以太坊地址投毒攻击剖析:资金机制、诈骗特征与通过Tornado Cash的洗钱行为
The Anatomy of Address Poisoning on Ethereum: Funding Mechanisms, Scam Signatures, and Laundering via Tornado Cash
浏览论文内容
中文总结 AI 辅助
本研究剖析以太坊地址投毒诈骗的资金机制、五类诈骗特征及通过Tornado Cash洗钱行为,为地址聚类和反洗钱提供新视角。
中文摘要 AI 辅助
地址投毒转账(APT)是一种普遍存在的区块链钓鱼诈骗,诈骗者通过生成一笔包含钓鱼地址的转账来污染受害者的地址簿,该钓鱼地址与受害者之前交互过的良性地址外观相似。尽管APT钓鱼攻击手法简单,但近年来已导致用户损失数百万美元,引起了研究界的关注(Ye等人,WWW'24;Guan-Li,CCS'24;Chen等人,NDSS'25;Tsuchiya等人,USENIX'25)。在本工作中,我们超越了检测层面,研究了APT三个重要且尚未充分探索的方面:诈骗资金机制、诈骗特征以及通过公共服务进行的诈骗收益洗钱。具体而言,我们提出了五类诈骗特征,这些特征捕捉了APT操作的关键方面,对地址聚类很有用。我们还首次调查了使用Tornado Cash为APT提供资金和清洗诈骗收益的情况。
英文摘要
Address-Poisoning Transfer (APT) is a prevalent blockchain phishing scam in which a scammer poisons a victim's address book by generating a transfer with a phishing address that looks similar to a benign address that the victim has previously interacted with. Although simple, APT phishing attacks have cost users millions of dollars in recent years, which has captured the attention of the research community (Ye et al. WWW'24, Guan-Li CCS'24, Chen et al. NDSS'25, Tsuchiya et al. USENIX'25). In this work, we go beyond detection and investigate three important and underexplored aspects of APT: scam funding mechanisms, scam signatures, and scam proceeds laundering via public services. In particular, we propose five families of scam signatures that capture key aspects of APT operations, which are useful for address clustering. We also conduct the first investigation into usage of Tornado Cash for funding APTs and laundering scam proceeds.
发表机构
- RMIT University(皇家墨尔本理工大学)
- CSIRO(澳大利亚联邦科学与工业研究组织)
机构由 AI 辅助整理,请以论文原文为准。