NDSS 2025 – Dissecting Payload-Based Transaction Phishing On Ethereum
嗯,用户让我帮忙总结一下这篇文章的内容,控制在一百个字以内,而且不需要用“文章内容总结”或者“这篇文章”这样的开头。直接写描述就行。 首先,我需要仔细阅读文章内容。文章主要讲的是以太坊上的一种新型钓鱼攻击,叫做Payload-Based Transaction Phishing(PTXPHISH)。这种攻击通过恶意载荷操纵智能合约交互来欺骗用户。2023年已经造成了超过7000万美元的损失,而研究者们进行了长期的数据收集,建立了第一个包含5000次钓鱼交易的数据集。 然后,他们将钓鱼战术分为四个主要类别和十一个子类别,并提出了一个多维检测方法,F1分数超过99%。他们还进行了大规模检测,发现了13万多起钓鱼交易,总损失超过3.419亿美元。此外,他们还分析了诈骗者的行为模式,并向社区报告了1726个钓鱼地址,帮助了1980名受害者。 现在要将这些内容浓缩到100字以内。重点包括:PTXPHISH的定义、造成的损失、数据集的建立、分类方法、检测效果、大规模检测的结果以及他们的贡献。 可能的结构是:以太坊上的新型钓鱼攻击PTXPHISH通过恶意载荷操纵智能合约欺骗用户,造成巨大损失。研究者建立数据集,分类战术,并提出高效检测方法,在大规模检测中发现大量钓鱼交易并协助受害者。 这样应该在100字以内。 </think> 文章研究了以太坊上一种新型的基于负载的交易钓鱼攻击(PTXPHISH),分析其战术并提出高效检测方法,在大规模检测中发现大量钓鱼交易并协助受害者。 2026-1-21 16:0:0 Author: securityboulevard.com(查看原文) 阅读量:0 收藏

Authors, Creators & Presenters: Zhuo Chen (Zhejiang University), Yufeng Hu (Zhejiang University), Bowen He (Zhejiang University), Dong Luo (Zhejiang University), Lei Wu (Zhejiang University), Yajin Zhou (Zhejiang University)
PAPER
Dissecting Payload-Based Transaction Phishing On Ethereum
In recent years, a more advanced form of phishing has arisen on Ethereum, surpassing early-stage, simple transaction phishing. This new form, which we refer to as payload-based transaction phishing (PTXPHISH), manipulates smart contract interactions through the execution of malicious payloads to deceive users. PTXPHISH has rapidly emerged as a significant threat, leading to incidents that caused losses exceeding $70 million in 2023 reports. Despite its substantial impact, no previous studies have systematically explored PTXPHISH. In this paper, we present the first comprehensive study of the PTXPHISH on Ethereum. Firstly, we conduct a long-term data collection and put considerable effort into establishing the first ground-truth PTXPHISH dataset, consisting of 5,000 phishing transactions. Based on the dataset, we dissect PTXPHISH, categorizing phishing tactics into four primary categories and eleven sub-categories. Secondly, we propose a rule-based multi-dimensional detection approach to identify PTXPHISH, achieving an F1-score of over 99% and processing each block in an average of 390 ms. Finally, we conduct a large-scale detection spanning 300 days and discover a total of 130,637 phishing transactions on Ethereum, resulting in losses exceeding $341.9 million. Our in-depth analysis of these phishing transactions yielded valuable and insightful findings. Scammers consume approximately 13.4 ETH daily, which accounts for 12.5% of the total Ethereum gas, to propagate address poisoning scams. Additionally, our analysis reveals patterns in the cash-out process employed by phishing scammers, and we find that the top five phishing organizations are responsible for 40.7% of all losses. Furthermore, our work has made significant contributions to mitigating real-world threats. We have reported 1,726 phishing addresses to the community, accounting for 42.7% of total community contributions during the same period. Additionally, we have sent 2,539 on-chain alert messages, assisting 1,980 victims. This research serves as a valuable reference in combating the emerging PTXPHISH and safeguarding users’ assets.
ABOUT NDSS
The Network and Distributed System Security Symposium (NDSS) fosters information exchange among researchers and practitioners of network and distributed system security. The target audience includes those interested in practical aspects of network and distributed system security, with a focus on actual system design and implementation. A major goal is to encourage and enable the Internet community to apply, deploy, and advance the state of available security technologies.

Our thanks to the Network and Distributed System Security (NDSS) Symposium for publishing their Creators, Authors and Presenter’s superb NDSS Symposium 2025 Conference content on the Organizations’ YouTube Channel.

Permalink

*** This is a Security Bloggers Network syndicated blog from Infosecurity.US authored by Marc Handelman. Read the original post at: https://www.youtube-nocookie.com/embed/malawGL3g3I?si=aVtKqAWoksBmoaVB


文章来源: https://securityboulevard.com/2026/01/ndss-2025-dissecting-payload-based-transaction-phishing-on-ethereum/
如有侵权请联系:admin#unsafe.sh