What's in Your Wallet? Privacy and Security Issues in Web 3.0

09/14/2021
by   Philipp Winter, et al.
0

Much of the recent excitement around decentralized finance (DeFi) comes from hopes that DeFi can be a secure, private, less centralized alternative to traditional finance systems but the accuracy of these hopes has to date been understudied; people moving to DeFi sites to improve their privacy and security may actually end up with less of both. In this work, we improve the state of DeFi by conducting the first measurement of the privacy and security properties of popular DeFi applications. We find that DeFi applications suffer from the same kinds of privacy and security risks that frequent other parts of the Web. For example, we find that one common tracker has the ability to record Ethereum addresses on over 56 sites can trivially link a user's Ethereum address with PII (e.g., name or demographic information) or phish users. This work also proposes remedies to the vulnerabilities we identify, in the form of improvements to the most common cryptocurrency wallet. Our wallet modification replaces the user's real Ethereum address with site-specific addresses, making it harder for DeFi sites and third parties to (i) learn the user's real address and (ii) track them across sites.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
01/18/2022

Tutela: An Open-Source Tool for Assessing User-Privacy on Ethereum and Tornado Cash

A common misconception among blockchain users is that pseudonymity guara...
research
02/18/2019

Another Brick in the Paywall: The Popularity and Privacy Implications of Paywalls

Funding the production and distribution of quality online content is an ...
research
06/13/2023

Is Your Wallet Snitching On You? An Analysis on the Privacy Implications of Web3

With the recent hype around the Metaverse and NFTs, Web3 is getting more...
research
10/07/2021

Attacks on Onion Discovery and Remedies via Self-Authenticating Traditional Addresses

Onion addresses encode their own public key. They are thus self-authenti...
research
01/21/2020

Information Leaks via Safari's Intelligent Tracking Prevention

Intelligent Tracking Prevention (ITP) is a privacy mechanism implemented...
research
10/03/2019

On the security and privacy of Interac e-Transfers

Nowadays, the Interac e-Transfer is one of the most important remote pay...

Please sign up or login with your details

Forgot password? Click here to reset