Investigating Ethereum Phishing Gangs in Action Using Blockchain
DOI:
https://doi.org/10.62643/Keywords:
Ethereum, phishing scams, blockchain security, phishing gang detection, transaction analysisAbstract
Phishing scams have become a major cybercrime threat within the evolving blockchain ecosystem, particularly in Ethereum, the second-largest blockchain network. These scams have led to significant financial losses. However, existing Ethereum phishing detection methods primarily rely on machine learning or transaction graph embedding techniques to identify fraudulent accounts individually, failing to uncover groups of interconnected scam-related accounts—referred to as “phishing gangs.” Due to Ethereum’s pseudonymous nature, these undisclosed conspirator accounts pose potential risks to the system. In this paper, we present the first study aimed at characterizing and detecting Ethereum phishing gangs. We analyze transaction behaviors within these gangs from individual, pairwise, and higher-order perspectives. Our findings reveal that despite the Ethereum transaction graph being sparse with a highly skewed degree distribution, phishing accounts within the same gang exhibit closer relationships and distinct transaction patterns. Based on these insights, we define the phishing gang detection problem and introduce PGDetector, a novel detection model. PGDetector starts with a known phishing account and identifies other potentially risky accounts within its community by leveraging genetic algorithm optimization. Extensive experiments on large-scale Ethereum transaction data validate the effectiveness of PGDetector in detecting phishing gangs.
Downloads
Published
Issue
Section
License

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.













