Security Threats from Bitcoin Wallet Smartphone Applications: Vulnerabilities, Attacks, and Countermeasures

Yiwen Hu, Sihan Wang, Guan Hua Tu, Li Xiao, Tian Xie, Xinyu Lei, Chi-Yu Li

研究成果: Conference contribution同行評審

13 引文 斯高帕斯(Scopus)

摘要

Nowadays, Bitcoin is the most popular cryptocurrency. With the proliferation of smartphones and the high-speed mobile Internet, more and more users have started accessing their Bitcoin wallets on their smartphones. Users can download and install a variety of Bitcoin wallet applications (e.g., Coinbase, Luno, Bitcoin Wallet) on their smartphones and access their Bitcoin wallets anytime and anywhere. However, it is still unknown whether these Bitcoin wallet smartphone applications are secure or if they are new attack surfaces for adversaries to attack these application users. In this work, we explored the insecurity of the 10 most popular Bitcoin wallet smartphone applications and discovered three security vulnerabilities. By exploiting them, adversaries can launch various attacks including Bitcoin deanonymization, reflection and amplification spamming, and wallet fraud attacks. To address the identified security vulnerabilities, we developed a phone-side Bitcoin Security Rectifier to secure Bitcoin wallet smartphone application users. The developed rectifier does not require any modifications to current wallet applications and is compliant with Bitcoin standards.

原文English
主出版物標題CODASPY 2021 - Proceedings of the 11th ACM Conference on Data and Application Security and Privacy
發行者Association for Computing Machinery, Inc
頁面89-100
頁數12
ISBN(電子)9781450381437
DOIs
出版狀態Published - 26 4月 2021
事件11th ACM Conference on Data and Application Security and Privacy, CODASPY 2021 - Virtual, Online, 美國
持續時間: 26 4月 202128 4月 2021

出版系列

名字CODASPY 2021 - Proceedings of the 11th ACM Conference on Data and Application Security and Privacy

Conference

Conference11th ACM Conference on Data and Application Security and Privacy, CODASPY 2021
國家/地區美國
城市Virtual, Online
期間26/04/2128/04/21

指紋

深入研究「Security Threats from Bitcoin Wallet Smartphone Applications: Vulnerabilities, Attacks, and Countermeasures」主題。共同形成了獨特的指紋。

引用此