Towards Understanding and Characterizing the Arbitrage Bot Scam In the Wild

Author:

Li Kai1ORCID,Guan Shixuan1ORCID,Lee Darren1ORCID

Affiliation:

1. San Diego State University, San Diego, CA, USA

Abstract

This paper presents the first comprehensive analysis of an emerging cryptocurrency scam named "arbitrage bot" disseminated on online social networks. The scam revolves around Decentralized Exchanges (DEX) arbitrage and aims to lure victims into executing a so-called "bot contract" to steal funds from them. To entice victims and convince them of this scheme, we found that scammers have flocked to publish YouTube videos to demonstrate plausible profits and provide detailed instructions and links to the bot contract. To collect the scam at a large scale, we developed a fully automated scam detection system namedCryptoScamHunter, which continuously collects YouTube videos and automatically detects scams. Meanwhile,CryptoScamHunter can download the source code of the bot contract from the provided links and extract the associated scam cryptocurrency address. Through deployingCryptoScamHunter from Jun. 2022 to Jun. 2023, we have detected 10,442 arbitrage bot scam videos published from thousands of YouTube accounts. Our analysis reveals that different strategies have been utilized in spreading the scam, including crafting popular accounts, registering spam accounts, and using obfuscation tricks to hide the real scam address in the bot contracts. Moreover, from the scam videos we have collected over 800 malicious bot contracts with source code and extracted 354 scam addresses. By further expanding the scam addresses with a similar contract matching technique, we have obtained a total of 1,697 scam addresses. Through tracing the transactions of all scam addresses on the Ethereum mainnet and Binance Smart Chain, we reveal that over 25,000 victims have fallen prey to this scam, resulting in a financial loss of up to 15 million USD. Overall, our work sheds light on the dissemination tactics and censorship evasion strategies adopted in the arbitrage bot scam, as well as on the scale and impact of such a scam on online social networks and blockchain platforms, emphasizing the urgent need for effective detection and prevention mechanisms against such fraudulent activity.

Funder

Ethereum Foundation

Publisher

Association for Computing Machinery (ACM)

Subject

Computer Networks and Communications,Hardware and Architecture,Safety, Risk, Reliability and Quality,Computer Science (miscellaneous)

Reference62 articles.

1. 2023. Back-running. https://www.mev.wiki/attack-examples/back-running. (June 2023 ). 2023. Back-running. https://www.mev.wiki/attack-examples/back-running. (June 2023).

2. 2023. Blockchain Explorer By Bitquery. https://explorer.bitquery.io/. (June 2023 ). 2023. Blockchain Explorer By Bitquery. https://explorer.bitquery.io/. (June 2023).

3. 2023. BscScan: BNB Smart Chain Explorer. https://bscscan.com. (June 2023 ). 2023. BscScan: BNB Smart Chain Explorer. https://bscscan.com. (June 2023).

4. 2023. Cloud Translation API. https://cloud.google.com/translate/docs/reference/rest. (June 2023 ). 2023. Cloud Translation API. https://cloud.google.com/translate/docs/reference/rest. (June 2023).

5. 2023. CronoScan Developer APIs. https://cronoscan.com/apis. (June 2023 ). 2023. CronoScan Developer APIs. https://cronoscan.com/apis. (June 2023).

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3