Connect with us

Crypto

Researchers uncover vulnerabilities leading to predatory trading in popular Ethereum cryptocurrency rollups

Published

on

Researchers uncover vulnerabilities leading to predatory trading in popular Ethereum cryptocurrency rollups
Ben Weintraub and his co-authors conducted a large-scale analysis of exploitative trading activities on Ethereum and across popular rollups. Credit: Matthew Modoono/Northeastern University

Ethereum, a decentralized online platform that allows users to conduct financial transactions in Ether cryptocurrency, prides itself on the system’s high security.

But new findings from Northeastern University’s computer scientists and researchers at ETH Zurich, a public research university in Switzerland, show that it might not be so bulletproof, and its users might be susceptible to some market participants’ predatory practices.

“There are direct monetary incentives,” says Ben Weintraub, a Northeastern doctoral student in the Khoury College of Computer Sciences. “So in my view, it’s better if researchers find and publicize it first before people mistakenly lose money.”

Weintraub presented the paper on the findings at the Association for Computing Machinery’s annual Conference on Computer and Communications Security (ACM CCS 2024) held Oct. 14–18 in Salt Lake City. The study is available on the arXiv preprint server.

Advertisement

He and his co-authors conducted a large-scale analysis of exploitative trading activities on Ethereum itself and across so-called rollups, or off-the-platform services that allow faster processing of higher volumes of transactions.

The researchers found evidence that certain actors can manipulate the market on rollups, which was previously thought to be impossible.

“It was known to be possible on regular Ethereum, but it was thought to be impossible on rollups and we showed that it is not impossible,” Weintraub says.

The paper presents three novel types of attacks in which predatory traders could have made about $2 million in profits in the last three years by manipulating transactions within Ethereum trading networks.

Advertisement

Ethereum is a network of independent computers across the world that follows the Ethereum protocol—a set of rules on how the computers in the global network can interact with each other. It uses blockchain technology, pioneered by Bitcoin.

A blockchain is a database of transactions that is shared across computers in a network. Once a new block, or a new set of transactions, is added to the blockchain, that data can no longer be removed by anybody, primarily due to cryptographic techniques that highlight any attempts at tampering.

Anyone can create an Ethereum account from anywhere, at any time. No central authority such as a government or a company has control over Ethereum, which means no individual can change the rules or restrict users’ access. Any Ethereum protocol changes require approval from more than half of the network.

Unlike Bitcoin, which is solely a payment system with a name-sake cryptocurrency, Ethereum allows users to build applications, communities and organizations on its platform.

The Ethereum network, however, has a scalability problem—as the number of people using it has grown, the blockchain has reached certain throughput limitations that further inflated the costs for conducting transactions on the platform.

Advertisement

One solution are the rollups, such as Arbitrum, Optimism and zkSync—which were analyzed by Weintraub—that aim to improve Ethereum’s speed by taking batches of transactions and calculations off Ethereum. This reduced the processing cost of a transaction to roughly 1 cent, Weintraub says.

Some actors make profits trading cryptocurrencies by trying to achieve maximal extractable value, he says, by manipulating the order of transactions that are pending inclusion on the blockchain. The research provides exclusive insights into the volume of maximal extractable value transactions on rollups, costs associated with them, profits made by such exploitative traders, competition between them and response time to such activities across Ethereum and the rollups.

Some methods that malicious actors use are common to financial markets, like arbitrage, when a user buys something on one exchange and quickly sells it for profit on another exchange.

“It’s generally thought to be a good thing because it keeps different exchanges balanced in terms of price,” Weintraub says. “But there are also types [of maximal extractable value] that are not good. One that’s fairly well-known in research is called sandwiching.”

In sandwiching, when a speculator sees someone is about to buy an asset, they buy it first, driving up the price. The speculator then quickly sells it at the higher price.

Advertisement

Sandwiching is considered a “bad,” manipulative trading strategy affecting the price that other traders get. On Ethereum, block producers—people or groups who get paid when their hardware is randomly selected to verify a block’s transactions—can try to maximize the amount of profit they make by manipulating how transactions are ordered or included in a block before it is added to the blockchain.

“The reason we call this an attack is because it is purely damaging to that victim, who now has to pay a little bit more for their transaction,” Weintraub says. “The system broadly does not benefit at all. There’s just the one who profits—the ‘sandwicher.’”

While the researchers didn’t find traditional sandwich attacks on popular rollups, they identified three potential strategies for them when transactions move between Ethereum and rollups with a time delay.

“This just came from analyzing the protocol and looking at the exact flow of transactions—when they get sent, when the rollup seems to respond to them or when they end up on the blockchain,” Weintraub says.

Advertisement

“We tested our attacks on [Ethereum’s] test-net, a network of ‘fake’ money that is used by developers to test their applications,” he says. “And, essentially, we stole all of the money from only ourselves.”

Weintraub is currently in contact with major rollups’ developers to see what can be done about the possibility of the attacks. Two types of these novel attacks can be prevented, Weintraub says, while it is unclear how to protect users from the third type.

“Our view is that it’s better to just get this information out there so people, at least, are aware of the risks,” he says.

More information:
Christof Ferreira Torres et al, Rolling in the Shadows: Analyzing the Extraction of MEV Across Layer-2 Rollups, arXiv (2024). DOI: 10.48550/arxiv.2405.00138

Journal information:
arXiv
Advertisement

Provided by
Northeastern University

This story is republished courtesy of Northeastern Global News news.northeastern.edu.

Advertisement

Citation:
Researchers uncover vulnerabilities leading to predatory trading in popular Ethereum cryptocurrency rollups (2024, November 11)
retrieved 11 November 2024
from https://techxplore.com/news/2024-11-uncover-vulnerabilities-predatory-popular-ethereum.html

This document is subject to copyright. Apart from any fair dealing for the purpose of private study or research, no
part may be reproduced without the written permission. The content is provided for information purposes only.

Advertisement

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Crypto

The Last Frontier For Cryptocurrency Adoption

Published

on

The Last Frontier For Cryptocurrency Adoption

While studies reveal institutional investors and wealth managers believe tokenized ETFs will drive mainstream market adoption for cryptocurrency, there looms the theft of bad actors that most often go untraceable.

Barriers to the expansion of tokenization are starting to fall as major investment firms consider launching tokenized ETFs, according to new global research by London-based Nickel Digital Asset Management (Nickel), Europe’s leading digital assets hedge fund manager founded by alumni of Bankers Trust, Goldman Sachs and JPMorgan.

Its study with institutional investors (pension funds, insurance asset managers and family offices) and wealth managers at organisations which collectively manage over $14 trillion in assets found almost all (97%) believe the potential launch of tokenized ETFs such as BlackRock’s will be important to the expansion of the sector with nearly one in three (32%) rating the development as very important.

The study also reflected the belief that tokenization will continue to grow, with nearly 70% of respondents believing that fund managers looking to tokenize investment funds and asset classes will increase over the next three years.

Advertisement

Nickel’s research with firms in the US, UK, Germany, Switzerland, Singapore, Brazil and the United Arab Emirates found growing awareness of the benefits of tokenization. Private markets are seen as offering the greatest potential for tokenization, with almost 70% seeing private equity funds as the asset class with the most opportunity, followed by fixed income (55%) and public equities (42%).

Anatoly Crachilov, CEO and Founding Partner at Nickel Digital, said: “Tokenization is quickly moving from theory to real-world adoption as institutional investors grow more comfortable with its benefits and see major players enter the space. When firms like BlackRock step in, it fundamentally shifts the conversation. This development is timely for our multi-manager vehicle as expanding liquidity depth will allow some of our pods to start trading tokenized assets in the coming months.”

To address potential criminal threat, an advanced detection system to identify and trace blockchain funds connected with criminal activity was presented earlier this week at the Annual CyberASAP Demo Day in London.

The system, called SynapTrack, enables faster and more accurate detection of fraudulent activity using blockchains and cryptocurrencies, where traditional anti-money laundering and counter-terrorist financing systems struggle to keep pace.

Although current fraud detection methods pick up unusual activity, they deliver an extremely high rate (40%) of false positive reports. These require manual checking by compliance professionals, resulting in backlogs in identifying and acting on suspicious activity.

Advertisement

The SynapTrack system is designed to deliver a substantially lower rate of false positives. It has already been tested using real-life data from the notorious 2025 Bybit hack, where criminals stole $1.5bn of digital tokens from a cryptocurrency exchange. SynapTrack traced the hacker with 98% accuracy.

The team behind SynapTrack is keen to hear from exchanges, financial regulators or law enforcement agencies who want to test the prototype in real-world conditions.

SynapTrack uses a validated methodology to score the likelihood of transactions being part of a money laundering scheme. It has a self-improving algorithm that continuously adapts to new tactics – dynamically identifying suspicious patterns in blockchain transactions. It has a universal cross-chain capability, and is designed around how compliance teams work, presenting results in a dashboard. No infrastructure changes are needed for installation.

It is relatively easy to obscure fraudulent or criminal activity by moving funds between blockchains, or dispersing them across many blockchains, in what are known as ‘cross-chain’ transactions. It is these transactions that pose the greatest difficulty for existing anti-money laundering systems.

SynapTrack was developed by University of Birmingham computer scientists Dr Pascal Berrang and PhD student Endong Liu, in collaboration with blockchain developer Nimiq. Dr Berrang’s research is in IT security and privacy on blockchain, artificial intelligence and machine learning. The subject of Endong Liu’s PhD is transaction tracing. Nimiq is supporting with blockchain-specific insights, knowledge of real-world constraints, and implementation.

Advertisement

The team is currently fundraising to ensure regulatory readiness and complete the team with a CEO and software developers.

Dr Berrang said: “The last few years have seen a near-exponential growth in blockchain transactions. While many of these are legitimate, blockchains are attractive to criminals as funds can be moved very quickly to other jurisdictions. Our work with Nimiq and the creation of SynapTrack is addressing this black spot, and will enable more effective regulation, making the whole ecosystem of blockchain safer and more trustworthy.”

With the financial market and cybersecurity industry converging, cryptocurrency is here to stay.

Continue Reading

Crypto

Bitcoin drops to $63,000 as U.S. and Israel launch strikes on Iran

Published

on

Bitcoin drops to ,000 as U.S. and Israel launch strikes on Iran

Bitcoin briefly reclaimed $65,000 before pulling back to $64,700 as the Iran conflict continued to escalate through Saturday.

Iranian state media reported at least 70 killed in its Hormozgan province, per Aljazeera, including a strike on an elementary school. Israel activated air raid alerts after detecting fresh missile launches from Iran.

Trump told the Washington Post that “all I want is freedom for the people.” NATO said it was “closely following” developments, China urged an immediate ceasefire, and Turkey offered to mediate.

Bitcoin’s inability to hold $65,000 on the bounce suggests sellers remain in control, but the relative stability given the severity of the headlines points to thin weekend order books rather than active selling pressure.

Headline risks persist for BTC traders as the U.S. day progresses.

Advertisement

What happened earlier

Earlier in the day, BTC neared $63,000 in Saturday trading after the U.S. and Israel launched military strikes on Iran, pushing the largest cryptocurrency down roughly 3% in a matter of hours and extending what had already been a difficult weekend for risk assets.
The move brought bitcoin to its lowest level since the Feb. 5 crash, when the token briefly dipped below $60,000.

Israeli Defense Minister Israel Katz declared an immediate state of emergency across all areas of Israel. A U.S. official confirmed American participation in the strikes, The Wall Street Journal reported.

The sell-off follows a well-established pattern. Bitcoin trades 24 hours a day, 7 days a week, while equity and bond markets are closed on weekends.

That makes it one of the only large, liquid assets available for traders to sell when geopolitical risk spikes outside of traditional market hours.

The result is that bitcoin often acts as a pressure valve for broader risk-off sentiment during weekend events, absorbing selling that would otherwise spread across equities, commodities, and currencies if those markets were open.

Advertisement

The attack risks a wider regional conflict in one of the most economically sensitive parts of the world, following a month-long U.S. military buildup and failed negotiations over Iran’s nuclear program.

Continue Reading

Crypto

Better Cryptocurrency to Buy With $5,000 and Hold Forever: XRP vs. Ethereum | The Motley Fool

Published

on

Better Cryptocurrency to Buy With ,000 and Hold Forever: XRP vs. Ethereum | The Motley Fool

Both Ethereum (ETH 6.03%) and XRP (XRP 3.76%) are tried-and-tested blockchains which have survived (and sometimes thrived) for years on end. That means they’re both sturdy enough to be candidates for a big investment, like $5,000, and for holding over the very long term, or even forever.

So which of these two leading coins is the better option for a forever hold?

Image source: Getty Images.

Ethereum has more ways to grow

Forever is a long time, especially for an investment in an emerging sector like crypto. Therefore, an asset’s optionality regarding where it can derive growth is a key factor, as today’s growth drivers might peter out and new ones are likely to emerge.

On that front, Ethereum has plenty of options. It already hosts a large decentralized finance (DeFi) ecosystem worth more than $53 billion today, powered by a massive stablecoin base of $159 billion. That existing base of capital is a strategic asset because it gives developers and financial institutions a reason to build new products right where liquidity already lives. It also gives investors exposure to many possible growth lanes at once, from the onboarding of tokenized real-world assets (RWAs) to the development of new settlement rails for payments between AI agents.

Advertisement
Ethereum Stock Quote

Today’s Change

(-6.03%) $-123.58

Current Price

$1924.97

Another advantage is that Ethereum has a track record of consistently shipping large protocol upgrades. The Pectra upgrade, for example, landed on the mainnet in May 2025, followed by the Fusaka upgrade in December. Two similarly large feature packages are expected for 2026, and they should help to build the chain’s ability to scale up without spiking transaction costs.

If you plan to hold an asset indefinitely, this network’s culture of iterative improvement reduces the risk that its technical capabilities will become irrelevant as emerging opportunities for growth arise. Its habit of attracting and retaining substantial capital also helps prevent that outcome.

XRP has to keep winning specific fights over time

XRP is not a bad crypto asset by any means, but its long-term burden is its far narrower positioning than Ethereum.

Ripple, the coin’s issuer, built the XRP Ledger (XRPL) ecosystem as a toolkit of financial technologies to support specific workflows in institutional finance, especially cross-border payments and money transfers, and, more recently, the management of tokenized asset capital. The coin’s value is thus derived from the utility of its ledger.

Advertisement

That focus could pay off if the financial companies the chain targets like what it’s offering, but it also concentrates risk. Financial institutions move cautiously, and winning them over is a slow, grinding process of catering to their needs and building strong relationships. Their technology adoption process can stall for years, even when the product works, and decision-makers broadly want to adopt the new tech.

To Ripple’s credit, the XRP Ledger includes plenty of features that match institutional requirements and seek to minimize their potential pain points. The network’s authorized trust lines, for instance, let tokenized asset issuers whitelist who can hold their issued tokens, which is a feature that supports regulatory constraints around who can legally custody an asset. Similarly, the ledger supports freezing tokens when suspicious activity appears, which is a control that traditional finance teams tend to expect in regulated asset workflows.

XRP Stock Quote

Today’s Change

(-3.76%) $-0.05

Current Price

$1.35

Advertisement

But holding a coin forever is unforgiving of sustained competitive pressure, which XRP doubtlessly faces. Its competitors include fintech companies and other cryptocurrencies, not to mention the internal tech development capabilities of many of its target users in big banks. So it’ll need to continuously one up the other players in its space if it’s going to grow over the long term, and it’s hard to believe that it’ll win every round that counts.

The verdict

The decision here is about resilience and resources.

Advertisement

Ethereum’s “grizzled veteran” reputation today stems from surviving numerous shifts in user demand patterns while maintaining a large on-chain capital pool and growing it all the while. Its success or failure in any given crypto market segment is not guaranteed, nor was it in the past, but its constant evolution has ensured that failures are not fatal, and also that missed opportunities aren’t very damaging overall.

XRP, on the other hand, is only just starting to scale up its on-chain capital base; it has only $418 million in stablecoins. Furthermore, while it has succeeded in attracting some financial institutions to its chain, the truth is that its growth trajectory has not yet been seriously tested, and is still finding an appropriate product-market fit. Its real competitive challenges have only just begun.

So if you want a coin to buy with $5,000 and hold forever, pick the asset that can win without needing to be perfect: Ethereum. XRP is still a decent long-term hold, assuming it’s part of a diversified crypto portfolio, but it’s riskier.

Continue Reading

Trending