Sweeping the Blockchain: Unmasking Illicit Accounts in Web3 Scams

Black Hat Asia 2025 · Day 1 · Briefings

Overview

The rapid expansion of the Web3 ecosystem, promising a decentralized future built on blockchain technology, has unfortunately attracted a new wave of sophisticated illicit activities. With its market value projected to reach $3.17 billion by 2024, driven by advancements in decentralized applications (dApps), DeFi protocols, and decentralized identifier systems, Web3 presents both immense opportunity and significant security challenges. Scams in this space are increasingly complex, ranging from deceptive fishing scams and airdrop/giveaway scams to advanced crypto-jackers, collectively resulting in staggering financial losses exceeding $500 million annually.

Watch on YouTube

Visual summary for Sweeping the Blockchain: Unmasking Illicit Accounts in Web3 Scams
Visual summary for Sweeping the Blockchain: Unmasking Illicit Accounts in Web3 Scams

Key moments

  1. 0:00 Introduction, team background, and talk overview
  2. 2:40 Web3 market growth and Ethereum network structure analysis
  3. 4:08 The growing problem of sophisticated Web3 scams
  4. 5:50 Limitations of existing graph and sequential learning methods
  5. 7:50 Introducing Scam Sweeper to address current method limitations
  6. 8:15 Scam Sweeper's four-part framework for scam detection
  7. 9:15 Graph construction challenges and limitations of random walk

Sweeping the Blockchain: Unmasking Illicit Accounts in Web3 Scams

Speakers: Wali, PhD Student, Hana University

Conference: Black Hat Asia

YouTube: https://www.youtube.com/watch?v=Nhrc_PbeNu8

Overview

The rapid expansion of the Web3 ecosystem, promising a decentralized future built on blockchain technology, has unfortunately attracted a new wave of sophisticated illicit activities. With its market value projected to reach $3.17 billion by 2024, driven by advancements in decentralized applications (dApps), DeFi protocols, and decentralized identifier systems, Web3 presents both immense opportunity and significant security challenges. Scams in this space are increasingly complex, ranging from deceptive fishing scams and airdrop/giveaway scams to advanced crypto-jackers, collectively resulting in staggering financial losses exceeding $500 million annually.

This talk, presented by Wali from Hana University, introduces Scam Sweeper, a novel framework designed to combat these evolving threats by unmasking illicit accounts on the blockchain. Recognizing the limitations of existing detection methods, Scam Sweeper combines sequential and graph-based learning techniques to effectively analyze the dynamic and often camouflaged behaviors of scammers. The framework offers a comprehensive solution to identify high-risk transaction paths and capture the temporal evolution of scam activities, providing a crucial defense mechanism in the burgeoning Web3 landscape.

Wali, a first-year PhD student, delivers this presentation on behalf of an experienced team in blockchain security, particularly focused on "serism" (security systems or scams). Their extensive work has been recognized in top academic conferences, leading to numerous awards and citations, and their contributions include applying for over 30 vulnerability IDs from CVE and CND, underscoring their expertise and commitment to enhancing digital security.

Background

▶ Watch: Introduction, team background, and talk overview (0:00)

The foundation of Web3's appeal lies in its decentralized nature, primarily powered by blockchain technology like Ethereum. Access to this ecosystem is diverse, encompassing NFT marketplaces, DeFi protocols (such as decentralized exchanges - DEXs), and metaverse platforms. Financial and crypto gaming industries account for the largest market share, with decentralized and centralized exchanges being central to asset transactions. Despite the allure of a "marvelous form of recreation" in virtual worlds, the underlying financial infrastructure remains a prime target for exploitation.

Analysis of the Ethereum blockchain reveals a network structure where account addresses act as nodes and transactions as edges. This network exhibits a power-law distribution, meaning a few nodes (typically exchanges or large entities) have a high degree, facilitating numerous large transactions, while the majority of ordinary users have a low degree, engaging in smaller, high-frequency trades. This concentration implies that if core nodes are compromised by scam risks, the impact can ripple through a significant portion of the network.

Web3 scams are notably sophisticated. Traditional fishing scams redirect users to malicious sites to steal tokens. More recently, scammers have employed tools like the R package to mimic legitimate wallet interfaces, stealing sensitive user information. Airdrop and giveaway scams lure users with promises of benefits to extract private data. The financial toll is substantial, with over $500 million lost in a single year due to these illicit activities, and fishing scams alone accounting for over $490 million. While crypto-jackers and fishing both exploit user trust for token transfers, crypto-jackers often present as legitimate service providers, embedding scam behaviors within the service delivery. On-chain transaction graphs reveal not only complex off-chain behavioral patterns but also clear distinctions in the on-chain activity of these scams.

Previous research has attempted to detect scam accounts using various methods. Graph learning methods, such as Graph Neural Networks (GNN) and Graph Attention Networks (GAT), utilize multi-hop learning to extract features from transaction graphs. However, the power-law distribution and large transaction network of Ethereum introduce significant noise with each hop, requiring many layers to learn features effectively, which is computationally intensive and prone to error. Alternatively, sequential learning methods process all transactions of an account in temporal order, aiming to capture the attacker's logic. While effective in principle, this approach faces severe scalability issues. Ethereum currently hosts 2.7 billion transactions, with some accounts possessing over a million transactions, making sequential analysis highly time and resource-consuming for large-scale detection. These limitations highlight a critical gap: existing methods struggle to capture dynamic evolutionary features and efficiently handle massive transaction volumes.

Key Findings

▶ Watch: The growing problem of sophisticated Web3 scams (4:08)

To address the shortcomings of prior detection techniques, the research team at Hana University developed Scam Sweeper, a novel framework that fundamentally shifts how illicit accounts are identified in Web3. The core innovation of Scam Sweeper lies in its ability to combine the strengths of both sequential and graph-based learning methods, effectively learning sequential features from a graph network.

The primary contributions and key findings of Scam Sweeper are:

  1. Introduction of STRAW-WORK (Structure Temporal Random Work): This novel random walk algorithm enables efficient sampling of high-risk transaction paths while meticulously preserving temporal dependencies. Unlike traditional random walks, STRAW-WORK considers both the structural attributes of the network and the temporal gaps between transactions, allowing it to capture more nuanced scam patterns. Experimental results, visualized with T-SNE, demonstrate STRAW-WORK's superior ability to distinguish between different account types, achieving near-linear separability.
  2. Development of the Vibration Transformer: Scam Sweeper incorporates a custom Vibration Transformer structure to model the dynamic relationship evolution within the transaction network. This component is crucial for capturing both structural changes in subgraphs and the temporal sequence patterns of transactions over time. By leveraging self-attention and feed-forward neural network layers, it effectively extracts dynamic evolutionary features that are indicative of scam activities.
  3. Comprehensive Solution for Web3 Scam Detection: By bridging the gap between temporal dynamics and structural analysis, Scam Sweeper provides the first truly comprehensive solution for Web3 illicit account detection. It overcomes the limitations of noise in graph methods and the high consumption of sequential methods, offering a scalable and accurate approach.
  4. Superior Performance Metrics: Experimental evaluation on a large dataset of the first 18 million Ethereum block heights demonstrated that Scam Sweeper consistently outperforms other methods across critical metrics including accuracy, F1 score, precision, and recall. This empirically validates its effectiveness in identifying sophisticated Web3 scams.
  5. Identification of Dynamic Scam Patterns: Scam Sweeper successfully detected and visualized dynamic evolutionary features specific to Web3 scams. It revealed patterns such as initial high interaction with many accounts, followed by a decrease in transaction amounts as stealing occurs, and then an attempt by scammers to mimic normal regularity. This detailed understanding of scam lifecycle provides invaluable insights for proactive defense.

Technical Deep Dive

▶ Watch: Limitations of existing graph and sequential learning methods (5:50)

The Scam Sweeper framework is meticulously designed to overcome the limitations of existing methods by integrating sequential and graph learning. It comprises four main parts: data collection, network simplification and splitting, subgraph feature learning, and sequence learning for classification.

1. Graph Construction and Sampling with STRAW-WORK

The initial step involves constructing a transaction network where account addresses are nodes and transactions are edges. Data is collected from sources like Etherscan and GitHub. Unlike previous works that often rely on simple random walks, which are inherently random and may miss specific patterns, Scam Sweeper introduces STRAW-WORK (Structure Temporal Random Work). This novel sampling method is designed to consider both the structural features of the network and the temporal attributes of transactions, making it more effective for detecting specific categories of illicit activity.

STRAW-WORK operates in two key steps:

  • Step 1: For a given node v_i, the algorithm calculates the proportion of the time gap in the sum of all time gaps for its neighbors. This proportion, p_i, is then used as a probability to select the next node, v_{i+1}, using an alien sampling method. This ensures that nodes with recent or significant temporal interactions are prioritized.
  • Step 2 (Optional for DRAW-WORK, essential for STRAW-WORK): Subsequently, the algorithm considers the inverse ratio of the number of neighborhoods of v_{i+1} and a probability p_n. This step further refines the sampling by considering the structural density around the chosen node, again using alien sampling to obtain the sub-network.

If only Step 1 is applied, the method is called DRAW-WORK. When both steps are included, it forms STRAW-WORK. The superiority of STRAW-WORK was demonstrated by embedding it alongside traditional random walk and deep walk methods. Visualizations using T-SNE showed that DRAW-WORK and STRAW-WORK could clearly distinguish between different account types, with STRAW-WORK achieving almost linear segmentation, indicating its effectiveness in capturing discriminative features.

2. Subgraph Feature Extraction

After generating a sampled network using STRAW-WORK, Scam Sweeper divides this network into several subgraphs based on predefined time intervals (e.g., one day). For each of these subgraphs:

  • Transactions are sorted chronologically.
  • Directed node and edge representations are obtained, reflecting the direction of the transactions. This is crucial because scam behaviors often involve specific flow directions (e.g., funds moving to a scammer).
  • A graph learning algorithm (specifically, a Graph Neural Network encoder) is then applied to extract features from these directed subgraphs.

A concrete example illustrates this process: for an "eagle network" centered around a core node, all connected agents and nodes are first identified. Then, nodes and their connected edges are aligned to construct node features. A "Key Lack Rule" is employed to align nodes and edges, obtaining height information instead of just node presence. Finally, two connected nodes with the same edge direction are aligned to represent the directed edge, and an importance score is computed for each edge. This comprehensive process yields a directed feature representation of the entire subgraph.

3. Dynamic Evolution Feature Capture with Vibration Transformer

Once features for all subgraphs have been extracted, they are sorted in chronological order. To capture the dynamic evolution of account behavior over time, Scam Sweeper utilizes a Vibration Transformer structure. This transformer is designed to process sequences of subgraph features and extract temporal dynamics.

The Vibration Transformer specifically incorporates:

  • Self-attention layers: These layers allow the model to weigh the importance of different past subgraph features when processing the current one, enabling it to understand long-range dependencies and contextualize current behavior within historical patterns.
  • Feed-forward neural network layers: These provide non-linearity and further transform the attention-weighted features into a more discriminative representation.

By applying this transformer, Scam Sweeper effectively captures how an account's behavior (as represented by its subgraph features) changes and evolves over time, which is a hallmark of sophisticated scam operations.

4. Classification

Finally, the dynamic evolutionary features extracted by the Vibration Transformer are fed into a simple conversion method for classification, categorizing accounts as either illicit or normal.

Experimental Evaluation

The efficacy of Scam Sweeper was rigorously evaluated using a substantial dataset comprising the first 18 million block heights on the Ethereum blockchain. This represents one of the largest datasets used in such research.

  • Data Labeling: Core data was labeled with the assistance of Etherscan (a public blockchain browser with a label cloud model for scam types) and Scam Sniffer (a research institute specializing in Web3 scams, used to identify and label related account addresses).
  • Normal Accounts: To establish a baseline, exchanges, money ICO wallets, and gambling accounts were designated as normal accounts.
  • Feature Analysis: Analysis of the distribution of in-degrees and out-degrees for Web3 scam accounts revealed distinct differences, confirming the utility of directed features in classification.
  • Model Performance: Scam Sweeper, combining the graph encoder and the Vibration Transformer (referred to as the T-transformer), was evaluated using F1 score and weighted F1 score. Both components proved effective, with the graph encoder showing slightly higher individual performance. Crucially, when compared against other graph and transformer methods, Scam Sweeper consistently outperformed them across all metrics: accuracy, F1 score, precision, and recall. This robust performance validates Scam Sweeper's ability to detect Web3 scams effectively.

Demo / Proof of Concept

▶ Watch: Scam Sweeper's four-part framework for scam detection (8:15)

While the talk did not feature a live, interactive demonstration, the speaker presented compelling visualizations derived from the Scam Sweeper framework's analysis of on-chain data, serving as a powerful proof of concept for its capabilities. These visualizations detailed the dynamic evolution of Web3 scam accounts.

Using STRAW-WORK to trace relevant transactions, the team visualized transaction paths with a time interval set to one day. The analysis revealed distinct behavioral phases:

  • Initial Interaction: In the first one to two days, a scam account typically interacts with a large number of other accounts in a short period. This phase represents the outreach or initial engagement with potential victims.
  • Stealing Phase: Subsequently, the transaction amounts begin to decrease as the actual stealing of assets occurs. This suggests a shift from broad interaction to focused exploitation.
  • Mimicking Normalcy: After the illicit gains are secured, scammers attempt to mimic normal transaction regularity. This phase aims to make the account appear less suspicious and blend in with legitimate activity, potentially to obscure the trail or prepare for further operations.

Furthermore, to counteract potential DoS attacks or to ensure the observed decrease in transaction volume was not merely downtime, the team checked subsequent transaction addresses. They found that these addresses were almost entirely inconsistent with previous transactions. This finding strongly suggests that users who had been victimized did not continue to trust or interact with the service provider, reinforcing the detection of malicious activity rather than a legitimate service's temporary lull. These visualizations effectively demonstrate Scam Sweeper's ability to not only detect static indicators but also to unravel the complex, time-evolving patterns characteristic of Web3 scams.

Defensive Implications

▶ Watch: Graph construction challenges and limitations of random walk (9:15)

The insights and capabilities offered by Scam Sweeper provide several critical implications for defenders in the Web3 ecosystem, from individual users to large-scale platforms and researchers.

  1. Proactive Monitoring and Early Warning Systems: Web3 platforms, exchanges, and wallet providers should integrate methodologies similar to Scam Sweeper for real-time, proactive monitoring. By analyzing transaction graphs with a focus on temporal dynamics and directed features, they can identify emerging scam patterns early. The observed "initial high interaction, then decrease, then mimicking normal regularity" pattern can serve as a powerful signature for flagging suspicious accounts.
  2. Enhanced Transaction Screening: Incorporate STRAW-WORK and the Vibration Transformer into transaction screening processes. STRAW-WORK's ability to efficiently sample high-risk transaction paths, while preserving temporal dependencies, can help prioritize which transactions and accounts require deeper scrutiny. The Vibration Transformer can then assess the dynamic evolution of an account's behavior to determine its risk profile before large-scale losses occur.
  3. User Education and Awareness: The dynamic patterns identified by Scam Sweeper can inform more effective user education. Users should be made aware that a sudden burst of interactions followed by a drop-off, or an account that rapidly changes its transaction patterns, could be indicative of a scam. Emphasizing the importance of verifying service providers and being wary of "too good to be true" offers is crucial.
  4. Leveraging Directed Graph Features: Defenders should pay closer attention to the directed nature of transactions (in-degree vs. out-degree) as a key indicator of illicit activity. Scam Sweeper highlighted that Web3 scams distinguish significantly in these metrics, suggesting that simple undirected graph analysis might miss crucial signals.
  5. Scalable Detection Solutions: For large blockchains like Ethereum with billions of transactions, traditional graph or sequential learning methods are often impractical. Scam Sweeper demonstrates that combining these approaches in an intelligent, resource-efficient manner (e.g., through smart sampling with STRAW-WORK and temporal sequence modeling with the Vibration Transformer) is essential for building scalable and effective detection systems.
  6. Collaborative Threat Intelligence: The data labeling efforts using Etherscan and Scam Sniffer underscore the importance of collaborative threat intelligence. Sharing labeled scam addresses and patterns across the industry can significantly enhance the collective ability to detect and mitigate these threats.

By adopting these defensive strategies, the Web3 community can move towards a more secure and trustworthy environment, safeguarding users and the integrity of decentralized finance.

Key Takeaways

  • Web3 scams are sophisticated and costly: Illicit activities in Web3, including fishing, airdrops, and crypto-jackers, result in over $500 million in losses annually, exploiting vulnerabilities in transaction networks.
  • Traditional detection methods fall short: Existing graph learning methods struggle with noise and the power-law distribution of blockchain networks, while sequential learning methods are computationally prohibitive for massive transaction volumes.
  • Scam Sweeper offers a novel, integrated approach: The framework effectively combines sequence and graph learning by extracting sequential features from graph networks, addressing the limitations of prior techniques.
  • STRAW-WORK is key for efficient, temporal sampling: The Structure Temporal Random Work algorithm efficiently samples high-risk transaction paths, preserving crucial temporal dependencies and demonstrating superior discriminative power.
  • Vibration Transformer captures dynamic evolution: This specialized transformer models the dynamic changes in account behavior over time, identifying subtle shifts that characterize scam operations.
  • Scam Sweeper outperforms existing solutions: Rigorous experiments on a large Ethereum dataset confirm Scam Sweeper's superior accuracy, F1 score, precision, and recall compared to other methods, providing a robust defense against Web3 scams.

About the Speaker(s)

The talk was presented by Wali, a first-year PhD student at Hana University. Wali is part of a sophisticated and experienced team specializing in blockchain security, particularly focusing on "serism" (security systems or scams within the blockchain context). Over the past five years, their team has made significant contributions to the field, sharing their research at various top academic conferences and earning a series of awards and high citations for their peer-recognized work. Demonstrating their commitment to practical security, the team has also applied for more than 30 vulnerability IDs from the CVE (Common Vulnerabilities and Exposures) and CND (China National Vulnerability Database), highlighting their active role in identifying and addressing security flaws in the digital landscape.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

Dr. Kozlov's assessment of "Sweeping the Blockchain" is highly positive. The talk introduces Scam Sweeper, a novel framework that effectively combines temporal and graph-based learning to detect illicit accounts on the Ethereum blockchain. The core innovations, STRAW-WORK for efficient, temporally-aware sampling and the Vibration Transformer for capturing dynamic scam evolution, directly address critical scalability and noise limitations of existing methods. This research provides a robust, empirically validated solution with significant practical implications for Web3 security, offering actionable insights for platforms and defenders.

Heather Calloway (CISO) — STRONG ACCEPT

This research on Scam Sweeper offers a compelling and empirically validated approach to combating sophisticated Web3 financial crime, a critical risk for any institution operating in or exposed to the decentralized ecosystem. By intelligently combining sequential and graph-based learning, it addresses significant limitations of prior detection methods, demonstrating superior performance in unmasking illicit accounts. While the direct implementation details would require substantial engineering, the framework provides essential strategic guidance for security leaders, platforms, and exchanges seeking to enhance proactive monitoring, strengthen transaction screening, and manage the…

→ Top-rated talks at Black Hat Asia 2025

All talks from Black Hat Asia 2025