Security Threats from Bitcoin Wallet Smartphone Applications: Vulnerabilities, Attacks, and Countermeasures

被引:9
作者
Hu, Yiwen [1 ]
Wang, Sihan [1 ]
Tu, Guan-Hua [1 ]
Xiao, Li [1 ]
Xie, Tian [1 ]
Lei, Xinyu [1 ]
Li, Chi-Yu [2 ]
机构
[1] Michigan State Univ, Dept Comp Sci & Engn, E Lansing, MI 48824 USA
[2] Natl Chiao Tung Univ, Dept Comp Sci, Hsinchu, Taiwan
来源
PROCEEDINGS OF THE ELEVENTH ACM CONFERENCE ON DATA AND APPLICATION SECURITY AND PRIVACY (CODASPY '21) | 2021年
基金
美国国家科学基金会;
关键词
Bitcoin wallets; Blockchain; Security; Mobile networks;
D O I
10.1145/3422337.3447832
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Nowadays, Bitcoin is the most popular cryptocurrency. With the proliferation of smartphones and the high-speed mobile Internet, more and more users have started accessing their Bitcoin wallets on their smartphones. Users can download and install a variety of Bitcoin wallet applications (e.g., Coinbase, Luno, Bitcoin Wallet) on their smartphones and access their Bitcoin wallets anytime and anywhere. However, it is still unknown whether these Bitcoin wallet smartphone applications are secure or if they are new attack surfaces for adversaries to attack these application users. In this work, we explored the insecurity of the 10 most popular Bitcoin wallet smartphone applications and discovered three security vulnerabilities. By exploiting them, adversaries can launch various attacks including Bitcoin deanonymization, reflection and amplification spamming, and wallet fraud attacks. To address the identified security vulnerabilities, we developed a phone-side Bitcoin Security Rectifier to secure Bitcoin wallet smartphone application users. The developed rectifier does not require any modifications to current wallet applications and is compliant with Bitcoin standards.
引用
收藏
页码:89 / 100
页数:12
相关论文
共 40 条
[1]   Mind Your Wallet's Privacy: Identifying Bitcoin Wallet Apps and User's Actions through Network Traffic Analysis [J].
Aiolli, Fabio ;
Conti, Mauro ;
Gangwal, Ankit ;
Polato, Mirko .
SAC '19: PROCEEDINGS OF THE 34TH ACM/SIGAPP SYMPOSIUM ON APPLIED COMPUTING, 2019, :1484-1491
[2]  
[Anonymous], 2020, BITCOIN CORE
[3]  
[Anonymous], 2020, FAC DET REC HOM
[4]  
[Anonymous], 2017, MURMURHASH3 HASH FUN
[5]  
[Anonymous], 2019, PROF BATT US BATT BA
[6]  
[Anonymous], 2020, SURV CAM STAT
[7]  
[Anonymous], 2019, VOIC WIF VOW MARK
[8]  
[Anonymous], 2019, STAT 4G LTE LTE A NE
[9]  
[Anonymous], 2018, BITC PROT
[10]  
[Anonymous], 2020, MOB START PROM YOUR