Before Ethereum made the "oracle problem" a household term, Bitcoin already had oracles serving as feeds, key-release services, federated signers, and arbiters that carried real value on the main chain. This study traces their use and the changing evidence of oracle activity from early days through July 2026. We combine a complete census of Counterparty betting (1,149 bets), analysis of the full Bitcoin chain through block 958,628, and searches for documented keys from Reality Keys, Orisi, Bitrated, and Oraclize in an 854-million-row public-key index. We also recover DLC oracle records from an archived explorer and live Nostr relays. Two results emerge. First, early contracts remain on-chain, but many event descriptions have disappeared, and protocol encoding and API limitations complicate access to the surviving record. However, for modern DLCs, public oracle announcements can survive even when the contracts using them cannot be identified on-chain. In the script classes examined, the share of spends that reveal no script peaks at 81.9% in 2024 after excluding spends containing inscription data. Second, public registries can give a misleading picture of oracle use. In Counterparty, 95% of pre-2018 sources declaring an oracle fee were never bet on. In Bitrated, 0.1% of archived keys appear on-chain overall, compared with 10 of 19 keys captured in 2014. Sport dominates Counterparty's matched volume, while a daily price series dominates the archived DLC announcements. These findings show how protocol design and data preservation shape the historical record of Bitcoin oracle use.
A person who answers an unexpected call claiming to come from a bank has no way to check the claim. Australian text messaging has labelled a message as unverified when the sender identifier is not registered since 1 July 2026, but a voice call still arrives with nothing behind it, and voice cloning has removed the last cue recipients relied on. We present BVI, which answers one question for the recipient: did the calling party prove it holds a credential a registered organisation issued for this call? BVI keeps the organisational record, its authorised channels and its revocation state on a public ledger in a directly queryable form, and puts all decision logic in the handset, which performs eleven checks, pays no transaction fee and holds no full-chain state. We define ten attack classes plus the case in which revocation cannot be resolved, compare them in a 10-by-4 coverage matrix spanning BBCA, the content digest, the detector and composed BVI, and run 27 automated scenario tests against isolated Hardhat fixture states of the BVI contract; all 27 pass. For media substitution and synthetic speech, the contract tests validate commitment and gating properties rather than claiming detector accuracy. The mandatory per-session anchor costs about 91.5k gas and is invariant in call duration and hop count; each participating intermediary additionally contributes one optional attestation write. In a 20,000-session-per-cell path simulation, at one quarter carrier participation BVI detects 20.6 per cent of randomly located in-path rewrites versus 0.1 per cent for the every-hop comparison, while identity and content evidence remain available even when path evidence is indeterminate. We also quantify the throughput ceiling of the anchoring design.
As enterprise blockchains become increasingly interconnected, access control must extend beyond the boundaries of a single network. Existing approaches mainly focus on controlling access within one blockchain, while cross-chain interactions involve multiple networks that may follow different access-control policies and administrative rules. In this paper, we propose InterAcct, an end-to-end access-control framework for secure interactions across permissioned blockchain networks. To avoid exposing sensitive internal information, InterAcct converts outgoing requests into a consortium-level representation before they are shared with another network. When a response is returned, the framework securely maps it back to the original requester within the source consortium, preserving confidentiality throughout the interaction. Our experimental results show that InterAcct can enforce end-to-end access control for cross-chain request-response interactions with low additional overhead and can continue to operate effectively as the workload increases.
Ethereum's electricity use fell by about 99.95% after the move from proof of work to proof of stake. Service providers still need to report operational energy use, e.g. under the EU Markets in Crypto-Assets Regulation (MiCAR). Existing estimates either apply one typical wattage to every node or start from aggregated monitoring counts. Both ignore attributes that nodes already advertise on the peer-to-peer network: client software, ARM or x86 hardware, hosting location, and validator role. We crawl the consensus and execution layers, assign each peer a wattage from those attributes using published measurements, and estimate the remaining incomplete peers with a Random Forest. On 6,934 peers from two Nebula crawls (19 and 22 June 2026), reachable nodes sum to 415 kW, or 3.63 GWh if that draw were held for a year. The same Lighthouse+Nethermind x86 wattage on every peer yields 431 kW. Observed attributes lower the total by 3.9%, mainly because nodes at Hetzner and other non-AWS clouds draw less than that home-desktop figure. AWS accounts for 15.6% of watts from 12.2% of peers, and validator-flagged nodes for 31.4% of watts from 25.7% of peers. The 415 kW snapshot is about 46% of the Cambridge Centre for Alternative Finance (CCAF) estimate of about 0.90 MW. Both use about 60 W per node, so the gap is mostly how many nodes each estimate includes. Rules cover 3,110 peers and the forest the other 3,824. On held-out labeled peers with client, architecture, and OS hidden, the forest's mean absolute error against the rule wattage is 4.3 W. Twenty-four-hour measurements on a gaming desktop differ from the predictions. After subtracting a 33 W idle graphics card that Ethereum clients do not need, both differences fall to about 19%.
As the dominant trading mechanism in decentralized finance, Automated Market Maker has been widely studied in research. However, limited research has been done with the trading fees taken into consideration. In this work, we study how much trading fee Liquidity Providers(LPs) can receive from arbitrage trading when the fee rate approaches zero. We give a closed-form formula for it and our result shows that the trading fees generated by arbitrage trading can fully offset the LVR loss when the price process is continuous. We further extend our conclusions to price processes with jumps and the theoretical analysis shows that jumps are the only cause of LP loss apart from market risks. Our results provide practical guidance for AMM designers as well as LPs.
While the literature on blockchain-assisted intrusion detection and prevention systems (IDS/IPS) for Internet of Things (IoT) and Industrial Internet of Things (IIoT) networks is mature, existing systematic reviews suffer from two critical limitations: they overlook the structural shift toward modern Endpoint Detection and Response (EDR) and Extended Detection and Response (XDR) architectures, and they conflate blockchain's distinct functional roles into a single monolithic category. This Systematization of Knowledge (SoK) addresses these gaps by proposing a three-axis taxonomy that classifies proposals by detection-system class (NIDS, HIDS, EDR/XDR), blockchain functional role, and response-automation maturity. Synthesizing research published in high-impact venues between 2019 and 2026, we provide a rigorous gap analysis exposing why a genuine per-endpoint blockchain-anchored response loop remains nearly nonexistent due to latency, deployment, and community mismatches. Furthermore, we evaluate structural, cross-cutting challenges persisting across the literature, including consensus latency on constrained devices, post-quantum cryptographic vulnerability, smart-contract attack surfaces, and the adversarial vulnerability of evolving LLM-based detection engines. Finally, we outline a comprehensive research agenda centered on hybrid on-chain/off-chain orchestration to bridge the gap between decentralized trust and rapid response automation.
Decentralized finance (DeFi) vaults are smart-contract-based asset management systems that pool deposits, execute programmable strategies, and mint tokenized shares representing claims on underlying assets and strategy performance. As vault designs have evolved from early yield aggregators to modular, actively managed systems, a new control layer, curation, has emerged to select strategies, configure risk parameters, and coordinate operational execution, introducing principal-agent dynamics and new failure modes. This paper systematizes DeFi vault architectures and curator-mediated control planes through (i) a unified system model and formal definitions for share accounting, roles, and operational dependencies, and (ii) three complementary taxonomies covering vault exposures and objectives, curator governance and accountability mechanisms, and strategy execution patterns together with their failure modes. We further map a representative set of production protocols to the proposed dimensions. The frameworks in this work aim to support rigorous analysis and safer design of blockchain-based financial applications.
Electronic invoices are replacing paper invoices worldwide, but today's centralized architectures leave three problems unsolved on the consumption side: an invoice can be submitted for reimbursement repeatedly, authenticity is difficult for recipients to verify, and data is siloed at a central authority that forms both a performance bottleneck and a single point of failure. This paper presents the design, formal analysis, and implementation of a complete blockchain-based electronic invoice system on Ethereum. We formalize the invoice lifecycle as a guarded labeled transition system and prove, under standard cryptographic and consensus assumptions, that the system guarantees: (i) reimbursement uniqueness--an invoice is reimbursed at most once, even across mutually distrusting organizations; (ii) face integrity--any verified invoice matches the recorded one unless keccak256 second-preimage resistance is broken; and (iii) authorization soundness for every lifecycle operation. The core invariants are machine-checked using Solidity SMTChecker, proving inductive validity across all reachable transaction sequences. The architecture models each invoice as a non-fungible, non-tradable token whose state transitions through five guarded subsystems, employing a lock-based protocol that makes duplicate reimbursement unrepresentable rather than merely detectable. We implement the design as a Solidity 0.8 contract with a four-role web application and evaluate it on a private Ethereum network: issuing costs 646,773 gas, full reimbursement costs under 135,000 gas, all operations run in O(1) time, and a single node sustains 137 issuances/s. Finally, the verified contract serves as a safety envelope for LLM-based reimbursement agents, provably rejecting unsafe actions (duplicate, over-limit, or forged-receipt claims) even when the agent's internal policy fails. All code and benchmarks are open-source.
Smart contracts underpin decentralized finance, where growing demand for on-chain/off-chain communication(OFC) has driven diverse applications such as cross-chain bridges, real-world asset tokenization, and fiat-backed stablecoins. TheOFC-related security incidents in these applications are increasingly frequent, but prior studies address separate vulnerability categories within OFC applications rather than providing a unified view, causing vulnerabilities outside known patterns to be missed.In this paper, we identify OFC inconsistency (OFCI) as a root cause of OFC vulnerabilities, which arises from business-logic flaw and ultimately breaks the equivalence between the on-chain and off-chain asset representations to induce inconsistency.Automatically detecting OFCIs faces two challenges including (1)locating heterogeneous business logic, and (2) transferring existing vulnerability knowledge to identify unseen OFCI instances. To this end, we propose SmartMemory, the first framework to leverage a memory-based agent for OFCI detection. To address heterogeneity, SmartMemory maps diverse implementations ofOFC contracts into a canonical business-semantic representation to locate the business logic for OFCI inspection. For knowledge reuse, SmartMemory integrates a memory-based agent to distill vulnerability knowledge from features into patterns and detection rules, enabling knowledge transfer across cases to identify unseenOFCIs. Lastly, SmartMemory performs taint analysis to verify the reachability, type, and impact of each candidate OFCI. We construct the first real-world OFCI dataset comprising 48 DApps with 81 OFCIs for evaluation, on which SmartMemory achieves80.68% precision and 87.65% recall. In addition, through an analysis of 325 real-world OFC applications, SmartMemory detects 36 previously unknown OFCIs, all of which have been confirmed and fixed by corresponding parties.
We propose Compact Shielded CSV, a private client-side validation blockchain for peer-to-peer payments designed for the postquantum era. Upgrading existing blockchains to quantum-resistant cryptography substantially increases on-chain overhead. By keeping all large cryptographic artifacts off-chain, Compact Shielded CSV keeps a minimal on-chain footprint independent of the size of the underlying cryptographic proofs and signatures. For a single input transaction, the onchain footprint is just 3 hashes (3x32 bytes): a nullifier, a degriefer, and a commitment to the transaction. We introduce the degriefer - a novel mechanism that enforces ownership and prevents double-spending using only hash commitments, eliminating the need for on-chain signatures entirely. These properties make Compact Shielded CSV a promising foundation for private, scalable, post-quantum digital payments.
As lotteries and other high-stakes decentralized applications increasingly depend on unpredictable randomness for their operations, the lack of a secure and transparent on-chain random number generator that is verifiable by all participants remains a critical open problem. Various approaches to blockchain-based random number generation have emerged over the years, each with their own strengths and limitations, and have consistently been superseded as blockchain technology evolved. This paper surveys existing approaches to on-chain randomness and proposes a new platform that builds upon the well-known commit-and-reveal scheme while directly addressing its principal vulnerability, the last revealer attack, in which the final participant can withhold their reveal in order to bias or abort the output upon seeing an unfavorable result. We further compare this solution with prior approaches and evaluate its entropy properties. The proposed architecture combines a web-based front-end with a Solidity smart contract deployed on the Polygon 2.0 blockchain. Implemented and tested on the Amoy testnet, the prototype is low-cost and simple to deploy, providing a practical, accessible proof-of-concept for verifiable on-chain randomness.
This paper proposes a blockchain-backed agentic security framework designed to safeguard the complete software development lifecycle (SDLC) while also securing the agentic AI components responsible for monitoring it. The framework coordinates a set of specialised security agents, covering source integrity, dependency and SBOM analysis, CI configura tion auditing, artifact verification, and runtime policy evaluation, each supported by a large language model (LLM) that interprets artefacts, reasons over tool outputs, and produces structured security reports. To ensure agent trustworthiness, every agent generates a cryptographically signed attestation that is recorded in a permissioned blockchain via smart contracts, including an agent registry, an immutable attestation log, and an enforceable release-policy module. Communication among agents and with blockchain nodes is secured using a consortium-operated certificate authority, ensuring authenticated and tamper-resistant interactions. A detailed use-case and sequence flow demonstrate how a source code security agent performs analysis, anchors its attestation on-chain, and triggers a verifiable allow/block deployment decision. The proposed framework of fers decentralised integrity transparent provenance, uninterrupted security assurance and a generalisable architecture to incorporate the agentic AI into the modern software supply chain security.
Contemporary on-chain artificial intelligence (AI) encounters an intractable Von Neumann memory and latency wall. Storing static floating-point neural weight matrices inside Ethereum Virtual Machine (EVM) storage costs millions of gas, rendering direct on-chain inference impossible. While Zero-Knowledge Machine Learning (ZK-ML) offloads matrix tensor multiplications to off-chain provers, it introduces fatal constraints: 10 to 300 seconds of SNARK proving latency and 250,000 to 500,000 gas per proof verification. Because decentralized finance (DeFi) exploits - such as uncollateralized flash-loan attacks, predatory sandwich MEV, and toxic loss-versus-rebalancing (LVR) flow - occur atomically inside a single block, ZK-ML oracles cannot react in time. Here, we present Werracle, a production-grade, zero-storage on-chain AI decision oracle fitting inside a single 32-byte EVM storage slot (bytes32). Leveraging foundational procedural Mandelbrot escape dynamics (z_{n+1} = z_n^2 + c) established by Dagli et al. (arXiv:2609.25498), Werracle derives continuous non-linear decision hyperplanes from a 24-byte coordinate triplet Theta = (c_x, c_y, zoom). Implemented in pure Solidity bytecode using fixed-point Q16.16 arithmetic (WerrMath.sol), Werracle evaluates a 16-point Pareto micro-grid in only 21,438 gas (under 0.0005 USD on Layer-2 rollups like Base and Arbitrum) with sub-millisecond execution latency. We demonstrate real-world DeFi efficacy via WerracleFeeHook.sol, a Uniswap v4 dynamic swap fee governor that measures orderbook turbulence on-the-fly and atomically adjusts liquidity provider fees between 0.05% and 0.50%. The protocol is formally verified against a 1,000-test cryptographically sealed deterministic verification suite (100.0% pass rate) with telemetry permanently disabled, operating live on a dedicated EVM devnet sandbox (Chain ID 4242).
This paper presents a Solidity, Hardhat, React, MetaMask, and ethers.js prototype for hospital ethics committee voting. Role controls, case-state checks, duplicate vote controls, and a receipt hash support public audit and transaction inclusion verification. Because vote events expose wallet addresses and vote values, the design provides pseudonymous auditability, not anonymous or secret-ballot voting; the receipt is neither receipt-free nor coercion-resistant. Evaluation reports 22 passing functional tests and local Hardhat gas use, including 284,137 gas per vote. A 12-participant simulation used assumed probabilities and is not human-subject evidence. Residual risks include multiple wallets, administrator or frontend compromise, credential reassignment, front-running, denial of service, and untested adversarial paths. Confidential deployment requires governed enrollment, encrypted ballots, independent audit, adversarial testing, reproducible benchmarks, and a real user study.
Blockchain and artificial intelligence (AI) are converging into a single infrastructural layer for securing data sharing, model integrity, and autonomous decision-making across distributed systems. This paper presents a meta-synthesis that draws together four constituent studies covering adversarial machine learning, AI-powered anomaly detection in cloud environments, automated vulnerability patching by multi-agent large language model (LLM) pipelines, and the broader landscape of securing AI systems across their lifecycle and situates their findings within the emerging literature on blockchain-enabled AI and autonomous AI agents. Each constituent study addresses a distinct point of failure in modern AI-driven security operations: the integrity of training data and model behavior, the reliability of real-time monitoring, and the trustworthiness of automated code remediation. We argue that blockchain's properties of immutability, decentralized consensus, and verifiable provenance directly address a gap common to all three: the difficulty of establishing trust in data, models, and autonomous agents that operate without a central authority. Building on real-world research on blockchain-secured data sharing, federated learning, and multi-agent coordination, we propose a layered reference architecture that couples adversarially hardened models, blockchain-anchored data provenance, AI-driven anomaly detection, and smart-contract-governed multi-agent remediation. We conclude by identifying open problems in scalability, privacy-transparency trade-offs, and the governance of autonomous agents that must be resolved before such integrated systems can be trusted in production-critical environments.
作者提供的摘要,转载自 arXiv 描述性元数据(CC0)。论文内容与主张仍归作者负责。
作者报告的发表信息: International Journal of Scientific Research and Management, Vol. 14, No. 08, 2026
Blockchains need more than post quantum single signer signatures. They need consensus profiled authentication objects with canonical bytes, priced invalid input rejection, stable transaction identifiers, hybrid downgrade resistance, public aggregation, merge semantics, accountable signer evidence, forward secure committee rotation, and light client consequences. We argue for domain specific post quantum signatures for blockchain roles, analogously to how hash function engineering produced domain specific primitives for hash table DoS and arithmetized proof systems. We formalize transaction authorization and quorum certificate requirements, instantiate them on Bitcoin, Ethereum, and a Sei Giga style high throughput BFT stress profile, and evaluate ML-DSA, SLH-DSA, Falcon/FN-DSA, HAWK, MAYO, SNOVA, UOV/QR-UOV, FAEST, SQIsign, LaBRADOR Falcon, Squirrel, Chipmunk, and DKKW/LeanSig. We find that NIST single signer signatures are necessary components, yet none of the current schemes is a sufficient drop in replacement for the signature layer of modern public blockchains. The missing object is a consensus ready post quantum signature profile, not another generic size table.
Address-Poisoning Transfer (APT) is a prevalent blockchain phishing scam in which a scammer poisons a victim's address book by generating a transfer with a phishing address that looks similar to a benign address that the victim has previously interacted with. Although simple, APT phishing attacks have cost users millions of dollars in recent years, which has captured the attention of the research community (Ye et al. WWW'24, Guan-Li CCS'24, Chen et al. NDSS'25, Tsuchiya et al. USENIX'25). In this work, we go beyond detection and investigate three important and underexplored aspects of APT: scam funding mechanisms, scam signatures, and scam proceeds laundering via public services. In particular, we propose five families of scam signatures that capture key aspects of APT operations, which are useful for address clustering. We also conduct the first investigation into usage of Tornado Cash for funding APTs and laundering scam proceeds.
The rapid emergence of decentralized finance (DeFi) has introduced complex challenges for cross-chain transactions, which involve transferring assets across disparate blockchain networks. A fundamental dilemma arises between user privacy and ensuring regulatory compliance. Unlike single-chain systems, cross-chain environments must address privacy and auditability across heterogeneous architectures. Existing approaches,ranging from transparent ledgers to anonymous cryptocurrencies, fail to reconcile these two requirements, hindering regulatory adoption. This research presents an auditable cross-chain framework that integrates three core components. First, zero-knowledge proofs (ZKPs) enable compliance verification (e.g., amount non-negativity, signature validity) without revealing transaction details. Second, a light-client mechanism enables trust-minimized cross-chain verification without dependence on third-party relayers. Third, a threshold view-key mechanism based on distributed key generation (DKG) restricts that audit access to authorized entities under legal triggers such as the FATF Travel Rule and MiCA Regulation. For cross-border investigations, the framework adheres to national laws and the EU Directive on Mutual Legal Assistance. This work systematically integrates ZKPs, threshold cryptography, and light-client verification into an auditable, privacy-preserving cross-chain protocol, and evaluates a prototype on the Ethereum Sepolia testnet. The results demonstrate the practical feasibility of privacy-preserving compliance verification for cross-chain DeFi. At the same time, broader interoperability and Regulatory Technology (RegTech) impact require further validation on additional chains and with real regulatory workflows.
The Ethereum blockchain utilizes the EIP-1559 algorithm to manage transaction inclusion and block assembly. However, EIP-1559 and much of the existing literature study this problem from a static perspective, focusing on price evolution without modelling transaction dynamics within the mempool. Motivated by this limitation, we study a dynamic transaction scheduling problem in which transactions with heterogeneous sizes and per-unit values arrive over time and remain in the mempool until scheduled. To capture the stochastic mempool evolution, we formulate the problem as a Markov Decision Process (MDP) whose state represents the mempool configuration and whose actions correspond to block prices. We first provide a primal-dual interpretation of the static EIP-1559 mechanism, showing that block prices arise naturally as dual variables of a social-welfare maximization problem. Building on this perspective, we extend the framework to the dynamic setting and formulate an objective that maximizes long-run discounted reward while incorporating holding costs and overshoot penalties. We then employ a Natural Policy Gradient (NPG) algorithm to compute the optimal policy. Our results show that dynamic pricing stabilizes the mempool while maximizing long-run discounted reward. In particular, as the overshoot penalty increases, the average scheduled transaction volume converges to the target block capacity, and the resulting NPG updates closely resemble the EIP-1559 price update rule. Finally, we study two special cases of the MDP formulation: homogeneous transactions and uniform arrivals. In the homogeneous setting, where the protocol directly controls scheduled volume, we show that the optimal policy has a threshold structure. We then propose a bang-bang pricing mechanism for uniform arrivals and derive a lower bound on the block capacity needed to ensure system stability.
While public blockchains provide transparent and auditable transaction histories, they inherently compromise user privacy. Existing privacy-enhancing protocols, such as those deployed on Ethereum, typically rely on succinct zero-knowledge proofs (zk-SNARKs) to obscure the transaction graph. However, implementing comparable cryptographic guarantees on high-throughput blockchains like Algorand is challenging due to strict per-call execution budgets and the state contention introduced by global Merkle accumulators. This paper presents Obscura, a decentralized, non-custodial privacy protocol tailored for constrained smart contract environments. Obscura achieves transaction anonymity using Linkable Spontaneous Anonymous Group (LSAG) signatures over the BN254 elliptic curve, verified entirely on-chain. To overcome limitations of the Algorand Virtual Machine (AVM), we introduce a novel state model that leverages Algorand's Box Storage for $O(1)$ commitment membership checks, eliminating the need for global Merkle accumulators, and a dynamic opcode-budget expansion mechanism via pooled inner application calls. Our implementation demonstrates that signer-ambiguous privacy is practical and efficient on Algorand without relying on trusted setups or succinct proofs. Obscura provides a robust privacy layer for transparent ledgers, bridging the gap between high-throughput blockchain architectures and the dual requirements of cryptographic privacy and selective auditability.
Despite holding over $1.7T in value, Bitcoin scales poorly: Layer-1 (L1) processes only a few transactions per second, and Layer-2 (L2) solutions suffer from operational and liquidity fragmentation that requires external bridges for cross-chain connectivity. We present Bitcoin-IPC, a protocol that horizontally scales Bitcoin via permissionless, interconnected, programmable Proof-of-Stake L2 subnets staked in L1 BTC. Subnets leverage Bitcoin L1 for interconnectivity, settlement, and security, including Sybil protection, equivocating validator slashing, unilateral exit for honest stake, long-range attack protection, and compromised subnet firewalling. Bitcoin-IPC cross-subnet transfers involve only source/destination subnet validators and L1, with no external bridges or per-path liquidity lock-up. Embedded and batched in Bitcoin's witness mechanism, cross-subnet settlements can approach 6 vB per transfer, 23x less than a native L1 payment. Filling Bitcoin blocks with such batches corresponds to L1 monetary throughput of about 273 transfers per second, without modifying Bitcoin.
Privacy-preserving blockchain systems are essential for protecting transaction data, yet they must also provide auditability that enables auditors to recover participant identities and transaction amounts when warranted. Existing designs often compromise the independence of auditing and transactions, introducing extra interactions that undermine usability and scalability. Moreover, many auditable solutions depend on auditors serving as validators or recording nodes, which introduces risks to both data security and system reliability. To overcome these challenges, we propose SilentLedger, a privacy-preserving transaction system with auditing and complete non-interactivity. To support public verification of authorization, we introduce a renewable anonymous certificate scheme with formal semantics and a rigorous security model. SilentLedger further employs traceable transaction mechanisms constructed from established cryptographic primitives, enabling users to transact without interaction while allowing auditors to audit solely from on-chain data. We formally prove security properties including authenticity, anonymity, confidentiality, and soundness, provide a concrete instantiation, and evaluate performance under a standard 2-2 transaction model. Our implementation and benchmarks demonstrate that SilentLedger achieves superior performance compared with state-of-the-art solutions.
Cryptocurrencies are widely used, yet current methods for analyzing transactions often rely on opaque, black-box models. While these models may achieve high performance, their outputs are usually difficult to interpret and adapt, making it challenging to capture nuanced behavioral patterns. Large language models (LLMs) have the potential to address these gaps, but their capabilities in this area remain largely unexplored, particularly in cybercrime detection. In this paper, we test this hypothesis by applying LLMs to real-world cryptocurrency transaction graphs, with a focus on Bitcoin, one of the most studied and widely adopted blockchain networks. We introduce a three-tiered framework to assess LLM capabilities: foundational metrics, characteristic overview, and contextual interpretation. This includes a new, human-readable graph representation format, LLM4TG, and a connectivity-enhanced transaction graph sampling algorithm, CETraS. Together, they significantly reduce token requirements, transforming the analysis of multiple moderately large-scale transaction graphs with LLMs from nearly impossible to feasible under strict token limits. Experimental results demonstrate that LLMs have outstanding performance on foundational metrics and characteristic overview, where the accuracy of recognizing most basic information at the node level exceeds 98.50% and the proportion of obtaining meaningful characteristics reaches 95.00%. Regarding contextual interpretation, LLMs also demonstrate strong performance in classification tasks, even with very limited labeled data, where top-3 accuracy reaches 72.43% with explanations. While the explanations are not always fully accurate, they highlight the strong potential of LLMs in this domain. At the same time, several limitations persist, which we discuss along with directions for future research.
Decentralized finance (DeFi) can broaden access while leaving activity, network position, and infrastructure concentrated. We develop a four-dimensional framework for participation, activity distribution, structural position, and infrastructure dependence, integrating network theory, theorem-consistent agent-based simulation, and longitudinal analysis of 1,956,216 Aave V3 Pool events. We study GHO issuance on Ethereum (15 July 2023) and its first cross-chain expansion to Aave's existing Arbitrum market (2 July 2024). Excluding each activation week, mean weekly active position-holder addresses increased by 91.0% around Ethereum issuance and 1.7% around Arbitrum expansion, while activity concentration fell by 31.5% on Ethereum but rose by 58.1% on Arbitrum. On a common 2024 calendar, the Arbitrum--Gnosis DiD-style change is +1.9833 for log participation and -0.01842 for position-holder-event HHI. Rule-based simulations recover the analytical equilibrium and show why aggregate growth can coexist with lower, unchanged, or higher concentration, while chain dispersion alone cannot establish route or shared-component resilience. Role-aware analysis further shows that network-structure conclusions vary by protocol action and scale. Intellectually, the framework explains why four dimensions of decentralization can diverge. Practically, it helps researchers, protocol designers, governance communities, and policymakers assess stablecoin growth without equating adoption with decentralization.