info" %}
There are many smart contract auditors out there, but they usually focus on projects and conduct audits manually or with low automation, which is slow and costly. Our approach is different. We recognize that true blockchain security must encompass not just the integrity of smart contracts but also the protection of every participant in the ecosystem.

Veritas protocol offers straightforward tools that let anyone audit tokens and any project's smart contracts 90% faster and at just 10% of the cost compared to competitors. Users can stay protected with scam prevention tools and forensics.

For blockchain projects and developers, Veritas provides a suite of advanced security solutions:<br>

* **Automated Audits**: Continuous, automated security checks ensure a project stays safe around the clock with minimal manual intervention.
* **AI Debugger**: Autonomous AI agents collaborate to review smart contract code and audit reports, suggesting or even deploying fixes in real-time.
* **Insurance Against Exploits**: Veritas offers financial protection against smart contract vulnerabilities and exploit-related losses through integrated insurance coverage.
  {% endhint %}

{% file src="/files/kvAjDjtk8f0KabyqeZjl" %}

<figure><img src="/files/ke7ZxrNNZb9mMW9xLchy" alt=""><figcaption></figcaption></figure>

### Customer Pain Points

Blockchain technology is with no doubt a game-changer, disrupting industries with its promise of unparalleled security, transparency, and efficiency. At the heart of this revolution lies the smart contract: a self-executing agreement where the terms are embedded directly in code. Smart contracts automate transactions, eliminating intermediaries and driving innovation in everything from finance to supply chain management.

While powerful, smart contracts aren't without their challenges. Their very strength, immutability, becomes a double-edged sword. Any weaknesses in the code can have irreversible consequences. The rapid growth of Decentralized Applications (DApps) unlocks exciting possibilities, but their reliance on smart contracts for user assets introduces critical security risks. Buggy code can open the door to hacks and exploits, as evidenced below:

* **Hacks & Exploits:** Over $15 billion of funds was lost due to exploits in the Web3 ecosystem to date. $1.7 billion in crypto was stolen in 2023 across over 200 hacks. (2022 was the biggest year ever for crypto theft, with $3.7 billion stolen).
* **Phishing & Scams:** The total funds lost by users to crypto phishing attacks amounted to $300 million during 2023. Exit scams accounted for $136 million over 263 cases in the same year.&#x20;

But why?

* **Costly Gatekeepers:** Traditional audits can cost tens to hundreds of thousands of dollars, creating a significant financial barrier for early stage projects.
* **Phishing & Scam Blind Spots:** Traditional audits cannot address external threats like phishing scams and social engineering attacks targeting users' crypto wallets and assets.
* **Focus on the Badge, Not Security:** The emphasis on securing a "stamp of approval" from a big-name auditor can overshadow the core goal of identifying and fixing vulnerabilities.
* **Launch Delays:** The time-consuming audit process can delay product launches and token listings, incentivizing some projects to bypass audits altogether in a rush to market, potentially exposing users to security risks.
* **Auditor Roulette:** The quality and clarity of reports, along with communication throughout the audit, can vary depending on the assigned auditor.

High-profile breaches in recent years have underscored the urgent need for stronger security measures. Traditional security and compliance tools simply can't keep up with the ever-evolving complexity of smart contracts. The industry craves a more sophisticated solution.

### Our Solution

At Veritas, we recognized a critical gap in smart contract security and knew that artificial intelligence was the key to bridging it. Our platform put to use the power of AI to completely transform how smart contracts are secured, audited, and monitored across blockchain networks.

#### Automated Audits: Revolutionizing Speed and Affordability

Traditional smart contract auditing processes are notoriously slow and expensive, primarily due to their reliance on manual labor and extensive time investments. Veritas shatters these limitations with our AI-driven platform, drastically reducing both the time and financial burden associated with audits. Our advanced AI algorithms expedite the auditing process, delivering results up to 10 times faster than conventional methods. What once took weeks or even months can now be accomplished in a matter of hours or even minutes.

Moreover, by leveraging AI efficiencies, we've managed to slash costs dramatically. Our automated audits are up to 90% more affordable than traditional approaches, making robust smart contract security accessible to projects of all sizes.&#x20;

#### AI Debugger: Real-Time Fixes Through Autonomous Agents

Veritas goes beyond mere vulnerability detection with AI Debugger. This feature deploys autonomous AI agents that not only identify issues but also suggest and even deploy fixes in real-time. These AI agents collaborate to review smart contract code and audit reports, providing immediate, actionable solutions to vulnerabilities.

This real-time approach to debugging and fixing smart contracts represents a necessary novelty in blockchain security. It minimizes the window of vulnerability between issue detection and resolution, significantly reducing the risk of exploits. Furthermore, by automating the fix suggestion and deployment process, we're enabling developers to focus on innovation while our AI takes care of the security heavy lifting.

#### Insurance Coverage: Financial Protection Against Exploits

Understanding that no system is infallible, Veritas offers an insurance coverage model to protect against financial losses from exploits. This feature provides an additional layer of security and peace of mind for smart contract deployers, investors and users alike.

Our insurance coverage is designed to mitigate the financial risks associated with potential smart contract vulnerabilities. In the event of an exploit, affected parties can be compensated, helping to maintain trust and stability within the blockchain ecosystem. This insurance model not only protects individual projects but also contributes to the overall resilience of the decentralized finance landscape.

#### Advanced Detection: Proactive Identification of Malicious Activities

Veritas employs comperhensive detection mechanisms to proactively identify a wide range of malicious activities, including phishing attempts, fraudulent dApps, scam projects, and other security threats. Our system continuously monitors blockchain networks, analyzing patterns and behaviors to spot potential risks before they can cause harm.

By leveraging machine learning and advanced heuristics, our detection system evolves and improves over time, staying ahead of emerging threat vectors. This proactive approach to security helps create a safer environment for all blockchain participants, from individual users to large-scale DeFi protocols.

Through these innovative solutions, Veritas is setting a new standard for blockchain security. We're not just providing a set of tools; we're establishing a comprehensive protocol designed to secure, innovate, and empower the entire Web3 space. By addressing the primary challenges facing blockchain security today – speed, cost, accuracy, and proactive protection – Veritas is leading the way for a more secure and trustworthy decentralized future.

{% hint style="info" %}
Our long term goal is to establish an interoperable security standard that unifies blockchain security measures into a coordinated ecosystem, developing a novel security architecture that supports high-throughput analysis, low-latency threat response, and eventual consensus on security states.
{% endhint %}

### Agentic Framework&#x20;

Veritas implements a multi-agent system for autonomous smart contract security auditing through a three-stage pipeline. Each stage contains specialized AI agents working in concert to detect vulnerabilities, propose fixes and validate solutions.

The framework consists of three sequential stages:&#x20;

#### 1. Input Stage

A preprocessing layer that handles contract ingestion through three channels:

* Address Scanner: Direct blockchain contract analysis
* Source Parser: Local source code processing
* GitHub Connector: Repository integration&#x20;

#### 2. Analysis Stage

The core security analysis phase, coordinated by an Audit Manager agent who orchestrates:

**Primary Analysis**

* Pattern Scanner: Identifies known vulnerability signatures
* Vulnerability Detector: Discovers potential security threats
* Compliance Checker: Validates ERC standard conformance
* Gas Optimizer: Evaluates computational efficiency

**Deep Analysis**

* Context Analyzer: Examines contract interaction patterns
* Cross-Contract Validator: Assesses dependencies and integrations
* Logic Verifier: Validates business logic implementation

**Observer Layer**&#x20;

A quality control system with three specialized agents monitoring the analysis process:

* Agent Observer: Validates agent performance
* Plan Observer: Ensures audit strategy effectiveness
* Action Observer: Verifies implementation accuracy

#### 3. Output Stage

Managed by an Output Manager agent coordinating three teams:

**Report Generation**

* Severity Classifier: Prioritizes security issues
* Metrics Analyzer: Quantifies vulnerability impacts
* Report Writer: Documents security findings into a security assessment

**Debugging & Fixes**

* Debug Analyst: Performs root cause analysis
* Fix Generator: Proposes code remediation
* Code Validator: Verifies fix effectiveness

**Quality Control**

* Report Validator: Ensures assessment accuracy
* Fix Validator: Validates fix implementations

<figure><img src="/files/32lULr0RhvZWppLkduIA" alt=""><figcaption><p>Framework Architecture</p></figcaption></figure>

The framework leverages 20 specialized AI agents working in autonomous collaboration. Through multiple validation layers and clearly defined responsibilities, these agents maintain high accuracy throughout the entire smart contract security analysis.

### Market Analysis

The smart contract market is on a tear, fueled by the widespread adoption of blockchain technology. According to the most recent report the global smart contracts market size is poised for significant growth, reaching $5.2 trillion in 2030, from $775 billion in 2023 \[1]. The sales are expected to witness a robust CAGR of 32% and generate over $450 billion in fees annually by 2030. However, with this growth comes complexity. The increasing value and intricate nature of smart contracts have made robust security and compliance paramount.

Our market analysis reveals a significant gap in existing solutions. Many are limited in scope, lacking real-time functionality or the ability to adapt to emerging threats. Some rely on manual code audits, a slow and resource-intensive process. Others offer automated vulnerability scanning, but these tools often fall short in predicting and preventing future attacks.

The market is expected to grow rapidly over the coming years as blockchain technology sees increasing real-world adoption. Key drivers of the smart contract market include the need for automation of manual processes, cost reduction, improved transactional security, and transparency.

By democratizing access to security audits, market intelligence company Messari expects that AI-native security networks will expand the total addressable market (TAM) by a factor of 5-10x \[2]. Table below is comparing centralized auditors vs decentralized security networks across crypto market cycles.&#x20;

|                                    | Certik in 20-22 | AI Audits in 24-26 |
| ---------------------------------- | --------------- | ------------------ |
| Peak-to-trough crypto market cap   | $200B →$2T      | $1T →???           |
| % projects getting security audits | 10%             | 50-75%             |
| % leader market share              | 60%             | 60-75%             |
| Projects audited                   | 10k+            | 100k+              |
| Capital raised                     | $230m           | fair launch        |
| Valuation                          | $2B             | $10B+              |

The demand for a comprehensive solution is undeniable. That's where we come in. Our platform offers a holistic approach, addressing these market needs with a single, scalable, and blockchain-agnostic solution. We deliver in-depth security analysis, real-time compliance monitoring, and future-oriented threat intelligence. As the smart contract landscape continues to evolve, our AI-driven approach positions us as a leader in securing and streamlining smart contracts across the entire blockchain ecosystem.

{% hint style="info" %}

1. ARK Investment Management LLC. (2024). Big ideas 2024: Annual research report. ARK Invest; Available online: <https://www.ark-invest.com/big-ideas-2024>
2. Messari. Smart Contract Market Analysis. Messari, 2023; Available online: <https://messari.io/report-pdf/f125632168e9a04e016fe43bc551f412389eda4f.pdf> &#x20;
   {% endhint %}

### Competitive Analysis

The smart contract security landscape is a crowded space, with solutions ranging from manual code audits to automated vulnerability scanners. But here's what sets our AI-powered platform apart:

* **Beyond Vulnerability Detection:** While some competitors focus solely on identifying existing vulnerabilities, our platform goes the extra mile. We offer a comprehensive suite of features, including predictive threat intelligence, real-time compliance monitoring, and automated auditing.
* **Proactive Protection:** Our AI muscle gives us a distinct edge. We don't just react to threats, we anticipate them. By harnessing the power of AI, we can predict and prevent future attacks, a capability largely missing from current solutions.
* **Constantly Evolving Defenses:** Traditional security solutions often become outdated as new threats emerge. Our platform is different. The AI models that power our platform continuously learn from new data, ensuring our security measures remain agile and adapt to the latest trends and threats in the ever-changing blockchain ecosystem.
* **Usability for Everyone:** Complex security and compliance data can be intimidating. Our user-friendly interface and actionable insights make this information accessible to everyone, even non-experts. This broader accessibility fosters wider adoption and empowers a larger user base to leverage the power of our platform.

While competitors offer various solutions, none can match the comprehensive and proactive approach delivered by our AI-powered platform. This competitive edge allows us to serve a broader spectrum of clients and navigate the rapidly changing landscape of blockchain technology and regulations with agility and confidence.

### Roadmap

Our roadmap isn't just a plan, it's a commitment to continuous improvement. It outlines the strategic development and deployment phases of our AI-powered platform for Web3 security and compliance. This roadmap reflects our dedication to staying ahead of the curve and addressing the evolving needs of the blockchain ecosystem.

#### 2023 Roadmap: Research, Data Collection, and Initial Testing

Our journey in 2023 was foundational, focusing on laying the groundwork for our AI-driven platform through extensive research, data collection, and initial testing phases. Here's a recap of our key milestones throughout the year:

**Q1 2023: Preliminary Research and Conceptualization**

* **Market and Technical Research**: Conducted comprehensive market analysis to understand the current landscape of smart contract vulnerabilities and existing security solutions. Parallelly, we embarked on technical research to explore the feasibility of applying AI in detecting and mitigating these vulnerabilities.
* **Concept Development**: Defined the core concept of our AI-driven platform, focusing on how it could uniquely address the challenges identified in our research.

**Q2 2023: Data Collection and Framework Design**

* **Data Collection**: Began collecting a vast array of data critical for training our AI models, including historical smart contract vulnerabilities, blockchain transaction records, and regulatory compliance guidelines. This data was sourced from public repositories, partner networks, and blockchain platforms.
* **AI Framework Design**: Developed the initial design for our AI framework, determining the key AI methodologies to be used (deep learning, machine learning, NLP) and outlining the architecture for integrating these technologies into our smart contract security platform.

**Q3 2023: Prototype Development and Internal Testing**

* **Alpha Prototype Development**: Translated our AI framework design into an initial prototype, capable of basic vulnerability detection and compliance checking for a limited set of smart contracts.
* **Internal Testing**: Conducted rigorous internal testing of the prototype to evaluate its effectiveness in identifying known vulnerabilities and to refine the AI algorithms based on initial findings.

**Q4 2023: Feedback Integration and Pilot Testing**

* **Feedback Collection**: After internal testing, we collected feedback from a select group of blockchain developers and security experts who interacted with our prototype, focusing on its usability, accuracy, and overall effectiveness.
* **Pilot Testing**: Launched a pilot test with a small number of partners, applying our platform to real-world smart contracts. This phase was crucial for understanding the platform's performance in live environments and for gathering actionable insights to inform further development.

Here's a sneak peek into what's on the horizon:

* **Q1-Q2 2024: Building the Foundation**&#x20;
  * **Platform Blueprint:** We delve deep into the "what" and "how" of using AI for smart contract security and beyond. This involves brainstorming innovative applications and conducting feasibility studies to ensure our vision is achievable.
  * **Tech Stack Selection:** Not all tools are created equal. We have and will meticulously choose the most powerful AI, machine learning, and blockchain technologies to form the backbone of our platform.
  * **Community Building and Awareness:** Engage with potential users and investors through social media, forums, and blockchain events to build a strong community and raise awareness about the project.
  * **Fair Launch:** Implement a fair launch strategy that includes a public sale with a capped purchase limit per participant to prevent whale domination, ensuring a wide and equitable token distribution.&#x20;
  * **Liquidity Provision:** Immediately after the TGE, allocate a portion of the raised funds to provide liquidity on decentralized exchanges (DEXs).&#x20;
* **Q3-Q4 2024: Refining the Experience**&#x20;
  * **Beta Launch – Behind the Scenes:** We'll unveil a closed beta version to a select group of trusted partners on our waitlist. Their feedback on core functionalities will be invaluable in shaping the platform's future.
  * **Community Rewards and Airdrops:** Implement rewards programs and airdrops for early supporters and active community members to incentivize participation and loyalty.
  * **Centralized Exchange (CEX) Listings**: Pursue listings on prominent centralized exchanges to enhance token liquidity and accessibility to a broader audience.&#x20;
  * **Incorporating Insights:** We'll take the feedback from the beta testers to heart. This includes refining our AI algorithms and user interface to ensure a smooth and intuitive experience.
  * **Beta Launch – Opening the Doors:** We'll open the doors to a wider audience with an open beta version. This broader testing phase will allow us to identify and rectify any lingering issues before the official launch.
* **Q1-Q2 2025: Going Live and Growing (Full-Scale Launch and Expansion)**
  * **Platform Launch – Ready for Business:** This is it! We'll officially release the platform with all its functionalities, empowering users to secure and streamline their smart contracts.
  * **Expanding Our Reach:** We won't limit ourselves to one blockchain. We'll integrate the platform with major blockchain networks, ensuring compatibility and accessibility across the ecosystem.
  * **Building open and transparent data interoperability layer:** We believe in collaboration. We'll foster a vibrant community of developers, security experts, and blockchain enthusiasts to share ideas and contribute to the platform's omnichain data network.&#x20;
* **Q3-Q4 2025 and Beyond: Staying Ahead of the Curve (Continuous Improvement and New Features)**
  * **AI on Autopilot:** Our AI engine is never idle and we want to make it fully autonomous. We'll continuously train and improve it with new data and attack vectors, ensuring it remains at the forefront of security threats but it will work on its own.&#x20;
  * **Regulatory Harmony:** The regulatory landscape is constantly shifting. We'll keep our compliance monitoring features up-to-date with the latest regulations, ensuring your smart contracts stay compliant.
  * **Global Expansion and Partnerships:** The world is our playing field. We'll expand our presence worldwide and forge strategic partnerships with leading blockchain platforms and enterprises.

{% hint style="info" %}
Our vision is to launch a revolutionary cross-chain security protocol, designed to unify blockchain security measures into a coordinated ecosystem, providing an open and transparent audit and protection layer for the DeFi 2.0 era. We're building a novel security architecture that bridges automated auditing and AI-driven scam detection across multiple chains, supporting high-throughput analysis, low-latency threat response, and eventual consensus on security states.

Our protocol will leverage cutting-edge AI to debug smart contracts in real-time, offering unparalleled protection for investors, users, and projects alike. By implementing a dual-verification mechanism, we'll achieve higher cybersecurity standards while maintaining the decentralized ethos of blockchain technology.

We'll continue expanding our security toolkit based on this omnichain data network, allowing developers to build robust, scam-resistant dApps and enabling users to interact with DeFi protocols with newfound confidence. Our goal is to create an interoperable security layer that becomes the gold standard for blockchain projects, fostering trust and accelerating mainstream crypto adoption.
{% endhint %}

### Business Model

Our business model is built on a win-win philosophy. We offer a range of services designed to deliver value to our customers while ensuring the sustainable growth of our platform. Whether you're a solo developer or a global enterprise, we have a solution to fit your needs.

* **Subscription Plans Tailored to Your Needs:**
  * **Basic Plan:** This starter plan is ideal for individual developers, users and small projects. It provides access to standard security audits and compliance checks, giving you a solid foundation for smart contract security.
  * **Premium Plan:** For enterprises and larger projects that require more advanced security measures, we offer a premium plan. This plan includes features like predictive threat intelligence, real-time monitoring, and priority support, giving you complete peace of mind.
* **Pay-Per-Audit Option for Flexibility:**

  Not everyone needs a full subscription. If you only require occasional audits, we offer a pay-per-audit pricing option. This allows you to get comprehensive security and compliance analysis without the commitment of a subscription.
* **Custom Enterprise Solutions for a Perfect Fit:**

  For our enterprise clients, we offer custom solutions. These solutions integrate our platform's capabilities seamlessly with your existing systems, providing bespoke security and compliance features tailored to your specific needs.

### Team & Advisors

The foundation of our success rests on the expertise and dedication of our team and advisors. We've assembled a dream team of individuals who are passionate about blockchain technology, AI, and security, and who possess a deep understanding of the challenges and opportunities within the smart contract landscape.

Firstly, we're a passionate group of dreamers and doers, united by a relentless pursuit of a more secure and efficient blockchain future. Secondly, we believe AI is the key to unlocking the full potential of Web3 security, and we're here to change the world, one secure line of code at a time.

**The Brains Behind the Operation**

* **Director of Cyber Resilience:** A seasoned entrepreneur and whitehat hacker with a proven track record in the blockchain and cybersecurity sectors. Her leadership and vision guide the overall direction of the company.
* **Chief Blockchain Architect:** With a mind like a cryptographic hash function, he has spent years dissecting the intricate workings of blockchain architecture. His expertise ensures our platform seamlessly integrates with various blockchain ecosystems, making security accessible to all.
* **Head of Research & AI:** A true AI whisperer, he possesses an uncanny ability to unlock the potential of artificial intelligence. He leads our research team, constantly pushing the boundaries of AI to develop the most advanced security protocols for Web3.
* **Security Architect:** Nicknamed "The Vigilante" within the cybersecurity community, she is a force to be reckoned with. A self-proclaimed "digital guardian angel," she's spent her career on the front lines, outsmarting hackers and plugging security holes in some of the most critical systems in the world. Her experience in identifying and thwarting cyberattacks is unparalleled, and her insights are crutial in building a platform that anticipates and neutralizes even the most cunning threats.

**The A-Team: Guiding Stars of the Blockchain**

Forget constellations – our development team is a supernova of brilliance! We've assembled the brightest minds in blockchain technology, cybersecurity, regulatory law, and business development. Each member brings a unique perspective and a wealth of experience to the table, united by a common goal: to revolutionize the way Web3 is secured.

* **Blockchain Architects:** These code wizards understand the intricate workings of various blockchain ecosystems, ensuring our platform integrates seamlessly and unlocks security for everyone.
* **Cybersecurity Stalwarts:** Our digital defenders are like fortress architects, constantly on guard against potential threats. They are [code4rena](https://code4rena.com/) judges and leverage their expertise to build robust security protocols that keep your smart contracts safe.
* **Regulatory Navigators:** The legal landscape surrounding blockchain is ever-evolving. Our legal eagles stay ahead of the curve, ensuring our platform adheres to the latest regulations and allowing you to operate with confidence.
* **Business Development Gurus:** These master strategists translate our vision into reality. They forge key partnerships within the blockchain ecosystem and ensure our platform reaches a global audience.

**Advisory Board: Guiding Lights for the Future**

Our advisory board isn't just a collection of advisors – they're the guiding lights that illuminate our path forward. Each member is a prominent figure in their respective field, bringing a wealth of experience and knowledge to the table:

* **Blockchain Visionaries:** These thought leaders have witnessed the evolution of blockchain technology firsthand. Their insights shape our strategic direction and ensure our platform remains at the forefront of innovation.
* **Cybersecurity Experts:** Our advisors possess an unmatched understanding of the evolving threat landscape. They help us anticipate and neutralize even the most sophisticated cyberattacks, constantly reinforcing our platform's security posture.
* **Regulatory Powerhouses:** Navigating the complex world of blockchain regulations is no small feat. These legal luminaries provide invaluable guidance, ensuring compliance and fostering trust within the ecosystem.
* **Business Development Titans:** Our advisors boast extensive networks and a deep understanding of the global market. They connect us with key players in the industry and help us expand our reach, ensuring our platform has a lasting impact.

**A Force Multiplier for Success**

By combining the exceptional skills and dedication of our core team with the strategic insights of our advisory board, we are uniquely positioned to address the complex challenges of Web3 security. Together, we are a force multiplier for success, propelling the blockchain ecosystem towards a more secure and compliant future. We are confident that our team's unwavering dedication and the power of AI will revolutionize the way smart contracts are secured and monitored.


# Challenge

Blockchain technology is with no doubt a game-changer, disrupting industries with its promise of unparalleled security, transparency, and efficiency. At the heart of this revolution lies the smart contract: a self-executing agreement where the terms are embedded directly in code. Smart contracts automate transactions, eliminating intermediaries and driving innovation in everything from finance to supply chain management.

While powerful, smart contracts aren't without their challenges. Their very strength, immutability, becomes a double-edged sword. Any weaknesses in the code can have irreversible consequences. The rapid growth of Decentralized Applications (DApps) unlocks exciting possibilities, but their reliance on smart contracts for user assets introduces critical security risks. Buggy code can open the door to hacks and exploits, as evidenced below:

* **Hacks & Exploits:** Over $15 billion of funds was lost due to exploits in the Web3 ecosystem to date. $1.7 billion in crypto was stolen in 2023 across over 200 hacks. (2022 was the biggest year ever for crypto theft, with $3.7 billion stolen).
* **Phishing & Scams:** The total funds lost by users to crypto phishing attacks amounted to $300 million during 2023. Exit scams accounted for $136 million over 263 cases in the same year.&#x20;

But why?

* **Costly Gatekeepers:** Traditional audits can cost tens to hundreds of thousands of dollars, creating a significant financial barrier for early stage projects.
* **Phishing & Scam Blind Spots:** Traditional audits cannot address external threats like phishing scams and social engineering attacks targeting users' crypto wallets and assets.
* **Focus on the Badge, Not Security:** The emphasis on securing a "stamp of approval" from a big-name auditor can overshadow the core goal of identifying and fixing vulnerabilities.
* **Launch Delays:** The time-consuming audit process can delay product launches and token listings, incentivizing some projects to bypass audits altogether in a rush to market, potentially exposing users to security risks.
* **Auditor Roulette:** The quality and clarity of reports, along with communication throughout the audit, can vary depending on the assigned auditor.

High-profile breaches in recent years have underscored the urgent need for stronger security measures. Traditional security and compliance tools simply can't keep up with the ever-evolving complexity of smart contracts. The industry craves a more sophisticated solution.


# Solution

At Veritas, we recognized a critical gap in smart contract security and knew that artificial intelligence was the key to bridging it. Our platform put to use the power of AI to completely transform how smart contracts are secured, audited, and monitored across blockchain networks.

{% hint style="info" %}
Our goal is to establish an interoperable security standard that unifies blockchain security measures into a coordinated ecosystem, developing a novel security architecture that supports high-throughput analysis, low-latency threat response, and eventual consensus on security states.
{% endhint %}

#### Automated Audits: Revolutionizing Speed and Affordability

Traditional smart contract auditing processes are notoriously slow and expensive, primarily due to their reliance on manual labor and extensive time investments. Veritas shatters these limitations with our AI-driven platform, drastically reducing both the time and financial burden associated with audits. Our advanced AI algorithms expedite the auditing process, delivering results up to 10 times faster than conventional methods. What once took weeks or even months can now be accomplished in a matter of hours or even minutes.

Moreover, by leveraging AI efficiencies, we've managed to slash costs dramatically. Our automated audits are up to 90% more affordable than traditional approaches, making robust smart contract security accessible to projects of all sizes.&#x20;

#### AI Debugger: Real-Time Fixes Through Autonomous Agents

Veritas goes beyond mere vulnerability detection with AI Debugger. This feature deploys autonomous AI agents that not only identify issues but also suggest and even deploy fixes in real-time. These AI agents collaborate to review smart contract code and audit reports, providing immediate, actionable solutions to vulnerabilities.

This real-time approach to debugging and fixing smart contracts represents a necessary novelty in blockchain security. It minimizes the window of vulnerability between issue detection and resolution, significantly reducing the risk of exploits. Furthermore, by automating the fix suggestion and deployment process, we're enabling developers to focus on innovation while our AI takes care of the security heavy lifting.

#### Insurance Coverage: Financial Protection Against Exploits

Understanding that no system is infallible, Veritas offers an insurance coverage model to protect against financial losses from exploits. This feature provides an additional layer of security and peace of mind for smart contract deployers, investors and users alike.

Our insurance coverage is designed to mitigate the financial risks associated with potential smart contract vulnerabilities. In the event of an exploit, affected parties can be compensated, helping to maintain trust and stability within the blockchain ecosystem. This insurance model not only protects individual projects but also contributes to the overall resilience of the decentralized finance landscape.

#### Advanced Detection: Proactive Identification of Malicious Activities

Veritas employs comperhensive detection mechanisms to proactively identify a wide range of malicious activities, including phishing attempts, fraudulent dApps, scam projects, and other security threats. Our system continuously monitors blockchain networks, analyzing patterns and behaviors to spot potential risks before they can cause harm.

By leveraging machine learning and advanced heuristics, our detection system evolves and improves over time, staying ahead of emerging threat vectors. This proactive approach to security helps create a safer environment for all blockchain participants, from individual users to large-scale DeFi protocols.

Through these innovative solutions, Veritas is setting a new standard for blockchain security. We're not just providing a set of tools; we're establishing a comprehensive protocol designed to secure, innovate, and empower the entire Web3 space. By addressing the primary challenges facing blockchain security today – speed, cost, accuracy, and proactive protection – Veritas is leading the way for a more secure and trustworthy decentralized future.


# Technology&#x20;

AI is the secret sauce behind our platform's effectiveness in securing smart contracts.

You can read the our [full research](/thesis/automated-audits) for in-deep understanding our aproach. Here's a peek under the hood to see how we leverage AI for specific security challenges:

* **AI in Smart Contract Security:** At the heart of our platform lies a powerful AI engine fueled by customized AI technologies specifically designed to tackle the unique challenges of smart contract security. For vulnerability detection, we utilize a combination of supervised and unsupervised machine learning models trained on massive datasets of real-world smart contract code. These models can not only identify known vulnerabilities but also detect anomalous patterns that might indicate new, previously undiscovered security risks.
* **Real-Time Monitoring and Compliance:** Our platform doesn't sleep. To ensure ongoing compliance and security, we leverage real-time monitoring mechanisms. Machine learning algorithms continuously analyze transactions and interactions with your smart contracts, flagging any activity that deviates from normal patterns or violates regulatory standards.
* **Automated Auditing Process:** The auditing process gets a major boost from our NLP and deep learning expertise. We use these powerful AI techniques to analyze the natural language within smart contracts and their comments. This allows us to automatically generate comprehensive audit reports that highlight potential security concerns and suggest optimizations for both efficiency and compliance.
* **Predictive Threat Intelligence:** Our platform takes a future-proof approach to security. We leverage a sophisticated predictive analytics framework that utilizes historical data and current trends to forecast future security challenges. This forward-thinking approach allows our platform to constantly adapt its security measures in anticipation of new threats, ensuring your smart contracts remain secure against evolving attack vectors.


# Architecture

We designed our AI-driven platform with scalability, security, and efficiency in mind. It's built to seamlessly integrate AI technologies into the entire smart contract lifecycle. Here's a breakdown of the key components that make it tick:

* **Data Ingestion Module:** This critical module acts like a data vacuum, constantly aggregating and pre-processing data from multiple sources. Blockchain transactions, smart contract code repositories, and regulatory databases are all fair game. This ensures our platform has a comprehensive dataset to work with for analysis.
* **AI Engine:** Consider this the brain of the operation. The AI engine is where the magic happens. Here, machine learning models, deep learning networks, and NLP algorithms are trained and put to work. This engine is the powerhouse behind all the platform's functionalities, from predictive analytics and vulnerability detection to compliance monitoring.
* **User Interface (UI):** We made sure our platform is user-friendly. A user-friendly dashboard provides clients with clear insights into their smart contracts' security posture, audit results, compliance status, and predictive analytics. The UI doesn't just present information; it empowers users. The dashboard allows for interaction with the platform, customization of monitoring parameters, and receipt of real-time security alerts.
* **Blockchain Interfacing Layer:** This component acts as a bridge, facilitating seamless communication between our platform and various blockchain networks. It ensures the platform can operate in a blockchain-agnostic manner. This layer plays a crucial role in deploying smart contracts, monitoring transactions, and executing security recommendations across different blockchains.
* **Security and Compliance Database:** Imagine a living encyclopedia of security threats and regulations. Our continuously updated security and compliance database acts as a central repository for security vulnerability signatures, compliance requirements, and regulatory guidelines. This ever-evolving database informs the AI engine's analyses, guaranteeing the platform's outputs are based on the latest and most accurate information.

The modular design of our platform is a key strength. Each component can be independently updated or scaled. This allows us to rapidly adapt to the ever-changing landscape of blockchain technology, advancements in AI, and evolving regulatory environments. Our platform is built to constantly improve, ensuring your smart contracts remain secure and compliant well into the future.


# Use Cases

Our AI-powered platform isn't a one-size-fits-all solution. It's a versatile toolbox designed to empower a wide range of players in the blockchain ecosystem. Here are a few real-world examples showcasing how different sectors can leverage our platform to fortify their smart contracts:

* **Decentralized Finance (DeFi):** DeFi platforms are prime targets for hackers, and a single exploit can drain millions in a matter of secounds. Our platform acts as a guardian for DeFi projects, proactively detecting and eliminating vulnerabilities before they wreak havoc. With predictive threat intelligence, we can foresee potential attack vectors, allowing developers to stay a step ahead and continuously strengthen their contracts.
* **RWA/NFT Marketplace:** The RWA/NFT market thrives on secure smart contracts for managing ownership, transfers, and royalties. Our platform's automated auditing process ensures these contracts are watertight, preventing disasters like unauthorized access or stolen NFTs. Real-time monitoring keeps a watchful eye, ensuring ongoing compliance with copyright laws and royalty structures.
* **Supply Chain:** Transparency and efficiency are hallmarks of blockchain-powered supply chains, where smart contracts automate transactions and track the origin of goods. Our platform empowers companies to safeguard these contracts from tampering, ensuring they adhere to international trade regulations and standards.

These are just a few examples. The applications extend far beyond. From finance and healthcare to real estate and logistics, the demand for robust smart contract security is skyrocketing across industries. Regulatory bodies are also taking notice, and the need for compliance monitoring tools is growing rapidly.

Our platform is built to address this growing demand. It's a future-proof solution, scalable and adaptable to any blockchain, offering in-depth security analysis, real-time compliance monitoring, and cutting-edge threat prediction. As the smart contract landscape continues to evolve, our AI-driven approach positions us as the go-to solution for securing and streamlining smart contracts across the entire blockchain ecosystem.


# Market Analysis

The smart contract market is on a tear, fueled by the widespread adoption of blockchain technology. According to the most recent report the global smart contracts market size is poised for significant growth, reaching $5.2 trillion in 2030, from $775 billion in 2023 \[1]. The sales are expected to witness a robust CAGR of 32% and generate over $450 billion in fees annually by 2030. However, with this growth comes complexity. The increasing value and intricate nature of smart contracts have made robust security and compliance paramount.

Our market analysis reveals a significant gap in existing solutions. Many are limited in scope, lacking real-time functionality or the ability to adapt to emerging threats. Some rely on manual code audits, a slow and resource-intensive process. Others offer automated vulnerability scanning, but these tools often fall short in predicting and preventing future attacks.

The market is expected to grow rapidly over the coming years as blockchain technology sees increasing real-world adoption. Key drivers of the smart contract market include the need for automation of manual processes, cost reduction, improved transactional security, and transparency.

By democratizing access to security audits, market intelligence company Messari expects that AI-native security networks will expand the total addressable market (TAM) by a factor of 5-10x \[2]. Table below is comparing centralized auditors vs decentralized security networks across crypto market cycles.&#x20;

|                                    | Certik in 20-22 | AI Audits in 24-26 |
| ---------------------------------- | --------------- | ------------------ |
| Peak-to-trough crypto market cap   | $200B →$2T      | $1T →???           |
| % projects getting security audits | 10%             | 50-75%             |
| % leader market share              | 60%             | 60-75%             |
| Projects audited                   | 10k+            | 100k+              |
| Capital raised                     | $230m           | fair launch        |
| Valuation                          | $2B             | $10B+              |

The demand for a comprehensive solution is undeniable. That's where we come in. Our platform offers a holistic approach, addressing these market needs with a single, scalable, and blockchain-agnostic solution. We deliver in-depth security analysis, real-time compliance monitoring, and future-oriented threat intelligence. As the smart contract landscape continues to evolve, our AI-driven approach positions us as a leader in securing and streamlining smart contracts across the entire blockchain ecosystem.

{% hint style="info" %}

1. ARK Investment Management LLC. (2024). Big ideas 2024: Annual research report. ARK Invest; Available online: <https://www.ark-invest.com/big-ideas-2024>
2. Messari. Smart Contract Market Analysis. Messari, 2023; Available online: <https://messari.io/report-pdf/f125632168e9a04e016fe43bc551f412389eda4f.pdf> &#x20;
   {% endhint %}


# Competitive Analysis

The smart contract security landscape is a crowded space, with solutions ranging from manual code audits to automated vulnerability scanners. But here's what sets our AI-powered platform apart:

* **Beyond Vulnerability Detection:** While some competitors focus solely on identifying existing vulnerabilities, our platform goes the extra mile. We offer a comprehensive suite of features, including predictive threat intelligence, real-time compliance monitoring, and automated auditing.
* **Proactive Protection:** Our AI muscle gives us a distinct edge. We don't just react to threats, we anticipate them. By harnessing the power of AI, we can predict and prevent future attacks, a capability largely missing from current solutions.
* **Constantly Evolving Defenses:** Traditional security solutions often become outdated as new threats emerge. Our platform is different. The AI models that power our platform continuously learn from new data, ensuring our security measures remain agile and adapt to the latest trends and threats in the ever-changing blockchain ecosystem.
* **Usability for Everyone:** Complex security and compliance data can be intimidating. Our user-friendly interface and actionable insights make this information accessible to everyone, even non-experts. This broader accessibility fosters wider adoption and empowers a larger user base to leverage the power of our platform.

While competitors offer various solutions, none can match the comprehensive and proactive approach delivered by our AI-powered platform. This competitive edge allows us to serve a broader spectrum of clients and navigate the rapidly changing landscape of blockchain technology and regulations with agility and confidence.


# Roadmap

Our roadmap isn't just a plan, it's a commitment to continuous improvement. It outlines the strategic development and deployment phases of our AI-powered platform for Web3 security and compliance. This roadmap reflects our dedication to staying ahead of the curve and addressing the evolving needs of the blockchain ecosystem.

{% hint style="info" %}
Our vision is to launch a revolutionary cross-chain security protocol, designed to unify blockchain security measures into a coordinated ecosystem, providing an open and transparent audit and protection layer for the DeFi 2.0 era. We're building a novel security architecture that bridges automated auditing and AI-driven scam detection across multiple chains, supporting high-throughput analysis, low-latency threat response, and eventual consensus on security states.

Our protocol will leverage cutting-edge AI to debug smart contracts in real-time, offering unparalleled protection for investors, users, and projects alike. By implementing a dual-verification mechanism, we'll achieve higher cybersecurity standards while maintaining the decentralized ethos of blockchain technology.

We'll continue expanding our security toolkit based on this omnichain data network, allowing developers to build robust, scam-resistant dApps and enabling users to interact with DeFi protocols with newfound confidence. Our goal is to create an interoperable security layer that becomes the gold standard for blockchain projects, fostering trust and accelerating mainstream crypto adoption.
{% endhint %}

#### 2023 Roadmap: Research, Data Collection, and Initial Testing

Our journey in 2023 was foundational, focusing on laying the groundwork for our AI-driven platform through extensive research, data collection, and initial testing phases. Here's a recap of our key milestones throughout the year:

**Q1 2023: Preliminary Research and Conceptualization**

* **Market and Technical Research**: Conducted comprehensive market analysis to understand the current landscape of smart contract vulnerabilities and existing security solutions. Parallelly, we embarked on technical research to explore the feasibility of applying AI in detecting and mitigating these vulnerabilities.
* **Concept Development**: Defined the core concept of our AI-driven platform, focusing on how it could uniquely address the challenges identified in our research.

**Q2 2023: Data Collection and Framework Design**

* **Data Collection**: Began collecting a vast array of data critical for training our AI models, including historical smart contract vulnerabilities, blockchain transaction records, and regulatory compliance guidelines. This data was sourced from public repositories, partner networks, and blockchain platforms.
* **AI Framework Design**: Developed the initial design for our AI framework, determining the key AI methodologies to be used (deep learning, machine learning, NLP) and outlining the architecture for integrating these technologies into our smart contract security platform.

**Q3 2023: Prototype Development and Internal Testing**

* **Alpha Prototype Development**: Translated our AI framework design into an initial prototype, capable of basic vulnerability detection and compliance checking for a limited set of smart contracts.
* **Internal Testing**: Conducted rigorous internal testing of the prototype to evaluate its effectiveness in identifying known vulnerabilities and to refine the AI algorithms based on initial findings.

**Q4 2023: Feedback Integration and Pilot Testing**

* **Feedback Collection**: After internal testing, we collected feedback from a select group of blockchain developers and security experts who interacted with our prototype, focusing on its usability, accuracy, and overall effectiveness.
* **Pilot Testing**: Launched a pilot test with a small number of partners, applying our platform to real-world smart contracts. This phase was crucial for understanding the platform's performance in live environments and for gathering actionable insights to inform further development.

Here's a sneak peek into what's on the horizon:

* **Q1-Q2 2024: Building the Foundation**&#x20;
  * **Platform Blueprint:** We delve deep into the "what" and "how" of using AI for smart contract security and beyond. This involves brainstorming innovative applications and conducting feasibility studies to ensure our vision is achievable.
  * **Tech Stack Selection:** Not all tools are created equal. We have and will meticulously choose the most powerful AI, machine learning, and blockchain technologies to form the backbone of our platform.
  * **Community Building and Awareness:** Engage with potential users and investors through social media, forums, and blockchain events to build a strong community and raise awareness about the project.
  * **Fair Launch:** Implement a fair launch strategy that includes a public sale with a capped purchase limit per participant to prevent whale domination, ensuring a wide and equitable token distribution.&#x20;
  * **Liquidity Provision:** Immediately after the TGE, allocate a portion of the raised funds to provide liquidity on decentralized exchanges (DEXs).&#x20;
* **Q3-Q4 2024: Refining the Experience**&#x20;
  * Decentralized Finance (DeFi) Integrations: Collaborate with DeFi platforms for staking, lending, and yield farming opportunities for token holders, fostering utility and demand for the token.&#x20;
  * **Beta Launch – Behind the Scenes:** We'll unveil a closed beta version to a select group of trusted partners on our waitlist. Their feedback on core functionalities will be invaluable in shaping the platform's future.
  * **Community Rewards and Airdrops:** Implement rewards programs and airdrops for early supporters and active community members to incentivize participation and loyalty.
  * **Centralized Exchange (CEX) Listings**: Pursue listings on prominent centralized exchanges to enhance token liquidity and accessibility to a broader audience.&#x20;
  * **Incorporating Insights:** We'll take the feedback from the beta testers to heart. This includes refining our AI algorithms and user interface to ensure a smooth and intuitive experience.
  * **Beta Launch – Opening the Doors:** We'll open the doors to a wider audience with an open beta version. This broader testing phase will allow us to identify and rectify any lingering issues before the official launch.
* **Q1-Q2 2025: Going Live and Growing (Full-Scale Launch and Expansion)**
  * **Platform Launch – Ready for Business:** This is it! We'll officially release the platform with all its functionalities, empowering users to secure and streamline their smart contracts.
  * **Expanding Our Reach:** We won't limit ourselves to one blockchain. We'll integrate the platform with major blockchain networks, ensuring compatibility and accessibility across the ecosystem.
  * **Building open and transparent data interoperability layer:** We believe in collaboration. We'll foster a vibrant community of developers, security experts, and blockchain enthusiasts to share ideas and contribute to the platform's omnichain data network.&#x20;
* **Q3-Q4 2025 and Beyond: Staying Ahead of the Curve (Continuous Improvement and New Features)**
  * **AI on Autopilot:** Our AI engine is never idle and we want to make it fully autonomous. We'll continuously train and improve it with new data and attack vectors, ensuring it remains at the forefront of security threats but it will work on its own.&#x20;
  * **Regulatory Harmony:** The regulatory landscape is constantly shifting. We'll keep our compliance monitoring features up-to-date with the latest regulations, ensuring your smart contracts stay compliant.
  * **Global Expansion and Partnerships:** The world is our playing field. We'll expand our presence worldwide and forge strategic partnerships with leading blockchain platforms and enterprises.

Our roadmap is a testament to our dedication to providing a state-of-the-art AI-powered solution. By continuously improving and innovating, we ensure our platform stays ahead of the curve, effectively meeting the security and compliance needs of our users in the ever-evolving blockchain ecosystem.


# Business Model

Our business model is built on a win-win philosophy. We offer a range of services designed to deliver value to our customers while ensuring the sustainable growth of our platform. Whether you're a solo developer or a global enterprise, we have a solution to fit your needs.

* **Subscription Plans Tailored to Your Needs:**
  * **Basic Plan:** This starter plan is ideal for individual developers, users and small projects. It provides access to standard security audits and compliance checks, giving you a solid foundation for smart contract security.
  * **Premium Plan:** For enterprises and larger projects that require more advanced security measures, we offer a premium plan. This plan includes features like predictive threat intelligence, real-time monitoring, and priority support, giving you complete peace of mind.
* **Pay-Per-Audit Option for Flexibility:**

  Not everyone needs a full subscription. If you only require occasional audits, we offer a pay-per-audit pricing option. This allows you to get comprehensive security and compliance analysis without the commitment of a subscription.
* **Custom Enterprise Solutions for a Perfect Fit:**

  For our enterprise clients, we offer custom solutions. These solutions integrate our platform's capabilities seamlessly with your existing systems, providing bespoke security and compliance features tailored to your specific needs.


# Team and Advisors

The foundation of our success rests on the expertise and dedication of our team and advisors. We've assembled a dream team of individuals who are passionate about blockchain technology, AI, and security, and who possess a deep understanding of the challenges and opportunities within the smart contract landscape.

Firstly, we're a passionate group of dreamers and doers, united by a relentless pursuit of a more secure and efficient blockchain future. Secondly, we believe AI is the key to unlocking the full potential of Web3 security, and we're here to change the world, one secure line of code at a time.

**The Brains Behind the Operation**

* **Director of Cyber Resilience:** A seasoned entrepreneur and whitehat hacker with a proven track record in the blockchain and cybersecurity sectors. Her leadership and vision guide the overall direction of the company.
* **Chief Blockchain Architect:** With a mind like a cryptographic hash function, he has spent years dissecting the intricate workings of blockchain architecture. His expertise ensures our platform seamlessly integrates with various blockchain ecosystems, making security accessible to all.
* **Head of Research & AI:** A true AI whisperer, he possesses an uncanny ability to unlock the potential of artificial intelligence. He leads our research team, constantly pushing the boundaries of AI to develop the most advanced security protocols for Web3.
* **Security Architect:** Nicknamed "The Vigilante" within the cybersecurity community, she is a force to be reckoned with. A self-proclaimed "digital guardian angel," she's spent her career on the front lines, outsmarting hackers and plugging security holes in some of the most critical systems in the world. Her experience in identifying and thwarting cyberattacks is unparalleled, and her insights are crutial in building a platform that anticipates and neutralizes even the most cunning threats.

**The A-Team: Guiding Stars of the Blockchain**

Forget constellations – our development team is a supernova of brilliance! We've assembled the brightest minds in blockchain technology, cybersecurity, regulatory law, and business development. Each member brings a unique perspective and a wealth of experience to the table, united by a common goal: to revolutionize the way Web3 is secured.

* **Blockchain Architects:** These code wizards understand the intricate workings of various blockchain ecosystems, ensuring our platform integrates seamlessly and unlocks security for everyone.
* **Cybersecurity Stalwarts:** Our digital defenders are like fortress architects, constantly on guard against potential threats. They are [code4rena](https://code4rena.com/) judges and leverage their expertise to build robust security protocols that keep your smart contracts safe.
* **Regulatory Navigators:** The legal landscape surrounding blockchain is ever-evolving. Our legal eagles stay ahead of the curve, ensuring our platform adheres to the latest regulations and allowing you to operate with confidence.
* **Business Development Gurus:** These master strategists translate our vision into reality. They forge key partnerships within the blockchain ecosystem and ensure our platform reaches a global audience.

**Advisory Board: Guiding Lights for the Future**

Our advisory board isn't just a collection of advisors – they're the guiding lights that illuminate our path forward. Each member is a prominent figure in their respective field, bringing a wealth of experience and knowledge to the table:

* **Blockchain Visionaries:** These thought leaders have witnessed the evolution of blockchain technology firsthand. Their insights shape our strategic direction and ensure our platform remains at the forefront of innovation.
* **Cybersecurity Experts:** Our advisors possess an unmatched understanding of the evolving threat landscape. They help us anticipate and neutralize even the most sophisticated cyberattacks, constantly reinforcing our platform's security posture.
* **Regulatory Powerhouses:** Navigating the complex world of blockchain regulations is no small feat. These legal luminaries provide invaluable guidance, ensuring compliance and fostering trust within the ecosystem.
* **Business Development Titans:** Our advisors boast extensive networks and a deep understanding of the global market. They connect us with key players in the industry and help us expand our reach, ensuring our platform has a lasting impact.

**A Force Multiplier for Success**

By combining the exceptional skills and dedication of our core team with the strategic insights of our advisory board, we are uniquely positioned to address the complex challenges of Web3 security. Together, we are a force multiplier for success, propelling the blockchain ecosystem towards a more secure and compliant future. We are confident that our team's unwavering dedication and the power of AI will revolutionize the way smart contracts are secured and monitored.


# Legal and Regulatory Considerations

The legal and regulatory landscape surrounding blockchain is a moving target. Our platform is designed with this dynamism in mind, offering the flexibility to adapt and ensure smart contracts remain compliant with the latest regulations across jurisdictions.

Here's what keeps us on top of the regulatory curve:

* **Global Compliance Chameleon:** Our platform's compliance monitoring tools are like chameleons. They can adapt to the unique regulatory requirements of different countries. This empowers users to navigate the complexities of international blockchain applications with confidence.
* **Data Privacy Fort Knox:** We understand the importance of data privacy. Our platform adheres to the strictest data privacy regulations, including GDPR in Europe and CCPA in California. Advanced security measures safeguard user data, ensuring complete privacy.
* **Smart Contract Legality Compass:** The legal treatment of smart contracts varies by jurisdiction. We provide users with the tools they need to ensure their smart contracts are legally enforceable wherever they operate. This eliminates ambiguity and fosters trust in the enforceability of these digital agreements.

Our commitment goes beyond simply reacting to changes. We're proactive. Our compliance database and monitoring algorithms are constantly updated to reflect new regulations and guidelines. Furthermore, we actively engage with legal experts and regulatory bodies to anticipate changes and integrate them proactively into our platform. This ensures our users are always a step ahead of the ever-evolving legal landscape.

{% hint style="info" %}
The table below provides a summary of digital asset legislative, regulatory, and licensing status as of January 2024. It factors in the implications of the EU's Markets in Crypto-Assets Regulation (MiCAR), which came into effect in June 2023.&#x20;
{% endhint %}

<figure><img src="/files/Vma4ETBliYk5NEepoR66" alt=""><figcaption><p>Source: PwC, January 2024</p></figcaption></figure>


# TECH PAPER

{% file src="/files/nitzSCVLML09pSFu3EVR" %}

**Abstract**

Veritas is an advanced AI-powered tool designed to strengthen the security and auditing of smart contracts, particularly on Ethereum and other blockchain platforms. Built upon the Qwen2.5-Coder architecture, Veritas specializes in automating the verification of Ethereum Request for Comment (ERC) standards and detecting vulnerabilities in smart contracts. By leveraging large-scale training on over 5.5 trillion tokens and processing context lengths of up to 131,072 tokens, Veritas offers a robust solution for auditing complex and large-scale smart contract ecosystems.

This report details Veritas's architecture, fine-tuning methodology, and performance across a wide range of code-related tasks and security auditing benchmarks. In comparative studies, Veritas demonstrated superior accuracy, identifying critical security vulnerabilities such as reentrancy, timestamp dependencies, and tx.origin misuse. The model outperformed both traditional static analysis tools and manual audits in terms of detection accuracy, speed, and cost-effectiveness, delivering results 14,605 times faster and reducing costs by over 11,000 times compared to manual services.

The application of advanced AI techniques, including supervised and reinforcement learning, allows Veritas to adapt to evolving threats and emerging vulnerabilities in blockchain ecosystems. These capabilities make Veritas an essential tool for developers, auditors, and organizations seeking to ensure the security and reliability of their smart contracts.

### 1. Introduction&#x20;

The rapid growth of blockchain technology and decentralized finance (DeFi) has led to an exponential increase in the deployment and use of smart contracts. These self-executing agreements, which run on blockchain networks, manage significant financial assets and critical operations. However, the complexity and immutability of smart contracts also make them attractive targets for malicious actors, as vulnerabilities can lead to substantial financial losses and reputational damage.

Traditional approaches to smart contract auditing—manual reviews and program analysis tools—are often slow, costly, and limited in their ability to detect complex security issues. Manual audits, while comprehensive, are time-consuming and expensive, making them impractical for many projects. Automated tools, on the other hand, can only identify a subset of issues, often missing nuanced or emerging vulnerabilities. These challenges are further compounded by the evolving nature of blockchain security threats and the growing complexity of smart contract systems.

To address these deficiencies, we present Veritas, a novel automated smart contract auditing system built upon the [Qwen2.5-Coder](https://qwen.readthedocs.io/en/latest/getting_started/concepts.html) architecture. Veritas has been specifically fine-tuned for auditing Ethereum Request for Comment (ERC) standards and detecting a wide array of vulnerabilities. By leveraging advanced natural language processing (NLP) and machine learning techniques, Veritas offers deep insights into both code structure and compliance with key blockchain standards, significantly improving upon the accuracy, speed, and cost-effectiveness of traditional auditing methods.

Key features of Veritas include:

1. Advanced language model foundation: Built on the sophisticated Qwen2.5-Coder architecture, which was trained on over 5.5 trillion tokens, Veritas can process and understand complex code structures across multiple programming languages used in smart contract development.
2. Comprehensive vulnerability detection: Veritas is fine-tuned to identify a wide range of vulnerabilities, including but not limited to reentrancy, timestamp dependency, unhandled exceptions, and improper use of tx.origin.
3. Long-context analysis: Leveraging its underlying model's ability to process context lengths up to 32,768 tokens (extendable to 131,072), Veritas can analyze large-scale projects and entire code repositories efficiently.
4. Multi-modal learning: By combining natural language processing and code analysis techniques, Veritas provides a holistic view of smart contract security.
5. Adaptive learning: Through its advanced AI architecture, Veritas can be continuously updated to learn from new vulnerabilities and adapt to emerging threats in the blockchain ecosystem.

#### 1.1. The Need for Automation in Smart Contract Auditing

The growing complexity of smart contracts and blockchain ecosystems necessitates automated tools that can keep pace with the dynamic security challenges of these environments. While static analysis tools and manual audits have historically been the primary methods for verifying contract security, their limitations become apparent as the scale and sophistication of smart contracts increase.

Veritas provides a holistic solution to these challenges by combining advanced AI capabilities with a deep understanding of blockchain security. By automating the auditing process, Veritas significantly reduces the time and cost associated with smart contract audits while improving the detection of critical vulnerabilities. This automation is particularly valuable in fast-moving sectors like DeFi, where security risks are high, and the need for reliable, real-time auditing is crucial.

#### 1.2. A New Paradigm for Smart Contract Security

The development and deployment of secure smart contracts are critical for the success of blockchain applications. By leveraging the Qwen2.5-Coder foundation and incorporating state-of-the-art vulnerability detection techniques, Veritas offers a new paradigm for smart contract auditing. It provides developers, auditors, and blockchain platforms with the tools they need to ensure the safety and integrity of their contracts.

### 2. Model Architecture

#### 2.1 Overview

Veritas is built upon a sophisticated transformer-based architecture of Qwen2.5-Coder, optimized for code understanding and generation. The model is available in two variants:

1. Base model: 1.5 billion parameters
2. Large model: 7 billion parameters

These models share the same fundamental architecture but differ in their hidden size and number of attention heads, allowing for flexibility in balancing resource constraints and task complexity.

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXclqYEmQtL_hg1u7prtR8C7xSAHz0pM-3o6WF1xcZ8wxejIq4ZX-yrVs3U_ctJ7Zo42lGJ6NpQf4Ai3YoaOl4X-D819os1VjS6Ek2oKv8YiGPn4LbmP0Eow4FB8MhvPvmtto0CLmHjuiKy59_7ICcO-tEYr?key=zIoSjBCJobLgnC-kkl6aaQ" alt="" width="375"><figcaption><p>Table 1: Architecture of Qwen2.5-Coder. (Qwen2.5-Coder Technical Report) </p></figcaption></figure>

The architecture of Qwen2.5-Coder features a multi-query attention mechanism for improved efficiency and rotary positional encoding (RoPE) to better handle long sequences, which are essential in analyzing the extensive codebases found in blockchain ecosystems. Veritas leverages these advanced features to efficiently process and audit smart contracts with deep contextual understanding.

#### 2.2 Tokenization and Special Tokens

Veritas employs a custom tokenizer designed to handle a wide range of programming languages, including Solidity, the primary language for Ethereum smart contracts. The tokenizer's vocabulary includes 151,646 tokens, many of which are tailored for code-specific tasks.

In particular, Veritas uses special tokens that enable it to better understand the unique structures of smart contracts and blockchain-related code. The Fill-in-the-Middle (FIM) tokens, for example, are instrumental in tasks such as code completion and vulnerability detection within incomplete or partially obfuscated code segments.

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXfkc9PUwczkZqO4Pj7iCT8U_lRqRY0AuCz9iGYZxqFht_k58nm9aGIg5lRcicLnYtKcZRLhMQ9YZPu4XQeQvjc3XwxHg7Nhxyusv07kd9fW7gZICNaPExWGBDL2VEGUUfzlzH3hih3_SaE1VxX6pGHfdvKP?key=zIoSjBCJobLgnC-kkl6aaQ" alt="" width="375"><figcaption><p>Table 2: Overview of the special tokens. (Qwen2.5-Coder Technical Report) </p></figcaption></figure>

These tokens ensure that Veritas can efficiently handle incomplete or non-linear code structures, making it highly effective in scenarios where code obfuscation or errors are present.

#### 2.3 Context-Length Capabilities

One of the key strengths of Veritas is its ability to process long sequences, a feature critical for auditing entire smart contract repositories and large DeFi protocols. The ability to handle longer sequences allows Veritas to audit not only individual contracts but also the relationships and interactions between multiple contracts, which is crucial for detecting vulnerabilities that may arise from complex interdependencies.

Base Context Length: Veritas can process up to 32,768 tokens in a single pass, which is sufficient to handle most standalone smart contracts and their associated files.

Extended Context Length: Using the YARN (Yet Another RoPE extensioN) mechanism, Veritas can extend its context length to 131,072 tokens, allowing it to process extremely large projects or repositories without breaking the context. This feature is necessary for performing a holistic analysis of smart contract ecosystems.

Hierarchical Analysis: For projects that exceed even the extended context length, Veritas employs a hierarchical analysis approach. This involves processing individual files or functions and then analyzing inter-file relationships and project-wide patterns. This method allows Veritas to maintain efficiency while providing a comprehensive audit.

These capabilities allow Veritas to:

* Analyze entire ecosystems: Including related contracts, external libraries, and dependencies.
* Detect cross-contract vulnerabilities: Identifying risks that emerge from interactions between multiple contracts.
* Provide detailed, project-wide insights: Ensuring that no vulnerability is overlooked due to the complexity or size of the project.

#### 2.4 Efficiency and Scalability

The Qwen2.5-Coder architecture is optimized for both throughput and depth of analysis, balancing the need for high-speed processing with the ability to delve into complex, semantic rule violations that are often missed by simpler static analysis tools. By utilizing efficient attention mechanisms and adaptive tokenization, Veritas can scale to meet the needs of projects of varying sizes, from small DeFi applications to large-scale blockchain ecosystems.

This architecture allows Veritas to:

* Audit large repositories in a fraction of the time required by manual auditing or static analysis tools.
* Scale its processing to handle projects with hundreds of smart contracts and complex interdependencies.
* Perform highly detailed audits without sacrificing speed, making it suitable for both time-sensitive and large-scale applications.

Overall, Qwen2.5-Coder foundation gives Veritas the processing power and flexibility needed for effective, scalable smart contract auditing. By combining long-context capabilities, efficient tokenization, and hierarchical analysis techniques, Veritas is positioned to handle the increasingly complex world of blockchain and DeFi security.

### 3. Model Foundation and Fine-tuning

#### 3.1 Qwen2.5-Coder Foundation

Veritas is built upon the Qwen2.5-Coder model, which was pretrained on a massive, diverse dataset of over 5.5 trillion tokens. This extensive corpus provides Veritas with a comprehensive understanding of code, including smart contracts, related documentation, and general programming knowledge. The dataset includes:

1. Source Code Data: Spanning 92 programming languages, including smart contract languages like Solidity.
2. Text-Code Grounding Data: Code-related text from web crawls, processed using a coarse-to-fine hierarchical filtering approach.
3. Synthetic Data: Generated to cover edge cases and rare patterns.
4. Math Data: Improving reasoning capabilities for complex financial logic.
5. Text Data: Enabling broad language understanding for clear, human-readable outputs.

<figure><img src="/files/EJSIJMlKsAm1nH6QtE6G" alt=""><figcaption><p>Figure 1: Number of data tokens across different cc-stages, and the validation effectiveness of training Qwen2.5-Coder using corresponding data. (Qwen2.5-Coder Technical Report) </p></figcaption></figure>

#### 3.2 Data Mixture

The Qwen2.5-Coder model, which forms the foundation of Veritas, uses an optimal mixture of:

* 70% Code data
* 20% Text data
* 10% Math data

As shown in Table 3, the 7:2:1 ratio outperformed the others, even surpassing the performance of groups with a higher proportion of code.&#x20;

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXdAwF9xdLa-g-tB7HEvOKWfhqFSMrr3arvCwQblDkI0VHOUyg1uK0PXq7YFAs1P1zgwmYGvxC9qZ5EOKKRfj1XiPozJ0UYugz2Z6J_laGDeor_-4bv0vikykoaJeMZRXFZacGMSheqanyCPowjSPxDCxIDf?key=zIoSjBCJobLgnC-kkl6aaQ" alt="" width="563"><figcaption><p>Table 3: The performance of Qwen2.5-Coder training on different data mixture policy.</p></figcaption></figure>

This balanced mixture provides Veritas with strong code-related capabilities while maintaining general language and mathematical proficiency.

#### 3.3 Veritas Fine-tuning

Building upon the Qwen2.5-Coder foundation, Veritas underwent specialized fine-tuning for smart contract auditing:

1\. Vulnerability-Focused Fine-tuning:

* &#x20; Focus: Specific smart contract vulnerabilities and ERC standard compliance
* &#x20; Data: Curated dataset of known vulnerabilities and audit reports, including:
  * 10,000 contracts from the Slither Audited Smart Contracts Dataset
  * 20,000 contracts from smartbugs-wild
  * 1,000 typical smart contracts with vulnerabilities identified through expert audits
* Techniques:
  * Supervised learning on labeled vulnerability data
  * Semi-supervised learning to leverage unlabeled contract data
  * Reinforcement learning to adapt to new vulnerability patterns
* Purpose: Specialized in detecting and explaining smart contract vulnerabilities, particularly:
  * Re-entrancy
  * Timestamp-Dependency
  * Unhandled-Exceptions
  * Improper use of tx.origin

2\. Long-Context Adaptation:

* Leveraged Qwen2.5-Coder's extended context capabilities (up to 131,072 tokens)
* Fine-tuned on repository-level smart contract data to enhance understanding of project-wide patterns and inter-contract relationships

3\. ERC Standards Specialization:

* Focused on Ethereum Request for Comment (ERC) standards compliance, particularly ERC20, ERC721, and ERC1155
* Trained on a diverse set of ERC-compliant and non-compliant contracts to improve detection of standard violations

Throughout the fine-tuning process, we incorporated:

* Dynamic sampling of smart contract-specific data
* Regular evaluation on held-out datasets of real-world smart contracts, including the SolidiFI benchmark dataset containing 9,369 bugs
* Optimization of model components

This fine-tuning approach enabled Veritas to leverage the robust foundation of Qwen2.5-Coder while developing specialized capabilities in smart contract auditing, vulnerability detection, and ERC compliance checking. The resulting model demonstrates superior performance in identifying a wide range of smart contract vulnerabilities and ERC standard violations, significantly outperforming traditional static analysis tools and manual auditing processes in both accuracy and efficiency.

### 4. Post-training

#### 4.1 Instruction Data Recipe

To transform Veritas into a powerful smart contract auditing assistant, we developed a comprehensive instruction dataset. This dataset was carefully crafted to cover a wide range of auditing tasks and vulnerability types. The instruction data recipe included:

* Multilingual Programming Code Identification:
  * Fine-tuned a model to categorize documents into nearly 100 programming languages
  * Focused on mainstream languages used in smart contract development (e.g., Solidity, Vyper)
  * Maintained some diversity in long-tail languages to ensure broad applicability<br>
* Instruction Synthesis from Real-World Contracts:
  * Extracted code snippets from popular blockchain platforms (Ethereum, Binance Smart Chain, etc.)
  * Used Veritas to generate natural language instructions describing the code's functionality
  * Created responses detailing potential vulnerabilities and best practices
  * Applied quality filters to ensure relevance and accuracy<br>
* Multilingual Code Instruction Data:
  * Implemented a multilingual multi-agent collaborative framework
  * Created language-specific agents for each supported smart contract language
  * Engaged agents in structured dialogues to formulate new instructions and solutions
  * Implemented cross-lingual knowledge distillation to share insights across languages<br>
* Vulnerability-Specific Instructions:
  * Created targeted instructions for detecting common vulnerabilities (e.g., reentrancy, integer overflow)
  * Included examples of both vulnerable and secure code implementations
  * Developed instructions for checking ERC standard compliance<br>
* Audit Report Generation:
  * Defined instructions for generating comprehensive, human-readable audit reports
  * Included examples of professional audit reports to guide the model's output style<br>
* Checklist-based Scoring for Instruction Data:
  * Developed a comprehensive scoring system to evaluate instruction-answer pairs
  * Criteria included consistency, relevance, difficulty, code correctness, and educational value
  * Used scores to filter and prioritize high-quality instruction data<br>
* Multilingual Sandbox for Code Verification:
  * Created a secure environment to execute and validate smart contract code
  * Supported multiple languages (Solidity, Vyper, etc.) and blockchain environments
  * Generated relevant unit tests based on instruction data
  * Used sandbox results to verify the correctness of Veritas's vulnerability detections

#### 4.2 Training Policy

The post-training phase employed a sophisticated approach to fine-tune Veritas for smart contract auditing tasks:

* Coarse-to-Fine Fine-tuning:
  * Initial stage: Used millions of diverse, lower-quality instruction samples to build broad capabilities
  * Refinement stage: Focused on high-quality, specialized instruction samples for precise auditing skills
  * Applied rejection sampling and supervised fine-tuning to improve performance on complex auditing tasks<br>
* Mixed Tuning Strategy:
  * Combined standard supervised fine-tuning with specialized techniques:&#x20;
    * Fill-in-the-Middle (FIM) tasks: Maintained the model's ability to understand and complete partial code&#x20;
    * Vulnerability injection and detection: Trained the model to identify intentionally inserted vulnerabilities&#x20;
    * ERC standard compliance checking: Focused on verifying adherence to common token standards<br>
* Multi-task Learning:
  * Simultaneously trained on various auditing tasks (vulnerability detection, code completion, report generation)
  * Used dynamic task weighting to balance performance across different objectives<br>
* Contrastive Learning:
  * Implemented contrastive learning techniques to enhance the model's ability to distinguish between secure and vulnerable code patterns<br>
* Adaptive Learning Rate:
  * Utilized a cyclical learning rate schedule to prevent overfitting and encourage exploration of the parameter space<br>
* Prompt Engineering:
  * Developed and refined a set of effective prompts for different auditing tasks
  * Incorporated few-shot learning techniques to improve performance on rare vulnerability types<br>
* Continuous Evaluation and Iteration:
  * Regularly evaluated the model on a held-out set of real-world smart contracts
  * Iteratively refined the instruction dataset and training approach based on performance metrics<br>
* Ethical Considerations:
  * Implemented safeguards to prevent the model from generating or promoting malicious code
  * Trained the model to prioritize responsible disclosure of vulnerabilities

This comprehensive post-training approach ensures that Veritas possesses broad knowledge of smart contract development and excels in the specific tasks required for thorough as well as accurate smart contract auditing. The resulting model combines the pattern recognition capabilities of large language models with the specialized knowledge needed for effective vulnerability detection and code analysis in the blockchain domain.

### 5. Evaluation

#### 5.1 Dataset Composition

To thoroughly evaluate Veritas, we utilized two primary datasets:

1. Large-scale Dataset:

* 200 contracts in total:
  * 100 ERC20 contracts
  * 50 ERC721 contracts
  * 50 ERC1155 contracts
* Sourced from popular platforms: Ethereum and Polygon
* Average of 847.7 lines of Solidity source code per contract

2. Ground-truth Dataset:

* 30 ERC20 contracts
* Manually audited by the Ethereum Commonwealth Security Department
* 142 known ERC violations:
  * 21 high-security impact
  * 60 medium-security impact
  * 61 low-security impact
  * Average of 260.9 lines of Solidity source code per contract

Additionally, we used the SolidiFI benchmark dataset as our test set, containing contracts with 9,369 identified bugs across various vulnerability types.

#### 5.2 Evaluation Metrics

In smart contract vulnerability detection, True Negatives (TN) are particularly challenging to quantify, as the absence of detected vulnerabilities doesn't always equate to the contract being secure. Therefore, metrics like Precision and Recall are more informative and relevant for evaluating Veritas’s performance.

We use the following key metrics for evaluating Veritas:

* True Positives (TP): Correctly identified vulnerabilities
* False Positives (FP): Incorrectly flagged non-vulnerabilities
* False Negatives (FN): Missed actual vulnerabilities
* Precision: TP / (TP + FP)
* Recall: TP / (TP + FN)
* F1 Score: 2 \* (Precision \* Recall) / (Precision + Recall)
* Execution Time: Total time taken to audit a contract
* Monetary Cost: Estimated cost of using the auditing tool

Given the challenges of accurately defining TN in this context, we have excluded Accuracy from the primary metrics used to evaluate Veritas. Instead, our focus on Precision, Recall, and F1 Score better represents the model’s real-world performance in vulnerability detection.

#### 5.3 Vulnerability Detection Performance

Veritas, built upon the Qwen2.5-Coder foundation and fine-tuned for smart contract auditing, was evaluated on its ability to detect four specific types of smart contract vulnerabilities: Re-entrancy, Timestamp-Dependency, Unhandled Exceptions, and tx.origin. Our results indicate that Veritas outperforms static detection tools in both recall and overall true positives.

<figure><img src="/files/6mIFWwTfsd6LjzHyYd3v" alt=""><figcaption><p>Table 4: Performance metrics of Veritas model.</p></figcaption></figure>

These metrics demonstrate Veritas's strong performance in smart contract auditing. The high recall (98.94%) indicates that Veritas catches nearly all vulnerabilities, while the high precision (94.90%) shows it has a low false positive rate. The F1 score (96.87%) balances precision and recall, confirming Veritas's overall effectiveness.

While Veritas demonstrates impressive precision and recall, it's important to acknowledge certain limitations:

* Novel Vulnerabilities: Veritas is primarily trained on existing vulnerability patterns. While the model is fine-tuned regularly to adapt to new threats, emerging vulnerabilities that have not been widely documented may evade detection.
* Underrepresented Datasets: The training data includes a broad range of contracts, but certain niche use cases or proprietary implementations may not be as thoroughly covered, potentially leading to missed vulnerabilities in those areas.

By continuously integrating new data through reinforcement learning, Veritas aims to improve performance in these areas, but we recommend additional manual review for particularly novel or proprietary contracts.

#### 5.4 Comparative Performance

We compared Veritas with baseline tools on the ground-truth dataset:

<figure><img src="/files/upaAdtqJBhAVs8eW9nfG" alt=""><figcaption><p>Table 5: Evaluation results on the ground-true dataset.</p></figcaption></figure>

**Results**: Veritas significantly outperformed both the automated tool SCE and the manual auditing service ECSD in terms of accuracy, speed, and cost-effectiveness. The key findings include:

* Veritas detected 279 true positives, compared to 73 by ECSD and 39 by SCE.
* Veritas reported only 15 false positives, compared to 12 by ECSD and none by SCE. While SCE produced zero false positives, it missed significantly more vulnerabilities (103 false negatives), highlighting the trade-off between conservative detection and thoroughness.
* Veritas missed only 3 vulnerabilities, while ECSD missed 69 and SCE missed 103.
* Veritas completed audits 14,605 times faster than ECSD, with ECSD's manual process requiring weeks or even months of manual work.
* Veritas reduced costs by a factor of approximately 11,468 compared to ECSD, making it a far more cost-effective solution for projects with similar requirements.

**Execution Time:** The speed comparison is based on auditing contracts with an average of 847.7 lines of code. Manual audits by ECSD are time-consuming, often taking weeks or months, as they involve multiple auditors meticulously reviewing each line of code, checking for vulnerabilities, and ensuring compliance with relevant standards. ECSD’s execution time of 26,000,000  seconds (or roughly 10 months) represents this prolonged and resource-intensive process.

Veritas, in contrast, leverages its automated pipeline, processing smart contracts in approximately 1780.1 seconds (or roughly 30 minutes). Veritas’s ability to audit contracts of this size quickly is due to its extended context length, which allows it to analyze entire codebases without breaking context. Smaller contracts typically complete audits in even shorter times, while very large ecosystems or repositories may take longer.

SCE's immediate response time of 0.02298 seconds is a result of its narrow focus on ERC compliance, bypassing the extensive vulnerability checks performed by Veritas. While SCE is lightning-fast, its performance on complex security audits is limited due to the scope of its analysis.

**Cost:** Manual auditing by ECSD is estimated to cost around $150,000, primarily due to the labor-intensive nature of the process, involving highly skilled auditors. This cost includes time spent on vulnerability research, manual code review, and compliance checks, which are critical for larger projects.

Veritas, in contrast, offers a far more affordable solution at $13.08. The cost reduction by a factor of 11,468 compared to ECSD is achieved through Veritas’s automation capabilities, which drastically reduce both labor and time requirements, making it an ideal choice for cost-conscious projects without sacrificing thoroughness.

Since SCE is an open-source software, no monetary expenditure is associated with its use.

#### 5.5 Violation Breakdown by Severity

Veritas's performance across different severity levels:

<figure><img src="/files/WsH6BnEy1Krns6WEdxX9" alt=""><figcaption><p>Table 6: Evaluation results across severity levels.</p></figcaption></figure>

These results show strong performance across all severity levels, particularly in detecting high-severity vulnerabilities. Notably, Veritas identified all 21 high-severity vulnerabilities with only 1 false positive.

#### 5.6 ERC Rule Violations

In the large-scale dataset, Veritas identified 279 ERC rule violations:

* 4 violations with high-security impact
* 112 violations with medium-security impact
* 163 violations with low-security impact

<figure><img src="/files/TCHl2MED4Ros16fMcuWg" alt=""><figcaption><p>Table 7: Evaluation results on the large dataset. ((𝑥,𝑦): 𝑥 true positives, and 𝑦 false positives)</p></figcaption></figure>

Notable findings include:

* Detection of a critical ERC20 vulnerability allowing unauthorized token transfers.
* Identification of ERC1155 vulnerabilities related to token transfer and recipient checks.
* Discovery of various medium-impact violations, including improper handling of zero-value transfers and missing function implementations.

#### 5.7 False Positives Analysis

Veritas reported only 15 false positives in the large-scale dataset. The reasons for these false positives were analyzed and categorized:

Complex or Long Input Code (3 cases):

* These cases occurred in contracts where the codebase was particularly complex, either due to long functions, intricate control flow structures, or multi-file interdependencies. Veritas flagged certain patterns as vulnerabilities because the depth of logic obscured the intended behavior.
* Example: A contract with nested loops and conditionals might have triggered a false positive if Veritas identified patterns that resembled known vulnerability signatures but were secure upon manual review.
* Future Mitigation: Improvements to Veritas's long-context processing will enhance its ability to maintain context over extended code sequences, reducing the likelihood of misidentifying legitimate complex structures as vulnerabilities.

Misunderstanding of Solidity's require Statement (3 cases):

* In these cases, Veritas misinterpreted the context in which the require statement was used. The require function in Solidity is often used for input validation or enforcing conditions that must be met for the contract to proceed. However, Veritas sometimes flagged correct usage of require as faulty due to missing nuances in the conditions.
* Example: A require statement ensuring valid function parameters might have been flagged if Veritas misunderstood the logic surrounding how the condition was being enforced or if it incorrectly assumed certain parameter types were vulnerable.
* Future Mitigation: Future updates will focus on enhancing Veritas’s ability to better parse conditional logic, particularly in cases where require statements are dependent on external factors or involve complex conditions.

Incorrect Inference of Program Semantics (8 cases):

* The majority of false positives fell into this category. In these instances, Veritas incorrectly inferred the intended semantics of the program. This issue arose primarily from ambiguities in how certain functions were named or structured, leading to confusion over their intended purpose.
* Example: A function designed to handle token transfers might be flagged due to how its logic is structured, despite there being no actual vulnerability. Veritas’s inference that a particular action could be exploited stemmed from semantic misunderstandings rather than actual risk.
* Future Mitigation: By enhancing its training on real-world contracts and diverse naming conventions, Veritas will develop better contextual understanding, reducing false positives associated with incorrect semantic inference.

Overly Strict Interpretation of Rules (1 case):

* In one case, Veritas enforced coding standards too strictly, flagging deviations from best practices as vulnerabilities even though they did not pose actual security risks.
* Example: Veritas might have flagged a non-standard but safe implementation of a function that deviated from typical ERC compliance patterns, despite being secure in practice.
* Future Mitigation: Future training will include more flexible rule interpretation, allowing Veritas to differentiate between deviations that introduce risk and those that are simply non-standard but harmless.

#### 5.8 Impact of Design Points on Performance

We conducted ablation studies to understand the contribution of key components:

<figure><img src="/files/wqECoenhqr9QBm602Uk8" alt=""><figcaption><p>Figure 3: Evaluation results on the ground-truth dataset with each design point deactivated. </p></figcaption></figure>

These results demonstrate the importance of each component in Veritas's architecture, particularly highlighting the significance of prompt specialization in reducing false positives and improving overall performance in smart contract auditing tasks.

#### 5.9 Practical Impact

Veritas's performance translates to significant practical benefits:

1. Efficiency: Veritas completes audits in 1780.1 seconds, compared to 26,000,000 seconds for manual auditing.
2. Cost-effectiveness: Veritas costs $13.08 per audit, compared to approximately $150,000 for manual auditing.
3. Accuracy: Veritas detects 50% more violations than baseline solutions while maintaining a low false positive rate.

Based on the evaluation results, Veritas, leveraging the Qwen2.5-Coder foundation and undergoing specialized fine-tuning, has demonstrated exceptional performance in smart contract auditing tasks. It significantly outperforms existing tools in vulnerability detection, offering substantial improvements in both accuracy and efficiency. These results position Veritas as a powerful tool for improving smart contract security in the blockchain ecosystem.

### 6. Conclusion

Veritas represents a significant advancement in automated smart contract auditing, offering substantial improvements in both speed and accuracy over traditional methods and competing AI models. Built upon the foundation of Qwen2.5-Coder and fine-tuned specifically for smart contract analysis, Veritas demonstrates exceptional capabilities in vulnerability detection and ERC rule compliance verification. Key achievements of Veritas include:

1. Superior Vulnerability Detection: Veritas demonstrated exceptional accuracy in detecting ERC rule violations, identifying 279 true positives with only 15 false positives. This performance significantly outpaces both automated tools and manual auditing services, with Veritas detecting 50% more violations than baseline solutions.
2. Efficiency and Cost-Effectiveness: Veritas performs audits orders of magnitude faster than traditional manual auditing services. It completes audits in 1780.1 seconds at a cost of $13.08, representing a dramatic improvement over manual auditing, which takes approximately 26,000,000 seconds and costs around $150,000. This translates to audits being completed 14,605 times faster and at a 99.99% cost reduction.
3. Comprehensive Vulnerability Coverage: Veritas excels at detecting vulnerabilities across various severity levels, showing particularly strong performance in identifying high-severity issues. It successfully identified all 21 high-severity vulnerabilities in the test set with only 1 false positive.
4. Code Generation and Reasoning: Veritas demonstrates strong capabilities in code generation and reasoning tasks, crucial for suggesting fixes and understanding complex smart contract logic.
5. Long-Context Processing: Veritas's ability to handle contexts up to 128k tokens enables the analysis of entire smart contract ecosystems, including related contracts and documentation. This capability is essential for comprehensive audits of complex DeFi protocols.
6. Architectural Robustness: Ablation studies highlight the importance of key components like rule sequentialization, prompt specialization, and code slicing in Veritas's architecture, contributing to its high performance and low false positive rate.
7. Practical Impact: Veritas's performance translates to significant practical benefits in terms of efficiency, cost-effectiveness, and accuracy. It can detect a wide range of vulnerabilities, including critical issues in ERC20 and ERC1155 implementations that could lead to unauthorized token transfers or loss of funds.

By leveraging advanced language modeling techniques and specialized training in blockchain security, Veritas offers unparalleled speed, accuracy, and cost-effectiveness in identifying potential vulnerabilities and ERC standard violations. The model's innovative approach combines supervised learning, semi-supervised learning, and reinforcement learning techniques to address the challenges of data scarcity and evolving vulnerability patterns.

Adaptability to New Architectures: Although Veritas is built upon Qwen2.5-Coder, future versions will explore adaptability to other base models. This ensures flexibility in environments where alternative architectures may provide specific advantages, such as different blockchain ecosystems or specialized contract types.

Scalability: Veritas claims scalability for large projects, and to further support these claims, upcoming versions will undergo stress tests and benchmarks on projects exceeding 100,000 lines of code. These tests will measure any performance degradation and help optimize Veritas for large-scale, real-time auditing tasks across extensive smart contract repositories.

Ethical Considerations and Responsible Disclosure: To prevent misuse, Veritas incorporates ethical guidelines that prioritize responsible vulnerability disclosure. As part of Veritas’s ongoing development, future reports will include case studies that illustrate how Veritas has successfully prevented the generation of malicious code, ensuring that the tool contributes positively to the blockchain security ecosystem.

Formal Verification Techniques: In the future, Veritas will incorporate formal verification methods to further enhance its auditing capabilities. By integrating tools such as SMT solvers and formal methods (e.g., verification frameworks like Keccak or Z3), Veritas will be able to mathematically verify the correctness of smart contracts. These techniques will allow Veritas to detect deeper, logic-based vulnerabilities that go beyond conventional pattern matching and static analysis. Our goal is to create a hybrid approach that maximizes both speed and accuracy by combining formal verification with existing machine learning methods.

The development and deployment of Veritas mark a significant step toward more secure, reliable, and efficient blockchain applications. By dramatically reducing the time and cost associated with thorough smart contract audits while simultaneously increasing their accuracy and comprehensiveness, Veritas is set to transform the landscape of blockchain security. This contribution to the overall growth and stability of the decentralized finance ecosystem will encourage greater trust and confidence in blockchain technology, ultimately accelerating its adoption and innovation.

<details>

<summary><strong>References</strong></summary>

* `Austin, J., Odena, A., Nye, M., Bosma, M., Michalewski, H., Dohan, D., ... & Le, Q. (2021). Program synthesis with large language models. arXiv preprint arXiv:2108.07732.`
* `Bai, J., Bai, S., Chu, Y., Cui, Z., Dang, K., Deng, X., ... & Lin, J. (2023). Qwen technical report. arXiv preprint arXiv:2309.16609.`
* `Bavarian, M., Jun, H., Tezak, N., Schulman, J., McLeavey, C., Tworek, J., & Chen, M. (2022). Efficient training of language models to fill in the middle. arXiv preprint arXiv:2207.14255.`
* `Brown, T. B., Mann, B., Ryder, N., Subbiah, M., Kaplan, J., Dhariwal, P., ... & Amodei, D. (2020). Language models are few-shot learners. arXiv preprint arXiv:2005.14165.`
* `Cassano, F., Gouwar, J., Nguyen, D., Nguyen, S., Phipps-Costin, L., Pinckney, D., ... & Wang, S. I. (2022). MultiPL-E: A scalable and extensible approach to benchmarking neural code generation. arXiv preprint arXiv:2208.08227.`
* `Chen, M., Tworek, J., Jun, H., Yuan, Q., Pinto, H. P. D. O., Kaplan, J., ... & Zaremba, W. (2021). Evaluating large language models trained on code. arXiv preprint arXiv:2107.03374.`
* `Cobbe, K., Kosaraju, V., Bavarian, M., Chen, M., Jun, H., Kaiser, L., ... & Irving, G. (2021). Training verifiers to solve math word problems. arXiv preprint arXiv:2110.14168.`
* `Guo, D., Zhu, Q., Yang, D., Xie, Z., Dong, K., Zhang, W., ... & Tang, J. (2024). DeepSeek-Coder: When the large language model meets programming–the rise of code intelligence. arXiv preprint arXiv:2401.14196.`
* `Hendrycks, D., Burns, C., Basart, S., Zou, A., Mazeika, M., Song, D., & Steinhardt, J. (2020). Measuring massive multitask language understanding. arXiv preprint arXiv:2009.03300.`
* `Hendrycks, D., Burns, C., Kadavath, S., Arora, A., Basart, S., Tang, E., ... & Steinhardt, J. (2021). Measuring mathematical problem solving with the math dataset. arXiv preprint arXiv:2103.03874.`
* `Li, R., Allal, L. B., Zi, Y., Muennighoff, N., Kocetkov, D., Mou, C., ... & Serre, T. (2023). StarCoder: May the source be with you! arXiv preprint arXiv:2305.06161.`
* `Liu, J., Xia, C. S., Wang, Y., & Zhang, L. (2023). Is your code generated by ChatGPT really correct? Rigorous evaluation of large language models for code generation. arXiv preprint arXiv:2305.01210.`
* `Lozhkov, A., Li, R., Allal, L. B., Cassano, F., Lamy-Poirier, J., Tazi, N., ... & Serre, T. (2024). StarCoder 2 and The Stack v2: The Next Generation. arXiv preprint arXiv:2402.19173.`
* `Peng, B., Quesnelle, J., Fan, H., & Shippole, E. (2023). YARN: Efficient context window extension of large language models. arXiv preprint arXiv:2309.00071.`
* `Roziere, B., Gehring, J., Gloeckle, F., Sootla, S., Gat, I., Tan, X. E., ... & Synnaeve, G. (2023). Code Llama: Open foundation models for code. arXiv preprint arXiv:2308.12950.`
* `Yu, T., Zhang, R., Yang, K., Yasunaga, M., Wang, D., Li, Z., ... & Radev, D. (2018). Spider: A large-scale human-labeled dataset for complex and cross-domain semantic parsing and text-to-sql task. arXiv preprint arXiv:1809.08887.`
* `Zhuo, T. Y., Vu, M. C., Chim, J., Hu, H., Yu, W., Widyasari, R., ... & Velloso, E. (2024). BigCodeBench: Benchmarking Code Generation with Diverse Function Calls and Complex Instructions. arXiv preprint arXiv:2406.15877.`

</details>

<br>


# Insurance Pool

Securing the Future: Blockchain-based Digital Insurance for Smart Contract Failures

By integrating AI-powered audits with a token-staking insurance model, Veritas Protocol creates a symbiotic relationship between security analysis and financial protection. This innovative approach not only safeguards projects against potential exploits but also encourages ongoing commitment to smart contract security best practices.

The Veritas Protocol insurance pool aims to redefine DeFi security through a system that is:

* Transparent: Community-driven DAO reviews ensure fair claim assessments.
* Incentivized: Continuous staking rewards encourage long-term participation.
* Sustainable: Multi-source funding and retained stakes support ongoing pool growth.
* Comprehensive: From initial audit to potential claim payout, the system provides end-to-end security solutions.

### **Insurance Pool Architecture**

<figure><img src="/files/Gt13zPm9WrkaE8aZIa2e" alt=""><figcaption></figcaption></figure>

1. Smart Contract Audit and Eligibility:
   * Projects submit their smart contracts for an automated or manual audit by Veritas.
   * Contracts that receive a "high" security grade become eligible for insurance coverage.
   * This process contributes to the Protocol Activity Fees, which in turn support the Insurance Pool.
2. Insurance Opt-In:
   * Eligible projects can opt into insurance coverage.
   * To activate coverage, projects stake a chosen amount of $VPT tokens in the Veritas insurance pool smart contract.
   * The staked amount and audit score determines the coverage limit for the project. Projects can get cover to up to 90% of their staking amount, with 10% withheld as the Primary Responsibility Amount (PRA).
3. Funding the Pool:
   * Primary Funding: Project stakes in $VPT tokens.
   * Secondary Funding: Protocol Activity Fees from audits and other Veritas services.
   * This dual funding approach ensures a robust and sustainable insurance reserve.
4. Staking Rewards:
   * Projects earn continuous staking rewards on their staked $VPT tokens.
   * These rewards incentivize long-term participation and commitment to security.
5. Claim Process:
   * In the event of an exploit, affected projects can submit an insurance claim.
   * Claims undergo a thorough DAO review to assess validity.
   * The DAO validates the claim and determines the appropriate payout amount, ensuring transparency and fairness.
6. Payout Mechanism:
   * Valid claims trigger compensation payouts from the insurance pool funds.
   * Payouts provide immediate liquidity to affected projects.
   * Importantly, the project's staked tokens remain in the pool, continuing to earn staking rewards but without the coverage.
7. Sustainable Pool Growth:
   * The combination of project stakes, ongoing fee contributions, and retained stakes after payouts allows for sustainable pool growth.
   * This model balances risk coverage with long-term ecosystem development.


# TOKENOMICS

0x00096697dc24bd10423690126d91546a20ccb3f0

**Token Ticker:** $VPT&#x20;

**Token Network:** Base&#x20;

**Token Standard:** ERC20

**Token Utility:** The token has three main utilities:

1. Holders get access to the products (token-gated membership), vote on platform decisions about risk, claims and updates
2. Projects get insurance coverage by depositing $VPT into an insurance pool and earn rewards on top of that
3. And it will also act as a Revenue share vehicle with so called token ageing approach, meaning, revenue share for holder increases based on token holding duration

**Total Supply:** 1,000,000,000&#x20;

**Initial Circulating Supply:** 85,389,610 (8.54%)

**Initial Implied Market Cap:** $597,727.27 (w/o liquidity $247,727)

<figure><img src="/files/j4x53uKjkuMO8FtUPEdv" alt=""><figcaption></figcaption></figure>


# RESEARCH

Deep Smart Contract Intent Detection

{% file src="/files/txZ9Dc8EPra8jtkIE91o" %}

AI-powered Fraud Detection in Decentralized Finance: A Project Life Cycle Perspective

{% file src="/files/EiGEomCxssOdYjAIjLmf" %}

Detecting Anomalies in Blockchain Transactions using Machine Learning Classifiers and Explainability Analysis

{% file src="/files/q1iG2Mt30NKPSRpD6naI" %}

Tackling Long-Range Malware Detection Tasks Using Holographic Global Convolutional Networks

{% file src="/files/wF2Z4EFGWVuxwVhauqzG" %}

Veritas: Layer-2 Scaling Solution for Decentralized Oracles on Ethereum Blockchain with Reputation and Real-Time Considerations

{% file src="/files/v1qZoUddxQhFKQxMPlyj" %}

Artificial Intelligence (AI) Cybersecurity Dimensions: A Comprehensive Framework for Understanding Adversarial and Offensive AI

{% file src="/files/y4fEBfqbd133TD6W6uLj" %}

THREATKG: A Threat Knowledge Graph for Automated Open-Source Cyber Threat Intelligence Gathering and Management

{% file src="/files/Rhk9p86vcIblTkGKHWT4" %}

The Intersection of Artificial Intelligence and Cybersecurity: Challenges and Opportunities

{% file src="/files/zedGuPDBQ9ek5D8HBdoG" %}

Vulnerability Scanners for Ethereum Smart Contracts: A Large-Scale Study

{% file src="/files/pwDjlNsOmF5X0H7ZXH98" %}

Towards Secure and Trusted-by-Design Smart Contracts

{% file src="/files/kMeiqca5HSQ5JS2AdsML" %}

DISL: Fueling Research with A Large Dataset of Solidity Smart Contracts

{% file src="/files/eW5KilTUmsK32Niy8ag6" %}

Combining Fine-Tuning and LLM-based Agents for Intuitive Smart Contract Auditing with Justifications

{% file src="/files/sFPEV4emOPrSNGNaGL5W" %}

Large Language Models for Blockchain Security: A Systematic Literature Review

{% file src="/files/u3doQ4GSiAJYlfVAkzWp" %}

AuditGPT: Auditing Smart Contracts with ChatGPT

{% file src="/files/gpk6NZafU5eJOsCCbX4Q" %}

Efficiently Detecting Reentrancy Vulnerabilities in Complex Smart Contracts

{% file src="/files/r5Z0VQ5MDBySnpX9i8gY" %}

Teaching Machines to Code: Smart Contract Translation With LLMs

{% file src="/files/FszNGwSWDHNNVsFNU2le" %}

Fixing Smart Contract Vulnerabilities: A Comparative Analysis of Literature and Developer’s Practices

{% file src="/files/AH9cGVDDLbJvTbmLbVTb" %}

SmartML: Towards a Modeling Language for Smart Contracts

{% file src="/files/Sq6YNkUqAu52z19qcuoy" %}

Empirical Review of Smart Contract and DeFi Security: Vulnerability Detection and Automated Repair

{% file src="/files/qJ3jPKKiB75jw1TkP4t8" %}

Evolution of Automated Weakness Detection in Ethereum Bytecode: a Comprehensive Study

{% file src="/files/3tTtXTpqESsSoGeJD6N4" %}

TxT: Real-time Transaction Encapsulation for Ethereum Smart Contracts

{% file src="/files/PNCUS2FKVYHOekO35z70" %}

Smart Contract and DeFi Security Tools: Do They Meet the Needs of Practitioners?

{% file src="/files/qCOf7ycO2dnstOudcXpd" %}


# THESIS

The thesis section demonstrates our focus, practical implications, and benefits through the development of the Veritas Protocol, which aims to strengthen the security, reliability, and trust in blockchain applications with the assistance of Artificial Intelligence.

<figure><img src="/files/tNJ7932NPdKxi6tyZlZd" alt=""><figcaption></figcaption></figure>


# Automated Audits

{% hint style="info" %}
The document presents a comprehensive solution leveraging AI techniques—such as machine learning, deep learning, and natural language processing—to enhance the detection of vulnerabilities, improve the accuracy of audits, and ensure the compliance of smart contracts across various blockchain platforms.
{% endhint %}

Smart contracts (SCs) are digital agreements that execute themselves and are stored on a blockchain. Despite the fact that they offer numerous advantages, such as automation and transparency, they are susceptible to a variety of assaults due to their complexity and lack of standardization. In this thesis, we present the use of artificial intelligence (AI) to improve SC security. We provide an overview of SCs and blockchain technology, as well as a mark-down of possible SC-based attacks. Then, we introduce various AI categories and their applications in cybersecurity, followed by a thorough analysis of how AI can be used to enhance SC security. Our research demonstrates that AI can provide an effective defense against assaults on SCs and contribute to their security and dependability. This thesis lays the groundwork for our development of AI for SC security.

According to the most recent report the global smart contracts market size is poised for significant growth, reaching $5.2 trillion in 2030, from $775 billion in 2023 \[1]. The sales are expected to witness a robust CAGR of 32% and generate over $450 billion in fees annually by 2030.

The market is expected to grow rapidly over the coming years as blockchain technology sees increasing real-world adoption. Key drivers of the smart contract market include the need for automation of manual processes, cost reduction, improved transactional security, and transparency.&#x20;

By democratizing access to security audits, market intelligence company Messari expects that AI-native security networks will expand current total addressable market (TAM) by a factor of 5-10x \[2]. Table 1 is comparing centralized auditors vs decentralized security networks across crypto market cycles.&#x20;

*Table 1. TAM potential for AI audit tools.*

<table><thead><tr><th width="361"></th><th width="205">Certik in 20-22</th><th>AI Audits in 24-26</th></tr></thead><tbody><tr><td>Peak-to-trough crypto market cap</td><td>$200B →$2T</td><td>$1T →???</td></tr><tr><td>% projects getting security audits</td><td>10%</td><td>50-75%</td></tr><tr><td>% leader market share</td><td>60%</td><td>60-75% </td></tr><tr><td>Projects audited</td><td>10k+</td><td>100k+</td></tr><tr><td>Capital raised</td><td>$230m</td><td>fair launch</td></tr><tr><td>Valuation</td><td>$2B</td><td>$10B+</td></tr></tbody></table>

### 1. Introduction

By automating complex financial transactions, blockchain-based SCs do away with the need for intermediaries like banks or attorneys. They represent a huge advancement in blockchain technology that has the potential to fundamentally change how business is conducted.

Ethereum is the largest digital contract network, with 68.5% of the market value of the top six networks in 2023 \[1]. In addition to Ethereum, these were BNB Chain, Solana, Avalanche, Tron, and Polygon. There are also other networks such as Hyperledger Fabric, Corda, EOS, and smilar. For creating SCs, many of these platforms have a unique language. One such example is the contract-oriented programming language Solidity, which is used by Ethereum. Similar to JavaScript, Solidity is designed to be simple to learn and use \[3,4]. Hyperledger Fabric is based on chaincode, which can be written in Go, Java, or JavaScript \[5,6,7]. The language used to develop Corda is called Kotlin, which is linked to Java \[8,9]. EOS and Tron both use C++ and Solidity for SC development, respectively. Different blockchain platforms employ various SC development programming languages, but they all aim to make it simple to develop secure and effective SCs that can function on the blockchain.

The security of SCs, however, is a crucial concern because it can be jeopardized by a variety of risks, including incorrect code, malicious inputs, and attacks on the blockchain network. Due to security flaws, blockchain platforms run the risk of losing money and losing their trust. Therefore, safeguarding SCs is crucial for the development of blockchain applications \[10,11].

Numerous high-profile SC hacking incidents have resulted in significant financial losses or data breaches. According to a recent report by Chainalysis \[12], illicit addresses received a staggering $24.2 billion in 2023. This substantial amount includes funds stolen by hackers and from other crypto-related attacks and scams. Over the last few years, cryptocurrency hacking has become a pervasive and formidable threat, leading to billions of dollars stolen from crypto platforms and exposing vulnerabilities across the ecosystem. 2022 was the biggest year ever for crypto theft with $3.7 billion stolen. In 2023, however, funds stolen decreased by 54.3% to $1.7 billion, though the number of individual hacking incidents actually grew, from 219 in 2022 to 231 in 2023 (Figure 1).

<figure><img src="https://lh7-us.googleusercontent.com/IGwE7FA2PVLbAdsq7DcnasXgEPWInGyh7Q3qDDycGAgdLZA2RKgJI6vVeqN1sz5jcsh-rvGzcm6uot-uBN7WRtAbclHucFooiM9ZDHQcwKVUOzVYUr4OUQ4HqelC4ai5NrPhHTW9cEd4aJphpOBzfx4" alt=""><figcaption><p>Figure 1. Yearly total value stolen in crypto hacks and number of hacks 2016- 2023</p></figcaption></figure>

Despite that drop, there still were several large hacks notable to DeFi protocols throughout 2023. In March, for instance, Euler Finance, a borrowing and lending protocol on Ethereum ,experienced a flash loan attack, leading to roughly $197 million in losses. July 2023 saw 33 hacks—the most of any month—which included $73.5 million  stolen from Curve Finance. We can see the spikes driven by those hacks below (Figure 2).

<figure><img src="https://lh7-us.googleusercontent.com/FgGMTfTxqApzbzLtw9xdz2mloGc41O92ubTbF7z8ktGO_D3Zq8V6fid2RfFe5LWB9mwSljiuzB_gMZlI58tXnvdMsPWt24YmGhu0rqAw0kSM84Xa2Fy2PetnGBM4CLYHoaPCjJVZXGt9YKgaWEzfzFA" alt=""><figcaption><p>Figure 2. Monthly total value stolen in crypto hacks and number of hacks 2023</p></figcaption></figure>

Similarly, several large exploits occurred in September and November 2023 on both DeFi and CeFi platforms: Mixin Network ($200 million), CoinEx ($43 million), Poloniex Exchange ($130 million), HTX ($113.3 million), and Kyber Network ($54.7 million).&#x20;

Attack vectors affecting DeFi are diverse and constantly evolving; it is therefore important to classify them to understand how hacks occur and how protocols might be able to reduce their likelihood in the future. According to Halborn \[13], DeFi attack vectors can be placed into one of two categories: vectors originating on-chain and vectors originating off-chain (Table 2):

*Table 2. DeFi attack vectors.*

<table><thead><tr><th width="258">Attack Vector Sub-category</th><th width="308">Definition</th><th>On-chain or Off-chain</th></tr></thead><tbody><tr><td>Protocol exploitation</td><td>When an attacker exploits vulnerabilities in a blockchain component of a protocol, such as ones pertaining to validator nodes, the protocol’s virtual machine, or in the mining layer.</td><td>On-chain</td></tr><tr><td>Insider attack</td><td>When an attacker working inside a protocol, such as a rogue developer, uses privileged keys or other private information to directly steal funds.</td><td>Off-chain</td></tr><tr><td>Phishing</td><td>When an attacker tricks users into signing permissions, often done by supplanting a legitimate protocol, allowing the attacker to spend tokens on users’ behalf. Phishing may also happen when an attacker tricks users into directly sending funds to malicious smart contracts.</td><td>Off-chain</td></tr><tr><td>Contagion</td><td>When an attacker exploits a protocol due to vulnerabilities created by a hack in another protocol. Contagion also includes hacks that are closely related to hacks in other protocols.</td><td>On-chain</td></tr><tr><td>Compromised server</td><td>When an attacker compromises a server that is owned by a protocol, thereby disrupting the protocol’s normal workflow or gaining knowledge to further exploit the protocol in the future.</td><td>Off-chain</td></tr><tr><td>Wallet hack</td><td>When an attacker exploits a protocol that provides custodial/wallet services and subsequently acquires information about the wallets’ operation.</td><td>Off-chain</td></tr><tr><td>Price manipulation hack</td><td>When an attacker exploits a smart contract vulnerability or utilizes a flawed oracle that does not reflect accurate asset prices, facilitating the manipulation of a digital token’s price.</td><td>On-chain</td></tr><tr><td>Smart contract exploitation</td><td>When an attacker exploits a vulnerability in a smart contract code, which typically grants direct access to various control mechanisms of a protocol and token transfers.</td><td>On-chain</td></tr><tr><td>Compromised private key</td><td>When an attacker acquires access to a user’s private key, which can occur through a leak or a failure in off-chain software, for example.</td><td>Off-chain</td></tr><tr><td>Governance attacks</td><td>When an attacker manipulates a blockchain project with a decentralized governance structure by gaining enough influence or voting rights to enact a malicious proposal.</td><td>On-chain</td></tr><tr><td>Third-party compromised</td><td>When an attacker gains access to an off-chain third-party program that a protocol uses, which provides information that can later be used for an exploit.</td><td>Off-chain</td></tr><tr><td>Other</td><td>Either the attack does not fit in any of the previous categories or there is not enough information to properly classify it.</td><td>On-chain/Off-chain</td></tr></tbody></table>

<figure><img src="https://lh7-us.googleusercontent.com/3rhope1dhRBzq9fMRBDNJce7Yc8L0ThVt2RO_BbJu9yRA471evCCBUkyiM08ahXL68wZcMv_yQeXkz7pm9NbP44ZI6-jLa3SFehs4XCj6CJFLqz8QZOEk28iyvZQziV_KLhSW1249Vd8-Gv-bkMu8Ig" alt=""><figcaption><p>Figure 3. Yearly share of value stolen in DeFi hacks by attack vector</p></figcaption></figure>

Overall, on-chain vulnerabilities drove the majority of DeFi hacking activity in 2023. We can’t say for sure whether the drop in DeFi hacking was driven primarily by better security practices or the drop in DeFi activity overall — most likely, it was a mix of the two. But, if the decrease in hacking was primarily driven by the drop in overall activity, then it would be important to watch whether DeFi hacking rises again in tandem with another DeFi bull market. Such a bull market would lead to higher TVL and therefore a larger pool of DeFi funds for hackers to target.&#x20;

These occurrences stress the significance of keeping SCs safe and of being on the lookout for vulnerabilities and attacks at all times. The current methods of SC security include drawbacks and difficulties that must be overcome. The complexity and difficulty in analysis and verification of SCs is a significant obstacle. There may still be undetected vulnerabilities despite the use of code review and rigorous verification. It might be challenging to ensure the ongoing security of SCs because they are frequently updated and often created by distributed teams. Another difficulty is that SCs often operate on public blockchains that are susceptible to attacks from bad actors. Theft of private keys, 51% attacks, and the use of SC coding flaws are all examples of possible attacks \[14,15,16,17]. In addition, code review and formal verification, two common traditional techniques in SC security, are both costly and time-consuming, making them impracticable for many engineers \[18]. Last but not least, the lack of uniformity in SC creation makes it tough to guarantee the safety of SCs on various platforms \[15,19].

In light of these difficulties, there is a growing curiosity about how machine learning and AI may be used to bolster SC security \[20,21]. By allowing for the detection of anomalies and unusual activity that may indicate a security breach, these methods may give a more thorough and proactive approach to security \[22,23]. By fixing these problems, we can make blockchain technology more reliable and inspire more faith in SCs.

### 2. Background on Smart Contracts

**2.1. Blockchain and Smart Contracts**

Blockchain technology is a distributed ledger that allows secure and transparent transactions to take place without the use of intermediaries such as financial institutions or governments \[24,25,26]. It is made up of a network of nodes that work together to maintain a shared database of transactions \[27]. Each node has a copy of the database, and the network uses a consensus process to verify all transactions. This ensures that the database cannot be tampered with and that all transactions are transparent and unchangeable. The concept of SCs is a significant breakthrough of blockchain technology. SCs are self-executing programs that operate on a blockchain to automate complex financial transactions without the use of intermediaries. They are saved on the blockchain and are automatically executed when certain conditions are met. Supply chain management, voting systems, and financial derivatives are just a few of the applications for SCs. The general architecture of blockchain is shown in Figure 4.

<figure><img src="https://lh7-us.googleusercontent.com/rGKzNq2Z1zC0Agk-islUsWUDJ7NzO7jrejwy0X5iGXk0tjCUrZcPnlegJKCs8RbzLrlxfd9uH2tQUFiAS0EhPAV7wRlhf3Y2gwnZ-ocrLrbAcPyNn9PnUxt02uPk17pMIGX6v-5R1MbxjMXKnbpiTWo" alt="" width="563"><figcaption><p>Figure 4. Blockchain General Architecture.</p></figcaption></figure>

SCs are a crucial blockchain technological innovation that has the potential to change the way we conduct business. They make it possible to automate complex financial transactions without intermediaries such as banks or attorneys. SCs are self-executing programs recorded on a blockchain that run automatically when certain criteria are satisfied. They are secure and trustworthy since they are tamper-proof and transparent.

**2.2. Application Domains**

The widespread adoption of blockchain and smart contract technologies might significantly alter several markets. In the financial sector, for instance, blockchain technology can be utilized to build a safer and more reliable payment system. By eliminating the need for middlemen and drastically cutting down on transaction fees, SCs are revolutionizing the way business is conducted. To further expand people’s and enterprises’ access to financial services, blockchain technology can be utilized to build decentralized lending and investing platforms.

The real estate market is another sector that could profit from blockchain \[28,29]. By eliminating middlemen and increasing accountability, blockchain technology has the capacity to revolutionize the property registration and transfer industry. If a sale is finalized or money is transferred, for instance, an SC can automatically transfer ownership to the buyer. For both parties involved, this can be a time- and cost-saving measure.

The healthcare sector is another that might greatly profit from blockchain implementation \[30,31]. A patient’s medical history can be kept on the distributed ledger technology known as blockchain. In order to better coordinate care and lower the likelihood of medical errors, SCs can be used to automate the sharing of medical records between healthcare providers. In addition, blockchain technology can help monitor drug authenticity and tampering as they travel through the supply chain.

Blockchain technology also has potential in the supply chain sector \[32,33]. Blockchain technology allows companies to keep tabs on product deliveries from start to finish, improving visibility while decreasing opportunities for fraud. Using SCs, the supply chain’s financial transactions can be automated, eliminating the need for middlemen while increasing speed and accuracy.

Voting is another area where blockchain technology can be put to use \[34,35]. With a blockchain-based voting system, we can eliminate the possibility of voter fraud and guarantee a fair and accurate tally of all votes cast. Vote tallying can be automated with the help of SCs, making the process quicker and more accurate.

A new revolution in the transportation sector called the Internet of Vehicles (IoV) has the ability to fix the problems with the established structure. The IoV’s data security and privacy, however, present significant difficulties. Blockchain technology can solve the authentication problems of cars traveling from one trusted authority to another when combined with physical unclonable functions \[36].

The widespread adoption of blockchain and smart contract technology might radically alter many sectors. Blockchain technology has the potential to enhance company operations, which in turn will benefit individuals and society at large, by making systems more secure, transparent, and efficient.

However, the security of SCs is a major concern because they are vulnerable to a variety of attacks, such as coding errors, malicious inputs, and blockchain network attacks. Securing SCs is critical to the viability of blockchain technology. Traditional techniques in SC security, such as code review and formal verification, are limited and may not always discover all sorts of vulnerabilities. As a result, there is increased interest in investigating the application of AI technology to improve SC security. By detecting anomalies and unusual behavior that may suggest a security breach, these techniques have the ability to provide a more thorough and proactive approach to security. We can improve trust and confidence in blockchain technology by increasing SC security and releasing its full potential for building a more decentralized and secure financial system. An SC developed in Solidity is presented in Figure 5.

<figure><img src="https://lh7-us.googleusercontent.com/7olBcM3pmHmYxJF0gnzVo3jOIKL2WMrwqVcshuTytIqYO7LeR5vcjICZkyCCStMSDqJD3LTVMKn5hpMfYo0ZafFJuJaFT-UWpS6yk_gmZS2yzilk7t4W1LHZ3EmLlxyib0IQC03JkYGWbhLUF_oVW4g" alt=""><figcaption><p>Figure 5. An SC developed in Solidity.</p></figcaption></figure>

Blockchain and SC solutions provide numerous advantages to consumers, businesses, and governments. Some are (Figure 6):

<figure><img src="https://lh7-us.googleusercontent.com/kRU7PzqRT6dMVq7TdqQ4cXlV7G6e8rb2D-LbkgoWSCkcVT8kMi2N0bhJ3DqAADgPVYnwczGUTogDOVNmnh5J1LI72_mS8Z4GxuRGTDFWV87lUfUUrH2j82Jg1CSVIqYxsFCbqnvH_47Qe0E1rbySZp8" alt=""><figcaption><p>Figure 6. The main advantages of Blockchain and SCs.</p></figcaption></figure>

* Transparency: Decentralized blockchains are completely transparent. Transactions on the blockchain are transparent and verifiable. Nobody can also update network information. As a result, a user or company owner can create or use an SC without fear of a hacker altering it to steal money or data.
* Efficiency in the Economy: SCs automate numerous agreement-processing commercial activities. SCs do not require the services of attorneys, banks, or brokers. Both provide for significant cost reductions.
* Time-Saving Autonomy: Writing and monitoring a standard contract takes time. SCs are simpler and faster to implement: the programmer writes the contract code once and then utilizes it any time it is required (such as when trying to construct an NFT or for automatically filling out a bill and making trades).
* Building Trust: There are no humans among the SCs. This builds long-term trust amongst counteragents. If something goes wrong, the parties will look into it together.
* Safe Backup: Since businesses and governments risk losing important data, everyone copies it and backs it up. Even the most secure backup mechanisms cannot ensure data preservation. Hackers can either succeed or fail. Blockchain and SCs differ in that data are stored on several devices until the blockchain functions.
* Fraud Prevention: SCs prevent fraudulent access if the blockchain code is correct. Phishing can be prevented with time.
* Safety and Dependability: SCs are well known for their data security and market-leading encryption in IT. Blockchain and SC agreements are the most secure contracts available today.

**2.3. Possible Attacks**

There is a wide variety of threats that can target SCs and cause financial loss and reputational harm to blockchain networks. These attacks include (Table 3):

*Table 3. Possible Types of Attacks.*

<br>

<table><thead><tr><th width="223">Attack Type</th><th width="271">Description</th><th>Example</th></tr></thead><tbody><tr><td>Reentrancy Attacks</td><td>Allows an attacker to repeatedly call an SC function before the previous call completes</td><td>Drain a contract’s funds by creating a malicious contract that calls the target contract’s function multiple times</td></tr><tr><td>Integer Overflow and Underflow</td><td>Exploits vulnerabilities in the way SCs handle integer values</td><td>Underflow a contract’s balance by sending a large negative number as input to a function expecting a positive number</td></tr><tr><td>Denial-of-Service (DoS)</td><td>Aims to overload an SC’s resources, making it unable to process legitimate transactions</td><td>Send a large number of transactions to the contract in a short period of time</td></tr><tr><td>Malicious Input</td><td>Involves sending malicious data inputs to an SC, causing it to behave in unintended ways</td><td>Transfer funds to an unintended recipient by sending malicious input data to a contract</td></tr><tr><td>Front-Running</td><td>Involves exploiting the time delay between a transaction being submitted and confirmed on the blockchain</td><td>Profit from a transaction by submitting a higher gas price transaction ahead of the original transaction</td></tr><tr><td>Logic Bombs</td><td>A piece of malicious code that lies dormant in an SC until a specific trigger condition is met</td><td>Transfer funds to the attacker’s account when a specific date or time is reached</td></tr><tr><td>Cross-Chain Attacks</td><td>Exploit vulnerabilities in the interaction between different blockchain networks</td><td>Steal funds from one network and transfer them to another by exploiting weaknesses in cross-chain transactions</td></tr><tr><td>Time Manipulation</td><td>Exploits the way SCs handle time-based events</td><td>Trigger an action prematurely or delay it indefinitely by manipulating the timestamp or block number</td></tr><tr><td>Authorization Flaws</td><td>Occurs when an SC fails to properly authenticate and authorize users who interact with it</td><td>Gain unauthorized access to a contract’s funds or execute unauthorized transactions</td></tr><tr><td>Gas Limit Attacks</td><td>Exploit the way SCs handle gas, the unit of measurement for computational work</td><td>Revert a transaction and potentially steal funds by setting a low gas limit on a transaction</td></tr></tbody></table>

* Reentrancy attacks: An attacker can use this vulnerability to drain the contract’s cash by repeatedly calling an SC function before the previous call has completed. An attacker can steal money from a contract by making a malicious contract that repeatedly calls the function of the target contract before the target contract has finished processing the previous call.
* Integer overflow and underflow attacks: These exploits make use of flaws in the way SCs handle integer values to subvert the contract’s logic and steal money. By sending a huge negative number to a contract function that expects a positive number, the attacker can trigger an underflow and gain access to a significant amount of tokens.
* Denial-of-Service (DoS) attacks: The goal of these assaults is to prevent an SC from handling valid transactions by overwhelming its resources. This can be achieved by flooding the contract with a large number of little transactions or by sending transactions with input data that are too large and so exceed the contract’s gas limit.
* Malicious input attacks: For these kinds of attacks, the attacker sends malicious data inputs to an SC in order to manipulate its behavior and, in the worst-case scenario, steal money. Input data sent by an attacker, for instance, could trigger a contract to transmit funds to an unauthorized address.
* Front-running attacks: To perform a front-running assault, one must take advantage of the brief window of opportunity between a transaction’s submission and confirmation on the blockchain. An adversary can profit from this vulnerability by watching the blockchain for pending transactions and then submitting their own transaction with a greater gas price.
* Logic bombs: A logic bomb is malicious code that waits in an SC until a certain trigger condition is met, at which point the code is activated. For instance, an adversary can craft a contract that, at first glance, appears to work as intended, but actually contains malicious code that, after a certain date or time is reached, transfers funds to the adversary’s account.
* Cross-chain attacks: These assaults take advantage of flaws in the way several blockchains communicate with one another. By taking advantage of differences in how several networks handle cross-chain transactions, an attacker can take cash from one network and move it to another.
* Time manipulation attacks: Time manipulation attacks take advantage of how SCs process information about the passage of time. An attacker may be able to cause a contract to execute too soon or wait forever if it depends on a timestamp or block number to trigger a certain action.
* Authorization flaws: A breach in authorization occurs when an SC does not adequately verify the identities of those who access the contract. An adversary could potentially use this flaw to conduct fraudulent transactions or gain access to the contract’s cash.
* Gas limit attacks: In order to execute a contract, SCs must perform a certain amount of computational labor, which is measured in gas. An attacker can cause a transaction to fail by setting a low gas limit, resulting in the contract running out of gas before its execution is complete. The attacker may then be able to undo the transaction and steal money from the contract.

**2.4. Bug categories**

We classify Ethereum smart contract bugs into the following 9 categories:

* **Data**. Bugs in data definition, initialization, mapping, access, or use, as found in a model, specification, or implementation.
* **Interface**. Bugs in specification or implementation of an interface.
* **Logic**. Bugs in decision logic, branching, sequencing, or computation algorithm, as found in natural language specifications or in implementation language.
* **Description**. Bugs in description of software or its use, installation, or operation.
* **Standard**. Nonconformity with a defined standard.
* **Security**. Bugs that threaten contract security, such as authentication, privacy/confidentiality, property.
* **Performance**. Bugs that cause increased *gas* consumption.
* **Interaction**. Bugs caused by contract interaction with other accounts.
* **Environment**. Bugs due to mistakes in the software that supports Ethereum smart contracts.

In order to express the classification results concisely, we provide the following classification diagrams:

<figure><img src="/files/Jekmj9qaQCCAwxUfUbko" alt=""><figcaption><p>Figure 7: Bug classification diagram.</p></figcaption></figure>

### 3. Background on Artificial Intelligence

**3.1. Artificial Intelligence**

Artificial intelligence (AI) is a vast area that includes the creation of intelligent computers capable of performing activities that normally require human intelligence \[37,38]. Machine learning (ML) is a branch of AI that focuses on developing systems that can learn from data and make decisions without being explicitly programmed \[39,40].

Developers use traditional programming techniques to manually write code to tackle a specific problem. The code is composed of a set of rules and instructions that the computer uses to generate output. This method necessitates a significant amount of human labor and is limited by the programmer’s ability to predict all conceivable circumstances and edge cases. In contrast, with machine learning and artificial intelligence (AI), the computer is trained on a big dataset and learns to recognize patterns and make predictions or judgments based on that data. This method is more adaptable to new data and situations that were not explicitly programmed. The difference between Classical Programming and AI is illustrated in Figure 7.

<figure><img src="https://lh7-us.googleusercontent.com/S6WAhViymJt_AGiKy6mWaC6grczEnptme_XWGj5bWpP_mnmydwOV7bCOiIxTj8KcJvTNIftkWYUCGjAZgUWJ0r7xyyVMO9NsZnIz-FTNY47phpOKNHVgShevXNcdcVLmXMgxJyh1Tbv6eR1DGi5xNtQ" alt=""><figcaption><p>Figure 8. The difference between Classical Programming and Machine Learning.</p></figcaption></figure>

The different phases of ML and AI include (Figure 8):

<figure><img src="https://lh7-us.googleusercontent.com/nLlotimLzsWqnIaNEB6vT3xgfWwudoMjHe5R-7-ZSLnYb_OO9SwDnjScXgTlmLNq7vaFCU0rhfTswFpqtsNydA0CEMLdEk4x67EaVQkFIumsrV9ll8s0QUs9zEGX8UOCO7z-wzEvTd1z5GtLE2cHgk4" alt=""><figcaption><p>Figure 9. An illustration of AI lifecycle.</p></figcaption></figure>

* Data collection: Collecting and preparing a large dataset that represents the problem domain.
* Data preprocessing: Cleaning and transforming the data to make it usable for ML models.
* Model selection and training: Choosing an appropriate ML model and training it on the dataset.
* Model evaluation: Evaluating the performance of the model on a separate dataset to measure its accuracy and effectiveness.
* Deployment: Implementing the model in a production system and integrating it with other systems as needed.
* Monitoring and maintenance: Continuously monitoring the model’s performance and making updates and improvements as necessary.

In sum, AI and ML are potent resources that can automate a wide range of jobs and generate highly accurate predictions and choices. They excel in areas where conventional programming methods would be too time-consuming or inefficient, such as those involving complexity.

**3.2. Different Types of AI**

There are four main types of AI \[41] (Table 4):

*Table 4. Different Types of AI.*

| Type of AI               | Description                                                                                                                                     | Examples                                                       |
| ------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------- |
| Supervised Learning      | Trained on labeled data to predict correct output for new, unseen input data.                                                                   | Image classification, speech recognition, language translation |
| Unsupervised Learning    | Trained on unlabeled data to discover patterns or relationships in the data.                                                                    | Clustering, anomaly detection, dimensionality reduction        |
| Semi-Supervised Learning | Trained on partially labeled data to predict correct output for new, unseen input data while discovering patterns or relationships in the data. | Object recognition, speech recognition, sentiment analysis     |
| Reinforcement Learning   | Learns to make decisions through trial and error and adjusts behavior to maximize reward.                                                       | Game playing, robotics, autonomous vehicles                    |

* Supervised learning (SL) \[42,43]: Supervised learning involves training an algorithm on a labeled dataset in which each input is accompanied by its corresponding label. The goal is to train the algorithm to correctly anticipate an output for inputs it has never seen before. Image categorization, voice recognition, and language translation are all applications of supervised learning.
* Unsupervised learning (USL) \[44,45]: Unsupervised learning involves training an algorithm on a dataset without an associated label or output. The purpose of the algorithm is to autonomously identify such links or patterns in the data. Clustering, anomaly detection, and dimensionality reduction are all types of unsupervised learning.
* Semi-supervised learning (SSL) \[46,47]: In semi-supervised learning, the algorithm is trained on a dataset with just some of the input data coupled with the right output or label. The goal is to train the algorithm to correctly predict an output for input data that it has never seen before, using both the labeled and unlabeled data to help it.
* Reinforcement learning (RL) \[48,49]: In reinforcement learning, the algorithm learns to make decisions through trial and error. The algorithm receives feedback in the form of rewards or punishments for its actions and adjusts its behavior to maximize the reward. Examples of reinforcement learning include game playing, robotics, and autonomous vehicles.

Each type of AI has its own strengths and weaknesses, and the choice of which type to use depends on the problem being solved and the available data. SL is useful when there is a well-defined output or label, USL is useful when there are no labeled data available, and RL is useful when the algorithm needs to learn through trial and error.

**3.3. AI for Cybersecurity in General**

The use of AI is increasingly vital in the field of cybersecurity \[50]. By analyzing massive volumes of data and discovering patterns that suggest possible hazards, AI can be used to detect and prevent cyber-attacks \[51,52]. Artificial intelligence algorithms can be taught to recognize common forms of assault and to spot novel ones that have certain traits. Patching security holes, keeping tabs on network traffic, and handling incidents are just some of the mundane responsibilities that may be automated with the help of AI \[53,54]. Cybersecurity experts can then devote their time and energy to solving problems that call for their unique set of skills. Artificial intelligence (AI) has great potential in this area, but it cannot yet entirely replace humans in this field. False positives and negatives can be avoided if artificial intelligence systems are trained, validated, and monitored effectively. Protecting AI systems from outside threats and ensuring their own safety is equally important. In general, AI has the ability to vastly improve cybersecurity by spotting and avoiding threats more quickly and correctly than before \[55].

### 4. AI for Smart Contract Security

Significant monetary losses have resulted from several high-profile events involving hacked SCs in recent years. The application of AI technology, however, can improve smart contract security and reduce the likelihood of such instances occurring \[56,57].

Using AI algorithms to examine the code and find flaws is one method of using AI to increase the safety of SCs. Patterns and abnormalities in the code that could suggest a security weakness can be trained into AI algorithms. AI algorithms can analyze enormous quantities of code to find common flaws, which can then be fixed in subsequent iterations of SCs \[58].

A temporal message propagation network for extracting graph features was proposed by \[59], who also investigated the application of graph neural networks and expert knowledge to discover vulnerabilities. Using a multi-layer bidirectional Transformer structure and using CodeBERT, VDDL was introduced by \[60]. The multi-modal AI framework developed by \[61] incorporated NLP, IR, and coding analysis methods. Using active SSL to combat the problem of insufficient labeled data and relying on bidirectional encoder representations from Transformers (BERT), Ref. \[62] proposed an SC vulnerability detection system called ASSBert. By combining vulnerability identification and location into a single debugging process, Ref. \[63] suggested a two-stage SC debugger dubbed ReVulDL, which employs a deep learning-based technique to detect and locate reentry vulnerabilities \[64,65].

The use of natural language processing (NLP) techniques is yet another AI-based method for making SCs more secure. To prevent hackers from taking advantage of loopholes in SCs, natural language processing algorithms can examine the contracts’ language for potential ambiguities and inconsistencies. Developers can improve the contract’s safety by fixing these problems early on.

The authors of \[66] developed a vulnerability detection model that included a hierarchical attention mechanism and made use of neural networks in AI, notably, BiLSTM (BiLSTM = bidirectional long short-term memory networks). To detect Ponzi schemes at the time of SC formation, Ref. \[67] created a larger dataset and extracted various independent features from multiple views using a multi-view cascading ensemble model (MulCas). A heterogeneous graph transformation network for SC anomaly detection (SHGTNs) was proposed by \[68] to identify instances of financial fraud on the Ethereum network. Using the bytecode of SCs as a new feature and GRU networks and attention mechanisms to obtain hidden information, Ref. \[69] introduced SCSGuard, a framework that applied AI to identify fraudulent conduct in SCs.

Artificial intelligence can also be used to review SCs in real time, looking for signs of fraud or other irregularities. In an SC, for instance, AI algorithms can be taught to track the flow of money and flag any unusual activity. If developers are able to identify and report these transactions, they can take preventative measures.

The problem of local information loss in conventional CNN models was solved by \[70] when they unveiled their new CNN architecture, CodeNet, for detecting flaws in SCs. To better uncover vulnerabilities in SCs, Ref. \[71] used deep reinforcement learning in combination with multi-agent fuzz testing \[72]. To determine whether SCs are vulnerable, Ref. \[73] developed three distinct deep learning (DL) models: GRU, ANN, and LSTM. In order to discover flaws in SCs, Ref. \[74] introduced a novel model called Link-DC, which uses deep and cross networks to build high-order nonlinear characteristics. By extracting features from both the high-level syntactic features and the low-level bytecode features of the SCs, the SmartMixModel vulnerability detection model presented by \[75] improves the accuracy with which vulnerabilities in SCs can be identified.

In addition, AI can be utilized to build trustworthy and distributed SC administration infrastructure. Using AI to validate transactions and stop fraudulent conduct is one way to improve the safety of blockchain technology, the foundation of SCs. SCs can be made more hacker- and exploitation-resistant if decentralized systems are built utilizing AI.

An AI approach named GVD-net was suggested by \[76] to identify flaws in Ethereum SCs. Ref. \[77] introduced a static analysis tool for SCs using AI called Eth2Vec, which compared the target contract’s code to a database of known vulnerable contract features learned automatically by neural networks. Ref. \[78] developed a systematic and modular vulnerability detection framework based on DL, named DeeSCVHunter, for reentrancy and time-dependence vulnerabilities, while \[79] used DL techniques to detect vulnerabilities in SCs by combining different representations of the code. To help find vulnerabilities in SCs, Hao et al. proposed SCscan, a scanning technique built on Support Vector Machines.

As a result, AI has the ability to greatly improve the security of SCs. Developers can limit the danger of hacking and exploitation by utilizing AI algorithms to examine code, natural language processing algorithms to detect linguistic ambiguities, and real-time monitoring of SCs. Furthermore, blockchain technology can be made more secure and transparent by developing decentralized systems for managing SCs. As SCs become more common, AI will play a growing role in guaranteeing their security and preventing fraudulent activities. A summary of the studies presented in this section is given in Table 5.

*Table 5. Summary of Main Findings.*

<table><thead><tr><th width="98">Ref.</th><th width="235">Adopted Technique</th><th>Contribution</th></tr></thead><tbody><tr><td>[<a href="https://www.mdpi.com/2073-431X/12/5/107#B59-computers-12-00107">59</a>]</td><td>GNN, Expert Knowledge, Temporal Message Propagation Network</td><td>Proposed a technique for vulnerability detection in SCs using graph neural networks and expert knowledge, and introduced a temporal message propagation network to extract graph features</td></tr><tr><td>[<a href="https://www.mdpi.com/2073-431X/12/5/107#B60-computers-12-00107">60</a>]</td><td>Multi-layer bidirectional Transformer structure, CodeBERT</td><td>Introduced VDDL, a vulnerability detection model that used a multi-layer bidirectional Transformer structure and incorporated CodeBERT</td></tr><tr><td>[<a href="https://www.mdpi.com/2073-431X/12/5/107#B61-computers-12-00107">61</a>]</td><td>NLP, Image Processing, Code Analysis Techniques</td><td>Used a multi-modal AI framework for vulnerability detection in SCs</td></tr><tr><td>[<a href="https://www.mdpi.com/2073-431X/12/5/107#B62-computers-12-00107">62</a>]</td><td>Active and SSL, BERT</td><td>Introduced ASSBert, an SC vulnerability detection framework that combines active SSL and employs BERT</td></tr><tr><td>[<a href="https://www.mdpi.com/2073-431X/12/5/107#B63-computers-12-00107">63</a>]</td><td>DL-based Approach</td><td>Proposed ReVulDL, a two-stage SC debugger that uses a DL-based approach to detect and locate re-entry vulnerabilities</td></tr><tr><td>[<a href="https://www.mdpi.com/2073-431X/12/5/107#B66-computers-12-00107">66</a>]</td><td>NN, BiLSTM, Hierarchical Attention Mechanism</td><td>Proposed a vulnerability detection tool that utilized neural networks and introduced a hierarchical attention mechanism</td></tr><tr><td>[<a href="https://www.mdpi.com/2073-431X/12/5/107#B67-computers-12-00107">67</a>]</td><td>Multi-view Cascading Ensemble Model (MulCas)</td><td>Constructed a larger dataset and extracted numerous independent features from multiple perspectives for identifying Ponzi schemes when SC are created</td></tr><tr><td>[<a href="https://www.mdpi.com/2073-431X/12/5/107#B68-computers-12-00107">68</a>]</td><td>Heterogeneous Graph Transformation Network</td><td>Proposed SHGTNs, a heterogeneous graph transformation network for detecting financial frauds on Ethereum platforms</td></tr><tr><td>[<a href="https://www.mdpi.com/2073-431X/12/5/107#B69-computers-12-00107">69</a>]</td><td>ML, Bytecode, GRU Networks, Attention Mechanisms</td><td>Developed SCSGuard, a tool that used ML technology for detecting fraudulent behaviors in SCs by leveraging the bytecode of SCs as a novel feature</td></tr><tr><td>[<a href="https://www.mdpi.com/2073-431X/12/5/107#B70-computers-12-00107">70</a>]</td><td>Convolutional Neural Network (CNN) Architecture</td><td>Introduced CodeNet, a new CNN architecture for detecting SC vulnerabilities that solved the problem of loss of local information in existing CNN models</td></tr><tr><td>[<a href="https://www.mdpi.com/2073-431X/12/5/107#B71-computers-12-00107">71</a>]</td><td>Deep Reinforcement Learning, Multi-Agent Fuzz Testing</td><td>Developed improved techniques for detecting vulnerabilities in SCs using deep reinforcement learning and multi-agent fuzz testing</td></tr><tr><td>[<a href="https://www.mdpi.com/2073-431X/12/5/107#B73-computers-12-00107">73</a>]</td><td>DL Models, LSTM, ANN, GRU</td><td>Trained three different DL models, GRU, ANN, LSTM and, and used them for predicting the existence of vulnerabilities in SCs</td></tr><tr><td>[<a href="https://www.mdpi.com/2073-431X/12/5/107#B74-computers-12-00107">74</a>]</td><td>Deep and Cross Networks</td><td>Presented Link-DC, a new SC vulnerability detection model that used deep and cross networks for constructing high-order nonlinear features</td></tr><tr><td>[<a href="https://www.mdpi.com/2073-431X/12/5/107#B75-computers-12-00107">75</a>]</td><td>High-level Syntactic Features, Low-level Bytecode Features</td><td>Introduced SmartMixModel, a vulnerability detection model that extracts features on two levels: low-level bytecode features and high-level syntactic features</td></tr><tr><td>[<a href="https://www.mdpi.com/2073-431X/12/5/107#B76-computers-12-00107">76</a>]</td><td>AI Model</td><td>Proposed GVD-net, an AI model to detect security vulnerabilities in Ethereum SCs</td></tr><tr><td>[<a href="https://www.mdpi.com/2073-431X/12/5/107#B77-computers-12-00107">77</a>]</td><td>AI-based Static Analysis Tool, Eth2Vec</td><td>Introduced Eth2Vec, an AI-based static analysis tool that utilized neural networks for automatically learning features of vulnerable contracts and detecting vulnerabilities in SCs</td></tr><tr><td>[<a href="https://www.mdpi.com/2073-431X/12/5/107#B79-computers-12-00107">79</a>]</td><td>DL, Various Code Representations</td><td>Utilized DL techniques for detecting vulnerabilities in SCs by combining various code representations</td></tr><tr><td>[<a href="https://www.mdpi.com/2073-431X/12/5/107#B78-computers-12-00107">78</a>]</td><td>DL, Modular and Systematic Vulnerability Detection Framework</td><td>Proposed DeeSCVHunter, a modular and systematic vulnerability detection framework based on DL, for reentrancy and time dependence vulnerabilities</td></tr><tr><td>[<a href="https://www.mdpi.com/2073-431X/12/5/107#B80-computers-12-00107">80</a>]</td><td>SVM</td><td>Proposed SCscan, a scanning tool based on SVM for identifying potential security risks in SCs</td></tr></tbody></table>

### 5. Manual vs Automated

Here are some concrete examples about the use of artificial intelligence to improve smart contract security:

* Vulnerability detection: AI-based techniques can find flaws in SCs. These programs can examine code and detect potential security flaws. This can assist developers in finding and fixing vulnerabilities faster more effectively than manual testing.
* Anomalies discovery: AI can monitor SCs and detect unusual behavior. A smart contract, for example, may suggest a security compromise if it suddenly begins performing a large number of transactions or accessing unexpected data. AI-based anomaly detection can aid in the rapid identification and response to these situations.
* Predictive analytics: AI can examine data from SCs and detect future security issues. For example, if a smart contract is utilized in a novel way, AI may analyze the data to predict whether this novel usage pattern is likely to result in security issues.
* Suspicious behavior detection: AI can be utilized for behavior-based security by monitoring the behavior of SCs and detecting suspicious behavior. For example, if a smart contract begins to behave abnormally, AI can flag it for further examination.

Table 6 summarizes the advantages of AI-based security over classical techniques, which include:

*Table 6. Comparison of Classical and AI-based Security Techniques for SCs.*

<table><thead><tr><th width="215"></th><th>Classical Techniques</th><th>AI-Based Techniques</th></tr></thead><tbody><tr><td>Vulnerability Detection</td><td>Manual code review and testing</td><td>Automated code analysis and vulnerability detection</td></tr><tr><td>Anomaly Detection</td><td>Manual monitoring and analysis</td><td>Automated behavior-based anomaly detection</td></tr><tr><td>Predictive Analytics</td><td>Limited predictive capabilities</td><td>Advanced predictive analytics using machine learning</td></tr><tr><td>Behavior-based Security</td><td>Limited behavior-based monitoring</td><td>Advanced behavior-based monitoring using machine learning</td></tr><tr><td>Advantages</td><td>Established techniques, but slower and less accurate than AI-based techniques</td><td>Faster, more accurate, scalable, adaptable, and able to learn from new data and threats</td></tr></tbody></table>

* Efficiency: Since AI-based technologies can analyze code and data far more quickly than humans can, software engineers are able to locate and resolve issues much more quickly.
* Accuracy: AI has the ability to analyze massive amounts of data and recognize patterns that people would miss. This has the potential to result in improved vulnerability identification and more accurate predictive analytics.
* Scalability: AI-based tools can scan vast volumes of SCs at once, enabling developers to detect problems in a large number of contracts quickly. This is made possible through scalability.
* Adaptability: AI-powered technologies may learn from fresh data and adapt to new threats over time, making them more effective.

In general, the use of AI-based techniques has a number of major advantages over the use of traditional techniques when it comes to improving the safety of SCs. To make their SCs more secure, developers should seriously consider employing AI-based technologies for vulnerability discovery, anomaly detection, predictive analytics, and behavior-based security.

### 6. Our Methodology

This section illustrates the complete process of developing our base for vulnerability detection model for smart contracts, which consists of three stages. The first stage involves building and preprocessing the labeled dataset of vulnerable Solidity code. In the second stage, training three models (Optimized-CodeBERT, Optimized-LSTM, and Optimized-CNN) and comparing their performance to determine the best one. Finally, in the third stage, the selected model is evaluated using the Sodifi-benchmark dataset to assess its effectiveness in detecting vulnerabilities.

6.1. Data collection

Our primary training dataset comprises three main sources: 10,000 contracts from the Slither Audited Smart Contracts Dataset, 20,000 contracts from smartbugs-wild, and 1,000 typical smart contracts with vulner- abilities identified through expert audits, overall 31,000 contracts. To effectively compare results with other auditing tools, we choose to use the SolidiFI benchmark dataset as our test set, a dataset containing contracts containing 9,369 bugs.

6.2. Dataset processing

Within our test set SolidiFI-benchmark, there are three static detection tools which are Slither, Mythril, and Smatcheck as well as all identified four common vulnerability types which are Re-entrancy, Timestamp-Depend- ency, Unhandled-Exception, and tx.origin. To ensure the completeness and fairness of the results, our model primarily focused on these four types of vulnerabilities for comparison.&#x20;

Considering that a complete contract might consist of multiple Solidity files and a single Solidity file might contain several vulnerable code snippets, we utilized the Slither tool to extract 30,000 functions containing these four types of vulnerabilities from the data sources. Additionally, we manually annotate the problematic code snippets within the contracts audited by experts, overall 1,909 snippets. The training set comprises 31,909 code snippets. For the test set, we extract 5,434 code snippets related to these four vulnerabilities from the SolidiFI- benchmark dataset.&#x20;

6.3. Data cleaning

The length of a smart contract typically depends on its functionality and complexity. Some complex contracts can exceed several thousand tokens. However, handling long text has been a long-standing challenge in deep learning. Transformer-based models can only handle a maximum of 512 tokens. Therefore, we attempted two methods to address the issue of text length exceeding 510 tokens.

Direct splitting. The data is split into chunks of 510 tokens each, and all the chunks are assigned the same label. For example, if we have a group of Re-entrancy vulnerability code with a length of 2000 tokens, it would be split into four chunks, each containing 510 tokens. If there are chunks with fewer than 510 tokens, we pad them with zeros. However, the training results show that the model’s loss does not converge. We speculate that this is due to the introduction of noise from unrelated chunks, which negatively affects the model’s generalization capability.

Vulnerability function code extraction. Audit experts extracted the function code of vulnerabilities from smart contracts and assigned corresponding vulnerability labels. If the extracted code exceeds 510 tokens, it is truncated, and if the code falls short of 510 tokens, it is padded with zeros. This approach ensures consistent input data length, addresses the length limitation of Transformer models, and preserves the characteristics of the vulnerabilities.

After comparing the two methods, we observed that training on vulnerability-based function code helped the model’s loss function converge better. Therefore, we chose to use this data processing method in subsequent experiments. Additionally, we removed unrelated characters such as comments and newline characters from the functions to enhance the model’s performance. We only extracted the function parts containing the vulnerability code, reducing the length of the training dataset while maintaining the vulnerability characteristics. This approach not only improves the model’s accuracy, but also enhances its generalization ability.

6.4. Data encoding

CodeBERT is a pretraining model based on the Transformer architecture, specifically designed for learning and processing source code. By undergoing pretraining on extensive code corpora, CodeBERT acquires knowledge of the syntax and semantic relationships inherent in source code, as well as the interactive dynamics between different code segments.

During the data preprocessing stage, CodeBERT is employed due to its strong representation ability. The source code undergoes tokenization, where it is segmented into tokens that represent semantic units. Subsequently, the tokenized sequence is encoded into numerical representations, with each token mapped to a unique integer ID, forming the input token ID sequence. To meet the model’s input requirements, padding and trunca- tion operations are applied, ensuring a fixed sequence length. Additionally, an attention mask is generated to distinguish relevant positions from padded positions containing invalid information. Thus, the processed data includes input IDs and attention masks, transforming the source code text into a numericalized format compatible with the model while indicating the relevant information through the attention mask.

For Optimized-LSTM and Optimized-CNN models, direct processing of input IDs and masks is not feasible. Therefore, CodeBERT is utilized to further process the data and convert it into tensor representations of embedding vectors. The input IDs and attention masks obtained from the preprocessing steps are passed to the CodeBERT model to obtain meaningful representations of the source code data. These embedding vectors can be used as inputs for Optimized-LSTM and Optimized-CNN models, facilitating their integration for subsequent vulnerability detection.

<figure><img src="/files/5bF4sbjxhwZrLyfB2IwD" alt=""><figcaption><p>Figure 10. Our Optimized-CodeBERT Model Architecture.</p></figcaption></figure>

<figure><img src="/files/ywQdEkRrYOtRZxMwbKxy" alt=""><figcaption><p>Figure 11. The Architecture of Optimized-LSTM.</p></figcaption></figure>

<figure><img src="/files/3FKrCCsxX7Ia5o5JZZtx" alt=""><figcaption><p>Figure 12. The Architecture of Optimized-CNN.</p></figcaption></figure>

6.5. Results

For the purpose of comparison with static analysis tools, we particularly focus on detecting four specific types of smart contract vulnerabilities: Re-entrancy, Timestamp-Dependency, Unhandled-Exceptions, and tx.origin. Through our comparative analysis, we observe instances where the static analysis tools fail to detect certain vulnerabilities. Our results indicate that our model outperforms the static detection tools, both in terms of recall and overall TP.&#x20;

| Metriccs           | F1 (%) | Accuracy (%) | Precision (%) | Recall (%) |
| ------------------ | ------ | ------------ | ------------- | ---------- |
| Optimized-CodeBERT | 93.53  | 96.77        | 96.77         | 93.55      |
| Optimized-LSTM     | 63.05  | 81.96        | 73.61         | 64.06      |
| Optimized-CNN      | 70.62  | 85.54        | 71.61         | 71.36      |

<figure><img src="/files/c9I0Ma9tAJEYfyYf1n82" alt=""><figcaption><p>Figure 13. Comparison of Recall Results.</p></figcaption></figure>

### 7. Analysis and Findings

From related work, it has been observed that some tools based on static analysis techniques suffer from false positives and false negatives, mainly due to their reliance on predefined rules. These tools lack the ability to perform syntax and semantic analysis, and the predefined rules can become outdated quickly and cannot adapt or generalize to new data. In contrast, deep learning methods do not require predefined detection rules and can learn vulnerability features during the training process.

AI approaches such as SL, SSL, and RL provide numerous advantages in SC vulnerability detection. SL is the most commonly used technique for effective pattern identification and feature extraction because of its ability to train on massive amounts of labeled data. This technique, however, has drawbacks, such as the requirement for a significant amount of labeled training data. SSL, albeit less widely utilized, offers the ability to alleviate this constraint by not requiring labeled training data in the pre-training phase. The potential of this technique to capture specific vulnerability features is its limitation. Due to the difficulty in collecting specific vulnerability features, USL approaches are rarely used in SC vulnerability identification. RL can be used to learn from the system’s rewards or penalties, although more research is needed to determine its usefulness in SC security detection.

The use of AI in conjunction with fuzz testing, dynamic analysis, and static analysis approaches can also increase SC security detection. Static analysis uses information extracted from an SC’s source code or bytecode for training AI models to find possible vulnerabilities. Dynamic analysis, on the other hand, records runtime data during contract execution in order to identify possible vulnerabilities and anomalous behaviors. Fuzz testing techniques generate random input data, and contract execution outcomes are evaluated to identify new vulnerabilities or abnormal behavior. However, there are still open issues, that we need further research and develop solutions for.&#x20;

Automatic vulnerability detection technology holds immense potential in enhancing the security of smart contracts. However, it is a double-edged sword. On the one hand, it can assist developers in swiftly identifying and rectifying vulnerabilities in software, thereby elevating its security. On the other hand, if such technology falls into the hands of malicious actors, they might exploit it to uncover undisclosed vulnerabilities and launch attacks. To address this, proactive measures are essential.

Developers should regularly conduct code audits and undergo secure coding training as well as adopt responsible vulnerability disclosure policies. It’s encouraged that researchers and developers, upon discovering security vulnerabilities, initially notify the relevant organizations or individuals privately. This provides them ample time for rectification before the information is made public. Concurrently, regular updates and maintenance of software and dependency libraries are crucial to ensure known security vulnerabilities which are addressed collaboratively.&#x20;

### 8. Future Development Plan&#x20;

Data privacy: AI-based SC vulnerability detection technologies necessitate access to massive volumes of data, raising privacy issues among users. SCs frequently contain sensitive information, such as financial transactions or personal data, which may be exposed if data are not anonymized or protected adequately. We are starting to concentrate on building privacy-preserving AI algorithms for detecting vulnerabilities in SCs while protecting user privacy.

Adversarial attacks: SCs are prone to adversarial attacks, in which attackers purposefully introduce malicious code or inputs to exploit contract weaknesses. Adversarial attacks provide a substantial barrier for AI-based SC security detection approaches because attackers can manipulate training data or circumvent detection by providing inputs targeted to elude detection. In future research we will concentrate on creating more robust AI models capable of detecting adversarial attacks.

Scalability: AI-based SC security detection solutions will require scalability as the number of SCs on blockchain networks continues to expand. Due to the extensive time and computing power needed to train on huge datasets, scalability is a major issue for AI systems. The increasing volume of SC data necessitates the development of more effective and scalable AI solutions in the future.

Interpretability: It can be difficult for users to comprehend the reasoning behind AI-based SC security detection models due to a lack of interpretability. Trust in the system is vital for the success of AI, and interpretability is the key to assuring the transparency and accountability of AI models. As our next step in SC security, we are going to focus on creating AI models that are easier to interpret for end users.

Integration challenges: Integrating AI with formal methodologies presents substantial obstacles, but the benefits of doing so for SC security is promising. Verifying the accuracy of an SC can be accomplished using either formal approaches, which use mathematical proofs and logical reasoning, or AI methods, which utilize statistical models and AI algorithms to spot trends and outliers in the data. Developing formal models that can handle large-scale data and introducing AI techniques into the formal verification process are only two of the many technical hurdles that must be cleared in order to successfully merge these two approaches. More thorough and powerful SC security analysis tools cannot be created until these integration issues are resolved in future studies.

While the potential of combining AI and formal approaches has been recognized, further R\&D is required to address open issues and explore full potential. AI isn't a silver bullet, it represents a significant advancement for smart contract auditing. The combination of AI techniques with human expertise creates a robust approach for minimizing risks and ensuring the security of these transformative agreements.

The near future of smart contract security audits is likely to become a collaboration between AI and human experts. AI will identify common vulnerabilities, while human auditors will leverage their expertise to handle the latest advancements and updates. In other words, AI won't replace human auditors just yet, but rather empower them to be more effective. The combined efforts of AI and blockchain will add significant value to the smart contract security experience.

Our focus remains on the creation of AI-powered detection tools for Web3-related security breaches that can handle ever-increasing amounts of data and help us fight scams, hacks and other cryptocurrency related breaches.&#x20;

<br>

***

<br>

<details>

<summary>References</summary>

1. ARK Investment Management LLC. (2024). Big ideas 2024: Annual research report. ARK Invest; Available online: <https://www.ark-invest.com/big-ideas-2024>
2. Messari. Smart Contract Market Analysis. Messari, 2023; Available online: <https://messari.io/report-pdf/f125632168e9a04e016fe43bc551f412389eda4f.pdf&#x20>;
3. Dannen, C. Introducing Ethereum and Solidity; Springer: Berlin/Heidelberg, Germany, 2017; Volume 1. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Introducing+Ethereum+and+Solidity\&author=Dannen,+C.\&publication_year=2017)]
4. Wohrer, M.; Zdun, U. Smart contracts: Security patterns in the ethereum ecosystem and solidity. In Proceedings of the 2018 International Workshop on Blockchain Oriented Software Engineering (IWBOSE), Campobasso, Italy, 20 March 2018; IEEE: Piscataway, NJ, USA, 2018; pp. 2–8. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Smart+contracts:+Security+patterns+in+the+ethereum+ecosystem+and+solidity\&conference=Proceedings+of+the+2018+International+Workshop+on+Blockchain+Oriented+Software+Engineering+\(IWBOSE\)\&author=Wohrer,+M.\&author=Zdun,+U.\&publication_year=2018\&pages=2%E2%80%938)]
5. Androulaki, E.; Barger, A.; Bortnikov, V.; Cachin, C.; Christidis, K.; De Caro, A.; Enyeart, D.; Ferris, C.; Laventman, G.; Manevich, Y.; et al. Hyperledger fabric: A distributed operating system for permissioned blockchains. In Proceedings of the Thirteenth EuroSys Conference, Porto, Portugal, 23–26 April 2018; pp. 1–15. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Hyperledger+fabric:+A+distributed+operating+system+for+permissioned+blockchains\&conference=Proceedings+of+the+Thirteenth+EuroSys+Conference\&author=Androulaki,+E.\&author=Barger,+A.\&author=Bortnikov,+V.\&author=Cachin,+C.\&author=Christidis,+K.\&author=De+Caro,+A.\&author=Enyeart,+D.\&author=Ferris,+C.\&author=Laventman,+G.\&author=Manevich,+Y.\&publication_year=2018\&pages=1%E2%80%9315)]
6. Baliga, A.; Solanki, N.; Verekar, S.; Pednekar, A.; Kamat, P.; Chatterjee, S. Performance characterization of hyperledger fabric. In Proceedings of the 2018 Crypto Valley conference on blockchain technology (CVCBT), Zug, Switzerland, 20–22 June 2018; IEEE: Piscataway, NJ, USA, 2018; pp. 65–74. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Performance+characterization+of+hyperledger+fabric\&conference=Proceedings+of+the+2018+Crypto+Valley+conference+on+blockchain+technology+\(CVCBT\)\&author=Baliga,+A.\&author=Solanki,+N.\&author=Verekar,+S.\&author=Pednekar,+A.\&author=Kamat,+P.\&author=Chatterjee,+S.\&publication_year=2018\&pages=65%E2%80%9374)]
7. Gorenflo, C.; Lee, S.; Golab, L.; Keshav, S. FastFabric: Scaling hyperledger fabric to 20000 transactions per second. Int. J. Netw. Manag. 2020, 30, e2099. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=FastFabric:+Scaling+hyperledger+fabric+to+20000+transactions+per+second\&author=Gorenflo,+C.\&author=Lee,+S.\&author=Golab,+L.\&author=Keshav,+S.\&publication_year=2020\&journal=Int.+J.+Netw.+Manag.\&volume=30\&pages=e2099\&doi=10.1002/nem.2099)] \[[CrossRef](https://doi.org/10.1002/nem.2099)]
8. Mohanty, D.; Mohanty, D. Corda architecture. In R3 Corda for Architects and Developers: With Case Studies in Finance, Insurance, Healthcare, Travel, Telecom, and Agriculture; Apress: New York, NY, USA, 2019; pp. 49–60. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Corda+architecture\&author=Mohanty,+D.\&author=Mohanty,+D.\&publication_year=2019\&pages=49%E2%80%9360)]
9. Nadir, R.M. Comparative study of permissioned blockchain solutions for enterprises. In Proceedings of the 2019 International Conference on Innovative Computing (ICIC), Lahore, Pakistan, 1–2 November 2019; IEEE: Piscataway, NJ, USA, 2019; pp. 1–6. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Comparative+study+of+permissioned+blockchain+solutions+for+enterprises\&conference=Proceedings+of+the+2019+International+Conference+on+Innovative+Computing+\(ICIC\)\&author=Nadir,+R.M.\&publication_year=2019\&pages=1%E2%80%936)]
10. Rouhani, S.; Deters, R. Security, performance, and applications of smart contracts: A systematic survey. IEEE Access 2019, 7, 50759–50779. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Security,+performance,+and+applications+of+smart+contracts:+A+systematic+survey\&author=Rouhani,+S.\&author=Deters,+R.\&publication_year=2019\&journal=IEEE+Access\&volume=7\&pages=50759%E2%80%9350779\&doi=10.1109/ACCESS.2019.2911031)] \[[CrossRef](https://doi.org/10.1109/ACCESS.2019.2911031)]
11. Tsankov, P.; Dan, A.; Drachsler-Cohen, D.; Gervais, A.; Buenzli, F.; Vechev, M. Securify: Practical security analysis of smart contracts. In Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, Toronto, ON, Canada, 15–19 October 2018; pp. 67–82. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Securify:+Practical+security+analysis+of+smart+contracts\&conference=Proceedings+of+the+2018+ACM+SIGSAC+Conference+on+Computer+and+Communications+Security\&author=Tsankov,+P.\&author=Dan,+A.\&author=Drachsler-Cohen,+D.\&author=Gervais,+A.\&author=Buenzli,+F.\&author=Vechev,+M.\&publication_year=2018\&pages=67%E2%80%9382)]
12. Chainalysis. The 2024 Crypto Crime Report. Chainalysis, 2024; pp. 1–50. Available online: <https://go.chainalysis.com/rs/503-FAP-074/images/The%202024%20Crypto%20Crime%20Report.pdf> &#x20;
13. Halborn. Top 50 DeFi Hacks. Halborn, 2023; Available online: <https://www.halborn.com/reports/top-50-defi-hacks&#x20>;
14. Krichen, M.; Maâlej, A.J.; Lahami, M. A model-based approach to combine conformance and load tests: An eHealth case study. Int. J. Crit. Comput.-Based Syst. 2018, 8, 282–310. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=A+model-based+approach+to+combine+conformance+and+load+tests:+An+eHealth+case+study\&author=Krichen,+M.\&author=Ma%C3%A2lej,+A.J.\&author=Lahami,+M.\&publication_year=2018\&journal=Int.+J.+Crit.+Comput.-Based+Syst.\&volume=8\&pages=282%E2%80%93310\&doi=10.1504/IJCCBS.2018.096437)] \[[CrossRef](https://doi.org/10.1504/IJCCBS.2018.096437)]
15. Almakhour, M.; Sliman, L.; Samhat, A.E.; Mellouk, A. Verification of smart contracts: A survey. Pervasive Mob. Comput. 2020, 67, 101227. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Verification+of+smart+contracts:+A+survey\&author=Almakhour,+M.\&author=Sliman,+L.\&author=Samhat,+A.E.\&author=Mellouk,+A.\&publication_year=2020\&journal=Pervasive+Mob.+Comput.\&volume=67\&pages=101227\&doi=10.1016/j.pmcj.2020.101227)] \[[CrossRef](https://doi.org/10.1016/j.pmcj.2020.101227)]
16. Bhargavan, K.; Delignat-Lavaud, A.; Fournet, C.; Gollamudi, A.; Gonthier, G.; Kobeissi, N.; Kulatova, N.; Rastogi, A.; Sibut-Pinote, T.; Swamy, N.; et al. Formal verification of smart contracts: Short paper. In Proceedings of the 2016 ACM Workshop on Programming Languages and Analysis for Security, Vienna, Austria, 24 October 2016; pp. 91–96. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Formal+verification+of+smart+contracts:+Short+paper\&conference=Proceedings+of+the+2016+ACM+Workshop+on+Programming+Languages+and+Analysis+for+Security\&author=Bhargavan,+K.\&author=Delignat-Lavaud,+A.\&author=Fournet,+C.\&author=Gollamudi,+A.\&author=Gonthier,+G.\&author=Kobeissi,+N.\&author=Kulatova,+N.\&author=Rastogi,+A.\&author=Sibut-Pinote,+T.\&author=Swamy,+N.\&publication_year=2016\&pages=91%E2%80%9396)]
17. Krichen, M. Contributions to Model-Based Testing of Dynamic and Distributed Real-Time Systems. Ph.D. Thesis, École Nationale d’Ingénieurs de Sfax (Tunisie), Sfax, Tunisia, 2018. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Contributions+to+Model-Based+Testing+of+Dynamic+and+Distributed+Real-Time+Systems\&author=Krichen,+M.\&publication_year=2018)]
18. Krichen, M.; Mihoub, A.; Alzahrani, M.Y.; Adoni, W\.Y.H.; Nahhal, T. Are Formal Methods Applicable To Machine Learning And Artificial Intelligence? In Proceedings of the 2022 2nd International Conference of Smart Systems and Emerging Technologies (SMARTTECH), Riyadh, Saudi Arabia, 9–11 May 2022; IEEE: Piscataway, NJ, USA, 2022; pp. 48–53. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Are+Formal+Methods+Applicable+To+Machine+Learning+And+Artificial+Intelligence?\&conference=Proceedings+of+the+2022+2nd+International+Conference+of+Smart+Systems+and+Emerging+Technologies+\(SMARTTECH\)\&author=Krichen,+M.\&author=Mihoub,+A.\&author=Alzahrani,+M.Y.\&author=Adoni,+W.Y.H.\&author=Nahhal,+T.\&publication_year=2022\&pages=48%E2%80%9353)]
19. Yang, Z.; Lei, H.; Qian, W. A hybrid formal verification system in coq for ensuring the reliability and security of ethereum-based service smart contracts. IEEE Access 2020, 8, 21411–21436. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=A+hybrid+formal+verification+system+in+coq+for+ensuring+the+reliability+and+security+of+ethereum-based+service+smart+contracts\&author=Yang,+Z.\&author=Lei,+H.\&author=Qian,+W.\&publication_year=2020\&journal=IEEE+Access\&volume=8\&pages=21411%E2%80%9321436\&doi=10.1109/ACCESS.2020.2969437)] \[[CrossRef](https://doi.org/10.1109/ACCESS.2020.2969437)]
20. Momeni, P.; Wang, Y.; Samavi, R. Machine learning model for smart contracts security analysis. In Proceedings of the 2019 17th International Conference on Privacy, Security and Trust (PST), Fredericton, NB, Canada, 26–28 August 2019; IEEE: Piscataway, NJ, USA, 2019; pp. 1–6. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Machine+learning+model+for+smart+contracts+security+analysis\&conference=Proceedings+of+the+2019+17th+International+Conference+on+Privacy,+Security+and+Trust+\(PST\)\&author=Momeni,+P.\&author=Wang,+Y.\&author=Samavi,+R.\&publication_year=2019\&pages=1%E2%80%936)]
21. Eshghie, M.; Artho, C.; Gurov, D. Dynamic Vulnerability Detection on Smart Contracts Using Machine Learning. In Proceedings of the Evaluation and Assessment in Software Engineering, Trondheim, Norway, 21–23 June 2021; pp. 305–312. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Dynamic+Vulnerability+Detection+on+Smart+Contracts+Using+Machine+Learning\&conference=Proceedings+of+the+Evaluation+and+Assessment+in+Software+Engineering\&author=Eshghie,+M.\&author=Artho,+C.\&author=Gurov,+D.\&publication_year=2021\&pages=305%E2%80%93312)]
22. Liao, J.W.; Tsai, T.T.; He, C.K.; Tien, C.W. Soliaudit: Smart contract vulnerability assessment based on machine learning and fuzz testing. In Proceedings of the 2019 Sixth International Conference on Internet of Things: Systems, Management and Security (IOTSMS), Granada, Spain, 22–25 October 2019; IEEE: Piscataway, NJ, USA, 2019; pp. 458–465. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Soliaudit:+Smart+contract+vulnerability+assessment+based+on+machine+learning+and+fuzz+testing\&conference=Proceedings+of+the+2019+Sixth+International+Conference+on+Internet+of+Things:+Systems,+Management+and+Security+\(IOTSMS\)\&author=Liao,+J.W.\&author=Tsai,+T.T.\&author=He,+C.K.\&author=Tien,+C.W.\&publication_year=2019\&pages=458%E2%80%93465)]
23. Xing, C.; Chen, Z.; Chen, L.; Guo, X.; Zheng, Z.; Li, J. A new scheme of vulnerability analysis in smart contract with machine learning. Wirel. Netw. 2020, 1–10. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=A+new+scheme+of+vulnerability+analysis+in+smart+contract+with+machine+learning\&author=Xing,+C.\&author=Chen,+Z.\&author=Chen,+L.\&author=Guo,+X.\&author=Zheng,+Z.\&author=Li,+J.\&publication_year=2020\&journal=Wirel.+Netw.\&pages=1%E2%80%9310\&doi=10.1007/s11276-020-02379-z)] \[[CrossRef](https://doi.org/10.1007/s11276-020-02379-z)]
24. Namane, S.; Ahmim, M.; Kondoro, A.; Dhaou, I.B. Blockchain-Based Authentication Scheme for Collaborative Traffic Light Systems Using Fog Computing. Electronics 2023, 12, 431. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Blockchain-Based+Authentication+Scheme+for+Collaborative+Traffic+Light+Systems+Using+Fog+Computing\&author=Namane,+S.\&author=Ahmim,+M.\&author=Kondoro,+A.\&author=Dhaou,+I.B.\&publication_year=2023\&journal=Electronics\&volume=12\&pages=431\&doi=10.3390/electronics12020431)] \[[CrossRef](https://doi.org/10.3390/electronics12020431)]
25. Krichen, M.; Ammi, M.; Mihoub, A.; Almutiq, M. Blockchain for modern applications: A survey. Sensors 2022, 22, 5274. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Blockchain+for+modern+applications:+A+survey\&author=Krichen,+M.\&author=Ammi,+M.\&author=Mihoub,+A.\&author=Almutiq,+M.\&publication_year=2022\&journal=Sensors\&volume=22\&pages=5274\&doi=10.3390/s22145274\&pmid=35890953)] \[[CrossRef](https://doi.org/10.3390/s22145274)] \[[PubMed](http://www.ncbi.nlm.nih.gov/pubmed/35890953)]
26. Namane, S.; Ben Dhaou, I. Blockchain-Based Access Control Techniques for IoT Applications. Electronics 2022, 11, 2225. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Blockchain-Based+Access+Control+Techniques+for+IoT+Applications\&author=Namane,+S.\&author=Ben+Dhaou,+I.\&publication_year=2022\&journal=Electronics\&volume=11\&pages=2225\&doi=10.3390/electronics11142225)] \[[CrossRef](https://doi.org/10.3390/electronics11142225)]
27. Abbas, A.; Alroobaea, R.; Krichen, M.; Rubaiee, S.; Vimal, S.; Almansour, F.M. Blockchain-assisted secured data management framework for health information analysis based on Internet of Medical Things. Pers. Ubiquitous Comput. 2021, 1–14. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Blockchain-assisted+secured+data+management+framework+for+health+information+analysis+based+on+Internet+of+Medical+Things\&author=Abbas,+A.\&author=Alroobaea,+R.\&author=Krichen,+M.\&author=Rubaiee,+S.\&author=Vimal,+S.\&author=Almansour,+F.M.\&publication_year=2021\&journal=Pers.+Ubiquitous+Comput.\&pages=1%E2%80%9314\&doi=10.1007/s00779-021-01583-8)] \[[CrossRef](https://doi.org/10.1007/s00779-021-01583-8)]
28. Latifi, S.; Zhang, Y.; Cheng, L.C. Blockchain-based real estate market: One method for applying blockchain technology in commercial real estate market. In Proceedings of the 2019 IEEE International Conference on Blockchain (Blockchain), Atlanta, GA, USA, 14–17 July 2019; IEEE: Piscataway, NJ, USA, 2019; pp. 528–535. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Blockchain-based+real+estate+market:+One+method+for+applying+blockchain+technology+in+commercial+real+estate+market\&conference=Proceedings+of+the+2019+IEEE+International+Conference+on+Blockchain+\(Blockchain\)\&author=Latifi,+S.\&author=Zhang,+Y.\&author=Cheng,+L.C.\&publication_year=2019\&pages=528%E2%80%93535)]
29. Gupta, A.; Rathod, J.; Patel, D.; Bothra, J.; Shanbhag, S.; Bhalerao, T. Tokenization of real estate using blockchain technology. In Proceedings of the Applied Cryptography and Network Security Workshops: ACNS 2020 Satellite Workshops, AIBlock, AIHWS, AIoTS, Cloud S\&P, SCI, SecMT, and SiMLA, Rome, Italy, 19–22 October 2020, Proceedings 18; Springer: Cham, Switzerland, 2020; pp. 77–90. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Tokenization+of+real+estate+using+blockchain+technology\&author=Gupta,+A.\&author=Rathod,+J.\&author=Patel,+D.\&author=Bothra,+J.\&author=Shanbhag,+S.\&author=Bhalerao,+T.\&publication_year=2020\&pages=77%E2%80%9390)]
30. Agbo, C.C.; Mahmoud, Q.H.; Eklund, J.M. Blockchain technology in healthcare: A systematic review. Healthcare 2019, 7, 56. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Blockchain+technology+in+healthcare:+A+systematic+review\&author=Agbo,+C.C.\&author=Mahmoud,+Q.H.\&author=Eklund,+J.M.\&publication_year=2019\&journal=Healthcare\&volume=7\&pages=56\&doi=10.3390/healthcare7020056\&pmid=30987333)] \[[CrossRef](https://doi.org/10.3390/healthcare7020056)] \[[PubMed](http://www.ncbi.nlm.nih.gov/pubmed/30987333)]
31. Hölbl, M.; Kompara, M.; Kamišalić, A.; Nemec Zlatolas, L. A systematic review of the use of blockchain in healthcare. Symmetry 2018, 10, 470. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=A+systematic+review+of+the+use+of+blockchain+in+healthcare\&author=H%C3%B6lbl,+M.\&author=Kompara,+M.\&author=Kami%C5%A1ali%C4%87,+A.\&author=Nemec+Zlatolas,+L.\&publication_year=2018\&journal=Symmetry\&volume=10\&pages=470\&doi=10.3390/sym10100470)] \[[CrossRef](https://doi.org/10.3390/sym10100470)]
32. Dutta, P.; Choi, T.M.; Somani, S.; Butala, R. Blockchain technology in supply chain operations: Applications, challenges and research opportunities. Transp. Res. Part E Logist. Transp. Rev. 2020, 142, 102067. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Blockchain+technology+in+supply+chain+operations:+Applications,+challenges+and+research+opportunities\&author=Dutta,+P.\&author=Choi,+T.M.\&author=Somani,+S.\&author=Butala,+R.\&publication_year=2020\&journal=Transp.+Res.+Part+E+Logist.+Transp.+Rev.\&volume=142\&pages=102067\&doi=10.1016/j.tre.2020.102067)] \[[CrossRef](https://doi.org/10.1016/j.tre.2020.102067)]
33. Chang, S.E.; Chen, Y. When blockchain meets supply chain: A systematic literature review on current development and potential applications. IEEE Access 2020, 8, 62478–62494. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=When+blockchain+meets+supply+chain:+A+systematic+literature+review+on+current+development+and+potential+applications\&author=Chang,+S.E.\&author=Chen,+Y.\&publication_year=2020\&journal=IEEE+Access\&volume=8\&pages=62478%E2%80%9362494\&doi=10.1109/ACCESS.2020.2983601)] \[[CrossRef](https://doi.org/10.1109/ACCESS.2020.2983601)]
34. Taş, R.; Tanrıöver, Ö.Ö. A systematic review of challenges and opportunities of blockchain for E-voting. Symmetry 2020, 12, 1328. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=A+systematic+review+of+challenges+and+opportunities+of+blockchain+for+E-voting\&author=Ta%C5%9F,+R.\&author=Tanr%C4%B1%C3%B6ver,+%C3%96.%C3%96.\&publication_year=2020\&journal=Symmetry\&volume=12\&pages=1328\&doi=10.3390/sym12081328)] \[[CrossRef](https://doi.org/10.3390/sym12081328)]
35. Kshetri, N.; Voas, J. Blockchain-enabled e-voting. IEEE Softw. 2018, 35, 95–99. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Blockchain-enabled+e-voting\&author=Kshetri,+N.\&author=Voas,+J.\&publication_year=2018\&journal=IEEE+Softw.\&volume=35\&pages=95%E2%80%9399\&doi=10.1109/MS.2018.2801546)] \[[CrossRef](https://doi.org/10.1109/MS.2018.2801546)]
36. Gupta, M.; Kumar, R.; Shekhar, S.; Sharma, B.; Patel, R.B.; Jain, S.; Dhaou, I.B.; Iwendi, C. Game Theory-Based Authentication Framework to Secure Internet of Vehicles with Blockchain. Sensors 2022, 22, 5119. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Game+Theory-Based+Authentication+Framework+to+Secure+Internet+of+Vehicles+with+Blockchain\&author=Gupta,+M.\&author=Kumar,+R.\&author=Shekhar,+S.\&author=Sharma,+B.\&author=Patel,+R.B.\&author=Jain,+S.\&author=Dhaou,+I.B.\&author=Iwendi,+C.\&publication_year=2022\&journal=Sensors\&volume=22\&pages=5119\&doi=10.3390/s22145119)] \[[CrossRef](https://doi.org/10.3390/s22145119)]
37. Boulila, W.; Driss, M.; Alshanqiti, E.; Al-Sarem, M.; Saeed, F.; Krichen, M. Weight initialization techniques for deep learning algorithms in remote sensing: Recent trends and future perspectives. In Advances on Smart and Soft Computing: Proceedings of ICACIn 2021; Springer: Singapore, 2022; pp. 477–484. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Weight+initialization+techniques+for+deep+learning+algorithms+in+remote+sensing:+Recent+trends+and+future+perspectives\&author=Boulila,+W.\&author=Driss,+M.\&author=Alshanqiti,+E.\&author=Al-Sarem,+M.\&author=Saeed,+F.\&author=Krichen,+M.\&publication_year=2022\&pages=477%E2%80%93484)]
38. Abdalzaher, M.S.; Salim, M.M.; Elsayed, H.A.; Fouda, M.M. Machine learning benchmarking for secured iot smart systems. In Proceedings of the 2022 IEEE International Conference on Internet of Things and Intelligence Systems (IoTaIS), Bali, Indonesia, 24–26 November 2022; IEEE: Piscataway, NJ, USA, 2022; pp. 50–56. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Machine+learning+benchmarking+for+secured+iot+smart+systems\&conference=Proceedings+of+the+2022+IEEE+International+Conference+on+Internet+of+Things+and+Intelligence+Systems+\(IoTaIS\)\&author=Abdalzaher,+M.S.\&author=Salim,+M.M.\&author=Elsayed,+H.A.\&author=Fouda,+M.M.\&publication_year=2022\&pages=50%E2%80%9356)]
39. Zidi, S.; Mihoub, A.; Qaisar, S.M.; Krichen, M.; Al-Haija, Q.A. Theft detection dataset for benchmarking and machine learning based classification in a smart grid environment. J. King Saud Univ.-Comput. Inf. Sci. 2023, 35, 13–25. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Theft+detection+dataset+for+benchmarking+and+machine+learning+based+classification+in+a+smart+grid+environment\&author=Zidi,+S.\&author=Mihoub,+A.\&author=Qaisar,+S.M.\&author=Krichen,+M.\&author=Al-Haija,+Q.A.\&publication_year=2023\&journal=J.+King+Saud+Univ.-Comput.+Inf.+Sci.\&volume=35\&pages=13%E2%80%9325\&doi=10.1016/j.jksuci.2022.05.007)] \[[CrossRef](https://doi.org/10.1016/j.jksuci.2022.05.007)]
40. Hamdy, O.; Gaber, H.; Abdalzaher, M.S.; Elhadidy, M. Identifying exposure of urban area to certain seismic hazard using machine learning and GIS: A case study of greater Cairo. Sustainability 2022, 14, 10722. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Identifying+exposure+of+urban+area+to+certain+seismic+hazard+using+machine+learning+and+GIS:+A+case+study+of+greater+Cairo\&author=Hamdy,+O.\&author=Gaber,+H.\&author=Abdalzaher,+M.S.\&author=Elhadidy,+M.\&publication_year=2022\&journal=Sustainability\&volume=14\&pages=10722\&doi=10.3390/su141710722)] \[[CrossRef](https://doi.org/10.3390/su141710722)]
41. Zhang, C.; Lu, Y. Study on artificial intelligence: The state of the art and future prospects. J. Ind. Inf. Integr. 2021, 23, 100224. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Study+on+artificial+intelligence:+The+state+of+the+art+and+future+prospects\&author=Zhang,+C.\&author=Lu,+Y.\&publication_year=2021\&journal=J.+Ind.+Inf.+Integr.\&volume=23\&pages=100224\&doi=10.1016/j.jii.2021.100224)] \[[CrossRef](https://doi.org/10.1016/j.jii.2021.100224)]
42. Cunningham, P.; Cord, M.; Delany, S.J. Supervised learning. In Machine Learning Techniques for Multimedia: Case Studies on Organization and Retrieval; Springer: Berlin/Heidelberg, Germany, 2008; pp. 21–49. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Supervised+learning\&author=Cunningham,+P.\&author=Cord,+M.\&author=Delany,+S.J.\&publication_year=2008\&pages=21%E2%80%9349)]
43. Hastie, T.; Tibshirani, R.; Friedman, J.; Hastie, T.; Tibshirani, R.; Friedman, J. Overview of supervised learning. In The Elements of Statistical Learning: Data Mining, Inference, and Prediction; Springer: New York, NY, USA, 2009; pp. 9–41. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Overview+of+supervised+learning\&author=Hastie,+T.\&author=Tibshirani,+R.\&author=Friedman,+J.\&author=Hastie,+T.\&author=Tibshirani,+R.\&author=Friedman,+J.\&publication_year=2009\&pages=9%E2%80%9341)]
44. Hastie, T.; Tibshirani, R.; Friedman, J.; Hastie, T.; Tibshirani, R.; Friedman, J. Unsupervised learning. In The Elements of Statistical Learning: Data Mining, Inference, and Prediction; Springer: New York, NY, USA, 2009; pp. 485–585. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Unsupervised+learning\&author=Hastie,+T.\&author=Tibshirani,+R.\&author=Friedman,+J.\&author=Hastie,+T.\&author=Tibshirani,+R.\&author=Friedman,+J.\&publication_year=2009\&pages=485%E2%80%93585)]
45. Ghahramani, Z. Unsupervised learning. In Advanced Lectures on Machine Learning: ML Summer Schools 2003, Canberra, Australia, 2–14 February 2003, Tübingen, Germany, 4–16 August 2003, Revised Lectures; Springer: Berlin/Heidelberg, Germany, 2004; pp. 72–112. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Unsupervised+learning\&author=Ghahramani,+Z.\&publication_year=2004\&pages=72%E2%80%93112)]
46. Zhou, Z.H.; Zhou, Z.H. Semi-supervised learning. In Machine Learning; Springer: Singapore, 2021; pp. 315–341. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Semi-supervised+learning\&author=Zhou,+Z.H.\&author=Zhou,+Z.H.\&publication_year=2021\&pages=315%E2%80%93341)]
47. Van Engelen, J.E.; Hoos, H.H. A survey on semi-supervised learning. Mach. Learn. 2020, 109, 373–440. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=A+survey+on+semi-supervised+learning\&author=Van+Engelen,+J.E.\&author=Hoos,+H.H.\&publication_year=2020\&journal=Mach.+Learn.\&volume=109\&pages=373%E2%80%93440\&doi=10.1007/s10994-019-05855-6)] \[[CrossRef](https://doi.org/10.1007/s10994-019-05855-6)]
48. Mazyavkina, N.; Sviridov, S.; Ivanov, S.; Burnaev, E. Reinforcement learning for combinatorial optimization: A survey. Comput. Oper. Res. 2021, 134, 105400. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Reinforcement+learning+for+combinatorial+optimization:+A+survey\&author=Mazyavkina,+N.\&author=Sviridov,+S.\&author=Ivanov,+S.\&author=Burnaev,+E.\&publication_year=2021\&journal=Comput.+Oper.+Res.\&volume=134\&pages=105400\&doi=10.1016/j.cor.2021.105400)] \[[CrossRef](https://doi.org/10.1016/j.cor.2021.105400)]
49. Sutton, R.S.; Barto, A.G. Reinforcement Learning: An Introduction; MIT Press: Cambridge, MA, USA, 2018. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Reinforcement+Learning:+An+Introduction\&author=Sutton,+R.S.\&author=Barto,+A.G.\&publication_year=2018)]
50. Dbouk, T.; Mourad, A.; Otrok, H.; Tout, H.; Talhi, C. A novel ad-hoc mobile edge cloud offering security services through intelligent resource-aware offloading. IEEE Trans. Netw. Serv. Manag. 2019, 16, 1665–1680. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=A+novel+ad-hoc+mobile+edge+cloud+offering+security+services+through+intelligent+resource-aware+offloading\&author=Dbouk,+T.\&author=Mourad,+A.\&author=Otrok,+H.\&author=Tout,+H.\&author=Talhi,+C.\&publication_year=2019\&journal=IEEE+Trans.+Netw.+Serv.+Manag.\&volume=16\&pages=1665%E2%80%931680\&doi=10.1109/TNSM.2019.2939221)] \[[CrossRef](https://doi.org/10.1109/TNSM.2019.2939221)]
51. Sarker, I.H.; Furhad, M.H.; Nowrozy, R. Ai-driven cybersecurity: An overview, security intelligence modeling and research directions. SN Comput. Sci. 2021, 2, 173. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Ai-driven+cybersecurity:+An+overview,+security+intelligence+modeling+and+research+directions\&author=Sarker,+I.H.\&author=Furhad,+M.H.\&author=Nowrozy,+R.\&publication_year=2021\&journal=SN+Comput.+Sci.\&volume=2\&pages=173\&doi=10.1007/s42979-021-00557-0)] \[[CrossRef](https://doi.org/10.1007/s42979-021-00557-0)]
52. Dash, B.; Ansari, M.F.; Sharma, P.; Ali, A. Threats and Opportunities with AI-based Cyber Security Intrusion Detection: A Review. Int. J. Softw. Eng. Appl. (IJSEA) 2022, 13. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Threats+and+Opportunities+with+AI-based+Cyber+Security+Intrusion+Detection:+A+Review\&author=Dash,+B.\&author=Ansari,+M.F.\&author=Sharma,+P.\&author=Ali,+A.\&publication_year=2022\&journal=Int.+J.+Softw.+Eng.+Appl.+\(IJSEA\)\&volume=13\&doi=10.5121/ijsea.2022.13502)] \[[CrossRef](https://doi.org/10.5121/ijsea.2022.13502)]
53. Jaber, A.; Fritsch, L. Towards AI-powered Cybersecurity Attack Modeling with Simulation Tools: Review of Attack Simulators. In Proceedings of the Advances on P2P, Parallel, Grid, Cloud and Internet Computing: Proceedings of the 17th International Conference on P2P, Parallel, Grid, Cloud and Internet Computing (3PGCIC-2022); Springer: Cham, Switzerland, 2022; pp. 249–257. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Towards+AI-powered+Cybersecurity+Attack+Modeling+with+Simulation+Tools:+Review+of+Attack+Simulators\&conference=Proceedings+of+the+Advances+on+P2P,+Parallel,+Grid,+Cloud+and+Internet+Computing:+Proceedings+of+the+17th+International+Conference+on+P2P,+Parallel,+Grid,+Cloud+and+Internet+Computing+\(3PGCIC-2022\)\&author=Jaber,+A.\&author=Fritsch,+L.\&publication_year=2022\&pages=249%E2%80%93257)]
54. Ansari, M.F.; Dash, B.; Sharma, P.; Yathiraju, N. The Impact and Limitations of Artificial Intelligence in Cybersecurity: A Literature Review. Int. J. Adv. Res. Comput. Commun. Eng. 2022. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=The+Impact+and+Limitations+of+Artificial+Intelligence+in+Cybersecurity:+A+Literature+Review\&author=Ansari,+M.F.\&author=Dash,+B.\&author=Sharma,+P.\&author=Yathiraju,+N.\&publication_year=2022\&journal=Int.+J.+Adv.+Res.+Comput.+Commun.+Eng.\&doi=10.17148/IJARCCE.2022.11912)] \[[CrossRef](https://doi.org/10.17148/IJARCCE.2022.11912)]
55. Srinivasan, S.; Ravi, V.; Sowmya, V.; Krichen, M.; Noureddine, D.B.; Anivilla, S.; Soman, K. Deep convolutional neural network based image spam classification. In Proceedings of the 2020 6th Conference on Data Science and Machine Learning Applications (CDMA), Riyadh, Saudi Arabia, 4–5 March 2020; IEEE: Piscataway, NJ, USA, 2020; pp. 112–117. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Deep+convolutional+neural+network+based+image+spam+classification\&conference=Proceedings+of+the+2020+6th+Conference+on+Data+Science+and+Machine+Learning+Applications+\(CDMA\)\&author=Srinivasan,+S.\&author=Ravi,+V.\&author=Sowmya,+V.\&author=Krichen,+M.\&author=Noureddine,+D.B.\&author=Anivilla,+S.\&author=Soman,+K.\&publication_year=2020\&pages=112%E2%80%93117)]
56. Demertzis, K.; Iliadis, L.; Tziritas, N.; Kikiras, P. Anomaly detection via blockchained deep learning smart contracts in industry 4.0. Neural Comput. Appl. 2020, 32, 17361–17378. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Anomaly+detection+via+blockchained+deep+learning+smart+contracts+in+industry+4.0\&author=Demertzis,+K.\&author=Iliadis,+L.\&author=Tziritas,+N.\&author=Kikiras,+P.\&publication_year=2020\&journal=Neural+Comput.+Appl.\&volume=32\&pages=17361%E2%80%9317378\&doi=10.1007/s00521-020-05189-8)] \[[CrossRef](https://doi.org/10.1007/s00521-020-05189-8)]
57. Yunis, M.M.; El-Khalil, R.; Ghanem, M. Towards a Conceptual Framework on the Importance of Privacy and Security Concerns in Audit Data Analytics. In Proceedings of the International Conference on Industrial Engineering and Operations Management, Sao Paulo, Brazil, 5–8 April 2021. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Towards+a+Conceptual+Framework+on+the+Importance+of+Privacy+and+Security+Concerns+in+Audit+Data+Analytics\&conference=Proceedings+of+the+International+Conference+on+Industrial+Engineering+and+Operations+Management\&author=Yunis,+M.M.\&author=El-Khalil,+R.\&author=Ghanem,+M.\&publication_year=2021)]
58. Kumar, N.; Singh, A.; Handa, A.; Shukla, S.K. Detecting malicious accounts on the Ethereum blockchain with supervised learning. In Proceedings of the Cyber Security Cryptography and Machine Learning: Fourth International Symposium, CSCML 2020, Be’er Sheva, Israel, 2–3 July 2020, Proceedings 4; Springer: Cham, Switzerland, 2020; pp. 94–109. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Detecting+malicious+accounts+on+the+Ethereum+blockchain+with+supervised+learning\&conference=Proceedings+of+the+Cyber+Security+Cryptography+and+Machine+Learning:+Fourth+International+Symposium,+CSCML+2020,+Be%E2%80%99er+Sheva,+Israel,+2%E2%80%933+July+2020,+Proceedings+4\&author=Kumar,+N.\&author=Singh,+A.\&author=Handa,+A.\&author=Shukla,+S.K.\&publication_year=2020\&pages=94%E2%80%93109)]
59. Liu, Z.; Qian, P.; Wang, X.; Zhuang, Y.; Qiu, L.; Wang, X. Combining graph neural networks with expert knowledge for smart contract vulnerability detection. IEEE Trans. Knowl. Data Eng. 2021. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Combining+graph+neural+networks+with+expert+knowledge+for+smart+contract+vulnerability+detection\&author=Liu,+Z.\&author=Qian,+P.\&author=Wang,+X.\&author=Zhuang,+Y.\&author=Qiu,+L.\&author=Wang,+X.\&publication_year=2021\&journal=IEEE+Trans.+Knowl.+Data+Eng.\&doi=10.1109/TKDE.2021.3095196)] \[[CrossRef](https://doi.org/10.1109/TKDE.2021.3095196)]
60. Jiang, F.; Cao, Y.; Xiao, J.; Yi, H.; Lei, G.; Liu, M.; Deng, S.; Wang, H. VDDL: A Deep Learning-Based Vulnerability Detection Model for Smart Contracts. In Proceedings of the International Conference on Machine Learning for Cyber Security; Springer: Cham, Switzerland, 2023; pp. 72–86. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=VDDL:+A+Deep+Learning-Based+Vulnerability+Detection+Model+for+Smart+Contracts\&conference=Proceedings+of+the+International+Conference+on+Machine+Learning+for+Cyber+Security\&author=Jiang,+F.\&author=Cao,+Y.\&author=Xiao,+J.\&author=Yi,+H.\&author=Lei,+G.\&author=Liu,+M.\&author=Deng,+S.\&author=Wang,+H.\&publication_year=2023\&pages=72%E2%80%9386)]
61. Jie, W.; Chen, Q.; Wang, J.; Koe, A.S.V.; Li, J.; Huang, P.; Wu, Y.; Wang, Y. A novel extended multimodal AI framework towards vulnerability detection in smart contracts. Inf. Sci. 2023, 636, 118907. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=A+novel+extended+multimodal+AI+framework+towards+vulnerability+detection+in+smart+contracts\&author=Jie,+W.\&author=Chen,+Q.\&author=Wang,+J.\&author=Koe,+A.S.V.\&author=Li,+J.\&author=Huang,+P.\&author=Wu,+Y.\&author=Wang,+Y.\&publication_year=2023\&journal=Inf.+Sci.\&volume=636\&pages=118907\&doi=10.1016/j.ins.2023.03.132)] \[[CrossRef](https://doi.org/10.1016/j.ins.2023.03.132)]
62. Sun, X.; Tu, L.; Zhang, J.; Cai, J.; Li, B.; Wang, Y. ASSBert: Active and semi-supervised bert for smart contract vulnerability detection. J. Inf. Secur. Appl. 2023, 73, 103423. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=ASSBert:+Active+and+semi-supervised+bert+for+smart+contract+vulnerability+detection\&author=Sun,+X.\&author=Tu,+L.\&author=Zhang,+J.\&author=Cai,+J.\&author=Li,+B.\&author=Wang,+Y.\&publication_year=2023\&journal=J.+Inf.+Secur.+Appl.\&volume=73\&pages=103423\&doi=10.1016/j.jisa.2023.103423)] \[[CrossRef](https://doi.org/10.1016/j.jisa.2023.103423)]
63. Zhang, Z.; Lei, Y.; Yan, M.; Yu, Y.; Chen, J.; Wang, S.; Mao, X. Reentrancy Vulnerability Detection and Localization: A Deep Learning Based Two-phase Approach. In Proceedings of the 37th IEEE/ACM International Conference on Automated Software Engineering, Rochester, MI, USA, 10–14 October 2022; pp. 1–13. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Reentrancy+Vulnerability+Detection+and+Localization:+A+Deep+Learning+Based+Two-phase+Approach\&conference=Proceedings+of+the+37th+IEEE/ACM+International+Conference+on+Automated+Software+Engineering\&author=Zhang,+Z.\&author=Lei,+Y.\&author=Yan,+M.\&author=Yu,+Y.\&author=Chen,+J.\&author=Wang,+S.\&author=Mao,+X.\&publication_year=2022\&pages=1%E2%80%9313)]
64. Abdalzaher, M.S.; Soliman, M.S.; El-Hady, S.M.; Benslimane, A.; Elwekeil, M. A deep learning model for earthquake parameters observation in IoT system-based earthquake early warning. IEEE Internet Things J. 2021, 9, 8412–8424. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=A+deep+learning+model+for+earthquake+parameters+observation+in+IoT+system-based+earthquake+early+warning\&author=Abdalzaher,+M.S.\&author=Soliman,+M.S.\&author=El-Hady,+S.M.\&author=Benslimane,+A.\&author=Elwekeil,+M.\&publication_year=2021\&journal=IEEE+Internet+Things+J.\&volume=9\&pages=8412%E2%80%938424\&doi=10.1109/JIOT.2021.3114420)] \[[CrossRef](https://doi.org/10.1109/JIOT.2021.3114420)]
65. Mihoub, A. A deep learning-based framework for human activity recognition in smart homes. Mob. Inf. Syst. 2021, 2021, 6961343. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=A+deep+learning-based+framework+for+human+activity+recognition+in+smart+homes\&author=Mihoub,+A.\&publication_year=2021\&journal=Mob.+Inf.+Syst.\&volume=2021\&pages=6961343\&doi=10.1155/2021/6961343)] \[[CrossRef](https://doi.org/10.1155/2021/6961343)]
66. Xu, G.; Liu, L.; Zhou, Z. Reentrancy Vulnerability Detection of Smart Contract Based on Bidirectional Sequential Neural Network with Hierarchical Attention Mechanism. In Proceedings of the 2022 International Conference on Blockchain Technology and Information Security (ICBCTIS), Huaihua, China, 15–17 July 2022; IEEE: Piscataway, NJ, USA, 2022; pp. 56–59. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Reentrancy+Vulnerability+Detection+of+Smart+Contract+Based+on+Bidirectional+Sequential+Neural+Network+with+Hierarchical+Attention+Mechanism\&conference=Proceedings+of+the+2022+International+Conference+on+Blockchain+Technology+and+Information+Security+\(ICBCTIS\)\&author=Xu,+G.\&author=Liu,+L.\&author=Zhou,+Z.\&publication_year=2022\&pages=56%E2%80%9359)]
67. Zheng, Z.; Chen, W.; Zhong, Z.; Chen, Z.; Lu, Y. Securing the Ethereum from Smart Ponzi Schemes: Identification Using Static Features. ACM Trans. Softw. Eng. Methodol. 2022. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Securing+the+Ethereum+from+Smart+Ponzi+Schemes:+Identification+Using+Static+Features\&author=Zheng,+Z.\&author=Chen,+W.\&author=Zhong,+Z.\&author=Chen,+Z.\&author=Lu,+Y.\&publication_year=2022\&journal=ACM+Trans.+Softw.+Eng.+Methodol.\&doi=10.1145/3571847)] \[[CrossRef](https://doi.org/10.1145/3571847)]
68. Liu, L.; Tsai, W\.T.; Bhuiyan, M.Z.A.; Peng, H.; Liu, M. Blockchain-enabled fraud discovery through abnormal smart contract detection on Ethereum. Future Gener. Comput. Syst. 2022, 128, 158–166. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Blockchain-enabled+fraud+discovery+through+abnormal+smart+contract+detection+on+Ethereum\&author=Liu,+L.\&author=Tsai,+W.T.\&author=Bhuiyan,+M.Z.A.\&author=Peng,+H.\&author=Liu,+M.\&publication_year=2022\&journal=Future+Gener.+Comput.+Syst.\&volume=128\&pages=158%E2%80%93166\&doi=10.1016/j.future.2021.08.023)] \[[CrossRef](https://doi.org/10.1016/j.future.2021.08.023)]
69. Hu, H.; Bai, Q.; Xu, Y. Scsguard: Deep scam detection for ethereum smart contracts. In Proceedings of the IEEE INFOCOM 2022-IEEE Conference on Computer Communications Workshops (INFOCOM WKSHPS), Virtual, 2–5 May 2022; IEEE: Piscataway, NJ, USA, 2022; pp. 1–6. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Scsguard:+Deep+scam+detection+for+ethereum+smart+contracts\&conference=Proceedings+of+the+IEEE+INFOCOM+2022-IEEE+Conference+on+Computer+Communications+Workshops+\(INFOCOM+WKSHPS\)\&author=Hu,+H.\&author=Bai,+Q.\&author=Xu,+Y.\&publication_year=2022\&pages=1%E2%80%936)]
70. Hwang, S.J.; Choi, S.H.; Shin, J.; Choi, Y.H. CodeNet: Code-targeted convolutional neural network architecture for smart contract vulnerability detection. IEEE Access 2022, 10, 32595–32607. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=CodeNet:+Code-targeted+convolutional+neural+network+architecture+for+smart+contract+vulnerability+detection\&author=Hwang,+S.J.\&author=Choi,+S.H.\&author=Shin,+J.\&author=Choi,+Y.H.\&publication_year=2022\&journal=IEEE+Access\&volume=10\&pages=32595%E2%80%9332607\&doi=10.1109/ACCESS.2022.3162065)] \[[CrossRef](https://doi.org/10.1109/ACCESS.2022.3162065)]
71. Andrijasa, M.F.; Ismail, S.A.; Ahmad, N. Towards Automatic Exploit Generation for Identifying Re-Entrancy Attacks on Cross-Contract. In Proceedings of the 2022 IEEE Symposium on Future Telecommunication Technologies (SOFTT), Johor Baharu, Malaysia, 14–16 November 2022; IEEE: Piscataway, NJ, USA, 2022; pp. 15–20. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Towards+Automatic+Exploit+Generation+for+Identifying+Re-Entrancy+Attacks+on+Cross-Contract\&conference=Proceedings+of+the+2022+IEEE+Symposium+on+Future+Telecommunication+Technologies+\(SOFTT\)\&author=Andrijasa,+M.F.\&author=Ismail,+S.A.\&author=Ahmad,+N.\&publication_year=2022\&pages=15%E2%80%9320)]
72. Kang, D. Bridging Fuzz Testing and Metamorphic Testing for Classification of Machine Learning. In Proceedings of the 2022 IEEE International Conference on Consumer Electronics (ICCE), Taipei, Taiwan, 6–8 July 2022; IEEE: Piscataway, NJ, USA, 2022; pp. 1–2. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Bridging+Fuzz+Testing+and+Metamorphic+Testing+for+Classification+of+Machine+Learning\&conference=Proceedings+of+the+2022+IEEE+International+Conference+on+Consumer+Electronics+\(ICCE\)\&author=Kang,+D.\&publication_year=2022\&pages=1%E2%80%932)]
73. Gupta, R.; Patel, M.M.; Shukla, A.; Tanwar, S. Deep learning-based malicious smart contract detection scheme for internet of things environment. Comput. Electr. Eng. 2022, 97, 107583. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Deep+learning-based+malicious+smart+contract+detection+scheme+for+internet+of+things+environment\&author=Gupta,+R.\&author=Patel,+M.M.\&author=Shukla,+A.\&author=Tanwar,+S.\&publication_year=2022\&journal=Comput.+Electr.+Eng.\&volume=97\&pages=107583\&doi=10.1016/j.compeleceng.2021.107583)] \[[CrossRef](https://doi.org/10.1016/j.compeleceng.2021.107583)]
74. Li, N.; Liu, Y.; Li, L.; Wang, Y. Smart Contract Vulnerability Detection Based on Deep and Cross Network. In Proceedings of the 2022 3rd International Conference on Computer Vision, Image and Deep Learning & International Conference on Computer Engineering and Applications (CVIDL & ICCEA), Changchun, China, 20–22 May 2022; IEEE: Piscataway, NJ, USA, 2022; pp. 533–536. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Smart+Contract+Vulnerability+Detection+Based+on+Deep+and+Cross+Network\&conference=Proceedings+of+the+2022+3rd+International+Conference+on+Computer+Vision,+Image+and+Deep+Learning+&+International+Conference+on+Computer+Engineering+and+Applications+\(CVIDL+&+ICCEA\)\&author=Li,+N.\&author=Liu,+Y.\&author=Li,+L.\&author=Wang,+Y.\&publication_year=2022\&pages=533%E2%80%93536)]
75. Shakya, S.; Mukherjee, A.; Halder, R.; Maiti, A.; Chaturvedi, A. SmartMixModel: Machine Learning-based Vulnerability Detection of Solidity Smart Contracts. In Proceedings of the 2022 IEEE International Conference on Blockchain (Blockchain), Espoo, Finland, 22–25 August 2022; IEEE: Piscataway, NJ, USA, 2022; pp. 37–44. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=SmartMixModel:+Machine+Learning-based+Vulnerability+Detection+of+Solidity+Smart+Contracts\&conference=Proceedings+of+the+2022+IEEE+International+Conference+on+Blockchain+\(Blockchain\)\&author=Shakya,+S.\&author=Mukherjee,+A.\&author=Halder,+R.\&author=Maiti,+A.\&author=Chaturvedi,+A.\&publication_year=2022\&pages=37%E2%80%9344)]
76. Wang, Z.; Zheng, Q.; Sun, Y. GVD-net: Graph embedding-based Machine Learning Model for Smart Contract Vulnerability Detection. In Proceedings of the 2022 International Conference on Algorithms, Data Mining, and Information Technology (ADMIT), Xi’an, China, 23–25 September 2022; IEEE: Piscataway, NJ, USA, 2022; pp. 99–103. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=GVD-net:+Graph+embedding-based+Machine+Learning+Model+for+Smart+Contract+Vulnerability+Detection\&conference=Proceedings+of+the+2022+International+Conference+on+Algorithms,+Data+Mining,+and+Information+Technology+\(ADMIT\)\&author=Wang,+Z.\&author=Zheng,+Q.\&author=Sun,+Y.\&publication_year=2022\&pages=99%E2%80%93103)]
77. Ashizawa, N.; Yanai, N.; Cruz, J.P.; Okamura, S. Eth2Vec: Learning contract-wide code representations for vulnerability detection on ethereum smart contracts. In Proceedings of the 3rd ACM International Symposium on Blockchain and Secure Critical Infrastructure, Virtual Event, Hong Kong, 7 June 2021; pp. 47–59. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Eth2Vec:+Learning+contract-wide+code+representations+for+vulnerability+detection+on+ethereum+smart+contracts\&conference=Proceedings+of+the+3rd+ACM+International+Symposium+on+Blockchain+and+Secure+Critical+Infrastructure\&author=Ashizawa,+N.\&author=Yanai,+N.\&author=Cruz,+J.P.\&author=Okamura,+S.\&publication_year=2021\&pages=47%E2%80%9359)]
78. Yu, X.; Zhao, H.; Hou, B.; Ying, Z.; Wu, B. Deescvhunter: A deep learning-based framework for smart contract vulnerability detection. In Proceedings of the 2021 International Joint Conference on Neural Networks (IJCNN), Shenzhen, China, 18–22 July 2021; IEEE: Piscataway, NJ, USA, 2021; pp. 1–8. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Deescvhunter:+A+deep+learning-based+framework+for+smart+contract+vulnerability+detection\&conference=Proceedings+of+the+2021+International+Joint+Conference+on+Neural+Networks+\(IJCNN\)\&author=Yu,+X.\&author=Zhao,+H.\&author=Hou,+B.\&author=Ying,+Z.\&author=Wu,+B.\&publication_year=2021\&pages=1%E2%80%938)]
79. Wang, B.; Chu, H.; Zhang, P.; Dong, H. Smart Contract Vulnerability Detection Using Code Representation Fusion. In Proceedings of the 2021 28th Asia-Pacific Software Engineering Conference (APSEC), Taipei, Taiwan, 6–9 December 2021; IEEE: Piscataway, NJ, USA, 2021; pp. 564–565. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=Smart+Contract+Vulnerability+Detection+Using+Code+Representation+Fusion\&conference=Proceedings+of+the+2021+28th+Asia-Pacific+Software+Engineering+Conference+\(APSEC\)\&author=Wang,+B.\&author=Chu,+H.\&author=Zhang,+P.\&author=Dong,+H.\&publication_year=2021\&pages=564%E2%80%93565)]
80. Hao, X.; Ren, W.; Zheng, W.; Zhu, T. SCScan: A SVM-Based Scanning System for Vulnerabilities in Blockchain Smart Contracts. In Proceedings of the 2020 IEEE 19th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom), Guangzhou, China, 29 December–1 January 2020; IEEE: Piscataway, NJ, USA, 2020; pp. 1598–1605. \[[Google Scholar](https://scholar.google.com/scholar_lookup?title=SCScan:+A+SVM-Based+Scanning+System+for+Vulnerabilities+in+Blockchain+Smart+Contracts\&conference=Proceedings+of+the+2020+IEEE+19th+International+Conference+on+Trust,+Security+and+Privacy+in+Computing+and+Communications+\(TrustCom\)\&author=Hao,+X.\&author=Ren,+W.\&author=Zheng,+W.\&author=Zhu,+T.\&publication_year=2020\&pages=1598%E2%80%931605)]

This thesis integrates insights from 'Strengthening the Security of Smart Contracts through the Power of Artificial Intelligence' by Moez Krichen, published in Computers 2023, 12(5), 107, under a [Creative Commons Attribution 4.0](https://creativecommons.org/licenses/by/4.0/) International License. Modifications were made to incorporate recent technological advancements in the AI  and Blockchain industry, including updates on AI chip development and quantum computing's impact on data processing. Additionally, new cybersecurity case studies from 2024 were added to reflect the latest market trends and challenges.&#x20;

</details>

<br>


# Smart Contract “Kill Switch”

Examining the Feasibility and Implications of Implementing Smart Contract Termination Mechanisms in Blockchain Systems

{% hint style="info" %}
**Understanding the Smart Contract Kill Switch**

\
The primary purpose of kill switch is to mitigate potential risks associated with smart contracts. While smart contracts are designed to be self-executing and irreversible, intervention becomes necessary in some situations. For instance, in fraud, illegal activities, or contracts that violate legal requirements, the kill switch allows developers to halt or modify the smart contract.

This mechanism, although controversial, is viewed as a means to ensure that smart contracts comply with existing legal frameworks and ethical standards. It provides a safety net for situations where the decentralized nature of blockchain technology could potentially be exploited for malicious purposes.

Administrators often use this mechanism to deactivate a device or software in response to a security threat. In the context of smart contracts, the kill switch can perform two functions: it can either terminate the contract entirely or initiate a pause, patch, and subsequent re-release of the contract, especially in cases involving significant bugs or security breaches.
{% endhint %}

### Abstract

The proliferation of blockchain technology across diverse sectors has sparked crucial debates regarding the necessity of regulatory frameworks. These discussions center on safeguarding consumer interests, ensuring financial system stability, and addressing privacy issues without compromising the core principles of decentralization and immutability that underpin blockchain platforms. This study investigates the current methods for smart contract termination across a range of prominent blockchain platforms, including Ethereum, BNB Smart Chain, Cardano, Solana, Hyperledger Fabric, Corda, IOTA, Apotos, and Sui. We evaluate how these mechanisms align with the EU Data Act's requirements, particularly in areas such as consumer protection, error rectification, and regulatory adherence. Our findings reveal a varied landscape of approaches, spanning from unalterable smart contracts with pre-programmed termination conditions to flexible contracts allowing post-deployment alterations. We explore the challenges associated with implementing so-called smart contract "kill switches," including balancing regulatory compliance with decentralization principles, assessing technical viability, and considering the ramifications for ecosystem security and user trust.

Keywords: Smart Contract Architecture, Contract Termination Protocols, Blockchain Regulation, EU Data Act Compliance

### I. Introduction

Blockchain technology represents a groundbreaking innovation with the potential to revolutionize various aspects of digital interaction and transaction processing. At the core of this transformation are smart contracts – self-executing agreements encoded in software that promise to redefine how we conduct business across sectors ranging from finance and healthcare to supply chain management. However, the integration of these technologies into societal frameworks raises complex regulatory, ethical, and operational questions. A primary challenge lies in reconciling the inherently decentralized and immutable nature of blockchains with evolving global regulatory landscapes, particularly in areas of consumer protection, privacy preservation, and financial system stability.

Recent research by Chen et al. \[1] highlighted that a significant number of smart contracts deployed on blockchain platforms suffer from issues related to security, availability, performance, maintainability, and reusability. Perez et al. \[2] further quantified this concern, identifying over 23,000 vulnerable contracts on the Ethereum platform alone, potentially jeopardizing millions of dollars worth of cryptocurrency held by unsuspecting users. These findings underscore the growing demand for robust regulatory mechanisms, including the concept of smart contract "kill switches."

The European Union's Data Act, specifically Article 30 \[3], proposes the implementation of a "kill switch" mechanism. This would empower regulatory bodies and potentially participants within blockchain ecosystems to directly intervene in smart contract operations – a concept that, at first glance, appears to contradict the fundamental principles of decentralization and immutability that define blockchain technology. While the EU Data Act presents a significant vision for enhancing smart contract functionality and safety, it is crucial to critically assess both its practicality and desirability. The implementation of comprehensive smart contract termination or interruption mechanisms faces several logistical hurdles, given that smart contracts are typically fixed in content and operation upon deployment, adhering to the "Code is Law" philosophy \[4]. This paper explores various approaches to developing smart contract standards for "kill switches" that can meet regulatory expectations while preserving the unique advantages offered by blockchain technology.

The structure of this paper is as follows: Section II provides contextual information on the regulatory landscape, debates surrounding smart contract regulation, potential applications of "kill switches" across various domains, and a review of related research. Section III examines existing blockchain solutions and their capacity to implement smart contract "kill switches." Section IV discusses the implications for current blockchain ecosystems. Finally, Section V concludes the paper and suggests directions for future research.

### II. Contextual Framework

The concept of smart contract "kill switches" has garnered significant attention in both academic literature and industry discussions. This interest stems from a growing recognition of the potential risks and challenges associated with deploying immutable and autonomous smart contracts, particularly in critical financial, legal, and social applications. Article 30 of the EU Data Act \[3] specifically addresses requirements for smart contracts used in data sharing contexts. The proposal outlines four key requirements for smart contracts to facilitate data availability: (1) resilience, (2) safe termination and interruption capabilities, (3) data archiving and continuity provisions, and (4) access control mechanisms. According to the Act, platform providers and individuals deploying smart contracts for data-sharing purposes must ensure that the smart contract is robust against errors and malicious attacks, protected by stringent access control measures, and capable of being terminated or interrupted. Additionally, the smart contract's data, logic, and code should be archivable to facilitate future auditing if termination occurs.

#### II-A. Addressing Challenges with Smart Contract "Kill Switches"

Smart contracts represent a significant advancement in blockchain technology but remain part of an evolving field. Once executed, these contracts cannot be unilaterally intercepted or modified, even if the underlying agreement is deemed invalid or unenforceable. As summarized in Table III, key challenges include a general lack of flexibility, dependence on external data sources (oracles), vulnerability to bugs and architectural changes (exemplified by the infamous Ethereum DAO hack and its aftermath \[5]), immutability and privacy concerns, and enforcement issues. Moreover, complexities arise when smart contracts diverge from their intended legal purposes, highlighting the difficulty of unwinding or terminating them when necessary \[6]. It is crucial to establish a clear distinction between a smart contract as a technical tool and the legal agreement it represents. This distinction underscores the challenges in aligning the programmed actions of smart contracts with the mutable and often subjective nature of legal interpretations and expectations.

In the broader context of this study, which examines "kill switches" as regulatory and safety mechanisms in smart contracts, it is imperative for these contracts to incorporate features that allow for legal intervention and adjustments. This is essential for ensuring legal compliance without compromising the decentralized and automated nature of blockchain systems.

Implementing such mechanisms involves weighing various benefits against potential drawbacks. Table I outlines several pros and cons of terminating a smart contract based on external triggers.

Table I: Advantages and Disadvantages of "Kill Switches"

<table><thead><tr><th width="157">Aspect</th><th>Advantages</th><th>Disadvantages</th></tr></thead><tbody><tr><td>Security</td><td>Improves protection against vulnerabilities and bugs</td><td>May become a target for malicious actors if not securely managed</td></tr><tr><td>Compliance</td><td>Facilitates adherence to regulations like the EU Data Act</td><td>May conflict with blockchain's principle of immutability</td></tr><tr><td>Governance</td><td>Can be designed to incorporate community consensus</td><td>Might introduce elements of centralized control</td></tr><tr><td>User Trust</td><td>Enhances confidence in safety mechanisms</td><td>Users may fear potential misuse or overreach</td></tr></tbody></table>

#### II-B. Potential Applications

<figure><img src="/files/HclOJ1Zq4KeP7jymoD5o" alt=""><figcaption><p>Figure 1: Relational Diagram for Smart Contract "Kill Switch" Implementation</p></figcaption></figure>

Smart contract "kill switches" have a wide range of potential applications across various industries, offering a valuable tool for enhancing security, compliance, and operational flexibility. Figure 1 illustrates the various components involved in managing the lifecycle and compliance of smart contracts in an idealized environment, highlighting the interconnected roles of governance, technology, and monitoring necessary for implementing a "kill switch" as mandated by regulation.

Domain-specific applications may emerge around the utility of "kill switches" in various industries beyond legislative interest. Table II outlines current and potential applications with some support for pausing and terminating the application.

Table II: Potential Applications of "Kill Switches" in Various Domains

| Domain                  | Application                                                                                                            | Purpose                                                                                                                                                                                                                 |
| ----------------------- | ---------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Finance                 | Decentralized Finance (DeFi) platforms involving stablecoins and other financial instruments                           | Enables freezing of transactions or adjustment of parameters during market crashes, suspicious activities, or security breaches \[7]                                                                                    |
| Healthcare              | Smart contracts managing sensitive patient data or automated drug delivery systems such as the BlockIoT system \[8, 9] | Protects privacy by terminating contracts in case of data breaches to comply with regulations like HIPAA, potentially utilizing standards-based ontological concepts for unexpected situations warranting a pause \[10] |
| Supply Chain Management | Contracts for tracking payloads with robotic agents managed through smart contracts \[11]                              | Allows for halting operations in response to detected anomalies in the operating environment \[12]                                                                                                                      |

#### II-C. Related Research

Table III summarizes the key contributions of several related studies addressing smart contract termination solutions. In contrast to these works, our analysis provides a comparative examination of smart contract termination mechanisms across several major blockchain platforms in Section III. We specifically address implementation challenges, governance models, and impact on decentralization, areas which these previous studies have not covered comprehensively.

Table III: Comparison of Related Research

| Study                      | Key Contributions                                                                                                                                                       | Gaps                                                                                                                       |
| -------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- |
| Casolari et al. \[13]      | Examine the role of smart contracts in the EU's Data Act architecture, identifying key challenges and proposing recommendations                                         | Lacks specific mechanisms for smart contract termination across various blockchain platforms                               |
| Olivieri and Pasetto \[14] | Analysis of EU Data Act requirements for smart contracts, focusing on interoperability, robustness, and safe termination                                                | Lacks specific mechanisms for smart contract termination across various blockchain platforms                               |
| Le et al. \[15]            | Method for proving conditional termination of smart contracts using the F\* programming language, checking conditions against current state and inputs before execution | Limited in automatically inferring termination proofs for complex programs, requiring manual intervention                  |
| Genet et al. \[16]         | Formal and mechanized proof of termination based on measures of EVM call stacks for intrinsic system-wide safeguards (gas and call stack limits)                        | Lacks comparative analysis of termination mechanisms across different blockchains                                          |
| Liu et al. \[17]           | Strengthening Hyperledger Fabric Chaincode smart contracts to handle unexpected situations through a novel voting algorithm                                             | Only applicable to private-permissioned blockchains; sandbox environment for voting may not be practical                   |
| Zhu et al. \[18]           | Recovering "lost" crypto tokens after a voting round, empirically shown to be resilient against Sybil attacks and adversarial collusion                                 | Questionable generalizability to other smart contract termination scenarios; sandbox voting environment may be impractical |
| Mohsin et al. \[19]        | Utilizing community-accepted off-chain ontologies as a guiding framework for action in case of anomalies or errors in deployed contracts                                | Ontology as a decision-support mechanism requires strong governance and trust guarantees                                   |
| Marino et al. \[20]        | Legal frameworks for altering and undoing smart contracts                                                                                                               | Solution through purely legal means may impact decentralization and user trust                                             |

### III. Existing Solutions

We outline approaches for smart contract termination already available in several prominent blockchains and how they could support the EU Data Act mandate for smart contract "kill switches" in Table IV. We compiled this table upon examination of some of the prominent blockchains that support smart contracts along several dimensions, including:

1. Strategy: The methods and strategies used by the blockchain platform to implement "kill switches" in smart contracts, which could include built-in functions, design patterns, or other relevant features.
2. Strengths: The inherent advantages of the platform for smart contract termination.
3. Weaknesses: The inherent limitations of the platform for smart contract termination.
4. Governance: (Abbreviated to Gov. in Table IV) Indicates whether any governance mechanisms or protocols within the blockchain allow network participants to intervene or make decisions regarding the termination or pausing of smart contracts.
5. Regulation Support: Discusses the potential or existing support for compliance with regulatory frameworks, specifically the European Union Data Act.

Table IV: Comparison of Smart Contract "Kill Switch" Approaches in Various Blockchain Implementations

<table><thead><tr><th width="134">Blockchain</th><th>Strategies</th><th>Strengths</th><th>Weaknesses</th><th width="64">Gov.</th><th>Regulation </th></tr></thead><tbody><tr><td>Ethereum [21] &#x26; BNB Smart Chain [22]</td><td>Self-destruct function in Solidity; Pause and emergency stop design patterns; Upgradeable contracts</td><td>Offers built-in functions for contract termination; Compatible with widespread tools and infrastructure</td><td>No external mechanism; Potential security risks; Possible removal of self-destruct function raises long-term viability concerns</td><td>No</td><td>Yes, through custom implementations using Solidity features</td></tr><tr><td>Cardano [23]</td><td>Design-specific conditions within smart contracts built into Plutus; Stateful smart contracts; Seamless interaction with off-chain code</td><td>Uses robust functional programming language (Haskell) for Plutus; Strong on-chain governance mechanisms</td><td>No external mechanism; Complex implementation and limited adoption compared to Ethereum</td><td>Yes</td><td>Yes, through design-specific conditions</td></tr><tr><td>Solana [24]</td><td>Upgradable programs; State management</td><td>High throughput and low latency with upgradable programs</td><td>No external mechanism; Immaturity of the ecosystem and less community support for governance models</td><td>No</td><td>Yes, through upgradable programs</td></tr><tr><td>Hyperledger Fabric [25]</td><td>Chaincode lifecycle management; Endorsement policies; Private data collection; Administrative control</td><td>Permissioned blockchain with strong lifecycle management and administrative controls</td><td>Centralized nature might not align with decentralization principles</td><td>Yes</td><td>Yes, through administrative control and governance mechanisms</td></tr><tr><td>Corda [26]</td><td>Built-in contract upgrade; Explicit termination conditions; Administrative control</td><td>Focus on privacy and business transactions with upgradable contracts</td><td>Limited use cases outside of enterprise applications</td><td>Yes</td><td>Yes, through explicit contract conditions</td></tr><tr><td>IOTA [27]</td><td>State management built into the ISCP; Ability to respond to external inputs or triggers that could include termination signals</td><td>Scalable with no transaction fees suitable for IoT</td><td>Still evolving with ongoing updates to smart contract capabilities</td><td>Yes</td><td>Yes, through decentralized control mechanisms</td></tr><tr><td>Aptos [28] &#x26; Sui [29]</td><td>Move language flexibility for contract updates; Expressive smart contract implementations tracking and managing assets</td><td>Strong type system for formal verification and security; Supports more complex governance and transaction models</td><td>Newer ecosystems with less mature tooling and support</td><td>Yes</td><td>Yes, through explicit contract conditions</td></tr></tbody></table>

<figure><img src="/files/jjs0QEGFa0mAhZdq66KW" alt=""><figcaption><p>Figure 2: Comparison of Kill Switch Approaches Across Platforms</p></figcaption></figure>

#### III-A. Ethereum

In Ethereum \[21], smart contract termination and interruption are primarily managed through the built-in functionalities of the smart contracts themselves. Ethereum does not provide an external "kill switch" or mechanism for forcibly terminating or interrupting smart contracts from outside the contract's code. Instead, the implementation of such features is left to the developers who write the smart contracts, typically managed through the following mechanisms:

• Self-Destruct Function: This function (originally called SUICIDE) allows a contract to be terminated, removing its code and storage from the blockchain \[30]. When a contract is self-destructed, it sends any remaining Ether to a designated address and removes the code from the blockchain, rendering it inoperable. However, the contract's code and past transactions remain immutable and part of the blockchain history. This function is typically used to remove contracts that are no longer needed or to recover funds in an emergency. It must be explicitly included in the smart contract code and can only be triggered by a function call within the contract, often restricted to the contract owner or other authorized entities. There is a recent proposal to remove this function \[31], as it is the only opcode that breaks important invariants, causing an unbounded number of state objects to be altered in a single block. Therefore, the long-term availability of this functionality is uncertain.

• Pause and Emergency Stop Patterns: For interruption rather than complete termination, EVM-based smart contracts can be designed with pause or emergency stop functionalities \[32]. These patterns allow certain contract functions to be temporarily disabled without removing the contract from the blockchain, which can be useful when a bug is discovered and the contract needs to be paused to prevent further damage while a fix is being developed. The pause pattern typically involves setting a boolean variable that controls the execution of sensitive functions. By changing this variable's state, the contract's critical operations can be enabled or disabled. The emergency stop pattern is more comprehensive, allowing for a phased approach to pausing and resuming contract functionalities, often with different levels of access control and conditions for triggering and reversing the pause state \[33].

• Upgradeable Contracts: Another approach to managing smart contract behavior over time, including termination and interruption, is through upgradeable contracts \[34]. This design pattern involves deploying a proxy contract that delegates calls to an implementation contract containing the logic. If the implementation needs to be changed, update ed, or fixed, a new implementation contract can be deployed, and the proxy contract is updated to delegate calls to the new contract. This approach allows bugs to be fixed and functionalities to be updated without terminating the contract. However, it may introduce complexity and potential security considerations.

Other popular public permissionless blockchains, such as BNB Smart Chain (BSC) \[22], formerly known as Binance Smart Chain, is a blockchain platform that operates in parallel with Binance Chain. It offers smart contract functionality and compatibility with Ethereum's existing infrastructure, including the Ethereum Virtual Machine (EVM). This compatibility enables it to support Ethereum tools and DApps, making it a popular choice for developers seeking to leverage the scalability and performance benefits of BSC while maintaining access to Ethereum's rich ecosystem. The approach to handling smart contract termination and interruption in BNB Smart Chain closely mirrors that of Ethereum, primarily due to its EVM compatibility.

#### III-B. Cardano

Cardano \[23] employs a layered architecture that separates the settlement layer, which handles transactions, from the computational layer, where smart contracts operate. It utilizes a unique proof-of-stake consensus algorithm called Ouroboros and supports smart contracts through its native programming language, Plutus \[35]. Plutus is designed to enable the creation, execution, and management of smart contracts on the Cardano blockchain. Contracts in Plutus are written in Haskell, a functional programming language renowned for its high fault tolerance and security features. The use of Haskell significantly influences how smart contracts, including their termination and interruption, are handled in Cardano.

• Design-Driven Termination: In Cardano, the termination or interruption of a smart contract is primarily a matter of the contract's design. Plutus allows for the creation of highly deterministic and secure contracts, enabling developers to incorporate specific conditions under which a contract may terminate or pause its operations. These conditions are encoded directly into the contract's logic and can be triggered by predefined events or states.

• State-Aware Smart Contracts: Cardano's smart contracts can manage state through the blockchain ledger, but the handling of state differs from other platforms. Termination or modification of a contract could involve creating transactions that update or conclude the contract's state according to the logic defined in the contract itself, ensuring that the contract's behavior remains predictable and tamper-resistant.

• Off-Chain Interaction: Cardano also supports off-chain code execution through its application framework, allowing for complex interactions with on-chain smart contracts. Interruptions or terminations initiated by off-chain components can be designed to interact with the on-chain contracts, providing an additional layer of control for managing contract lifecycles. This off-chain logic can facilitate scenarios where user interaction or external data triggers the pause or stop conditions in the smart contract.

• Governance and Update Mechanisms: Cardano's governance model can play a role in contracts that require the ability to evolve or might need to incorporate mechanisms for interruption or termination post-deployment. Through on-chain governance mechanisms, stakeholders can propose and vote on updates or changes to smart contracts, assuming the contract is designed to be upgradable and the governance model supports such actions. This approach allows the community or stakeholders to have a say in the contract's lifecycle management.

#### III-C. Solana

Solana \[24] is a high-performance blockchain platform engineered to support scalable, decentralized applications and cryptocurrencies. It employs a unique consensus mechanism called Proof of History (PoH), combined with an underlying Proof of Stake (PoS) consensus, to achieve high throughput and low latency. Unlike Ethereum and other blockchains where smart contract termination and interruption mechanisms are more explicitly discussed and implemented, Solana's approach to smart contract management, including termination and interruption, differs due to its architecture and programming model. In Solana, smart contracts are referred to as "programs." These programs are written in Rust or C, compiled to Berkeley Packet Filter (BPF) bytecode, and deployed to the Solana blockchain. Once deployed, a program can be interacted with by sending transactions from Solana accounts, but it is immutable, meaning there is no built-in "kill switch" or termination mechanism for a Solana program once it is live on the network. However, termination-like behavior can be achieved through the following methods:

• Upgradable Programs: Solana provides a mechanism for program upgradability through the use of a "Program Upgradeable Loader" \[36], which allows developers to deploy a new version of a program to replace the old one. This process involves deploying the new program version as a separate entity and then "switching" the program authority to point to the new program. While this method doesn't terminate the old program, it effectively redirects interactions to the new, upgraded program version.

• State Management: Traditional termination or interruption of a program's operation may not directly apply to Solana's model. However, programs can manage their state through accounts that hold data. By modifying the state held in these accounts, a program can implement mechanisms to halt or modify its operations based on specific conditions, essentially allowing for a form of "interruption" of its functions.

#### III-D. Hyperledger Fabric

Hyperledger Fabric \[25] is a permissioned blockchain platform designed primarily for enterprise use. In Hyperledger Fabric, smart contracts are referred to as "chaincode." The approach to smart contract termination and interruption in Hyperledger Fabric is characterized by its lifecycle management features, endorsement policies, and the control mechanisms provided by its permissioned network structure. Collectively, these features offer a structured and governed way to manage chaincode operations, including their update, interruption, and termination, in line with the needs and policies of the enterprise blockchain network.

• Chaincode Lifecycle Management: Hyperledger Fabric introduces sophisticated lifecycle management for chaincodes \[37], allowing organizations to agree on chaincode parameters before deployment to the network. This lifecycle management process enables more granular control over the deployment, upgrade, and management of chaincode, including their termination and interruption. Hyperledger Fabric also allows upgrading the chaincode contract to a new version by deploying the new contract on the network and performing an upgrade transaction. The upgrade can introduce new logic, fix issues, or modify the chaincode's behavior. This process is controlled and requires consensus from the participating organizations, ensuring that changes are agreed upon before implementation.

• Chaincode Endorsement Policies: Hyperledger Fabric employs endorsement policies \[38] that define the rules under which a transaction is considered valid. These rules could include those that might terminate or interrupt chaincode operations. Chaincode can require that transactions be endorsed by a specific number of peers from certain organizations within the network, offering a high level of control and security over chaincode execution, including any operations that could stop or alter the chaincode's function.

• Private Data Collections: Hyperledger Fabric supports private data collections \[39], which allow a subset of the network to transact privately, maintaining confidentiality. If such a chaincode contract is updated or removed, the data governed by the policies of the private data collection remains, ensuring that sensitive information is handled according to the requirements, even if the chaincode's operation is interrupted or terminated.

• Administrative Operations: Due to the permissioned nature of Hyperledger Fabric, network administrators have more control over the chaincode contracts, including their deployment, operation, and termination. Therefore, if necessary, chaincode contracts can be administratively stopped or removed by parties with the appropriate permissions, according to the governance model of the specific Hyperledger Fabric network.

#### III-E. Corda

Corda's architecture and operational model offer unique mechanisms for managing the lifecycle of 'Corda Contracts' \[26]. Corda's design emphasizes privacy and finality in transactions, influencing how contract termination and interruptions are perceived and managed. Transactions in Corda are only shared with parties directly involved or who need to validate them. Once a transaction is finalized, it is considered immutable and authoritative, aligning with business needs for certainty and finality in agreements.

Corda handles smart contract termination and interruption through its contract upgradeability features, contract constraints governing state evolution, and explicitly modeling termination logic within contract code. Its architecture supports the management of the contract lifecycle in a way that aligns with the platform's focus on direct, private, and final transactions among business entities.

• Upgradability: Corda provides a built-in mechanism for contract upgradability, allowing network participants to evolve their contracts over time as business needs change or in response to discovering issues with the original contract. Upgrading a contract in Corda involves transitioning the states governed by an old version of the contract to a new version under the agreement of all relevant parties.

• Contract Constraints: Corda uses a concept called "contract constraints" to govern which contract codes can constrain the evolution of ledger states. These constraints ensure that once states are created under a specific contract, future transactions that consume and evolve these states are validated by the same contract code or an agreed-upon upgraded version, providing a form of governance over contract changes.

• Explicit Termination and State Evolution: Contracts can be designed to include termination logic or conditions within their clauses. Since contracts in Corda govern the transition of states, a contract can explicitly define conditions under which a state is considered final or can no longer be evolved, effectively terminating the contract's applicability to that state. Additionally, business processes can be modeled to include explicit termination transactions that move states to a final, consumed status, where they cannot be used in future transactions.

• Flow Framework: Corda's Flow Framework \[40], which facilitates the automation of transactions between nodes, can be used to manage the execution of contract termination or state evolution logic. Through flows, participants can coordinate complex processes, including those involving contract or state termination, under the rules defined by their Corda contracts.

• Administrative Intervention: In a permissioned network like Corda, network operators have administrative control over the network, including the ability to intervene in the operation of contracts and nodes in accordance with the network's governance policies. This process includes managing membership and potentially coordinating contract upgrades or the resolution of disputes related to contract execution.

#### III-F. IOTA

IOTA \[27] is a blockchain designed primarily for the Internet of Things (IoT) environment, focusing on scalability, speed, and the elimination of transaction fees. Unlike public permissionless networks like Ethereum or permissioned networks like Hyperledger Fabric, IOTA utilizes a unique data structure called the Tangle \[41], which is a form of Directed Acyclic Graph (DAG) that facilitates different operational characteristics and advantages, particularly in terms of scalability and transaction fees. IOTA introduced smart contracts as part of its ecosystem to provide more complex and conditional transaction capabilities through the IOTA Smart Contracts Protocol (ISCP).

ISCP operates on the second layer on top of the IOTA Tangle, providing the flexibility needed for complex computations and smart contracts that wouldn't be feasible directly on the Tangle due to its structure aimed at handling transactions efficiently. This adaptability ensures that ISCP can handle a wide range of smart contract scenarios, providing reassurance to developers and users alike. In ISCP, smart contracts run on their separate chains, known as "chain accounts," which are independent but anchored to the main IOTA Tangle. This design allows for greater scalability, as each smart contract can operate on its own chain without overwhelming the main network.

Smart contracts in IOTA can define their validators (known as committee nodes), who are responsible for executing the contract and reaching a consensus on its state. This design allows contract creators to tailor the security and consensus mechanisms to their needs, balancing decentralization, security, and efficiency. With ISCP, developers can program smart contracts in Rust, a language known for its safety and performance. This choice underlines the focus on creating secure and efficient smart contracts capable of supporting various applications, from DeFi to IoT.

It is worth noting that the IOTA project has undergone significant updates and expansions to its technology stack, aiming to address various challenges and expand its use cases beyond the IoT. These updates include enhancements to smart contract functionalities, interoperability features, and scalability solutions, which may influence how smart contract termination and interruption are handled in future iterations.

#### III-G. Aptos and Sui

More recent entries into the field of blockchains that utilize DAGs, such as Aptos \[28] and Sui \[29], are making notable advancements by adopting the Move programming language \[42] for their smart contract functionality. The Move language, designed with safety and security as its core principles, caters directly to the needs of financial applications and services by enabling a precise definition of custom resource types. These resources are linear types that cannot be copied or implicitly discarded, ensuring assets are tracked and managed securely throughout their lifecycle.

Move's ability to define resource types aligns well with the transactional requirements of these DAG-based blockchains, allowing for more expressive and flexible smart contract implementations compared to traditional scripting languages. This design choice not only reduces the likelihood of bugs that lead to significant vulnerabilities (such as reentrancy attacks) but also opens up possibilities for implementing more complex governance and transaction models that can adapt over time while maintaining rigorous security and integrity standards.

### IV. IV. Thesis

As demonstrated in Section III, blockchain platforms employ a variety of approaches to smart contract termination and interruption. Ethereum and BNB Smart Chain utilize smart contract-level features such as self-destruct functions and pause patterns. In contrast, platforms like Hyperledger Fabric and Corda rely more heavily on governance and administrative controls to manage contract lifecycle and termination. Cardano and Corda distinguish themselves by emphasizing design-specific conditions and explicit contract terms built into their respective smart contract languages.

This diversity in approaches leads us to our central thesis: The integration of smart contract "kill switch" mechanisms is fundamentally a balancing act between program-defined measures and governance-based solutions, with the nature of the blockchain (public, private, or consortium) and its consensus mechanisms playing crutial roles in determining the feasibility and implementation of these features.

We argue that:

1. Public blockchains face greater challenges in implementing "kill switches" due to their need for broader consensus, potentially complicating rapid deployment of termination mechanisms.
2. Private and consortium blockchains can more readily implement "kill switch" features due to their centralized governance structures, but this ease of implementation may come at the cost of true decentralization.
3. The incorporation of "kill switches" into smart contracts has far-reaching implications for the blockchain ecosystem, particularly in terms of: <br>

   a) Decentralization: "Kill switches" present a paradox, offering necessary safety measures while potentially undermining the core principle of decentralization. \
   \
   b) Asset security: The risk of asset loss due to "kill switch" activation necessitates robust safeguards and recovery mechanisms. \
   \
   c) Security considerations: The implementation of "kill switches" introduces new attack vectors that must be carefully managed.
4. A hybrid model, balancing decentralized governance with regulatory compliance, is likely necessary for the successful and widely accepted implementation of smart contract "kill switches."

This thesis challenges us to innovate solutions that preserve the core values of decentralization and immutability while providing necessary safeguards and flexibility to meet regulatory requirements and ensure user protection.

<figure><img src="/files/m8UeB02tamNFuIbVSnGt" alt=""><figcaption><p>Figure 3: Balancing Factors in Kill Switch Implementation</p></figcaption></figure>

### V. Conclusion

This study has explored the feasibility and implications of implementing smart contract "kill switch" mechanisms within the framework of blockchain technology, considering the requirements set forth by the European Union's Data Act legislation \[3]. Our findings contribute to the ongoing discourse on regulating blockchain technology, offering insights into how current blockchain platforms can adapt to meet legislative requirements without stifling innovation while remaining accessible and comprehensible to non-technical users. The debate surrounding smart contract "kill switches" is multifaceted, reflecting a convergence of academic, legislative, and industry perspectives.

The challenge lies in designing "kill switch" mechanisms that align as closely as possible with the ethos of decentralization, potentially through decentralized governance models or community consensus mechanisms. We posit that a hybrid model, where decentralized platforms can interface with regulatory frameworks without compromising their decentralized nature, is necessary for the successful implementation of smart contract "kill switches." The adoption of "kill switches" in smart contracts within the blockchain ecosystem demands careful consideration of their impacts on decentralization, asset security, and the broader trust in blockchain technologies. By addressing these concerns thoughtfully, it's possible to design systems that retain the benefits of decentralization while providing mechanisms to protect users and the integrity of the network. This process involves striking a delicate balance between control and freedom, requiring ongoing dialogue and innovation within the community to navigate these complex issues effectively.

<figure><img src="/files/lCNhYGrlI5LZ0gmAHfWV" alt=""><figcaption><p>Figure 4: Implications of Kill Switch Mechanisms</p></figcaption></figure>

Future research could explore the design, implementation, and effectiveness of decentralized governance models specifically tailored to manage smart contract "kill switch" mechanisms. Investigating automated mechanisms within smart contracts that dynamically adjust to changing regulatory requirements without manual intervention could be a significant area for exploration, particularly for already deployed smart contracts. It may be necessary to consider protocol updates through hard forks or the governance models of various blockchain projects that allow for changes to be made to operational parameters. A more in-depth analysis of how "kill switch" mechanisms affect the security, trust, and overall perception of blockchain networks among users before and after implementing "kill switches," along with security vulnerability assessments related to their deployment, would provide insights into the long-term viability of smart contract termination solutions.

Additionally, with the increasing diversity of blockchain platforms, there is a growing need to focus on developing cross-chain solutions and interoperability standards that facilitate regulatory compliance across different blockchains. Future research is likely to delve deeper into these discussions, proposing frameworks, models, and real-world trials that balance the autonomy of smart contracts with the safety, security, and compliance requirements of the broader ecosystem.

The implementation of smart contract "kill switches" represents a critical juncture in the evolution of blockchain technology. It embodies the tension between the original vision of decentralized, immutable systems and the practical necessities of governance, risk management, and regulatory compliance. As the blockchain industry continues to mature and integrate more deeply with traditional financial and legal structures, finding a harmonious balance between these competing priorities will be essential.

Future research directions might include:

1. Developing and testing decentralized governance models specifically designed for managing "kill switch" mechanisms, ensuring that the power to terminate contracts is distributed and subject to consensus.
2. Exploring the use of artificial intelligence and machine learning in creating adaptive smart contracts that can self-regulate and potentially self-terminate based on predefined conditions, reducing the need for external intervention.
3. Investigating the psychological and economic impacts of "kill switch" mechanisms on user trust and platform adoption rates in various blockchain ecosystems.
4. Designing and implementing cross-chain "kill switch" protocols that can function across multiple blockchain platforms, addressing the growing need for interoperability in the blockchain space.
5. Analyzing the legal and ethical implications of smart contract termination, particularly in cases where multiple jurisdictions are involved.
6. Developing standardized audit processes and certification frameworks for smart contracts with "kill switch" functionalities to ensure their reliability and security.

In conclusion, the integration of "kill switch" mechanisms in smart contracts represents both a challenge and an opportunity for the blockchain industry. While it introduces complexities and potential vulnerabilities, it also paves the way for broader adoption and regulatory acceptance of blockchain technology. The key to success will lie in developing solutions that preserve the core values of decentralization and immutability while providing necessary safeguards and flexibility. As the technology evolves, so too must our approaches to governance, security, and compliance in the blockchain space.

By continuing to explore and refine these concepts, Veritas Protocol can work towards creating more robust, adaptable, and trustworthy systems that can meet the needs of a wide range of stakeholders, from individual users to large institutions and regulatory bodies. The future of smart contracts and blockchain technology will likely be shaped by our ability to navigate these complex issues and find innovative solutions that serve the diverse needs of an increasingly interconnected digital world.

***

<details>

<summary>References </summary>

\[1] J. Chen, X. Xia, D. Lo, J. Grundy, X. Luo, and T. Chen, "Defining smart contract defects on ethereum," IEEE Transactions on Software Engineering, vol. 48, no. 1, pp. 327–345, 2020.

\[2] D. Perez and B. Livshits, "Smart contract vulnerabilities: Vulnerable does not imply exploited," in 30th USENIX Security Symposium (USENIX Security 21), pp. 1325–1341, 2021.

\[3] European Parliament and Council of the European Union, "Regulation (EU) 2023/2854 of the European Parliament and of the Council of 5 October 2023 on harmonised rules on fair access to and use of data (Data Act)." <https://eur-lex.europa.eu/eli/reg/2023/2854/oj>, 2023. Accessed: Mar 04, 2024.

\[4] P. De Filippi and S. Hassan, "Blockchain technology as a regulatory technology: From code is law to law is code," arXiv preprint arXiv:1801.02507, 2018.

\[5] V. Dhillon, D. Metcalf, M. Hooper, V. Dhillon, D. Metcalf, and M. Hooper, "The dao hacked," blockchain enabled applications: Understand the blockchain Ecosystem and How to Make it work for you, pp. 67–78, 2017.

\[6] O. Meyer, "Stopping the unstoppable: Termination and unwinding of smart contracts," J. Eur. Consumer & Mkt. L., vol. 9, p. 17, 2020.

\[7] D. Li, D. Han, T.-H. Weng, Z. Zheng, H. Li, and K.-C. Li, "On stablecoin: Ecosystem, architecture, mechanism and applicability as payment method," Computer Standards & Interfaces, vol. 87, p. 103747, 2024.

\[8] M. Shukla, J. Lin, and O. Seneviratne, "BlockIoT: Blockchain-based health data integration using IoT devices," in AMIA Annual Symposium Proceedings, vol. 2021, p. 1119, American Medical Informatics Association, 2021.

\[9] M. Shukla, J. Lin, and O. Seneviratne, "Blockiot-retel: Blockchain and iot based read-execute-transact-erase-loop environment for integrating personal health data," in 2021 IEEE International Conference on Blockchain (Blockchain), pp. 237–243, IEEE, 2021.

\[10] M. Li, L. Xia, and O. Seneviratne, "Leveraging standards based ontological concepts in distributed ledgers: a healthcare smart contract example," in 2019 IEEE International Conference on Decentralized Applications and Infrastructures (DAPPCON), pp. 152–157, IEEE, 2019.

\[11] J. Grey, I. Godage, and O. Seneviratne, "Swarm contracts: Smart contracts in robotic swarms with varying agent behavior," in 2020 IEEE International Conference on Blockchain (Blockchain), pp. 265–272, IEEE, 2020.

\[12] S. Mallikarachchi, C. Dai, O. Seneviratne, and I. Godage, "Managing collaborative tasks within heterogeneous robotic swarms using swarm contracts," in 2022 IEEE International Conference on Decentralized Applications and Infrastructures (DAPPS), pp. 48–55, IEEE, 2022.

\[13] F. Casolari, M. Taddeo, A. Turillazzi, and L. Floridi, "How to improve smart contracts in the european union data act," Digital Society, vol. 2, no. 1, p. 9, 2023.

\[14] L. Olivieri, L. Pasetto, et al., "Towards compliance of smart contracts with the european union data act," in CEUR WORKSHOP PROCEEDINGS, vol. 3629, pp. 7–11, CEUR-WS, 2023.

\[15] T. C. Le, L. Xu, L. Chen, and W. Shi, "Proving conditional termination for smart contracts," in Proceedings of the 2nd ACM Workshop on Blockchains, Cryptocurrencies, and Contracts, pp. 57–59, 2018.

\[16] T. Genet, T. Jensen, and J. Sauvage, Termination of Ethereum's smart contracts. PhD thesis, Univ Rennes, Inria, CNRS, IRISA, 2020.

\[17] S. Liu, F. Mohsin, L. Xia, and O. Seneviratne, "Strengthening Smart Contracts To Handle Unexpected Situations," in 2019 IEEE International Conference on Decentralized Applications and Infrastructures (DAPPCON), pp. 182–187, IEEE, 2019.

\[18] Y. Zhu, L. Xia, and O. Seneviratne, "A Proposal for Account Recovery in Decentralized Applications," in 2019 IEEE International Conference on Blockchain (Blockchain), pp. 148–155, IEEE, 2019.

\[19] F. Mohsin, X. Zhao, Z. Hong, G. de Mel, L. Xia, and O. Seneviratne, "Ontology aided smart contract execution for unexpected situations," in BlockSW/CKG@ ISWC, 2019.

\[20] B. Marino and A. Juels, "Setting standards for altering and undoing smart contracts," in Rule Technologies. Research, Tools, and Applications: 10th International Symposium, RuleML 2016, Stony Brook, NY, USA, July 6-9, 2016. Proceedings 10, pp. 151–166, Springer, 2016.

\[21] V. Buterin et al., "Ethereum white paper," GitHub repository, vol. 1, pp. 22–23, 2013.

\[22] Binance, "Bnb chain whitepaper." <https://github.com/bnb-chain/whitepaper/blob/master/WHITEPAPER.md>, 2022.

\[23] C. Hoskinson, "Why we are building Cardano? A subjective approach." <https://whitepaper.io/document/581/cardano-whitepaper>, 2017.

\[24] A. Yakovenko, "Solana: A new architecture for a high performance blockchain v0. 8.13," Whitepaper, 2018.

\[25] E. Androulaki, A. Barger, V. Bortnikov, C. Cachin, K. Christidis, A. De Caro, D. Enyeart, C. Ferris, G. Laventman, Y. Manevich, et al., "Hyperledger fabric: a distributed operating system for permissioned blockchains," in Proceedings of the thirteenth EuroSys conference, pp. 1–15, 2018.

\[26] R. G. Brown, J. Carlyle, I. Grigg, and M. Hearn, "Corda: an introduction," R3 CEV, August, vol. 1, no. 15, p. 14, 2016.

\[27] O. Saa, A. Cullen, and L. Vigneri, "IOTA 2.0 Incentives and Tokenomics Whitepaper," 2023.

\[28] Aptos Foundation, "Aptos blockchain whitepaper." <https://aptosfoundation.org/whitepaper/aptos-whitepaper\\_en.pdf>, 2022.

\[29] Mysten Labs, "Sui: Simplifying blockchain for a multiverse future." <https://docs.sui.io/paper/sui.pdf>, 2023.

\[30] J. Chen, X. Xia, D. Lo, and J. Grundy, "Why do smart contracts self-destruct? investigating the selfdestruct function on ethereum," ACM Transactions on Software Engineering and Methodology (TOSEM), vol. 31, no. 2, pp. 1–37, 2021.

\[31] V. Buterin, "A note on selfdestruct." <https://hackmd.io/@vbuterin/selfdestruct>, 2024.

\[32] "Pausing smart contracts." <https://ethereum-blockchain-developer.com/022-pausing-destroying-smart-contracts/03-pausing-smart-contracts/>, 2024.

\[33] Fravoll, "Emergency stop." <https://fravoll.github.io/solidity-patterns/emergency\\_stop.html>, 2021.

\[34] M. Salehi, J. Clark, and M. Mannan, "Not so immutable: Upgradeability of smart contracts on ethereum," arXiv preprint arXiv:2206.00716, 2022.

\[35] Cardano, "Plutus." <https://developers.cardano.org/docs/smart-contracts/plutus>, 2023.

\[36] Solana, "Module solana program bpf loader upgradeable." <https://docs.rs/solana-program/latest/solana\\_program/bpf\\_loader\\_upgradeable/index.html>, 2023.

\[37] H. Fabric, "Fabric chaincode lifecycle." <https://hyperledger-fabric.readthedocs.io/en/release-2.2/chaincode\\_lifecycle.html>, 2024.

\[38] H. Fabric, "Fabric Endorsement Policies." <https://hyperledger-fabric.readthedocs.io/en/release-2.2/endorsement-policies.html>, 2024.

\[39] H. Fabric, "Fabric Private Data Collections." <https://hyperledger-fabric.readthedocs.io/en/latest/private-data/private-data.html>, 2024.

\[40] Corda, "Flows." <https://docs.r3.com/en/platform/corda/4.9/enterprise/cordapps/api-flows.html>, 2024.

\[41] S. Popov, "The tangle," White paper, vol. 1, no. 3, p. 30, 2018.

\[42] S. Blackshear, E. Cheng, D. L. Dill, V. Gao, B. Maurer, T. Nowacki, A. Pott, S. Qadeer, D. R. Rain, S. Sezer, et al., "Move: A language with programmable resources," Libra Assoc, p. 1, 2019.

\[43] F. Rodrigues, "Blockchain devs expect complications from EU smart contract kill switch," Nov 2023. Accessed: Mar 4, 2024.

</details>


# WHY AI?

From Training to Hacking - A Powerful Shift, Responsibly Managed

The fusion of AI with cybersecurity represents a significant step towards more robust digital defenses. By leveraging AI's capabilities, cybersecurity operations can achieve greater effectiveness in threat detection, vulnerability analysis and incident response.

<figure><img src="/files/49UvQkx03wu75Ebt0kcr" alt=""><figcaption></figcaption></figure>

* **AI's Role in Cybersecurity**: AI transforms cybersecurity by improving threat detection, vulnerability analysis, and incident response through machine learning (ML) and natural language processing (NLP).
* **Threat Detection Advancements:** AI methods exceed traditional detection approaches by analyzing large datasets, identifying subtle anomalies, and providing real-time threat identification with fewer errors.
* **Vulnerability Analysis Improvements**: AI enables automated vulnerability scanning and prioritizes threats based on severity and potential impact, addressing the limitations of traditional methods in scale and accuracy.
* **Faster Incident Response:** AI automation reduces response times, minimizes errors, and adapts to new cybersecurity threats through continuous learning.

<figure><img src="/files/qS1B2LDPERdwn94BrXaV" alt=""><figcaption></figcaption></figure>

### AI Protection for Web3 and Cryptocurrency

AI strengthens security in Web3 and cryptocurrency through several key functions:

* **Threat Detection and Response:** AI identifies and responds to threats by analyzing network traffic and user behavior to detect anomalies in cryptocurrency transactions and Web3 interactions. Models trained on cyber threats can recognize phishing attempts, wallet attacks, and unauthorized blockchain activities.
* **Vulnerability Management:** AI scans Web3 infrastructure and cryptocurrency applications to find security weaknesses. These scanners prioritize vulnerabilities based on risk factors, which helps prevent financial losses by identifying exploitable weaknesses in smart contracts and distributed ledger technologies.
* **Rapid Incident Response:** AI automation speeds up incident response for Web3 and crypto assets where transaction speed matters. This prevents attacks from spreading across networks and protects digital assets and blockchain trust.
* **Predictive Analytics:** AI examines past attack data to forecast and counter future threats. This helps anticipate attack methods and implement preventive measures to protect assets and infrastructure.
* **Anomaly Detection:** Machine learning identifies deviations from normal patterns in network traffic and system logs, which helps monitor Web3 applications and crypto networks. This can identify unusual transaction patterns that may indicate fraud or compromised wallets.
* **Behavioral Analysis:** AI tracks user activities across systems to detect insider threats, credential misuse, and unauthorized access attempts—critical concerns for cryptocurrency and decentralized Web3 platforms.

### **Privacy Preservation and Ethical Considerations**

While leveraging AI for cybersecurity, it's important to address privacy and ethical implications, especially considering the decentralized and often anonymous nature of web3 and crypto activities. Ensuring data anonymization, implementing privacy-first technologies, and maintaining transparency and fairness are critical to sustaining trust and security in the ecosystem.

### **Sum Sum**

AI offers advanced capabilities to detect, analyze, and respond to cybersecurity threats, which is vital for Web3 and cryptocurrency security. As these technologies develop, AI will play a larger role in protecting digital assets, requiring ongoing research and ethical considerations.


# MANUAL AUDITS

Some of the recent manual audits

{% file src="/files/1rlBDZSyysNfL4KI9eLj" %}


# GUIDES


# A Guide on What to do After Your Funds Have Been Stolen

### Background

In the swiftly evolving cryptocurrency landscape, the allure of rapid innovation and the potential for significant financial gain coexist with the omnipresent risk of cyber threats. The inherent anonymity and complex technology of digital currencies render them susceptible to exploitation by hackers and scammers, leaving victims in a state of vulnerability, grappling with both financial loss and emotional distress. This guide seeks to shed light on the recovery path, offering structured advice while spotlighting the crucial role Veritas Protocol plays in guiding victims through these challenging times.

### Stay Calm and Methodically Assess

The initial shock of discovering a breach can instinctively trigger panic. It's imperative, however, to maintain composure. Scammers often prey on this vulnerability, offering false promises of recuperating losses. Scammers exploit such moments of weakness - Beware of scammers posing as recovery agents. A calm and collected approach allows for a clearer assessment of the breach. Identifying precisely what's been compromised — be it private keys, funds from an exchange, only certain tokens or sensitive personal information — is the first step toward mitigating the impact. Documenting every detail and retracing steps to understand how the breach occurred is essential, laying the groundwork for preventing similar incidents in the future.

### Secure Remaining Assets

Immediate action is required to safeguard any assets still within your control. If there's a suspicion that your private keys have been exposed, swiftly move your assets to a new wallet with uncompromised security. Please for the love of god, if you think your wallet is compromised, DO NOT continue to use it. For those with hacked exchange accounts, it's crucial to update passwords, activate two-factor authentication, and notify the platform's customer support promptly to prevent further unauthorized access.

### The Reporting Process

#### Engaging with Platforms and Authorities:

Immediate communication with the affected platform can initiate the recovery process, while reporting the incident to local law enforcement and relevant financial or cybercrime agencies solidifies the formal response. The specificity of attention to digital crimes can vary by region, underscoring the importance of making these reports.

### Veritas Protocol Investigations — A Beacon of Hope

At Veritas Protocol, we work with teams specialized in the recovery of assets lost to crypto scams and hacks. Through direct engagement strategies and a comprehensive network of exchanges, Veritas Protocol aims to halt and reverse the flow of stolen assets. Offering a complimentary consultation for all affected parties, Veritas Protocol provides tailored advice and outlines potential recovery strategies, demonstrating a commitment to victim support. You can submit a request here for a free consultation and one of our investigators will reach out promptly.

### In-Depth with Veritas Protocol Investigations

All investigation process can be broken down into two crucial steps:

#### Tracking:

At Veritas Protocol, our approach begins with an initial focus on identifying the funding source and establishing a means of contact with the scammer or hacker. Our next step involves attempting to communicate directly with the perpetrator. If these efforts do not yield results, we shift our strategy towards tracing the funds across the blockchain. Upon observing any transfer of funds to an exchange, we utilize our broad network of exchanges and projects to advocate for a freeze on the transactions in question. It is critical to acknowledge that the cooperation we receive from each exchange is governed by its specific policies on information sharing and fund freezing. The spectrum of responses we encounter ranges from full support to situations where direct intervention by law enforcement is necessary. This brings us to our next step, law enforcement involvement.

#### Law Enforcement Involvement:

A critical component of our investigations is the involvement of law enforcement. While we can facilitate the freezing of funds, their release is strictly to law enforcement authorities. Recognizing that not all law enforcement agencies are versed in blockchain investigations, we offer guidance and support in this area, contingent on their willingness to collaborate.

For victims, the initial step should always be to report the incident to their local law enforcement or a cybercrime agency. This is because our ability to intervene is significantly enhanced by their involvement.

### Major RED Flags

* Any agency or person that can guarantee returns without law enforcement should be taken with extreme skepticism
* At any point they request your private key, see our report here: "Double Deception: Beware of Scammers Posing as Recovery Agents."
* Any agency or person that can guarantee 100% returns

### Strengthening Your Digital Defenses

In the wake of a security breach, reinforcing your digital defenses is non-negotiable. [The Dark Forest Manual Guide](https://app.gitbook.com/o/gCIP1Bd3P4IkbQXhQhLY/s/UFhgIP5fPj0D5R0MmvSp/~/changes/68/research/the-dark-forest-manual-guide), written by Veritas Protocol, serves as an invaluable resource, offering comprehensive insights into the best practices for securing digital assets against future threats.

### Maintaining Vigilance

Consistent monitoring of your accounts, coupled with the establishment of transaction alerts, can serve as a critical line of defense, enabling swift action in the event of any unauthorized access or suspicious activity.

### Conclusion: Emerging Stronger

The journey through the aftermath of a crypto hack or scam is undeniably daunting. Yet, it is not insurmountable. By taking informed and decisive steps towards recovery, engaging with platforms and authorities, and leveraging the support of entities like Veritas Protocol, victims can navigate their way out of these dire circumstances. Armed with security measures and a deeper understanding of the crypto environment, individuals are better prepared to face the challenges of the digital age. The path forward is fraught with challenges, but equipped with the right knowledge and tools, the vast opportunities of the cryptocurrency world remain accessible and promising.


# Security Audit Checklist for Account Abstraction Wallets

A baseline checklist for auditing account abstraction wallets implemented based on the EIP4337 standard

### Introduction

This guide provides auditors with a fundamental checklist for reviewing account abstraction wallets based on the EIP4337 standard, along with targeted auditing guidelines. It assumes auditors are familiar with the [EIP4337 Account Abstraction Standard](https://eips.ethereum.org/EIPS/eip-4337) and the [EIP7562 Account Abstraction Validation Scope Rules Standard.](https://eips.ethereum.org/EIPS/eip-7562) We'll briefly cover the EIP4337 architecture and wallet transaction execution flow.

### Architecture

#### Transaction Execution

In EIP4337, an EOA signs [UserOperation](https://eips.ethereum.org/EIPS/eip-4337#useroperation) data and submits it to a separate [Alt Mempool](https://eips.ethereum.org/EIPS/eip-4337#alternative-mempools) via RPC. This mempool, distinct from Ethereum's, aggregates user-submitted UserOp data. The Bundler extracts and simulates UserOps [locally ](https://eips.ethereum.org/EIPS/eip-4337#simulation)before execution, discarding failed simulations. All UserOp executions occur through the Bundler calling the EntryPoint contract. After verification, [EntryPoint ](https://eips.ethereum.org/EIPS/eip-4337#entrypoint-definition)calls the user's AA wallet to execute the user's calldata. Users pay the Bundler for on-chain execution fees or specify a [Paymaster ](https://eips.ethereum.org/EIPS/eip-4337#extension-paymasters)to cover costs.

<figure><img src="/files/ZvJwqcPzlJl710Zgl5zw" alt=""><figcaption></figcaption></figure>

#### Execution Details

Auditors should understand the process of the Bundler calling the user's wallet via EntryPoint:

* Detailed flow chart: [4337 Execution Details](https://www.figma.com/board/BdfLFkbZkh8vQlsANfojbL/4337-Execution-Details_EN?node-id=0-1\&t=KB21kmnkI4r4X0vY-1)

<figure><img src="/files/eHKxsnGsXQeUB3IItMpw" alt=""><figcaption></figcaption></figure>

### Checklist

The following checklist items ensure each 4337 wallet passes crucial security checks:

1. Verify Compatibility with All EVM-Compatible Chains

AA wallets may deploy on various chains. Post-Shanghai Ethereum mainnet introduced PUSH0 bytecode, affecting Solidity versions [0.8.20+](https://soliditylang.org/blog/2023/05/10/solidity-0.8.20-release-announcement/). Auditors should check the Solidity version or compiled files for PUSH0 bytecode. For multi-chain deployment, use a compiler version below 0.8.20 or specify the paris compilation version.

```solidity
solidityCopysolc = "0.8.19"
evm_version = "paris"
```

2. Ensure Interface Implementation and Return Values Comply with EIP4337

Wallets must implement core interfaces with specific return value structures. Paymasters must also implement required interfaces. Signature validation should return appropriate values or revert as specified.

3. Verify Trusted Wallet Callers

[EIP4337 ](https://eips.ethereum.org/EIPS/eip-4337#account-contract-interface)interfaces should only allow trusted EntryPoint calls to prevent unauthorized wallet use.

Example Code:

```solidity
solidityCopyfunction entryPoint() public view virtual override returns (IEntryPoint) {
   return _entryPoint;
}

function execute(address dest, uint256 value, bytes calldata func) external {
    _requireFromEntryPointOrOwner();
    _call(dest, value, func);
}

function executeBatch(address[] calldata dest, uint256[] calldata value, bytes[] calldata func) external {
    _requireFromEntryPointOrOwner();
    ...
}
```

4. Check Fee Payment Implementation

Wallets should implement logic to transfer missingAccountFunds to the EntryPoint contract when necessary.

Example Code:

```solidity
solidityCopyfunction validateUserOp(
    PackedUserOperation calldata userOp,
    bytes32 userOpHash,
    uint256 missingAccountFunds
) external virtual override returns (uint256 validationData) {
    ...
    _payPrefund(missingAccountFunds);
}
```

5. Verify Wallet Creation Method

Factories must use CREATE2 for deterministic wallet creation addresses.

Example Code:

```solidity
solidityCopyfunction createAccount(address owner,uint256 salt) public returns (SimpleAccount ret) {
    address addr = getAddress(owner, salt);
    uint256 codeSize = addr.code.length;
    if (codeSize > 0) {
        return SimpleAccount(payable(addr));
    }
    ret = SimpleAccount(payable(new ERC1967Proxy{salt : bytes32(salt)}(
            address(accountImplementation),
            abi.encodeCall(SimpleAccount.initialize, (owner))
        )));
}
```

6. Check Return Value for Repeated Wallet Creation

Ensure consistent address returns for already-created wallets.

Example Code:

```solidity
solidityCopyfunction createAccount(address owner,uint256 salt) public returns (SimpleAccount ret) {
    address addr = getAddress(owner, salt);
    uint256 codeSize = addr.code.length;
    if (codeSize > 0) {
        return SimpleAccount(payable(addr));
    }
    ...
}
```

7. Prevent Wallet Takeover During Creation

Verify that wallet creation cannot be front-run and that ownership is correctly set.

[Example of Incorrect Code:](https://code4rena.com/reports/2023-01-biconomy#h-03-attacker-can-gain-control-of-counterfactual-wallet) (entryPoint not involved in address calculation, can be takeover and modified to a malicious entryPoint)

```
function deployCounterFactualWallet(address _owner, address _entryPoint, address _handler, uint _index) public returns(address proxy){
    bytes32 salt = keccak256(abi.encodePacked(_owner, address(uint160(_index))));
    bytes memory deploymentData = abi.encodePacked(type(Proxy).creationCode, uint(uint160(_defaultImpl)));
    // solhint-disable-next-line no-inline-assembly
    assembly {
        proxy := create2(0x0, add(0x20, deploymentData), mload(deploymentData), salt)
    }
    require(address(proxy) != address(0), "Create2 call failed");
    // EOA + Version tracking
    emit SmartAccountCreated(proxy,_defaultImpl,_owner, VERSION, _index);
    BaseSmartAccount(proxy).init(_owner, _entryPoint, _handler);
    isAccountExist[proxy] = true;
}
```

8. Validate Signature Verification

Ensure rigorous signature validation in validateUserOp/validatePaymasterUserOp.

Example Code:

```solidity
solidityCopyfunction validateUserOp(
    PackedUserOperation calldata userOp,
    bytes32 userOpHash,
    uint256 missingAccountFunds
) external virtual override returns (uint256 validationData) {
    _requireFromEntryPoint();
    validationData = _validateSignature(userOp, userOpHash);
    _validateNonce(userOp.nonce);
    _payPrefund(missingAccountFunds);
}
```

9. Verify Correct ERC1271 Implementation

Check ERC1271 standard compliance and signature verification logic security.

Example Code:

```solidity
solidityCopyfunction isValidSignature(bytes32 _dataHash, bytes calldata _signature) public view override returns (bytes4) {
    // Caller should be a Safe
    ISafe safe = ISafe(payable(msg.sender));
    bytes memory messageData = encodeMessageDataForSafe(safe, abi.encode(_dataHash));
    bytes32 messageHash = keccak256(messageData);
    if (_signature.length == 0) {
        require(safe.signedMessages(messageHash) != 0, "Hash not approved");
    } else {
        safe.checkSignatures(messageHash, _signature);
    }
    return EIP1271_MAGIC_VALUE;
}
```

10. Prevent Permanent Locking of Staked Tokens

Ensure staking logic doesn't allow permanent token locking.

Example Code:

```solidity
solidityCopyfunction addStake(uint32 unstakeDelaySec) external payable onlyOwner {
    entryPoint.addStake{value: msg.value}(unstakeDelaySec);
}
```

11. Restrict Non-EntryPoint Transaction Execution

Verify that wallets implement proper permission checks for non-EntryPoint executions.

Example Code:

```solidity
solidityCopy    function execute(address dest, uint256 value, bytes calldata func) external {
        _requireFromEntryPointOrOwner();
        _call(dest, value, func);
    }
```

12. Limit Wallet Storage Access

Ensure wallets only access storage fields associated with the sender.

13. Verify Paymaster's Failure Handling Logic

Check that Paymasters correctly handle fees in case of execution failures.

14. Ensure Secure Implementation of Modular Wallets

Verify safe management of wallet modules and secure data storage when using DELEGATECALL.

### Conclusion

This checklist provides a foundation for auditing account abstraction wallets based on the current EIP4337 standard. Given the early stages of EIP4337 implementation and varying wallet designs, auditors should conduct thorough checks based on specific wallet implementations.&#x20;


# Upgrade to Public Blockchain Security Audit Guide

As blockchain technology becomes more widespread, more users are conducting transactions on Layer1. This has led to noticeable issues such as slower transaction speeds and higher transaction fees on Layer1. In response, Layer2 has emerged as a solution to enhance the scalability and performance of blockchain platforms without compromising the security and decentralization characteristics of Layer1.&#x20;

Over the years, the Veritas Protocol security team has accumulated extensive experience in mainnet security audits and advanced vulnerability detection techniques. We have openly shared our mainnet security audit methods with the industry, aiming to collaboratively build a safer blockchain ecosystem.

Security is an ongoing process, and audit methodologies must evolve to meet the industry's needs. Our security team continuously monitors industry trends, identifies prevalent security issues within the blockchain ecosystem, and understands user security requirements. This knowledge forms the basis for developing and optimizing security audit schemes. Recently, the Veritas Protocol security team has updated the public blockchain security audit guide to reflect current developments in Layer1 and Layer2. The specific details of the updated security audit scheme are as follows:

### Scheme 1: Mainnet & layer2 project security audits

In the Mainnet & Layer2 project security audit, the Veritas Protocol security team employs a "black box + gray box" strategy to conduct rapid security testing in a manner that closely simulates real attacks. The vulnerabilities we check include:

* Insufficient entropy of private key random numbers
* Precision loss in private key seed conversion
* Theoretical reliability assessment of symmetric encryption algorithms
* Supply chain security of symmetric crypto algorithm reference libraries
* Keystore encryption strength detection
* Hash algorithm length extension attack
* Theoretical reliability assessment of hash algorithms
* Theoretical reliability assessment of signature algorithms
* secp256k1 k-value randomness security
* secp256k1 r-value reuse private key extraction attack
* ECC signature malleability attack
* ed25519 private key extraction attack
* Schnorr private key extraction attack
* ECC twist attack
* Merkle-tree Malleability attack (CVE-2012–2459)
* Native characteristic false recharge
* Contract call-based false recharge
* Native chain transaction replay attack
* Cross-chain transaction replay attack
* Transaction lock attack
* Transaction fees not dynamically adjusted
* RPC remote key theft attack
* RPC port identifiability
* RPC open cross-domain vulnerability to local phishing attacks
* JsonRPC malformed packet denial-of-service attack
* RPC database injection
* RPC communication encryption
* Excessive administrator privileges
* Non-privacy/Non-dark Coin Audit
* Insufficient number of core nodes
* Excessive concentration of core node physical locations
* P2P node maximum connection limit
* P2P node independent IP connection limit
* P2P inbound/outbound connection limit
* P2P shapeshift attack
* P2P communication encryption
* P2P port identifiability
* Consensus algorithm potential risk assessment
* Block time offset attack
* Miner grinding attack
* PoS/BFT double-signing penalty

### Scheme 2: Code-based Testing Audit

The source code security audit adopts a "white box" strategy, conducting the most comprehensive security testing on the project's relevant source code. White box auditing typically combines automated static code analysis with manual analysis.

#### Static Source Code Analysis

The Veritas Protocol team utilizes open-source or commercial code scanning tools for static code analysis and manually examines the identified issues. We support all popular languages, including C/C++/Golang/Rust/Java/Nodejs/C#.

The static coding issues checked by the Veritas Protocol team include:

* Unused Variables or Imports
* Code Formatting Issues
* Improper Resource Closure
* Magic Numbers
* Potential Security Vulnerabilities
* Integer Overflow
* Floating-Point Precision Issues
* Deadlocks
* Race Conditions
* Memory Leaks
* Infinite Recursion
* String Formatting Vulnerabilities
* Divide-by-Zero Errors
* Null Pointer Dereferencing
* Buffer Overflow
* Type Conversion Errors
* Hard-Coded Keys or Sensitive Information
* High Code Complexity
* Code Duplication
* Inconsistent Naming
* Insufficient or Outdated Comments
* High Coupling
* Low Cohesion
* Improper Exception Handling
* Hard-Coding
* Inconsistent Code Formatting
* Performance Issues
* Poor Testability
* Violation of Design Principles
* Poor Readability
* Insecure Random Number Generation
* Time and State Issues
* Path Traversal
* Outdated Dependencies

#### Manual Code Review

The Veritas Protocol team performs a line-by-line code review to identify coding flaws and logical errors. The vulnerabilities we focus on mainly include:

* Cryptographic signature security
* Account and transaction security
* RPC security
* P2P security
* Consensus security
* Business logic security

### Scheme 3: Application Chain Security Audit

The Veritas Protocol team adopts the strategy of "White-box" to conduct a complete security test on the project, looking for common coding pitfalls as follows:

* Replay Vulnerability
* Reordering Vulnerability
* Race Conditions Vulnerability
* Authority Control Vulnerability
* Block data Dependence Vulnerability
* Explicit Visibility of Functions
* Arithmetic Accuracy Deviation Vulnerability
* Malicious Event Log
* Asynchronous Call Security

Currently we support:

* Cosmos-SDK Framework Based Blockchain Audit
* Substrate Framework Based Blockchain Audit


# Security Guide for Securing X (Twitter) Account

## Background Overview

Recently, there have been frequent incidents where Web3 project owners or celebrities' X accounts have been hacked and used to send phishing tweets. Hackers often use various methods to steal user accounts, with some common tactics including:

1. Tricking users into clicking on fake Calendly/Kakao meeting links to steal account authorization or control their devices.
2. Sending direct messages to lure users into downloading Trojan-infected programs (disguised as games, meeting apps, etc.), which can steal private keys/mnemonics and X account permissions.
3. Using SIM Swap attacks to steal X account permissions that rely on phone numbers.

Given the frequent occurrences of such incidents, many users are unaware of how to enhance the security of their X accounts. The Veritas Protocol Security Team will explain how to conduct authorization checks and security settings for X accounts. Here are the specific steps:

## Authorization Check

We use the web version as an example. After opening the x.com page, click on the "More" sidebar and find the "Settings and privacy" option, which is mainly used for setting account security and privacy.

<figure><img src="/files/RR5swUw0PQjfo8M2YqOg" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/rT7inZlmNmxsQCAqAOXz" alt=""><figcaption></figcaption></figure>

After entering the "Settings" section, select "Security and account access" to set the security and access permissions for the account.

<figure><img src="/files/loq27VyU22HTGQbCUHao" alt=""><figcaption></figcaption></figure>

### Review Authorized Applications

Many phishing methods involve tricking users into clicking on application authorization links, which can result in granting tweet posting permissions to the X account, leading to the account being used for phishing.

Check method: Select the "Apps and sessions" section to see which applications the account has authorized, as shown below, the demonstration account has authorized these three applications.

<figure><img src="/files/4sIUqvBSodsBKRXEfky4" alt=""><figcaption></figcaption></figure>

After selecting a specific application, you can see the corresponding permissions. Users can remove permissions through the "Revoke app permissions" option.

<figure><img src="/files/v4FtI6eARFdZoZeST1r5" alt=""><figcaption></figcaption></figure>

### Review Delegation Status

Check method: Settings → Security and account access → Delegate

<figure><img src="/files/rtZmMLI7k4JXLob948Vt" alt=""><figcaption></figcaption></figure>

If you find that the account allows invitation management, you need to enter "Members you've delegated" to see which accounts the current account is shared with. If sharing is no longer needed, delegation should be canceled immediately.

<figure><img src="/files/wRSmxTW5ltMh5BG9bFT3" alt=""><figcaption></figcaption></figure>

### Review Abnormal Login Logs

If users suspect that their account has been maliciously accessed, they can check the login logs to see abnormal login devices, dates, and locations.

Check method: Settings → Security and account access → Apps and sessions → Account access history

<figure><img src="/files/qkpXUx7YLbZ7xbqpBtXu" alt=""><figcaption></figcaption></figure>

As shown below, entering Account access history allows you to view the device model, login date, IP, and region. If abnormal login information is found, the account may have been compromised.

<figure><img src="/files/IvSUsVvbNdBLC93KX5Be" alt=""><figcaption></figcaption></figure>

### Review Login Devices

If a malicious login occurs after an X account is stolen, users can view the current login devices for the account and log out the suspicious device.

Check method: Select "Log out the device shown" to log the account out from a specific device.

<figure><img src="/files/pVsRsSbOFxXpzrnCtNm2" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/f2dT736mo5HenD4B4Zjn" alt=""><figcaption></figcaption></figure>

## Security Settings

### 2FA Verification

Users can enable 2FA verification to set up two-factor authentication, reducing the risk of account takeover if the password is leaked.

Configuration method: Settings → Security and account access → Security → Two-factor authentication

<figure><img src="/files/tRWGiETpWoqtXAFHX2xW" alt=""><figcaption></figcaption></figure>

You can set up the following 2FA methods to enhance account security, such as SMS verification codes, authentication apps, and security keys.

<figure><img src="/files/NmIjFFNiIRxlI3CSfwxN" alt=""><figcaption></figcaption></figure>

### Additional Password Protection

In addition to setting account passwords and 2FA, users can enable additional password protection to further enhance X account security.

Configuration method: Settings → Security and account access → Security → Additional password protection

<figure><img src="/files/7B7EzpfKAdSKmVQatnUD" alt=""><figcaption></figcaption></figure>

## Summary

Regularly checking authorized applications and login activities is key to ensuring account security. The Veritas Protocol Security Team recommends that users regularly conduct authorization checks on their X accounts according to the steps outlined to strengthen account security and reduce the risk of hacker attacks. If you discover that your account has been compromised, immediately take action to change your account password, conduct authorization checks, revoke suspicious authorizations, and enhance security settings for your account.


# Navigating Wallet Types and Risks

### Background

As the cryptocurrency market heats up, Web3 projects are rapidly evolving, and the excitement among users is constantly growing. Along with this surge comes the risk of users inadvertently falling victim to hacks or scams when learning about various new projects. This guide primarily covers, but is not limited to: risks involved in downloading and using wallets; pitfalls that might be encountered while participating in various Web3 ecosystems; how to better discern whether signature authorizations are dangerous; and what to do if unfortunately hacked. (Note: The content is subject to change based on new developments and editorial decisions, so the final version may differ slightly in detail and length.)

Whether you're a Web3 newcomer overwhelmed by industry jargon and unknown risks, or an experienced enthusiast facing challenges in the blockchain space, this guide is for you. Our aim is to help every user effectively safeguard their assets and confidently navigate the dark forest of blockchain.

### Wallet category

It is well-known that wallets serve as both the gateway to the crypto world and a fundamental component of Web3 infrastructure. So, without further ado, let us introduce the first topic: Wallet Types and Risks.

#### Browser wallets

Browser wallets such as MetaMask, Rabby, etc. are installed as browser plug-ins in the user's browser (such as Google Chrome, Firefox, etc.). They are typically easier to access and use, not requiring the download or installation of additional software.

Example: <https://metamask.io/download/>

#### Web wallets (not recommended)

Web wallets allow users to access and manage their crypto assets through a web browser. While convenient, the risks associated with web wallets are significant. Typically, web wallets encrypt mnemonic phrases and store them in the browser's local storage, making them vulnerable to malware and cyber attacks.

Example: <https://www.myetherwallet.com/wallet/access/software?type=overview>

#### Mobile wallets

Similar to web wallets, mobile wallets operate as apps that users can download and install on their smartphones.

Example: <https://token.im/download?locale=en-us>

#### Desktop wallets

Desktop wallets were more common in the early days of cryptocurrency, with well-known ones such as Electrum, Sparrow, etc. These wallets are installed as applications on a computer, with private keys and transaction data stored locally on the user's device, giving users full control over their crypto keys.

Example: <https://sparrowwallet.com/>

#### Hardware wallets

Hardware wallets, such as Trezor, imKey, Ledger, Keystone, and OneKey, are physical devices used to store cryptocurrencies and digital assets. They offer offline storage of private keys, meaning private keys are not exposed online during interactions with DApps.

Example: <https://shop.ledger.com/products/ledger-nano-s-plus/matte-black>

#### Paper wallets (not recommended)

Paper wallets involve printing a cryptocurrency's address and its private key on paper as a QR code, which is then used to conduct transactions by scanning the code.

Example: <https://www.walletgenerator.net>

### Common wallet risks

#### Downloading Fake wallets

Due to a person's geographical locations, limitations like the absence of Google Play support or network issues, many users are forced to download wallets from third-party sites or randomly through browser searches, often leading to the installation of fake wallets. This is especially dangerous since ad space and search rankings can be bought, allowing scammers to lure users with fake wallet websites. The picture below shows the results of searching for TP wallet using Baidu:

<figure><img src="/files/IybdFFpYKsc4Xx6vdvhk" alt=""><figcaption></figcaption></figure>

#### Buying Fake Wallets

Supply chain attacks pose a significant threat to the security of hardware wallets. If not purchased from official stores or authorized dealers, there's uncertainty about how many hands the wallet has passed through before reaching the user, and whether its components have been tampered with. In the picture below, the hardware wallet on the right has been tampered with.

<figure><img src="/files/VoJaz4cRpOH4tZFeqKVB" alt=""><figcaption></figcaption></figure>

#### Trojans on Computers

Wallets can be compromised by malware if a computer is infected. It's advised to install antivirus software like Kaspersky, AVG, or 360, keep real-time protection active, and regularly update the virus database.

#### Inherent Wallet Vulnerabilities

Even if you download an authentic wallet and are cautious in its use, vulnerabilities in the wallet's design could still expose it to hacker attacks. This underscores the importance of choosing wallets not just for their convenience, but also for the openness of their source code. External developers and auditors can identify potential vulnerabilities through open-source code, reducing the likelihood of attacks. Should a breach occur due to a vulnerability, security personnel can quickly locate and address the issue.

### Summary

We've introduced different types of wallets and highlighted common risks. Regardless of the type or brand of wallet you choose, always keep your mnemonic phrases and private keys confidential and secure. Consider combining the strengths of different types of wallets, such as using a combination of well-known hardware and software.

{% hint style="info" %}
Note: The wallet brands and images mentioned are solely for educational purposes and should not be considered endorsements or guarantees.
{% endhint %}


# The Dark Forest Manual Guide

Master the security of your cryptocurrency

No matter who you are - if you are a cryptocurrency holder or you want to jump into the crypto world in the future, this guide will help you a lot. You should read this guide closely and apply its teachings in real life.

Additionally, to understand this guide completely requires some background knowledge. However, please do not worry. As for beginners, do not be afraid of the knowledge barriers which can be overcome. If you encounter something that you don't understand, and need to explore more, Google is highly recommended. Also, it is important to keep one security rule in mind: Be skeptical! No matter what information you see on the web, you should always seek out at least two sources for cross-reference.

Blockchain is a great invention that brings about a change in production relations and solves the problem of trust to some degree. Specifically, blockchain creates many "trust" scenarios without the need for centralization and third parties, such as immutability, execution as agreed, and prevention of repudiation. However, the reality is cruel. There are many misunderstandings about blockchain, and the bad guys will use these misunderstandings to exploit the loophole and steal money from people, causing a lot of financial losses. Today, the crypto world has already become a dark forest.

Please remember the following two security rules to survive the blockchain dark forest.

1. **Zero Trust**: To make it simple, stay skeptical, and always stay so.
2. **Continuous Security Validation**: In order to trust something, you have to validate what you doubt, and make validating a habit.

{% hint style="info" %}
*Note: The two security rules above are the core principles of this guide, and all the other security principles mentioned in this guide are derived from them.*
{% endhint %}

Okay, that's all for our introduction. Let's start with a diagram and explore this dark forest to see what risks we will encounter and how we should deal with them.

<figure><img src="/files/8UQ86srZbpzxMkWl5DbM" alt=""><figcaption></figcaption></figure>

## A Diagram

You can skim through this diagram before taking a closer look at the rest of the guide. It is all about the key activities in this world (whatever you want to call it: blockchain, cryptocurrency or Web3), which consists of three main processes: creating a wallet, backing up a wallet and using a wallet.

Let's follow these three processes and analyze each of them.

### Create A Wallet

The core of the wallet is the private key (or seed phrase).

Here's how the private key looks like:

> 0xa164d4767469de4faf09793ceea07d5a2f5d3cef7f6a9658916c581829ff5584

In addition, here's how the seed phrase looks like:

> cruel weekend spike point innocent dizzy alien use evoke shed adjust wrong

{% hint style="info" %}
*Note: We are using Ethereum as an example here. Please check out more details of private keys/seed phrase yourself.*
{% endhint %}

The private key is your identify. If the private key is lost/stolen, then you lost your identify. There are many well-known wallet applications, and this guide won't cover all of them.

However, I will mention some specific wallets. Please note, the wallets mentioned here can be trusted to some degree. But I cannot guarantee they will have no security issues or risks, expected or not, during use (I won't repeat more. Please always keep in mind the two main security rules mentioned in the prologue)

Classified by application, there are PC wallets, browser extension wallets, mobile wallets, hardware wallets and web wallets. In terms of internet connection, they can be mainly divided into cold wallets and hot wallets. Before we jump into the crypto world, we must first think about the purpose of the wallet. The purpose not only determines which wallet we should use, but also how we use the wallet.

No matter what kind of wallet you choose, one thing is for sure: after you have enough experience in this world, one wallet is not enough.

Here we should keep in mind another security principle: isolation, i.e., don't put all your eggs in one basket. The more frequently a wallet is used, the more risky it is. Always remember: when trying anything new, first prepare a separate wallet and try it out for a while with a small amount of money. Even for a crypto veteran like me, if you play with fire, you are more easily to get burned.

#### Download

This sounds simple, but in fact it is not easy. The reasons are as follows:

1. Many people cannot find the real official website, or the right application market, and eventually install a fake wallet.
2. Many people do not know how to identify whether the downloaded application has been tampered or not.

Thus, for many people, before they enter the blockchain world, their wallet is already empty.

To solve the first problem above, there are some techniques to find the correct official website, such as

* using Google (Exercise caution with the advertised entries in search results, as they are often unreliable.)
* using well-known official websites, such as CoinMarketCap
* asking trusted people and friends

You can cross-reference the information obtained from these different sources, and ultimately there is only one truth :) Congratulations, you have found the correct official website.

Next, you have to download and install the application. **If it is a PC wallet**, after downloading from the official website, you need to install it yourself. It is highly recommended to verify whether the link has been tampered before installation. Although this verification may not prevent cases where the source code was altered completely (due to insider scam, internal hacking, or the official website may be hacked, etc.) However, it can prevent cases such as the partial tampering of the source code, man-in-the-middle attack, etc.

The method to verify whether a file has been tampered is the file consistency check. Usually there are two ways:

* **Hash checks**: such as MD5, SHA256, etc. MD5 works for most cases, but there is still a tiny risk of hash collision, so we generally choose SHA256, which is safe enough.
* **GPG signature verification**: this method is also very popular. It is highly recommended to master GPG tools, commands, and methods. Although this method is a bit difficult for newcomers, you will find it very useful once you get familiar with it.

However, there are not many projects in the crypto world that provides verification. So, it is lucky to find one. For example, here is a bitcoin wallet called Sparrow Wallet. Its download page says "Verifying the Release", which is really impressive, and there are clear guidelines for both of the methods mentioned above, so you can use for reference:

> <https://sparrowwallet.com/download/>

The download page mentioned two GPG tools:

* GPG Suite, for MacOS.
* Gpg4win, for Windows.

If you pay attention, you will find the download pages for both GPG tools give some instructions on how to check the consistency of both methods. However, there is no step-by-step guide, that is to say, you need to learn and practice yourself :)

**If it is a browser extension wallet**, such as MetaMask, the only thing you have to pay attention to is the download number and rating in the Chrome web store. MetaMask, for example, has more than 10 million downloads and more than 2,000 ratings (though the overall rating is not high). Some people might think that the downloads number and ratings may be inflated. Truth to be told, it is very difficult to fake such a large number.

**The mobile wallet** is similar to the browser extension wallet. However, it should be noted that the App Store has different versions for each region. Cryptocurrency is banned in Mainland China, so if you downloaded the wallet with your Chinese App Store account, there is only one suggestion: don't use it, change it to another account in a different region such as the US and then re-download it. Besides, the correct official website will also lead you to the correct download method (such as imToken, OneKey, Trust Wallet, etc. It is important for official websites to maintain high website security. If the official website is hacked, there will be big problems.).

**If it is a hardware wallet**, it is highly recommended to buy it from the official website. Do not buy them from online stores. Once you receive the wallet, you should also pay attention to whether the wallet is intact. Of course, there are some shenanigans on the packaging that are hard to detect. In any case, when using a hardware wallet, you should create the seed phrase and wallet address at least three times from scratch. And make sure that they are not repeated.

**If it is a web wallet**, we highly recommend not to use it. Unless you have no choice, make sure it is authentic and then use it sparingly and never rely on it.

#### Mnemonic Phrase

After creating a wallet, the key thing that we deal with directly is the mnemonic phrase/seed phrase, not the private key, which is easier to remember. There are standard conventions for mnemonic phrases (e.g., BIP39); there are 12 English words in general; it could be other numbers (multiples of 3), but not more than 24 words. Otherwise it is too complicated and not easy to remember. If the number of words is less than 12, the security is not reliable. It is common to see 12/15/18/21/24 words. In the blockchain world, 12-word is popular and secure enough. However, there are still hardcore hardware wallets such as Ledger that starts with 24 words. In addition to English words, some other languages are also available, such as Chinese, Japanese, Korean and so on. Here is a 2048 words list for reference:

> <https://github.com/bitcoin/bips/blob/master/bip-0039/bip-0039-wordlists.md>

When creating a wallet, your seed phrase is vulnerable. Please be aware that you are not surrounded by people or webcams or anything else that can steal your seed phrase.

Also, please pay attention to whether the seed phrase is randomly generated. Normally well-known wallets can generate a sufficient number of random seed phrases. However, you should always be careful. It's hard to know whether there's something wrong with the wallet. Be patient because it can be very beneficial to develop these habits for your security. Lastly, sometimes you can even consider disconnecting from the Internet to create a wallet, especially if you are going to use the wallet as a cold wallet. Disconnecting from the Internet always works.

#### Keyless

Keyless means no private key. Here we divide Keyless into two major scenarios (for ease of explanation. Such division is not industry standard)

* **Custodial**. Examples are centralized exchange and wallet, where users only need to register accounts and do not own the private key. Their security is completely dependent on these centralized platforms.
* **Non-Custodial**. The user has a private key-like control power, which is not an actual private key (or seed phrase). It relies on well-known Cloud platforms for hosting and authentication/authorization. Hence the security of the Cloud platform becomes the most vulnerable part. Others make use of secure multi-party computing (MPC) to eliminate single point of risk, and also partner with popular Cloud platforms to maximise user experience.

Personally, I have used various kinds of Keyless tools. Centralized exchanges with deep pockets and good reputations provide the best experience. As long as you are not personally responsible for losing the token (such as if your account information was hacked), centralized exchanges will usually reimburse your loss. The MPC-based Keyless program looks very promising and should be promoted. I have good experience with ZenGo, Fireblocks and Safeheron. The advantages are obvious:

* MPC algorithm engineering is becoming more and more mature on the well-known blockchains, and only needs to be done for private keys.
* One set of ideas can solve the problem of different blockchains having vastly different multi-signature schemes, creating a consistent user experience, which is what we often call: universal multi-signature.
* It can ensure that the real private key never appears and solve the single point of risk through multi-signature calculation.
* Combined with Cloud (or Web2.0 technology) makes MPC not only secure but also creates a good experience.

However, there are still some disadvantages:

* Not all open source projects can meet the accepted standards of the industry. More work needs to be done.
* Many people basically only use Ethereum (or EVM-based blockchain). As such, a multi-signature solution based on smart contract approach like Gnosis Safe is enough.

Overall, no matter which tool you use, as long as you feel safe and controllable and have a good experience, it's a good tool.

So far we have covered what we need to be aware of regarding the creation of wallets. Other general security issues will be covered in later sections.

### Back up your wallet

This is where many good hands would fall into traps, including myself. I did not back up properly and I knew it would happen sooner or later. Luckily, it was not a wallet with a large amount of assets and friends at Veritas Protocol helped me recover it. Still, it was a scary experience which I don't think anyone would ever want to go through. So buckle up and let's learn how to back up your wallet safely.

#### Mnemonic Phrase / Private Key

When we talk about backing up a wallet, we are essentially talking about backing up the mnemonic phrase (or the private key. For convenience, we will use the mnemonic phrase in the following). Most mnemonic phrases can be categorized as follows:

* Plain Text
* With Password
* Multi-signature
* Shamir's Secret Sharing, or SSS for short

I will briefly explain each type.

**Plain Text**, Plain text is easy to understand. Once you have those 12 English words, you own the assets in the wallet. You can consider doing some special shuffling, or even replace one of the words with something else. Both would increase the difficulty for hackers to hack into your wallet, however, you would have a big headache if you forget about the rules. Your memory isn't bulletproof. Trust me, your memory will tangle up after several years. A few years ago, when I used the Ledger hardware wallet, I changed the order of the 24-word-mnemonic phrase. After a few years, I forgot the order and I wasn't sure if I had replaced any word. As mentioned earlier, my problem was solved with a special code breaker program that uses brute force to guess the correct sequence and words.

**With Password**, According to the standard, mnemonic phrases can have a password. It's still the same phrase but with the password, a different seed phrase will be obtained. The seed phrase is used to derive a series of private keys, public keys and corresponding addresses. So you should not only back up the mnemonic phrases, but also the password. By the way, private keys can also have a password and it has its own standards, such as BIP 38 for bitcoin and Keystore for ethereum.

**Multi-Signature**, As the name suggests, it requires signatures from multiple people to access wallets. It's very flexible as you can set your own rules. For example, if there're 3 people have the key (mnemonic words or private keys), you can require at least two persons to sign to access the wallets. Each blockchain has its own multi-signature solution. Most well-known Bitcoin wallets support multi-signature. However, in Ethereum, multi-signature is mainly supported through smart contracts, such as Gnosis Safe. Furthermore, MPC, or Secure Multi-Party Computation is becoming more and more popular. It provides an experience similar to the traditional multi-signature, but with different technology. Unlike multi-signature, MPC is blockchain agnostic and can work with all protocols.

**SSS**, Shamir's Secret Sharing, SSS breaks down the seed into multiple shares (normally, each share contains 20 words). To recover the wallet, a specified number of shares has to be collected and used. For details, refer to the industry best practices below:

> <https://guide.keyst.one/docs/shamir-backup> <https://wiki.trezor.io/Shamir\\_backup>

Using solutions such as multi-signature and SSS will give you peace of mind and avoid single-point risks, but it could make management relatively complicated and sometimes multiple parties will be involved. There is always a compromise between convenience and security. It is up to the individual to decide but never be lazy in principles.

#### Encryption

Encryption is a very, very broad concept. It doesn't matter if the encryption is symmetric, asymmetric or uses other advanced technologies; as long as an encrypted message can be easily decrypted by you or your emergency handling team easily but nobody else after decades, it is good encryption.

Based on the security principle of "zero trust", when we are backing up wallets, we have to assume that any step could be hacked, including physical environments such as a safe. Keep in mind that there is no one other than yourself who can be fully trusted. In fact, sometimes you can't even trust yourself, because your memories may fade away or misplaced. However, I won't make pessimistic assumptions all the time, otherwise it would lead me to some unwanted results.

When backing up, special consideration must be given to disaster recovery. The main purpose of disaster recovery is to avoid a single point of risk. What would happen if you are gone or the environment where you store the backup is down? Therefore, for important stuff, there must be a disaster recovery person and there must be multiple backups.

I won't elaborate too much on how to choose the disaster recovery person because it depends on who you trust. I will focus on how to do the multi-backups. Let's take a look at some basic forms of backup locations:

* Cloud
* Paper
* Device
* Brain

**Cloud**, Many people don't trust backup on Cloud, they think it is vulnerable to hacker attacks. At the end of the day, it is all about which side - the attacker or the defender - put in more effort, in terms of both manpower and budgets. Personally, I have faith in cloud services powered by Google, Apple, Microsoft, etc., because I know how strong their security teams are and how much they have spent on security. In addition to fighting against external hackers, I also care a lot about internal security risk control and private data protection. The few service providers I trust are doing a relatively better job in these areas. But nothing is absolute. If I choose any of these cloud services to back up important data (such as wallets), I will definitely encrypt the wallets at least one more time.

I strongly recommend mastering GPG. It can be used for the "signature verification", and provides strong security of encryption and decryption in the meantime. You can learn more about GPG at:

> <https://www.ruanyifeng.com/blog/2013/07/gpg.html>

Okay, you have mastered GPG :) Now that you have encrypted related data in your wallet (mnemonic phrase or private key) with GPG in an offline secured environment, you can now throw the encrypted files directly into these cloud services and save it there. All will be good. But I need to remind you here: never lose the private key to your GPG or forget the password of the private key...

At this point, you might find this extra level of security is quite troublesome: you have to learn about GPG and back up your GPG private key and passwords. In reality, if you have done all the aforementioned steps, you are already familiar with the process and won't find it as difficult or troublesome. I will say no more because practice makes perfect.

If you want to save some effort, there is another possibility but its security may be discounted. I can't measure the exact discount but sometimes I would be lazy when I would use some well-known tools for assistance. That tool is 1Password. The latest version of 1Password already supports direct storage of wallet-related data, such as mnemonic words, passwords, wallet addresses, etc., which is convenient for users. Other tools (such as Bitwarden) can achieve something similar, but they are not as convenient.

**Paper**, Many hardware wallets come with several high-quality paper cards on which you can write down your mnemonic phrases (in plaintext, SSS, etc.). In addition to paper, some people also use steel plates (fire-resistant, water-resistant and corrosion-resistant, of course, I have not tried those). Test it after you copy over the mnemonic phrases and if everything works, put it in a place where you feel secure, such as in a safe. I personally like using paper a lot because if properly stored, paper has a much longer lifespan than electronics.

**Device**, It refers to all kinds of equipment; electronics are a common type for backup, such as a computer, an iPad, an iPhone, or a hard drive, etc, depending on personal preference. We also have to think about the secure transmission between devices. I feel comfortable using peer-to-peer methods such as AirDrop and USB where it is difficult for a middleman to hijack the process. I am just naturally uneasy about the fact that electronic equipment may break down after a couple of years, so I maintain the habit of checking the device at least once a year. There are some repeated steps (such as encryption) which you can refer to the Cloud section.

**Brain**, Relying on your memory is exciting. In fact, everyone has their own "memory palace". Memory is not mysterious and can be trained to work better. There are certain things that are indeed safer with memory. Whether to rely solely on the brain is a personal choice. But pay attention to two risks: firstly, memory fades away as time goes and could cause confusion; the other risk is that you may have an accident. I will stop here and let you explore more.

Now you are all backed up. Don't encrypt too much, otherwise you will suffer from yourself after several years. According to the security principle of "continuous verification", your encryption and backup methods, whether excessive or not, must be verified continuously, both regularly as well as randomly. The verification frequency depends on your memory and you do not have to complete the whole process. As long as the process is correct, partial verification also works. Finally, it is also necessary to pay attention to the confidentiality and security of the authentication process.

Okay, let's take a deep breath here. Getting started is the hardest part. Now that you are ready, let's enter this dark forest :)

### How to use Your Wallet

Once you have created and backed up your wallets, it comes to the real challenge. If you don't move around your assets frequently, or you barely interact with any smart contracts of DeFi, NFT, GameFi, or Web3, the popular term referred to frequently these days, your assets should be relatively safe.

#### AML

However, "relatively safe" doesn't mean "no risk at all". Cause "you never know which comes first, tomorrow or accidents", right?. Why is it? Think about it, where did you get the cryptocurrency? It didn't just come from nowhere, right? You may encounter AML (Anti Money Laundering) on all the cryptocurrencies you get any time. This means that the cryptocurrency you're holding at the moment may be dirty, and if you're not lucky, it may even be frozen directly on the chain. According to public reports, Tether once freezed some USDT assets as per request from law enforcement agencies. The list of frozen funds can be found here.

> <https://dune.xyz/phabc/usdt---banned-addresses>

You can verify if an address is frozen by Tether from the USDT contract.

> <https://etherscan.io/token/0xdac17f958d2ee523a2206206994597c13d831ec7#readContract>

Use the target wallet address as input int isBlackListed to check. Other chains that take USDT have similar verification way.

However, your BTC and ETH should never ever get frozen. If this does happen one day in the future, the belief of decentralization would crash as well. Most cryptocurrency asset frozen cases we have heard today actually happened in centralized platforms (such Binance, Coinbase, etc.) but not on the blockchain. When your cryptocurrency stays in Centralized Exchange platforms, you don't actually own any of them. When the centralized platforms freeze your account, they are actually revoking your permission to trade or withdraw. The concept of freezing could be misleading to newbies in the area. As a result, some reckless self media would spread all kinds of conspiracy theories about BitCoin.

Though your BTC and ETH assets won't be frozen on the blockchain, centralized exchanges might freeze your assets according to the requirement of AML once your assets get transferred into these platforms and they are involved in any open cases that law enforcements are working on.

To better avoid AML issues, always choose platforms and individuals with a good reputation as your counterparty. There are actually a few solutions for this type of problem. For example, on Ethereum, almost all bad guys and people who care a lot about their privacy use Tornado Cash for coin mixing. I won't dig any more into this topic since most methods here are being used for doing evil.

#### Cold Wallet

There are different ways to use a cold wallet. From a wallet's perspective, it can be considered as a cold wallet as long as it's not connected to any network. But how to use it when it's offline? First of all, if you just want to receive cryptocurrency, it's not a big deal. A cold wallet could provide excellent experience by working with a Watch-only wallet, such as imToken, OneKey, Trust Wallet, etc. These wallets could be turned into watch-only wallets by simply adding target wallet addresses.

If we want to send cryptocurrency using cold wallets, here are the most commonly used ways:

* QRCode
* USB
* Bluetooth

All of these require a dedicated app (called Light App here) to work with the cold wallet. The Light App will be online along with the aforementioned Watch-only wallet. Once we understand the underlying essential principle, we should be able to understand these approaches. The essential principle is: eventually, it's just a matter of figuring out how to broadcast signed content onto the blockchain. Detailed process is as follows:

* The content to be signed is transmitted by the Light App to the Cold Wallet by one of these means.
* The signature is processed by the cold wallet that has the private key and then transmitted back to the Light App using the same way
* The Light App broadcasts the signed content on the blockchain.

So no matter which method is used, QR code, USB or Bluetooth, it should be following the above process. Of course, details might vary from different methods. For example, QR code has a limited information capacity, so when the signature data is too large, we would have to split it up.

It seems to be a bit troublesome, but it becomes better when you get used to it. You would even feel a full sense of security. However, don't consider it 100% secure because there are still risks here, and there have been many cases of heavy losses because of these risks. Here are risk points:

* The target address of the coin transfer was not checked carefully, resulting in the coin being transferred to someone else. People are lazy and careless, sometimes. For example, most of the time they only check the beginning and ending few bits of a wallet address instead of fully checking the whole address. This leaves a backdoor to bad guys. They will run programs to get the wallet address with the same first and last few bits as your desired target address and then replace your coin transfer target address with the one under their control using some tricks.
* Coins are authorized to unknown addresses. Usually authorization is the mechanism of the Ethereum smart contract tokens, the "approve" function, with one argument being the target authorization address and the other being the quantity. Many people don't understand this mechanism, so they may authorize an unlimited number of tokens to the target address, at which point the target address has permission to transfer all those tokens away. This is called authorized coin theft, and there are other variants of the technique, but I won't expand on it here.
* Some signatures that seem not important actually have huge traps in the back, and I won't dig into it now, but will explain the details later.
* The cold wallet may not have provided enough necessary information, causing you to be careless and misjudged.

It all boils down to two points:

* The user interaction security mechanism of "What you see is what you sign" is missing.
* Lack of relevant background knowledge of the user.

#### Hot Wallet

Compared to a cold wallet, a hot wallet has basically all the risks that a cold wallet would have. Plus, there is one more: the risk of theft of the secret phrase (or private key). At this point there are more security issues to consider with hot wallets, such as the security of the runtime environment. If there are viruses associated with the runtime environment, then there is a risk of getting stolen. There are also hot wallets that have certain vulnerabilities through which the secret phrase can be directly stolen.

In addition to the regular coin transfer function, if you want to interact with other DApps (DeFi, NFT, GameFi, etc.), you either have to access them directly with your own browser or interact with the DApps opened in your PC browser via the WalletConnect protocol.

*Note: References of DApps in this handbook refer by default to smart contract projects running on the Ethereum blockchains.*

By default, such interactions do not lead to secret phrase theft, unless there is a problem with the wallet security design itself. From our security audits and security research history, there is a risk of wallet secret phrases being stolen directly by malicious JavaScript on the target page. However, this is a rare case, as it is actually an extremely low-level mistake that no well-known wallet is likely to make.

None of these are actually my actual concerns here, they are manageable for me (and for you too). My biggest concern/concern is: how does each iteration of a well-known wallet ensure that no malicious code or backdoor is planted? The implication of this question is clear: I verified that the current version of the wallet has no security issues and I'm comfortable using it, but I don't know how secure the next version will be. After all, I or my security team can't have that much time and energy to do all the verifications.

There have been several incidents of coin theft caused by malicious code or backdoors as described here, such as CoPay, AToken, etc. You can search for the specific incidents yourself.

In this case, there are several ways of doing evil:

* When the wallet is running, the malicious code packages and uploads the relevant secret phrase directly into the hacker-controlled server.
* When the wallet is running and the user initiates a transfer, information such as the target address and amount is secretly replaced in the wallet backend, and it is difficult for the user to notice.
* Corrupting the random number entropy values associated with the generation of secret phrases, which makes them relatively easy to decipher.

Security is a thing of ignorance and knowledge, and there are many things that could be easily ignored or missed. So for wallets that hold important assets, my security rule is also simple: no easy updates when it's enough to use.

#### What is DeFi Security

When we talk about DApp, it could be DeFi, NFT or GameFi etc. The security fundamentals of these are mostly the same, but they will have their respective specifics. Let's first take DeFi as an example to explain. When we talk about DeFi security, what exactly do we mean? People in the industry almost always only look at smart contracts. It seems that when smart contracts are good, everything will be fine. Well actually, this is far from true.

DeFi security includes at least the following components:

* Smart Contract Security
* Blockchain Foundation Security
* Frontend Security
* Communication Security
* Human Security
* Financial Security
* Compliance Security

**Smart Contract Security**

Smart contract security is indeed the most important entry point for security audit, and Veritas Protocol's security audit standards for smart contracts can be found at:

> <https://www.veritasprotocol.com/service-smart-contract-security-audit.html>

For advanced players, if the security of the smart contract part itself is controllable (whether they can audit themselves or understand security audit reports issued by professional organizations), then it doesn't matter if the other parts are secure. Controllable is a tricky concept, some of which depends on the player's own strength. For example, players have certain requirements in respect of the risk from excessive smart contract authority. If the project itself is strong and the people behind it have a good reputation, complete centralization would not matter. However, for those less well-known, controversial or emerging projects, if you realize that the project's smart contracts possess excessive permission risk, especially if such permissions can also affect your principal or earnings, you will certainly be reluctant.

The risk of excessive permission is very subtle. In many cases, it is in place for the admin of the project to conduct relevant governance and risk contingency. But for users, this is a test on human nature. What if the team decides to do evil? So there is a trade-off practice in the industry: adding Timelock to mitigate such risks of excessive permission, for example:

> Compound, an established and well-known DeFi project, the core smart contract modules Comptroller and Governance, both have Timelock mechanism added to their admin permission:\
> Comptroller(0x3d9819210a31b4961b30ef54be2aed79b9c9cd3b)\
> Governance(0xc0da02939e1441f497fd74f78ce7decb17b66529)\
> The admin these 2 modules is\
> Timelock(0x6d903f6003cca6255d85cca4d3b5e5146dc33925)

You can directly find out on chain that the Timelock (delay variable) is 48 hours (172,800 seconds):

That is to say, if the admin of Compound needs to change some key variables of the target smart contract, the transaction will be recorded after it is initiated on the blockchain, but 48 hours must be waited before the transaction can be finalized and executed. This means that if you would like, you can audit every single operation from the admin, and you will have at least 48 hours to act. For example, if you are unsure, you can withdraw your funds within 48 hours.

Another way to mitigate the risk of excessive permission of admin is to add multi-signature, such as using Gnosis Safe for multisig management, so that there will at least be no dictator. It should be noted here that multisig can be "the emperor's new clothes". For example, one person may hold multiple keys. Therefore, the multisig strategy of the target project needs to be clearly stated. Who holds the keys, and the identity of each key holder must be reputable.

It is worth mentioning here that any security strategy may lead to the problem of "the emperor's new clothes", which the strategy may appear to be well done, but in reality is not, resulting in an illusion of security. Take another example, Timelock looks good on paper. Actually, there have been cases where Timelock deployed by some projects has backdoors. Generally, users don't look into the source code of Timelock, and they would not necessarily understand it even if they do, so the admin puts a backdoor there, and no one would really notice for a long enough time.

In addition to the risk of excessive permission, other elements of smart contract security are also critical. However, I will not expand here, in consideration of the prerequisites for understanding. Here is my advice: you should at least learn to read the security audit report, and practice makes perfect.

**Blockchain Foundation Security**

Blockchain foundation security refers to the security of the blockchain itself, such as consensus ledger security, virtual machine security etc. If the security of the blockchain itself is worrisome, the smart contract projects running on the chain would suffer directly. It is so important to choose a blockchain with sufficient security mechanism and reputation, and better with a higher probability of longevity.

**Frontend Security**

Frontend security is really the devil. It is too close to the users, and it is especially easy to fool users into deception. Perhaps everyone's main focus is on the wallet and smart contract security, resulting in frontend security being easily overlooked. I want to emphasize again that frontend security is the devil! Allow me to dig deeper.

My biggest concern regarding frontend security is: How do I know that the contract I am interacting with from this specific frontend page is the smart contract that I'm expecting?

This insecurity is mainly due to two factors:

* Inside job
* Third party

It is straightforward to understand the inside job. For example, the devs secretly replaces the target smart contract address in the frontend page with a contract address that has a backdoor, or planting an authorization phishing script. When you visit this rigged frontend page, a series of subsequent operations involving cryptos in your wallet may be done in a trap. Before you realized, the coins would be already gone.

The third party mainly refers to two types:

* One is that the dependencies chain is infiltrated. For example, the third-party dependency used by the frontend page has a backdoor which gets sneaked into the target frontend page along with the packaging and release. The following is the package dependency structure of SushiSwap (for illustration only, it doesn't necessarily mean that the project in the screenshot has such issue):

<figure><img src="/files/lB74cKNsqxhMC7lc53yP" alt=""><figcaption></figcaption></figure>

* The other example is third-party remote JavaScript files imported by the frontend page. If this JavaScript file is hacked, it's possible that the target frontend page gets affected as well, such as OpenSea (for illustration only, it doesn't necessarily mean that the project in the screenshot has such an issue):

<figure><img src="/files/QIXxQyss5G59aK78L9ET" alt=""><figcaption></figcaption></figure>

The reason why we said it's just possible but not certainly is that the risk could be mitigated if devs refer to a third-party remote JavaScript file on the frontend page in the following way:

```
// <script src="https://example.com/example-framework.js" integrity="sha384-Li9vy3DqF8tnTXuiaAJuML3ky+er10rcgNR/VqsVpcw+ThHmYcwiB1pbOxEbzJr7" crossorigin="anonymous"></script>
```

The key point here is a nice security mechanism of HTML5: integrity attribute in tags (SRI mechanism). integrity supports SHA256, SHA384 and SHA512. If third-party JavaScript files do not meet the hash integrity check, the files will not be loaded. This can be a good way to prevent unintended code execution. However, utilizing this mechanism requires the target resource to support CORS response. For details, refer to the following:

> <https://developer.mozilla.org/zh-CN/docs/Web/Security/Subresource\\_Integrity>

**Communication Security**

Let's focus on HTTPS security in this section. First, the target website must use HTTPS, and HTTP plaintext transmission should never be allowed. This is because HTTP plaintext transmission is too easy to be hijacked by man-in-the-middle attacks. Nowadays HTTPS is very common as a secure transmission protocol. If there is a man-in-the-middle attack on HTTPS, and attackers have injected malicious JavaScript into the web application's front-end, a very obvious HTTPS certificate error alert will be displayed in the user's browser.

Let's use the MyEtherWallet incident as an example to illustrate this point.

MyEtherWallet used to be a very popular web application wallet, and up till now it's still very well known. However it's no longer just a web application wallet. As mentioned before, I strongly discourage the use of web application wallets due to security reasons. In addition to various issues in front-end security, HTTPS hijacking is also a big potential risk.

On April 24, 2018, there was a major security incident of HTTPS hijacking in MyEtherWallet. The recap of the incident can be found here:

> <https://www.reddit.com/r/MyEtherWallet/comments/8eloo9/official\\_statement\\_regarding\\_dns\\_spoofing\\_of/\\>
> <https://www.reddit.com/r/ethereum/comments/8ek86t/warning\\_myetherwalletcom\\_highjacked\\_on\\_google/>

In the attack, the hacker hijacked the DNS service (Google Public DNS) used by a large number of MyEtherWallet users via BGP, an ancient routing protocol, which directly led to the display of HTTPS error alerts in every user's browser when they tried to visit MyEtherWallet website. In fact, users should stop when they see this alert, as it basically indicates that the target web page has been hijacked. In reality however, many users just quickly ignored the alert and proceeded to continue with their interactions with the hijacked site, because they didn't understand the security risk behind the HTTPS error alert at all.

Since the target web page had been hijacked and the hacker had injected malicious JavaScript in there, upon users' interaction, the hackers would have successfully stolen their plaintext private key and transferred away their funds (mostly ETH).

This is definitely a classic case where hackers used BGP hijacking techniques to steal crypto. It's just overkill. Ever after this there have been several similar cases, and I won't mention them in detail here. To the user there is only one thing that really needs attention: if you ever decide to use a web application wallet, or try to interact with a DApp, always make sure you stop and close the page whenever you see a HTTPS certificate error alert! And your funds will be fine. There is a cruel reality in security: when there is a risk, don't give users any choices. As if you do, there will always be users falling into the trap for whatever reasons. In fact, the project team needs to take up the responsibility. As of today, there are already very effective security solutions to the HTTPS hijacking issue mentioned above: the project team needs to properly configure HSTS. HSTS stands for HTTP Strict Transport Security; it is a web security policy mechanism supported by most modern browsers. If HSTS is enabled, in case of a HTTPS certificate error the browser will force users to stop accessing the target web applications and the restriction can't be bypassed. Now you get what I mean?

**Human Nature Security**

This section is easy to understand. For example the project team is evil minded and acts in a dishonest way. I have mentioned some relevant contents in previous sections, so here I won't go into more details. More to be covered in later sections.

**Financial Security**

Financial Security should be deeply respected. In DeFi, users pay utmost attention to token price and return. They want superior, or at least steady return on investment. In other words, as a user, I play the game to win and if I lose, at least I need to be convinced that it is a fair game. This is just human nature.

Financial security in DeFi is susceptible to attacks in the forms of:

* Unfair launch practices such as pre-mining or pre-sale;
* Crypto whale attack;
* Pump and dump;
* Black swan events, like sudden market waterfall; or let's say when one DeFi protocol is nested or interoperated with other DeFi/Tokens, its security/reliability will be highly depending on other protocols
* Other technical attacks or what we refer to as scientific techniques such as front running, sandwich attack, flash loan attacks, etc

**Compliance Requirements**

Compliance requirement is a very big topic, the previously mentioned AML(Anti Money Laundering) is just one of the points. There are also aspects like KYC(Know Your Customer), sanctions, securities risks, etc. In fact for us users these are not something under our control. When we interact with a certain project, as it may be subject to relevant regulations in certain countries, our privacy information might get collected. You might not care about such privacy issues, but there are people who do.

For example, in early 2022 there was a small incident: some wallets decided to support Address Ownership Proof Protocol(AOPP) protocol:

I took a look at the protocol design, it turned out that wallets supporting AOPP might leak user privacy. Regulators might get to know the interconnection between a regulated crypto exchange and an unknown external wallet address.

> <https://gitlab.com/aopp/address-ownership-proof-protocol>

No wonder many privacy-oriented wallets are so concerned about user's feedback and quickly removed AOPP support from their products. But to be honest: The protocol design is quite interesting. I have noticed that some wallets have no plans to remove support for AOPP, such as EdgeWallet. Their opinion is that AOPP doesn't necessarily expose more user privacy, on the contrary it helps to enhance the circulation of cryptocurrency. In many regulated crypto exchanges, users are not allowed to withdraw to a particular external wallet address, before he can prove his ownership to it.

At first, the well-known hardware wallet Trezor refused to remove AOPP support. But later it was forced to compromise and did so due to pressures from the community and users on Twitter.

As you can see, it's such a small incident but to some people, privacy is really important. This is not to say that we should go against regulations, and totally ignore compliance requirements. As a matter of fact I do believe it's necessary to have a certain level of compromise to compliance requirements. We won't continue to deep dive into this topic, feel free to digest the contents in your own ways.

So far, we have covered the majority of content in the DeFi Security section.

What's more, there are also security issues introduced by future additions or updates. We often say "security posture is dynamic, not static". For example nowadays most project teams do security audits and show clean security audit reports. If you ever read the good-quality reports carefully you will notice that these reports will clearly explain the scope, timeframe, and the unique identifier of the audited contents (e.g. the verified open source smart contract address, or the commit address on GitHub repo, or the hash of the target source code file). This is to say, the report is static, but if in a project you have observed any deviations from what is mentioned in the report, you can point it out.

#### NFT Security

All the previously mentioned contents on DeFi security can be applied to NFT security, and NFT itself has a few very specific and unique security topics, for example:

* Metadata security
* Signature security

Metadata refers mainly to the embedded picture , motion pictures and other contents. It's recommended to refer to OpenSea on the specific standards:

> <https://docs.opensea.io/docs/metadata-standards>

There are two main security concerns that may arise here:

* One is that the URI where the image (or motion picture) is located might not be trustworthy. It can just be a randomly selected centralized service, on one hand there is no guarantee of availability, on the other hand the project team can modify the images at will, thus the NFT will no longer become an immutable "digital collectible". Generally it's recommended to use decentralized storage solutions such as IPFS, Arweave, and select a well-known URI gateway service.
* Another is the potential for privacy leakage. A randomly selected URI service might capture user's basic information (such as IP, User-Agent, etc)

Signing security is another big concern here, and we will illustrate it below.

#### BE CAREFUL With Signing!

Signature security is something that I want to mention specifically as there are SO MANY pitfalls and you should be careful all the time. There have been several incidents, especially on NFT trading. However, I have noticed that not too many people understand how to prepare for and deal with such security problems. The underlying reason is few people have ever made the problem clear enough.

The NO.1 and most important security principle in signature security is: **What you see is what you sign**. That is, the message in the signature request you received is what you should expect after signing. After you sign it, the result should be what you expected instead of something you would regret.

Some details of signature security have been mentioned in the "Cold Wallet" section. If you can't recall, I would suggest you revisit that section. In this section, we will focus on other aspects.

There were several well-known NFT hacks on OpenSea around 2022. On Feb 20th, 2022, there was a major outbreak. The root causes are:

* Users signed NFT listing requests on OpenSea.
* Hackers phished to obtain relevant signatures from users.

It is actually not hard for hackers to obtain the relevant signature. The hacker needs to 1). construct the message to be signed, 2). hash it, 3). trick the target user to sign the request (this would be a blind signing, which means users don't actually know what they are signing), 4). get the signed content and construct the data. At this point, the user has been hacked.

I will use Opensea as an example (in reality, it could be ANY NFT marketplace). After the target user authorizes the NFT listing operation in the marketplace, the hacker would construct the message to be signed. After hashing it with Keccak256, a signature request would pop up on the phishing page. Users would see something like the following:

<figure><img src="/files/USAVGzVIJa6SKNtNiwAU" alt=""><figcaption></figcaption></figure>

Look closely. What kind of information can we get from this MetaMask popup window? Account Info and account balance, the source website where the signature request comes from, the message that users are about to sign and...nothing else. How could users suspect that the disaster is already on the way? And how could they realize that once they click the "Sign" button, their NFTs would be stolen.

This is actually an example of blind signing. Users are not required to sign within the NFT marketplace. Instead, users can be tricked into any phishing website to sign the message without fully understanding the actual meaning and consequence of these signatures. Unfortunately, hackers know. As a user, just keep in mind: NEVER BLIND SIGN ANYTHING. OpenSea used to have the blind signing problem, and they fixed it by adopting EIP-712 after Feb 20th 2022. However, without blind signing, users could still be careless and hacked in other ways.

The most essential reason why this is happening is that the signing isn't restricted to follow the browser's same-origin policy. You can simply understand it as: the same-origin policy can ensure that an action only happens under a specific domain and will not cross domains, unless the project team intentionally wants domain crossing to happen. If signing follows the same-origin policy, then even if the user signs a signature request generated by the non-target domain, hackers can't use the signature for attacks under the target domain. I will stop here before going into more details. I have noticed new proposals on security improvement at the protocol level, and I hope this situation can be improved as soon as possible.

We have mentioned most of the major attack formats that could occur when signing a message, but there are actually quite a few variants. No matter how different they look, they follow similar patterns. The best way to understand them is to reproduce an attack from beginning to end by yourselves, or even create some unique attack methods. For example, the signature request attack mentioned here actually contains a lot of details, such as how to construct the message to be signed, and what is generated exactly after signing? Is there any authorization methods other than "Approve" (yes, for example: increaseAllowance). Well, it would be too technical if we expand here. The good thing is you should already understand the importance of signing a message.

Users can prevent such attacks at the source by canceling the authorization/approval. The following are some well-known tools that you could use.

* Token Approvals

  > <https://etherscan.io/tokenapprovalchecker\\>
  > This is the tool for authorization check and cancellation provided by Ethereum's official browser. Other EVM compatible blockchains have something similar as their blockchain browsers are basically developed by Etherscan. For example:\
  > <https://bscscan.com/tokenapprovalchecker\\>
  > <https://hecoinfo.com/tokenapprovalchecker\\>
  > <https://polygonscan.com/tokenapprovalchecker\\>
  > <https://snowtrace.io/tokenapprovalchecker\\>
  > <https://cronoscan.com/tokenapprovalchecker>
* Revoke.cash

  > <https://revoke.cash/\\>
  > Super old school with good fame & Multi-chain Supporting with increasingly power
* Rabby extension wallet

  > <https://rabby.io/\\>
  > One of the wallets that we have collaborated with a lot. The number of EVM compatible blockchains where they provide "authorization check and cancellation" function is the most that I have ever seen

:warning: **Note**: If you want a more comprehensive and in-depth understanding of SIGNATURE SECURITY, please check the extensions in the following repository additions as a reference:

> <https://github.com/evilcos/darkhandbook\\>
> It is true that the knowledge of SIGNATURE SECURITY is quite challenging for beginners. The repository compiles relevant content, and carefully reading through it will help you grasp the security knowledge. Thus, you will no longer find it difficult. (If you can read and understand everything, I believe that security knowledge will no longer be tough for you :)

#### Be CAREFUL With Counter-intuitive Signatures Requests!

I would like to particularly mention another risk: **counter-intuitive risk**.

What is counter-intuitive? For example, you are already very familiar with Ethereum, and have become an OG of all kinds of DeFi and NFTs. When you first enter the Solana ecosystem, you probably would encounter some similar phishing websites. You may feel so well prepared that you start to think "I have seen these a thousand times in the Ethereum ecosystem and how could I get fooled?"

In the meantime, hackers would be happy as you already got fooled. People follow their intuitive feelings which makes them careless. When there's a counter-intuitive attack, people would fall into the trap.

Ok, let's take a look at a real case that took advantage of counter-intuitiveness.

First of all, a warning: Authorization phishing on Solana is way more cruel. The example above happened on March 5th, 2022. The attackers airdropped NFTs to users in batches (Figure 1). Users entered the target website through the link in the description of the airdropped NFT (www\_officialsolanarares\_net) and connected their wallets (Figure 2). After they clicked the "Mint" button on the page, the approval window popped up (Figure 3). Note that there was no special notification or message in the pop up window at this time. Once they approved, all SOLs in the wallet would be transferred away.

When users click the "Approve" button, they are actually interacting with the malicious smart contracts deployed by the attackers: *3VtjHnDuDD1QreJiYNziDsdkeALMT6b2F9j3AXdL4q8v*

The ultimate goal of this malicious smart contract is to initiate "SOL Transfer", which transfers almost all of the user's SOLs. From analysis of on-chain data, the phishing behavior continued for several days, and the number of victims kept increasing during the period of time.

There are two pitfalls from this example that you need to pay attention to:

1. After the user approves, the malicious smart contract can transfer the user's native assets (SOL in this case). This is not possible on Ethereum. The authorization phishing on Ethereum can only affect other tokens but not the native asset of ETH. This is the counter-intuitive part that would make users lower vigilance.
2. The most well-known wallet on Solana, Phantom, has loopholes in its security mechanism that it doesn't follow the "what you see is what you sign" principle (we haven't tested other wallets yet), and it doesn't provide enough risk warning to users. This could easily create security blind spots that cost users' coins.

#### Some Advanced Attacking Methodologies

Actually, there are many advanced attacking methodologies, but they are mostly regarded as phishing from the perspective of the public. However, some are no normal phishing attacks. For example:

> <https://twitter.com/Arthur\\_0x/status/1506167899437686784>

Hackers sent a phishing e-mail with such an attachment:

> A Huge Risk of Stablecoin(Protected).docx

To be honest, it is an attractive document. However, once opened user's computer will be implanted with a Trojan (generally through Office macro or 0day / 1day exploit), which usually contains the following functions:

* Collecting all sorts of credentials, for example, browser related, or SSH related, etc. In this way, hackers can extend their access to other services of the target user. Therefore, after infection users are generally advised not only to clean up the target device, but also relevant account permissions as well.
* Keylogger, in particular targeting those temporarily appearing sensitive information such as passwords.
* Collecting relevant screenshots, sensitive files, etc.
* If it is ransomware, all files in the target system would be strongly encrypted, and waiting for the victim to pay for the ransom, usually by bitcoin. But in this case it was not ransomware which has more obvious & noisy behavior and straightforward intentions.

In addition, Trojans targeting the crypto industry will be specially customized to collect sensitive information from well known wallets or exchanges, in order to steal user's funds. According to professional analysis, the above mentioned Trojan would conduct a targeted attack on Metamask:

> <https://securelist.com/the-bluenoroff-cryptocurrency-hunt-is-still-on/105488/>

The Trojan will replace user's MetaMask with a fake one with back doors. A backdoored MetaMask basically means that any funds you store inside are no longer yours. Even if you are using a hardware wallet, this fake MetaMask will manage to steal your funds by manipulating the destination address or amount information.

This approach is specially crafted for well known targets with known wallet addresses. What I have noticed is that many such people are too arrogant to prevent themselves from getting hacked. After the hack, many would learn from the lesson, conduct full reviews, have significant improvements, and also form long term cooperation and friendship with trusted security professionals or agencies. However, there are always exceptions in this world. Some people or projects keep getting hacked again and again. If each time it is because of something no one has encountered before, I would highly respect them and call them pioneers. High chance they will be successful as time goes on. Unfortunately many of the incidents are the results of very stupid and repetitive mistakes that could be avoided easily. I would advise staying away from these projects.

Comparingly, those mass phishing attacks are not comprehensive at all. Attackers would prepare a bunch of similarly looking domain names and spread the payloads by buying accounts, followers, and retweets on Twitter or other social platforms. If managed well, many will fall into the trap. There is really nothing special in this kind of phishing attack, and normally the attacker will just brutally make the user authorize tokens (including NFT) in order to transfer them away.

There are other kinds of advanced attacks, for example using techniques like XSS, CSRF, Reverse Proxy to smoothen the attack process. I won't elaborate on all of them here, except one very special case (Cloudflare Man-in-the-Middle attack) which is one of the scenarios in Reverse Proxy. There have been real attacks that caused financial loss utilizing this extremely covert method.

The problem here is not Cloudflare itself being evil or getting hacked. Instead it's the project team's Cloudflare account that gets compromised. Generally the process is like this: If you use Cloudflare, you will notice this "Worker" module in the dashboard, whose official description is:

> Building serverless applications and deploying them instantly around the world, achieving excellent performance, reliability and scale. For details, please refer to <https://developers.cloudflare.com/workers/>

I made a test page a long time ago:

> <https://xssor.io/s/x.html>

When you visit the page there will be a pop-up window saying:

> xssor.io, Hijacked by Cloudflare.

<figure><img src="/files/XWR4IOpgwEinmPYUku0U" alt=""><figcaption></figcaption></figure>

In fact, this pop-up, and even the whole content of x.html, doesn't belong to the document itself. All of them are provided by Cloudflare. The mechanism is shown below:

The indication of the code snippet in the screenshot is very simple: If I were the hacker and I have controlled your Cloudflare account, I can use Workers to inject arbitrary malicious script to any web page. And it's very difficult for the users to realize that the target web page has been hijacked and tampered with, as there will be no error alerts (such as HTTPS certificate error). Even the project team won't easily identify the problem without having to spend a huge amount of time checking the security of their servers and personnel. By the time they realise it is Cloudflare Workers, the loss could already be significant.

Cloudflare is actually a good tool. Many websites or web applications will use it as their web application firewall, anti DDoS solution, global CDN, reverse proxy, etc. Because there is a free version, they have a big customer base. Alternatively, there are services like Akamai etc.

Users must pay attention to the security of such accounts. Account security issues arise with the rise of the Internet. It's such a common topic in the world that almost everyone is talking about it everywhere, but still many people are getting hacked because of it. Some root causes might be they don't use a unique strong password for important services (Password managers like 1Password isn't that popular anyway), some might be they don't bother to turn on 2 factor authentication (2FA), or maybe they don't even know of the thingy. Not to mention for some certain services, passwords should be reset at least annually.

All right, this will be the end of this section. You only need to understand that this is indeed a dark forest, and you should know about as many attacking methodologies as possible. After seeing enough on paper, if you have at least fallen into the traps once or twice, you can consider yourself as an amateur security professional (which will benefit yourself anyway).

### Traditional Privacy Protection

Congratulations, you've made it to this part. Traditional privacy protection is an old topic: Here's the article I wrote in 2014.

> You've got to learn a few tricks to protect yourself in the age of privacy breaches.\
> <https://evilcos.me/yinsi.html>

Rereading this article, although this was an entry level article in 2014, however, most of the advice in it is not outdated. After reading the article again, I'll introduce something new here: in fact, privacy protection is closely related to security. Traditional privacy is the cornerstone of security. This section includes your private keys are part of privacy. If the cornerstones are not secure, the privacy of the cornerstones are meaningless, then the superstructure will be as fragile as a building in the air.

The following two resources are highly recommended:

> SURVEILLANCE SELF-DEFENSE\
> TIPS, TOOLS AND HOW-TOS FOR SAFER ONLINE COMMUNICATIONS\
> <https://ssd.eff.org/>

SURVEILLANCE SELF-DEFENSE is short for SSD. Launched by the well-known Electronic Frontier Foundation (EFF), which has specially issued relevant guidelines to tell you how to avoid big brother watching you in the monitoring Internet world, of which including several useful tools (such as Tor, WhatsApp, Signal

, PGP, etc.)

> Privacy Guide: Fight Surveillance with Encryption and Privacy Tools\
> <https://www.privacytools.io/>

The above website is comprehensive listing a number of tools. It also recommends some cryptocurrency exchanges, wallets, etc. However, it should be noted that I don't use very many tools listed on the website, because I have my own way. Thus, you should also develop your own way, with comparing and improving continuously.

Here are some highlights of the tools that I suggest that you should use.

#### Operation System

Windows 10 Edition (and higher) and macOS are both secure options. If you have the ability, you can choose Linux, such as Ubuntu, or even extremely security & privacy focused ones like Tails, or Whonix.

On the topic of Operation System, the most straightforward security principle is: pay close attention to system updates, and apply them asap when available. The capability to master the Operating System comes next. People might ask, what on earth do you need to learn in order to master an Operating System like Windows or MacOS? Isn't it just clicking around? Well it's actually far from being enough. For novice users, a good antivirus software, like Kaspersky, BitDefender, is a must, and they both are available on MacOS.

And then, don't forget about download security, which I mentioned before. You will have eliminated most of the risks, if you don't download and install programs recklessly.

Next, think about what you are gonna do, if your computer got lost or stolen. Having a boot password is obviously not good enough. If disk encryption is not turned on, bad actors can just take out the harddisk and retrieve the data inside. Thus my advice is that disk encryption should be turned on for important computers.

> <https://docs.microsoft.com/en-us/windows/security/encryption-data-protection\\>
> <https://support.apple.com/en-us/HT204837>

We also have powerful and legendary tools such as VeraCrypt (the former TrueCrypt), feel free to try it out if you are interested:

> <https://veracrypt.fr/>

You can go one step further to enable BIOS or firmware password. I have done it myself but it's totally up to your own choice. Just remember: if you do, remember the password very clearly, or else no one can ever help you out. I am lucky enough to have fallen into the rabbit hole myself before, which cost me a laptop, some crypto, and a week's time. On the other hand, it's a very good learning experience too.

#### Mobile phone

Nowadays iPhone and Android are the only two mainstream mobile phones categories. I used to be a big fan of BlackBerry, but its glory faded away with time. In the past, the security posture of Android phones worried me a lot. On one hand it was still in the early stage, on the other hand the versions were very fragmented, each brand would have its own forked Android version. But now things have improved a lot.

On mobile phones we also need to pay attention to security updates and download security. In addition, pay attention of the following points:

* Do not jailbreak/root your phone, it's unnecessary unless you are doing relevant security research. If you are doing it for pirated software it really depends on how well you can master the skill.
* Don't download apps from unofficial app stores.
* Don't do it unless you know what you are doing. Not to mention there are even many fake apps in official app stores.
* The prerequisite of utilising the official Cloud synchronization function, is that you have to make sure your account is secure, otherwise if the Cloud account gets compromised, so will the mobile phone.

Personally I rely more on the iPhone. And you will need at least two iCloud accounts: one China and one overseas. You will need them to install apps with different regional restrictions. (which sounds pretty weird but welcome to the reality)

#### Network

Network security issues used to be a pain in the ass, but there are already significant improvements in recent years, especially since the mass adoption of HTTPS Everywhere policy.

In case of an ongoing network hijacking (man-in-the-middle attack) attack, there will be corresponding system error alerts. But there are always exceptions, so when you have a choice use the more secure option. For example, don't connect to unfamiliar Wi-Fi networks unless the more popular & secure 4G/5G network is not available or not stable.

#### Browsers

The most popular browsers are Chrome and Firefox, in crypto fields some will use Brave too. These well known browsers have a strong team and there will be timely security updates. The topic of browser security is very broad. Here are some tips for you to be aware of:

* Update as quickly as possible, don't take chances.
* Don't use an extension if not necessary. If you do, make your decisions based on user's reviews, number of users, maintaining company, etc, and pay attention to the permission it asks for. Make sure you get the extension from your browser's official app store.
* Multiple browsers can be used in parallel, and it is strongly recommended that you perform important operations in one browser, and use another browser for more routine, less important operations.
* Here are some well-known privacy focused extensions (such as uBlock Origin, HTTPS Everywhere, ClearURLs, etc.), feel free to try them out.

In Firefox in particular, I will also use the legendary ancient extension NoScript, which had a proven record of fending off malicious JavaScript payloads. Nowadays browsers are becoming more and more secure as they add support for things like same-origin policy, CSP, Cookie security policy, HTTP security headers, extension security policy, etc. Thus the need of using a tool such as NoScript is becoming smaller and smaller, feel free to take a look if interested.

#### Password Manager

If you haven't used a password manager yet, either you don't know the convenience of using one, or you have your own strong memory palace. The risk of brain memory has also been mentioned before, one is that time will weaken or disrupt your memory; the other is that you may have an accident. In either case, I still recommend that you use a password manager to go with your brain memory, use a well-known one like 1Password, Bitwarden, etc.

I don't need to cover this part too much, there are so many related tutorials online, it's easy to get started without even needing a tutorial.

What I need to remind you here is:

* Do not ever forget your master password, and keep your account information safe, otherwise everything will be lost.
* Make sure your email is secure. If your email is compromised, it might not directly compromise the sensitive information in your password manager, but bad actors have the capability to destroy it.
* I have verified the security of the tools I mentioned (such as 1Password), and have been closely watching the relevant security incidents, user reviews, news, etc. But I cannot guarantee that these tools are absolutely secure, and no black swan events are ever gonna happen in the future to them.

One thing I do appreciate is the introduction and description of 1Password's security page, for example.

> <https://1password.com/security/>

This page has security design concepts, relevant privacy and security certificates, security design white papers, security audit reports, etc. This level of transparency and openness also facilitates the necessary validation in the industry. All project teams should learn from this.

Bitwarden goes one step further, as it is fully open source, including the server side, so anyone can validate, audit, and contribute. Now you see? The intention of 1Password and Bitwarden is very clear:

> I am very secure and I am concerned about privacy. Not only do I say it myself, third party authorities say so as well. Feel free to audit me, and in order to make it easy for your audits, I spend a lot of effort to be open wherever possible. If what I do doesn't match what I say, it's easy to challenge me. And this is called Security Confidence.

#### Two-Factor Authentication

Speaking of your identity security on the Internet, the first layer relies on passwords, the second layer relies on two factor authentication, and the third layer relies on the risk control ability of the target project itself. I can't say that two factor authentication is a must-have. For example, if you are using a decentralized wallet, one layer of password is annoying enough (now they basically support biometric identification such as facial recognition or fingerprint to improve user experiences), no one wants to use the second factor. But in a centralized platform, you have to use 2FA. Anyone can access the centralized platform, and if your credentials get stolen, your account is breached and your fund will be lost. On the contrary, the password for your decentralized wallet is just a local authentication, even if the hacker gets the password, they still need to get access to the device where your wallet is located.

Now you see the differences? Some well-known two-factor authentication (2FA) tools include: Google Authenticator, Microsoft Authenticator, etc. Of course, if you use a password manager (such as 1Password), it also comes with a 2FA module, which is very handy. Always remember to make backups, because losing 2FA can be a hassle.

In addition, two-factor authentication can also be a broader concept. For example, when an account identifier and a password are used to log in to the target platform, our account identifier is normally an email or mobile phone number. At this time, the mailbox or mobile phone number can be used as 2FA to receive a verification code. But the security level of this method is not as good. For example, if the mailbox is compromised or the SIM card gets hijacked, or the third-party service used for sending emails and text messages is hacked, then the verification code sent by the platform will also be revealed.

#### Scientific Internet Surfing

For policy reasons, let's not talk too much about this, just pick one of the well-known solutions. Things will be more under control if you can build your own solution. After all, our starting point is to surf the Internet scientifically and securely.

If you are not using a self-built solution, you can't fully rule out the possibility of a man-in-the-middle attack. As mentioned earlier, the Internet security situation is not as bad as it used to be, especially after the mass adoption of HTTPS Everywhere policy. However, some of the peace may be just the surface of the water, and there are already undercurrents beneath the surface that are not easily noticeable. To be honest, I don't really have a silver bullet for this. It's not easy to build your own solution, but it's definitely worth it. And if you can't, make sure you check using multiple sources and choose a reputable one that has been around for a long time.

#### Email

Email is the cornerstone of our web based identity. We use email to sign up for a lot of services. Almost all of the email services we use are free. It seems like air, and you don't think it would disappear. What if one day your Email service is gone, then all the other services that depend on it will be in a rather awkward situation. This extreme situation is really not impossible if there're wars, natural disasters, etc. Of course, if these extreme situations occur, Email will be less important to you than survival.

When it comes to Email services providers, you should choose from tech giants, such as Gmail, Outlook, or QQ Email. It happens that my previous security researches cover this area. The security posture of these mailboxes is good enough. But still you have to be careful about Email phishing attacks. You don't need to deal with every single Email, especially the embedded links and attachments, where Trojans may be hidden.

If you come across a highly sophisticated attack on your Email services providers, you're on your own.

Besides the email services of these tech giants, if you are very concerned about privacy, you can take a look at these two well-known privacy-friendly email services: ProtonMail and Tutanota. My suggestion is to separate these private-friendly mailbox from daily usage, and only use them for services that requires special attention to privacy. You also need to regularly use your free Email services to prevent your accounts from being suspended due to long time inactivity.

#### SIM Card

SIM card and mobile phone number are also very important basic identities in many cases, just like email. In recent years, the major operators in our country have done a very good job in the security protection of mobile phone numbers. For example, there are strict security protocols & verification processes for canceling and re-issuing SIM cards, and they all happen on site. On the topic of SIM card attacks, let me give you an example:

In 2019.5, someone's Coinbase account suffered a SIM Port Attack (SIM card transfer attack), and unfortunately lost more than 100,000 US dollars of cryptocurrency. The attack process is roughly as follows:

The attacker obtained the privacy information of the target user through social engineering and other methods, and tricked the Mobile phone operator to issue him a new SIM card, and then he easily took over the target user's Coinbase account through the same mobile phone number. The SIM has been transferred, which is very troublesome. It's very troublesome if your SIM card got transferred by the attacker, as nowadays, many of the online services use our mobile phone number as a direct authentication factor or 2FA. This is a very centralized authentication mechanism, and the mobile phone number becomes the weak point.

For detailed analysis, please refer to:

> <https://medium.com/coinmonks/the-most-expensive-lesson-of-my-life-details-of-sim-port-hack-35de11517124>

The defence suggestion for this is actually simple: enable a well-known 2FA solution.

The SIM card has another risk: that is, if the phone is lost or stolen, it will be embarrassing that the bad guy can take out the SIM card and use it. Here is what I did: Enable the SIM card password (PIN code), so every time when I turn on my phone or use my SIM card in a new device, I need to enter the correct password. Please ask Google for detailed howtos. Here's the reminder from me: don't forget this password, otherwise it will be very troublesome.

#### GPG

Many contents in this part have been mentioned in previous sections, and I would like to add more basic concepts here: Sometimes you will encounter similar-looking names such as PGP, OpenPGP, and GPG. Simply distinguish them as follows:

* PGP, short for Pretty Good Privacy, is a 30-year-old commercial encryption software now under the umbrella of Symantec.
* OpenPGP is an encryption standard derived from PGP.
* GPG, the full name is GnuPG, is an open source encryption software based on the OpenPGP standard.

Their cores are similar, and with GPG you are compatible with the others. Here I strongly recommend again: In security encryption, don't try to reinvent the wheel; GPG, if used in a correct way, can improve security level significantly!

#### Segregation

The core value behind the security principle of segregation, is the zero trust mindset. You have to understand that no matter how strong we are, we will be hacked sooner or later, no matter if it's by external hackers, insiders or ourselves. When hacked, stop loss should be the first step. The ability to stop loss is ignored by many people, and that's why they get hacked again and again. The root cause is that there is no security design, especially straightforward methods such as segregation

A good segregation practice can ensure that in case of security incidents, you only lose those directly related to the compromised target, without affecting other assets.

For example:

* If your password security practice is good, when one of your accounts gets hacked, the same password will not compromise other accounts.
* If your cryptocurrency is not stored under one set of mnemonic seeds, you will not lose everything if you ever step into a trap.
* If your computer is infected, luckily this is just a computer used for casual activities, and there is nothing important in there So you do not have to panic, as reinstalling the computer would solve most of the problems. If you are good at using virtual machines, things are even better, as you can just restore the snapshot. Good virtual machine tools are: VMware, Parallels.
* To summarize, you can have at least two accounts, two tools, two devices, etc. It is not impossible to completely create an independent virtual identity after you are familiar with it.

I mentioned a more extreme opinion before: privacy is not for us to protect, privacy should be controlled.

The reason for this viewpoint is that: in the current Internet environment, privacy has actually been leaked seriously. Fortunately, privacy-related regulations have become more and more widely adopted in recent years, and people are paying more and more attention. Everything is indeed going in the right direction. But before that, in any case, when you have mastered the knowledge points I have listed, you will be able to control your privacy with ease. On the Internet, if you are used to it, you may have several virtual identities that are almost independent of each other.

### Security of Human Nature

Human is always at the highest and eternal risk. There's a quote from The Three-Body Problem: "Weakness and ignorance are not barriers to survival, but arrogance is."

* Don't be arrogant: If you think you're already strong, you're fine with yourself. Don't look down on the whole world. In particular, don't be overly proud and think you can challenge global hackers. There is no end to learning, and there are still many obstacles.
* Don't be greedy: Greed is indeed the motivation to move forward in many cases, but think about it, why is such a good opportunity just reserved for you?
* Don't be impulsive: impulsiveness is the devil which will lead you to traps. Rash action is gambling.

There are endless things in human nature to talk about and you can't be more careful. Please pay special attention to the following points, and see how bad actors take advantage of the weakness in human nature, utilizing various convenient platforms.

#### Telegram

I've said before that Telegram is the biggest dark web. I have to say that people like Telegram for its security, stability, and open design features. But the open culture of Telegram also attracts bad guys: huge numbers of users, highly customisable functionality, easy enough to build all kinds of Bot services. Combining with cryptocurrency, the actual trading experiences are far beyond those dark web marketplaces in Tor. And there are too many fishes in it.

Normally, the unique identifier of social media accounts is only something like a username, user id, but these can be completely cloned by the bad actors. Some social platforms have account validation mechanisms, such as adding a blue V icon or something. Public social media accounts can be validated through some indicators, such as the follower's number, the contents posted, interaction with fans, etc. The non-public social media accounts are a bit more difficult. It's nice to see that Telegram released the function of "Which Groups we are in together".

Wherever there are loopholes that can be exploited and the gains are considerable, a bunch of bad guys must be already there, that's human nature.

As a result, social media platforms are full of phishing traps. For example: In a group chat, someone who looks like the official customer service suddenly appeared and started a private chat (any2any private chat is the feature of Telegram, there is no need for friend request), and then out of the classic tactics of spam, fish will bite one after another.

Or attackers might go one step further, and add you into another group. All participants buy you are fake, but to you it looks so realistic. We refer to this technique as Group Cloning in underground society.

These are just the basic methods of manipulating human nature, the advanced techniques will be combined with vulnerabilities and thus are more difficult to prevent.

#### Discord

Discord is a new and popular social platform/IM software raised in the past two years. The core function is community servers (not the concept of traditional server), as the official statement says:

Discord is a free voice, video, and text chat app that's used by tens of millions of people ages 13+ to talk and hang out with their communities and friends.

People use Discord daily to talk about many things, ranging from art projects and family trips to homework and mental health support. It's a home for communities of any size, but it's most widely used by small and active groups of people who talk regularly.

It looks great but requires a quite strong security design standard. Discord has specific security rules and policies as in:

> <https://discord.com/safety>

Unfortunately, most people will not bother to read it carefully. What's more, Discord won't always be able to illustrate certain core security issues clearly, because they will have to put on an attacker's hat which is not always feasible.

For instance:

With so many NFT thefts on Discord, what are the key attack methods? Before we figure this out, Discord security advice is useless.

The key reason behind many project Discord hacks is actually the Discord Token, which is the content of the authorization field in the HTTP request header. It has existed in Discord for a very long time. For hackers, if they can find a way to get this Discord Token, they can almost control all the privileges of the target Discord server. That is to say, if the target is an administrator, an account with administrative privileges or a Discord bot, the hackers can do anything they want to. For example by announcing a NFT phishing site, they make people think it's the official announcement, and fish will bite the hook.

Some might ask, what if I add two-factor authentication (2FA) to my Discord account? Absolutely a good habit! But Discord Token has nothing to do with your account 2FA status. Once your account is breached, you should change your Discord password immediately to make the original Discord Token invalid.

For the question of how the hacker can get the Discord Token, we have figured out at least three major techniques, and we will try to explain it in detail in the future. For normal users, there are a lot that can be done, but the core points are: don't rush, don't be greedy, and verify from multiple sources.

#### "Official" phishing

The bad actors are good at taking advantage of role playing, especially the official role. For example we have mentioned the fake customer service method before. Besides that, in April 2022, many users of the well-known hardware wallet Trezor, received phishing emails from trezor.us, which is not the official Trezor domain trezor.io. There is a minor difference in the domain name suffix. What's more, the following domains were also spread via phishing emails.

> [https://suite.trẹzor.com](https://suite.tr%E1%BA%B9zor.com)

\<img src="res/trezor\_phishing.jpg" width="800">

This domain name has a "highlight spot", look closely at the letter ẹ in it, and you can find that is not the letter e. Confusing? It is actually Punycode, the standard description is as below:

> A Bootstring encoding of Unicode for Internationalized Domain Names in Applications (IDNA) is an internationalized domain name encoding that represents a limited set of characters in both Unicode and ASCII codes.

If someone decode trẹzor, it looks like this: xn-trzor-o51b, which is the real domain name!

Hackers have been using Punycode for phishing for years, back in 2018, some Binance users were compromised by the same trick.

These kinds of phishing sites can already make many people fall, not to mention those more advanced attacks such as official mailbox getting controlled, or mail forgery attacks caused by SPF configuration issues. As a result, the source of the email looks exactly the same as the official one.

If it is a rogue insider, the user can do nothing. project teams should put a lot of effort into preventing insider threats. Insiders are the biggest Trojan horse, but they very often get neglected.

#### Web3 Privacy Issues

With the growing popularity of Web3, more and more interesting or boring projects appeared: like all kinds of Web3 infrastructures, social platforms, etc. Some of them have done massive data analysis and identified various behavioral portraits of the targets, not only on the blockchain side, but also on well-known Web2 platforms. Once the portrait comes out, the target is basically a transparent person. And the appearance of Web3 social platforms may also aggravate such privacy issues.

Think about it, when you play around with all these Web3-related things, such as signature binding, on chain interactions, etc., are you giving away more of your privacy? Many might not agree, but as many pieces come together there will be a more accurate & comprehensive picture: which NFTs you like to collect, which communities you joined, which whitelists you're on, who you're connected with, which Web2 accounts you're bound to, what time periods you're active in, and so on. See, blockchain sometimes makes privacy worse. If you care about privacy, you will have to be careful with everything newly emerged and keep the good habit of segregating your identity.

At this point, if the private key is accidentally stolen, the loss is not as simple as just money, but all the carefully maintained Web3 rights and interests. We often say that the private key is the identity, and now you have a real ID problem.

Never test human nature.

## Blockchain Shenanigans

Blockchain technology created a whole new industry. Whether you call it BlockFi, DeFi, cryptocurrency, virtual currency, digital currency, Web3, etc, the core of everything is still the blockchain. Most hype centered on financial activities, such as crypto assets, including non-fungible tokens (or NFT, digital collectible).

Blockchain industry is highly dynamic and fascinating, but there are just too many ways to do evil. The special characteristics of blockchain give rise to some rather unique evils, including and not limited to crypto theft, cryptojacking, ransomware, dark web trading, C2 attack, money laundering, Ponzi schemes, gambling, etc. I made a mind map back in 2019 for reference.

> <https://github.com/slowmist/Knowledge-Base/blob/master/mindmaps/evil_blockchain.png>

Meanwhile, the Veritas Protocol team has been maintaining and updating Veritas Protocol Hacked - a growing database for blockchain-related hacking activities.

> <https://hacked.veritasprotocol.io/>

This handbook has introduced many security measures, and if you can apply them to your own security, then congratulations. I won't elaborate too much on the blockchain shenanigans. If you are interested, you can learn it on your own, which is definitely a good thing, especially since new scams and frauds are continuously evolving. The more you learn, the better you can defend yourself and make this industry better.

## What to do When You get hacked

It is only a matter of time before you eventually get hacked. So what to do then? I'll simply cut straight to the chase. The following steps are not necessarily in order; there are times when you have to go back and forth, but the general idea is this.

### Stop Loss First

Stop loss is about limiting your loss. It can be broken down to at least two phases.

* The Immediate Action Phase. Act immediately! If you see hackers are transferring your assets, think no more. Just Hurry up and transfer the remaining assets to a safe place. If you have experience in front running trades, just grab and run. Depending on the type of asset, if you can freeze your assets on the blockchain, do it as soon as possible; if you can do on-chain analysis and find your assets are transferred into a centralized exchange, you can contact their risk control department.
* The Post-Action Phase. Once the situation is stabilized, your focus should be on making sure there would not be secondary or tertiary attacks.

### Protect The Scene

When you find that something is wrong, stay calm and take a deep breath. Do remember to protect the scene. Here are a few suggestions:

* If the accident happens on a computer, server or other devices connected to the Internet, disconnect the network immediately while keeping the devices on with power supply. Some people may claim that if it is a destructive virus, the local system files will be destroyed by the virus. They are right, however shutting down only helps if you can react faster than the virus...
* Unless you are capable of handling this by yourself, waiting for security professionals to step in for analysis is always the better choice.

This is really important as we have encountered quite a few times that the scene was already in a mess by the time we stepped in to do the analysis. And there were even cases when key evidence (e.g. logs, virus files) appeared to have been cleaned up. Without a well-preserved crime scene, it can be extremely disruptive to the subsequent analysis and tracing.

### Root Cause Analysis

The purpose of analyzing the cause is to understand the adversary and output the hacker's portrait. At this point, the incident report is very important, which is also called Post Mortem Report. Incident Report and Post Mortem Report refer to the same thing.

We have met so many people who came to us for help after their coins were stolen, and it was very difficult for many of them to clearly tell what happened. It's even harder for them to produce a clear incident report. But I think this can be practiced and it would be helpful by referring to examples. The following can be a good starting point:

* Summary 1: Who was involved, when did this happen, what has happened, and how much was the total loss?
* Summary 2: The wallet addresses related to the loss, the wallet address of the hacker, the type of the coin, the quantity of the coin. It could be much clearer with the help of just a single table.
* Process description: this part is the most difficult. You will need to describe all aspects of the incident with all the details, which is useful to analyze various kinds of traces related to the hacker and eventually get the hacker portrait from them (including the motivation)

When it comes to particular cases, the template will be much more complex. Sometimes human memory can also be unreliable, and there is even a deliberate concealment of key information which can lead to wasted time or delayed timing. So in practice, there would be a huge consumption and we need to use our experience to guide the work well. Finally we produce an incident report with the person or the team who lost the coins, and continue to keep this incident report updated.

### Source Tracing

According to Rocca's Law, where there is an invasion, there is a trail. If we investigate hard enough, we will always find some clues. The process of investigation is actually forensic analysis and source tracing. We will trace the sources according to the hacker portrait from the forensic analysis, and constantly enrich it, which is a dynamic and iterative process.

Source tracing consists of two main parts:

* On-chain intelligence. We analyze the asset activities of the wallet addresses, such as going into centralized exchanges, coin mixers, etc., monitor it and get alerts of new transfers.
* Off-chain intelligence: this part covers the hacker's IP, device information, email address and more information from the correlation of these associated points, including behavioral information.

There is plenty of source tracing work based on this information, and it would even require the involvement of law enforcement.

### Conclusion of Cases

Of course we all want a happy ending, and here are some examples of publicly-disclosed events that we have involved which have good results:

* Lendf.Me, Worth of $25 million
* SIL Finance, Worth of $12.15 million
* Poly Network, Worth of $610 million

We have experienced many other unpublished cases that ended in good or okay results. However most of them had bad endings, which is quite unfortunate. We've gained a lot of valuable experiences in these processes and we hope to raise the ratio of good endings in the future.

This part is briefly mentioned as above. There is a huge amount of knowledge related to this area and I'm not quite familiar with some of it. Thus, I'm not going to give a detailed explanation here. Depending on the scenario, the abilities we need to master are:

* Smart Contract Security Analysis and Forensics
* Analysis and forensics of on-chain fund transfers
* Web Security Analysis and Forensics
* Linux Server Security Analysis and Forensics
* Windows Security Analysis and Forensics
* macOS Security Analysis and Forensics
* Mobile Security Analysis and Forensics
* Malicious code analysis and forensics
* Security analysis and forensics of network devices or platforms
* Insider security analysis and forensics
* ...

It covers almost every aspect of security and so does this handbook. However, those security points are only briefly mentioned here as an Introductory guide.

## Misconception

From the very beginning, this handbook tells you to stay skeptical! This includes everything mentioned in here. This is an extremely vibrant and promising industry, full of all kinds of traps and chaos. Here let's take a look at some of the misconceptions, which, if taken for granted as truth, can easily make you fall into the traps and become part of the chaos itself.

### Code Is Law

Code is law. However, when a project (especially smart contract related ones) gets hacked or rugged, no single victim would ever wish for "Code Is Law", and it turns out they still need to rely on the law in the real world.

### Not Your Keys, Not Your Coins

If you don't own your keys, you don't own your coins. As a matter of fact, many users failed to properly manage their own private keys. Due to various security mispractices they even lose their crypto assets. Sometimes you will find that it's actually more secure to put your crypto asset in big and reputable platforms.

### In Blockchain We Trust

We trust it because it's blockchain. In fact, blockchain itself does have the capability to solve many of the fundamental trust issues, since it's tamper-proof, censorship-resistant, etc; if my asset and related activities are on chain, I can trust by default that no one else will be able to take away my asset or tamper with my activity without authorization. However the reality is often harsh, firstly not every blockchain is able to achieve these fundamental points, and secondly human nature always becomes the weakest link. Many of the hacking techniques nowadays are beyond the imagination of most of us. Though we always say that attack and defense is the balance between cost and impact, when you don't own a big asset no hacker will waste time to target you. But when there are multiple targets like yourself, it will be very profitable for the hackers to launch the attack.

My security advice is very simple: Distrust by default (that is, question everything by default), and conduct continuous verification. Verify is the key security action here, and continuous verification basically means that security is never in a static state, it's secure now doesn't mean it's secure tomorrow. The capability to properly verify is hereby the biggest challenge for us all, but it's quite interesting, as you will get to master a lot of knowledge in the process. When you are strong enough, no one can easily harm you.

### Cryptographic Security is Security

Cryptography is powerful and important. Without all the hard work of cryptographers, all the solid cryptographic algorithms & engineering implementations, there will be no modern communications technology, Internet, or blockchain technology. However, some individuals consider cryptographic security as absolute security. And thus a bunch of weird questions arises:

Isn't blockchain so secure, that it took trillions of years to break a private key? How come the FBI could decrypt Dark Web Bitcoin? Why on earth could my NFT get stolen?

I can bear with these novice questions... what I can't bear with is the fact that many so-called security professionals use cryptographic security concepts to fool the public, they are mentioning terms such as military-grade encryption, world's best encryption, cosmic-level encryption, absolute system security, unhackability, etc.

Hackers? They don't give a shit...

### Is it humiliating to be hacked?

It is true that getting hacked can bring mixed feelings, and there will be a sense of shame sometimes. But you need to understand that getting hacked is almost 100% guaranteed so there is nothing to be ashamed of.

Once getting hacked, it doesn't matter if you are only responsible for yourself. However, if you are responsible for many others, you have to be transparent and open when you are dealing with the incident.

Although people may question or even accuse you of staging the hack by yourself, a transparent and open updated process will always bring good luck and understanding.

Think of it this way: if your project isn't well-known, no one will hack you. The shame is not being hacked; the shame is your arrogance.

From a probability point of view, getting hacked is a common phenomenon, normally, the majority of the security issues are just small problems, which could help your project grow. However, the severe big problems still have to be avoided as much as possible.

### Immediately Update

For many times this guide suggests to pay attention to updating. If there is a security update available, apply it immediately. Now think carefully, is this a silver bullet?

Actually, in most cases, "update now" is the right thing to do. However, there have been times in history when an update solves one problem but introduces another. An example is iPhone and Google Authenticator:

There was a risk of the iOS 15 update, that the information in Google Authenticator may be wiped or doubled after the iPhone upgrade. In this case, never delete the duplicate entries if you find that they are doubled, as it may cause the loss of all the information in Google Authenticator after reopening.

For those who have not upgraded to the iOS 15 system and are using Google Authenticator, it is highly recommended to back it up before upgrading.

Later, Google has updated the Authenticator app, solving this problem permanently.

Besides, I don't recommend updating wallets frequently, especially for asset-heavy wallets, unless there is a major security patch, or a very important feature that leads to an inevitable update. In which cases you will have to do your own risk assessment and make your own decision.

## Conclusion

Recall that this guide starts with this diagram :)

Have you noticed that I have marked in red the person in the diagram? I do so to remind everybody again that humans are the foundation of all (referred to as "anthropic principle" in cosmology). No matter if it's human nature security, or the ability to master security skills, it all depends on you. Yes, when you are strong enough, no one can easily harm you.

I started to expand based on the diagram, and explained many security key points in the three processes, creating wallet, backing up wallet and using wallet. Then I introduced traditional privacy protection. I stated that such traditional ones are the cornerstones and the building blocks for us to stay secure in blockchain ecosystems. The human nature security part cannot be overdressed. It's good to understand more about the various ways of doing evil, especially if you step into a few pits, the security awareness on paper may eventually become your security experience. There is no absolute security, so I explained what to do when you get hacked. I don't want an unfortunate event to happen to you, but in case it happens, I hope this handbook could help you. The last thing is to talk about some misconceptions. My intention is very simple, I hope you can build up your own critical thinking, because the world is both beautiful and terrible.

When you have finished reading this guide, you must practice, become proficient and draw inferences. When you have your own discovery or experience afterwards, I hope you will contribute. If you feel there is sensitive information you can mask them out, or anonymise the information.

Finally, thanks to the global maturity of security and privacy-related legislation and enforcement; thanks to the efforts of all the pioneering cryptographers, engineers, ethical hackers and all those involved in the creation of a better world, which includes Satoshi Nakamoto.

## Appendix

### Security rules and principles

The security rules and principles mentioned in this handbook are summarized as follows. Quite a few rules are being incorporated into the above text and will not be specifically refined here.

Two major security rules:

* **Zero trust**. To make it simple, stay skeptical, and always stay so.
* **Continuous validation**. In order to trust something, you have to validate what you doubt, and make validating a habit.

Security principles:

* For all the knowledge from the Internet, refer to at least two sources, corroborate each other, and always stay skeptical.
* Segregate. Don't put all the eggs in one basket.
* For wallets with important assets, don't do unnecessary updates.
* What you see is what you sign. You need to be aware of what you are signing, and of the expected result after the signed transaction is sent out. Don't do things that will make you regret afterwards.
* Pay attention to system security updates. Apply them as soon as they are available.
* Don't download & install programs recklessly can actually prevent most risks.

### Official Sites

```
Veritas Protocol https://www.veritasprotocol.com
CoinMarketCap https://coinmarketcap.com/
Sparrow Wallet https://sparrowwallet.com/
MetaMask https://metamask.io/
imToken https://token.im/
Trust Wallet https://trustwallet.com/
TokenPocket https://www.tokenpocket.pro/
Gnosis Safe https://gnosis-safe.io/
ZenGo https://zengo.com/
Fireblocks https://www.fireblocks.com/
Safeheron https://www.safeheron.com/
Keystone https://keyst.one/
Trezor https://trezor.io/
OneKey https://onekey.so/
imKey https://imkey.im/
Rabby https://rabby.io/
OKX Wallet https://www.okx.com/web3
EdgeWallet https://edge.app/
MyEtherWallet https://www.myetherwallet.com/
Phantom https://phantom.app/
Tornado Cash https://tornado.cash/
Binance https://www.binance.com/
Coinbase https://coinbase.com
Compound https://compound.finance/
SushiSwap https://www.sushi.com/
OpenSea https://opensea.io/
Revoke.cash https://revoke.cash/
Scam Sniffer https://www.scamsniffer.io/
Wallet Guard https://www.walletguard.app/
Pocket Universe https://www.pocketuniverse.app/

Jike App https://okjike.com/
Kaspersky https://www.kaspersky.com.cn/
Bitdefender https://www.bitdefender.com/
Cloudflare https://www.cloudflare.com/
Akamai https://www.akamai.com/
SURVEILLANCE SELF-DEFENSE https://ssd.eff.org/
Privacy Guide https://www.privacytools.io/
OpenPGP https://www.openpgp.org/
GPG https://gnupg.org/
GPG Suite https://gpgtools.org/
Gpg4win https://www.gpg4win.org/
1Password https://1password.com/
Bitwarden https://bitwarden.com/
Google Authenticator https://support.google.com/accounts/answer/1066447
Microsoft Authenticator https://www.microsoft.com/en-us/security/mobile-authenticator-app
ProtonMail https://protonmail.com/
Tutanota https://tutanota.com/
VMware Workstation https://www.vmware.com/products/workstation-pro.html
Parallels https://www.parallels.com/
```


# Understanding Known-Plaintext Attacks and How to Prevent Them

A known-plaintext attack (KPA) occurs when an attacker uses pairs of plaintext and corresponding ciphertext to uncover the encryption algorithm or key.

**Key Concept**

In a KPA, the attacker has access to both the original plaintext and its encrypted form. By analyzing these pairs, the attacker identifies patterns that reveal the encryption method or key.

For example, if the word "blockchain" encrypts to "eorfnfkdlq," this pair can help the attacker decode other ciphertexts encrypted with the same key.

**Exploitation of Weaknesses**

Known-plaintext attacks exploit vulnerabilities in encryption systems. Two common techniques are:

* **Frequency Analysis:** Simple substitution ciphers map each letter or symbol to a fixed counterpart. Attackers analyze letter frequencies in plaintext and ciphertext to deduce the key.
* **Pattern Matching:** Repeated patterns in plaintext and ciphertext reveal trends that attackers can use to identify the encryption algorithm and decrypt messages.

**How a Known-Plaintext Attack Works**

Attackers reverse-engineer encryption methods using known plaintext-ciphertext pairs. Access to more pairs increases the likelihood of success. Here’s an example using the "blockchain" and "eorfnfkdlq" pair:

1. **Collecting Known Pairs:** Attackers gather plaintext-ciphertext pairs from intercepted data, leaks, or other sources.
2. **Analyzing Patterns:** They compare plaintext and ciphertext to identify transformation patterns, such as letter shifts or substitutions.
3. **Guessing the Cipher:** By analyzing transformations, attackers hypothesize the encryption algorithm. For example, a Caesar cipher shifts letters by a fixed number of positions.
4. **Breaking the Encryption:** Once the encryption method is identified, attackers decrypt other messages or future communications using the same method or key.

**Comparison: Known-Plaintext vs. Chosen-Plaintext Attacks**

* **Known-Plaintext Attack (KPA):** The attacker already has plaintext-ciphertext pairs and analyzes them.
* **Chosen-Plaintext Attack (CPA):** The attacker selects plaintext, encrypts it, and studies the resulting ciphertext.

### **Defense Strategies**

To prevent known-plaintext attacks, adopt the following practices:

1. **Use Strong Encryption Algorithms:** Algorithms like Advanced Encryption Standard (AES) prevent plaintext patterns from correlating with ciphertext. AES is a widely used symmetric encryption method known for security and efficiency.
2. **Secure Key Management:** Store keys in secure repositories, rotate them regularly, and use strong key generation techniques.
3. **Encrypt Entire Data Sets:** Avoid encrypting predictable or discrete data chunks to reduce exposure to known-plaintext analysis.
4. **Session-Specific Keys:** Use unique encryption keys for different sessions to minimize risk if one key is compromised.
5. **Add Randomness:** Include cryptographic salts or random values before encrypting plaintext. This ensures unique ciphertexts for identical plaintexts.
6. **Update Systems Regularly:** Maintain up-to-date software and libraries to address vulnerabilities.
7. **Avoid Weak Encryption Methods:** Choose algorithms resistant to known-plaintext attacks.

Known-plaintext attacks highlight the importance of robust encryption practices. Strong algorithms, secure key management, and randomness in encryption processes are critical to maintaining data security.


# Asset Audit

Security Checkup for Token

**For who:**&#x20;

* Investors and users who want to investigate projects before they commit.

**Flow:**&#x20;

* It is designed to assist users in identifying potential rug pull scams by providing an in-depth analysis of a smart contract's code and highlighting any potential red flags that may indicate a scam.
* Support for 14 chains.

**Deliverables:**

* Detailed report on token contract source code.
* Assessment of on-chain metrics (top holders, liquidity, etc.).
* Scan results with token score.

<br>


# Transaction Shield

Stop, Scan, Secure: Anti-Scam Chrome Extension

**For who:**&#x20;

* Users initiating transactions seeking assurance against scams and malicious contracts.

**Flow:**&#x20;

* Performs a series of security checks from domain verification to simulating transactions to identify risks before the transaction is confirmed.

**Deliverables:**

* Domain check results to avoid fake project websites.
* Contract check status based on openness of source code.
* Simulation results for detecting unauthorized token transfers.
* Address check report on suspicious address behaviors.
* Malicious code detection and risk alerts.
* Sign check against malicious sign-requests.
* Verification for transaction initiation.

<br>

<br>


# AML Crypto Tracker

Combatting Cryptocurrency Money Laundering

**For who:**

* **Regulatory bodies and financial institutions** looking for robust tools to monitor and regulate digital asset movements.
* **Crypto exchanges and fintech companies** aiming to enhance their compliance with global AML regulations.
* **Investors and users** desiring to perform due diligence on crypto transactions and addresses for enhanced security.

**Flow:** The AML Crypto Tracker is designed to meticulously track and analyze transactions across multiple blockchain networks to identify and report suspicious activities. It utilizes an extensive database of addresses linked to known illicit activities, providing crucial insights into transaction flows and patterns.

**Support for 11 chains:**\
Currently supports major networks like Bitcoin, Ethereum, BNB Smart Chain (BSC), TRON, IoTeX, Avalanche, Polygon, Arbitrum One, Base, Optimism, and Merlin chain, with plans to expand to additional networks soon.

**Deliverables:**

* **Comprehensive AML Reports:** Detailed insights into transaction histories, with specific focus on addresses flagged for potential AML risks.
* **Threat Intelligence Analysis:** Access to a database of 500K Threat Intelligence addresses and over 90M addresses associated with malicious activities.
* **Entity Tracking:** Tracks thousands of addresses linked to various entities, enhancing the ability to monitor and understand complex transaction networks.

This tool not only assists in ensuring compliance with AML regulations but also empowers users and institutions to proactively prevent potential risks associated with money laundering activities in the cryptocurrency space.


# Real-Time DeFi Guardian

Contract Monitoring & Compliance

**For who:**&#x20;

* Protocols&#x20;
* Bridges&#x20;
* Chains&#x20;
* Asset Managers&#x20;
* DAOs&#x20;
* Web3 Apps&#x20;
* Wallet Providers&#x20;
* ... looking to prevent fund losses for their end-users.

**Flow:**&#x20;

* Leveraging machine learning for real-time detection of phishing campaigns, fraudulent dApps, malicious transactions, scam projects, malicious governance proposals and more.&#x20;

**Deliverables:**

* Real-time alerts on security issues and compliance deviations.
* Continuous compliance status reports.

-> Phishing, fraud and scams detection

->  Exploits and hacks detection&#x20;

->  Smart contracts risk analysis&#x20;

->  Governance proposal analysis

->  Privacy preserving blocklists

<br>


# Smart Contract Bug Hunter

AI-Powered Contract Vulnerability Detection

**For who:**&#x20;

* Developers and audit teams aiming to identify and fix vulnerabilities in smart contracts.

**Flow:**&#x20;

* Utilizes supervised and unsupervised machine learning models to analyze smart contracts for known and potential vulnerabilities.

**Deliverables:**

* List of detected vulnerabilities with severity ratings.
* Recommendations for mitigation and enhancement of contract security.

<br>

<br>

<br>


# Automated Audit Reports

Streamlined Full Audit Results

**For who:**&#x20;

* Smart contract developers needing fast, comprehensive and understandable audit results.

**Flow:** &#x20;

* Applies NLP and deep learning to automatically generate detailed audit reports from the analysis of contract code and comments, all in clear and understandable language.

**Deliverables:**

* Comprehensive audit reports highlighting security concerns.
* Suggested optimizations for efficiency and compliance.
* Issuing an SoulBound Audit Token (SAT).

<br>


# Veritas Explorer (B2C)

<figure><img src="/files/opECoin7Sl62B4ClWVss" alt=""><figcaption></figcaption></figure>

### Risk Scanning

Risk scanner enables users to perform in-depth asset and smart contract analyses across multiple blockchain networks with ease and speed.

Key features:

* Multi-chain compatibility: Scan assets and contracts on various blockchain networks seamlessly.
* Rapid analysis: Deliver results within seconds, ensuring real-time protection.
* Concise reporting: Provide easy-to-understand analysis reports, breaking down complex security concepts into accessible information.
* Broad coverage: Examine a wide range of potential vulnerabilities and risks associated with digital assets and smart contracts.

This tool democratizes blockchain security, allowing even non-technical users to make informed decisions about their digital assets and interactions with smart contracts.&#x20;

### Advanced Threat Detection

Advanced Threat Detection system serves as a proactive shield against a wide array of malicious activities in the blockchain space. This feature leverages machine learning algorithms to identify and mitigate potential threats before they can cause harm.

Key capabilities:

* Phishing campaign detection: Identify and flag suspicious websites and communications attempting to steal user credentials or assets.
* Fraudulent dApp identification: Analyze decentralized applications to detect those with malicious intent or vulnerabilities.
* Scam project recognition: Utilize pattern recognition and behavioral analysis to identify potential scam projects before they can attract victims.
* Real-time monitoring: Continuously scan the blockchain ecosystem for emerging threats and new attack vectors.
* Predictive analysis: Use historical data and AI to anticipate potential future threats and vulnerabilities.

By providing users with early warnings and detailed threat assessments, this feature significantly reduces the risk of falling victim to blockchain-related scams and frauds.&#x20;

### Digital Footprint Checker

Digital footprint checker is an advanced tool designed to provide users with a comprehensive overview of their internet presence and activity. This feature is offering deep insights into a user's digital identity and interactions across the web.

Key functionalities:

* DIgita footprint analysis: Automatically enumerate a user's digital presence across various platforms and websites.
* Wallet address profiling: Collect and analyze linked address labels, providing a detailed characterization of wallet activity.
* ENS name integration: Incorporate Ethereum Name Service data for a more human-readable and comprehensive profile.
* Behavioral analysis: Examine transaction patterns, timing, and involved entities to build a detailed picture of user activity.
* Risk assessment: Identify potential security risks based on historical interactions and connections.

This tool serves dual purposes. For individual users, it offers unprecedented visibility into their own web activities, helping them understand their digital footprint and identify any potential security risks. For investigators and security professionals, it provides a powerful means of tracking and analyzing the activities of potential threat actors.

### Advanced Forensics

Veritas Protocol's forensics tool is a sophisticated system designed for in-depth investigation of cryptocurrency transactions and movements. This feature combines on-chain and off-chain data analysis to provide a comprehensive view of digital asset flows and interactions.

Key capabilities:

* Transaction tracing: Follow the path of cryptocurrency transactions across multiple wallets and exchanges.
* Cross-chain analysis: Track assets as they move between different blockchain networks.
* Temporal mapping: Visualize transaction timelines to identify patterns and anomalies.
* Entity identification: Link transactions to known entities, including exchanges, mixers, and other services.
* Off-chain data integration: Incorporate relevant off-chain data sources to provide context and enhance investigative capabilities.
* Anomaly detection: Utilize machine learning algorithms to flag unusual transaction patterns or behaviors.

This powerful forensics tool is invaluable for a range of users, from individual investors tracking their own assets to law enforcement agencies investigating financial crimes.&#x20;


# Veritas Audit (B2B)

<figure><img src="/files/tbDlTJGKBGxBCRVWgsTW" alt=""><figcaption></figcaption></figure>

### Automated, 24/7 Audits

Veritas Protocol's automated audit system leverages advanced AI and machine learning technologies to provide continuous, high-speed auditing of smart contracts and blockchain projects.

Key benefits:

* Rapid auditing: Conduct security audits 10 times faster than traditional methods, allowing for quick deployment and iteration of smart contracts.
* Cost-effective: Reduce audit costs by up to 90%, making comprehensive security measures accessible to projects of all sizes.
* Continuous monitoring: Perform automated security checks around the clock, ensuring constant protection against emerging vulnerabilities.
* Minimal manual intervention: Streamline the auditing process, freeing up developer resources for innovation and improvement.
* Immutable audit records: Issue non-transferable audit tokens as permanent proof of a project's security status and credibility.

By providing fast, affordable, and continuous auditing, Veritas enables projects to maintain the highest levels of security without compromising on innovation or speed to market.

### AI Debugger

The AI Debugger is Veritas Protocol's cutting-edge solution for real-time smart contract debugging and optimization. This feature deploys autonomous AI agents that work collaboratively to review smart contract code, identify potential issues, and even implement fixes on the fly.

Key capabilities:

* Real-time analysis: Continuously monitor smart contract behavior to detect anomalies or potential vulnerabilities as they emerge.
* Autonomous debugging: AI agents identify and diagnose issues in smart contract code without human intervention.
* Predictive maintenance: Anticipate potential future issues based on code structure and historical data.
* Automated fix suggestions: Generate and propose code fixes for identified vulnerabilities or inefficiencies.
* Learning and adaptation: Continuously improve debugging capabilities through machine learning, staying ahead of emerging threat vectors.
* Integration with development workflows: Seamlessly incorporate AI debugging into existing smart contract development and deployment processes.

The AI Debugger represents a significant advancement in smart contract security and efficiency. By providing real-time, autonomous debugging capabilities, it allows developers to focus on innovation while ensuring their smart contracts remain secure and optimized.&#x20;

### Insurance Against Exploits

Veritas protocol's insurance system offers a solution to one of the most significant risks in the blockchain space: financial losses due to smart contract vulnerabilities and exploits. This feature provides a safety net for projects and their users, boosting trust and stability in the decentralized finance ecosystem.

Key features:

* Comprehensive coverage: Protect against financial losses resulting from smart contract vulnerabilities and exploits.
* Risk assessment: Utilize advanced analytics to accurately price insurance premiums based on contract complexity and potential vulnerabilities.
* Rapid claim processing: Smart contract-based claim verification and payout systems for quick resolution of valid claims.
* Ecosystem stability: Contribute to the overall resilience of the DeFi landscape by mitigating the impact of potential exploits.
* Customizable plans: Offer flexible coverage options to suit the needs and risk profiles of different projects.

This insurance feature represents a crucial step towards maturity and mainstream adoption of blockchain technologies, addressing one of the key concerns that has held back wider institutional and retail participation in the space.


# Private Security Audit

AI Checks, Human Audits

**For who:**

* Projects with stable quality code and detailed documentation.

**Flow:**&#x20;

* AI audit.&#x20;
* Вug Fixing.
* Manual audit.&#x20;
* Final audit (Deployment verification).&#x20;
* Issuing a Public Report.

**Deliverables:**&#x20;

* Comprehensive code check.
* Suggested optimizations for efficiency and compliance.
* Issuing an SoulBound Audit Token (SAT).


# Security Audit Methodology

A group of security engineers are involved in working on the audit. The security engineers check the provided source code independently of each other in accordance with the methodology described below:

### 1. Project architecture review

* Project documentation review.
* General code review.
* Reverse research and study of the project architecture based on the source code alone.

Stage goals:

* Build an independent view of the project's architecture.
* Identify logical flaws.

### 2. Checking the code in accordance with the vulnerabilities checklist

* Manual code check for the vulnerabilities listed on the Contractor's internal checklist. The Contractor's checklist is constantly updated based on the analysis of hacks, research, and audit of the clients' codes.
* Code check with the use of static analyzers (i.e., Slither, Mythril, etc.).

Stage goal:

* Eliminate typical vulnerabilities (e.g., reentrancy, gas limit, flash loan attacks, etc.).

### 3. Checking the code for compliance with the desired security model

* Detailed study of the project documentation.
* Examination of contracts tests.
* Examination of comments in the code.
* Comparison of the desired model obtained during the study with the reversed view obtained during the blind audit.
* Exploits PoC development with the use of such programs as Brownie and Hardhat.

Stage goal:

* Detect inconsistencies with the desired model.

### 4. Consolidation of the auditors' interim reports into one

* Cross-check: each auditor reviews the reports of the others.
* Discussion of the issues found by the auditors.
* Issuance of an interim audit report.

Stage goals:

* Double-check all the found issues to make sure they are relevant and the determined threat level is correct.
* Provide the Customer with an interim report.

### 5. Bug fixing & re-audit

* The Customer either fixes the issues or provides comments on the issues found by the auditors. Feedback from the Customer must be received on every issue/bug so that the Contractor can assign them a status (either "fixed" or "acknowledged").
* Upon completion of bug fixing, the auditors double-check each fix and assign it a specific status, providing a proof link to the fix.
* A re-audited report is issued.

Stage goals:

* Verify the fixed code version with all the recommendations and its statuses.
* Provide the Customer with a re-audited report.

### 6. Final code verification and issuance of a public audit report

* The Customer deploys the re-audited source code on the mainnet.
* The Contractor verifies the deployed code with the re-audited version and checks them for compliance.
* If the versions of the code match, the Contractor issues a public audit report.

Stage goals:

* Conduct the final check of the code deployed on the mainnet.
* Provide the Customer with a public audit report.


# SoulBound Audit Token

Soulbound NFT Certificates as Proof-of-Audit

While auditing is undoubtedly a critical first step in securing a smart contract, the reality is that the challenge doesn’t end there. The audit reports, often detailed and technical, may not be easily accessible or understandable to the average user or investor. How can we bridge this gap? How can we make these technical audit reports understandable to anyone using smart contracts? This forms the problem that SoulBound Audit Tokens (SATs) aims to solve!&#x20;

SAT act as an on-chain certification system, a Proof-of-Audit, establishing a level of trust and transparency that has been notably absent in the smart contracts security industry. By providing a visible, color-coded security rating directly on the blockchain, SATs make it simpler for users to understand the security level of a smart contract, enabling them to engage with confidence.

Notably, the SAT provides key information about the audit score and links to the full audit report right within the blockchain itself.

**Three-Level Certification**

SAT offers a three-tiered certification system to make the security level of smart contracts instantly recognizable. Each class is visually distinct and color-coded to provide an immediate understanding of the smart contract’s security status. Below are the specifics:

**High-Security Certifications**

* **Color:** Gree&#x6E;**.**
* **Implication:** The contract is highly secure, with minimal to no vulnerabilities detected.
* **Decentralization Grades**: Decentralized/Semi-Centralized/Centralized.

**Medium-Security Certifications**

* **Color:** Yellow.
* **Implication:** The smart contract has passed the audit, but some areas could benefit from further optimization. It is considered safe, but with reserves, often linked to the owner’s privileges.
* **Note:** Users should read the full audit report for detailed insights.
* **Decentralization Grades**: Decentralized/Semi-Centralized/Centralized.

**Low-Security Certifications**

* **Color:** Red.
* **Implication:** The smart contract has undergone an audit and has significant vulnerabilities or areas requiring immediate attention. A list of critical recommendations for improvement often accompanies this rating.
* **Note:** It is advised to proceed with extreme caution and await updates or fixes before interacting with such contracts.
* **Decentralization Grades**: Decentralized/Semi-Centralized/Centralized.

<figure><img src="/files/z7vyoRD3DKFypw2B6vQx" alt=""><figcaption><p> SoulBound Audit Tokens</p></figcaption></figure>

Each contract will display both a color-coded security rating and a label for decentralization, making it easier for users to make informed decisions when interacting with smart contracts.


# Add-Ons

Additional Services

* Blockchain development.&#x20;
* Deployment scripts verification.&#x20;
* Monitoring system design and implementation.&#x20;
* Validation of the project and assessment of possible risks.&#x20;
* Preparation of AI models according to monitoring system design.&#x20;
* Verification of the deployed contracts (e.g. all initialization parameters check, check of the migration to another implementation of upgradeable contract, etc.).&#x20;
* Delivering additional security research tasks from the customer aimed at increasing overall system security, availability and decentralization.
* ...


# Predictive Threat Intelligence

The Future of DeFi Security

**For who:**&#x20;

* Project teams and security officers aiming to preemptively address potential threats.

**Flow:**&#x20;

* Analyzes historical data and current trends to forecast future security challenges and provides actionable insights.

**Deliverables:**

* Predictive analytics dashboard with future threat forecasts.
* Strategic recommendations to preempt potential vulnerabilities.

<br>


