Pulling Off The Mask: Forensic Analysis of the Deceptive Creator Wallets Behind Smart Contract Fraud
Mingxuan Yao, Runze Zhang, Haichuan Xu, Ryan Chou, Varun Chowdhary Paturi, Amit Kumar Sikder
IEEE Symposium on Security and Privacy 2024 · Day 2 · Continental Ballroom 6
Overview
The proliferation of smart contracts on public blockchains like Ethereum has unfortunately been accompanied by a significant rise in sophisticated fraud schemes. These schemes often involve deceptive creator wallets (DCWs), which are digital wallets used by scammers to deploy numerous fraudulent contracts. Traditional investigative methods, such as tracing the flow of stolen funds, prove largely ineffective against these DCWs because the funds rarely interact directly with the creator wallet itself. This talk, "Pulling Off The Mask," introduces Coco, a novel forensic analysis framework designed to overcome these limitations.

Key moments
- 0:00 Jake's dilemma: Inefficient fraud investigation and fund tracking
- 2:00 Introducing Deceptive Creator Wallets (DCW) and Coco's solution
- 4:00 Coco's symbolic analysis uncovers dynamic recipient resolution
- 5:40 Real-world impact: $1.2B stolen, 1M contracts uncovered
- 6:00 Analyzing profit distribution and operational patterns of DCWs
- 8:00 Uncovering 500K victims; collaboration with EtherScan and FBI
- 9:50 Future research directions and Coco's public availability
Pulling Off The Mask: Forensic Analysis of the Deceptive Creator Wallets Behind Smart Contract Fraud
Speakers: Mingxuan Yao, Runze Zhang, Haichuan Xu, Ryan Chou, Varun Chowdhary Paturi, Amit Kumar Sikder
Conference: IEEE S&P
YouTube: https://www.youtube.com/watch?v=uRdmzkdfGwA
Overview
The proliferation of smart contracts on public blockchains like Ethereum has unfortunately been accompanied by a significant rise in sophisticated fraud schemes. These schemes often involve deceptive creator wallets (DCWs), which are digital wallets used by scammers to deploy numerous fraudulent contracts. Traditional investigative methods, such as tracing the flow of stolen funds, prove largely ineffective against these DCWs because the funds rarely interact directly with the creator wallet itself. This talk, "Pulling Off The Mask," introduces Coco, a novel forensic analysis framework designed to overcome these limitations.
Coco provides a scalable and comprehensive approach to identifying DCWs, uncovering the full scope of their fraudulent campaigns, and analyzing their operational capabilities to inform proactive mitigation strategies. By combining transaction analysis with advanced bytecode analysis, Coco unmasks the hidden infrastructure of smart contract fraud, revealing the intricate connections between seemingly disparate incidents. The research highlights the severe limitations of current investigative practices and demonstrates Coco's significant impact through collaborations with major industry players like Etherscan and law enforcement agencies such as the FBI.
The significance of this work lies in its ability to provide investigators and blockchain platforms with a powerful tool to combat the escalating problem of smart contract fraud. By moving beyond reactive fund-tracing to proactive identification of threat actors and their modus operandi, Coco offers a path toward disrupting fraud campaigns at their source, preventing future victims, and recovering stolen assets on a much larger scale than previously possible. The findings underscore the vast financial and human impact of these frauds, revealing hundreds of millions of dollars stolen and hundreds of thousands of victims affected.
Background
▶ Watch: Jake's dilemma: Inefficient fraud investigation and fund tracking (0:00)
The decentralized nature of blockchain technology, while offering transparency and immutability, also presents unique challenges for fraud investigation. Smart contracts, self-executing code stored on a blockchain, are often exploited by malicious actors to create elaborate scams. These scams frequently involve promises of high returns, fake investment platforms, or phishing attempts, all orchestrated through carefully designed smart contracts. Victims are lured into sending funds to these fraudulent contract addresses, believing they are participating in legitimate financial activities.
A primary hurdle for investigators, exemplified by the talk's narrative character "Jake," is the sheer volume and complexity of these fraud incidents. Each reported scam often appears as an isolated event, requiring individual investigation. The traditional investigative approach, which focuses on fund flow tracking, involves following the path of stolen cryptocurrencies across various addresses and contracts. While effective for simple thefts, this method falls short when dealing with sophisticated smart contract fraud orchestrated by DCWs. As the speakers explain, stolen funds rarely flow directly to or from the DCW itself, making it an invisible orchestrator within the fund flow graph. This disconnect renders it nearly impossible for investigators to identify the common source—the DCW—behind multiple related frauds.
Furthermore, the rapid deployment cycle of new fraudulent contracts means that by the time an investigator finishes analyzing one incident, ten more have already appeared. This creates an unmanageable workload and a reactive stance where mitigation efforts always lag behind new deployments. The problem is exacerbated by sophisticated contract behaviors, such as dynamic recipient resolution, where the destination of stolen funds can change based on external inputs or on-chain data, making static analysis or simple fund tracing inadequate. Prior work often focused on identifying individual malicious contracts or patterns within contract bytecode, but lacked a holistic approach to link these contracts back to their common creator and understand the full scope of a fraud campaign. This gap highlighted the urgent need for a solution that could not only identify the deceptive creator wallets but also uncover all associated frauds and analyze their capabilities for effective, proactive intervention.
Key Findings
▶ Watch: Coco's symbolic analysis uncovers dynamic recipient resolution (4:00)
The deployment and subsequent evaluation of Coco yielded several critical findings that underscore the pervasive nature of smart contract fraud and the effectiveness of the proposed forensic framework. Through a collaboration with Etherscan, the most popular Ethereum block explorer, Coco was tasked with analyzing a dataset of 157 initial fraud contracts that had been reported to Etherscan.
The results were striking:
- Identification of DCWs: Coco successfully identified 91 unique deceptive creator wallets (DCWs) responsible for deploying these initial fraudulent contracts. This demonstrated Coco's core capability in unmasking the hidden orchestrators of fraud.
- Vast Scale of Fraudulent Contracts: These 91 DCWs were found to have created an astonishing more than 1 million additional fraudulent contracts. This finding dramatically expanded the known scope of these fraud campaigns, illustrating how a small number of DCWs can be responsible for an enormous network of malicious activity.
- Staggering Financial Losses: By calculating the value of stolen assets using historical Ethereum exchange rates, Coco uncovered more than $200 million in stolen funds. The speakers noted that if scammers had held onto their profits, the current value would be significantly higher due to Ethereum's price appreciation.
- Profit Distribution: Analysis of profit distribution revealed that while many DCWs made significant profits (from $1,000 to $1 million), a substantial number also operated with lower profits per contract but deployed a high volume of contracts. The top 10 most profitable DCWs alone accounted for over $1.7 million in illicit gains.
- Long-Term Operation: The fraudulent activities traced back to these DCWs date as far back as September 2017, just two years after Ethereum's introduction, indicating a long-standing and evolving threat landscape.
- Underestimated Victim Count: Perhaps one of the most impactful findings was the stark contrast between traditional investigation methods and Coco's comprehensive analysis. While traditional fund flow tracking could only identify approximately 15,000 victims associated with the analyzed frauds, Coco, by identifying all related contracts and campaigns, uncovered almost 500,000 victims. This highlights the severe underestimation of the true human cost of smart contract fraud when relying solely on traditional methods.
- Successful Collaboration and Mitigation: The research led to successful collaborations with both Etherscan and the FBI. Etherscan utilized Coco's findings to flag the identified 91 DCWs and over 1 million fraud contracts, displaying warnings to users interacting with these addresses. Discussions with the FBI are ongoing to integrate Coco's capabilities for broader fraud mitigation and prevention efforts.
These findings collectively paint a grim picture of the scale and sophistication of smart contract fraud, while simultaneously demonstrating Coco's unprecedented ability to expose and combat these threats effectively.
Technical Deep Dive
▶ Watch: Real-world impact: $1.2B stolen, 1M contracts uncovered (5:40)
Coco’s efficacy stems from its innovative combination of deploying chain analysis with bytecode analysis, specifically through symbolic execution. This hybrid approach allows it to identify DCWs, uncover related fraud incidents, and analyze the operational capabilities of the fraudulent contracts.
The process begins with a single reported fraudulent contract as input. Coco first performs deploying chain analysis to identify the DCW. Unlike tracing stolen funds, this analysis focuses on the creation transaction of the fraud contract itself, linking it back to the wallet that deployed it. This initial step is crucial for establishing the origin point of the malicious campaign, circumventing the issue of funds not directly interacting with the DCW.
Once a DCW is identified, Coco moves to implicit fraud identification to uncover all other incidents orchestrated by the same campaign. This involves querying the blockchain for all other contracts created by the identified DCW, effectively revealing the full breadth of the scammer's operations. This is where Coco's power truly shines, as it connects seemingly unrelated fraud reports under a single malicious actor.
The most technically sophisticated aspect of Coco is its capability analysis, which delves into the bytecode of the fraudulent contracts to understand how they operate and identify patterns that can inform mitigation. This is particularly important for identifying advanced fraud techniques like dynamic recipient resolution. The talk provides a compelling example: an investigator (Jake) observes a fraud contract (Contract 1) that, at different times, sends stolen funds to entirely different recipient addresses. This behavior is confusing if only fund flow is tracked.
Coco addresses this through symbolic analysis. When analyzing Contract 1, Coco marks its input, storage variables, and internal balance as symbolic values. This means these values are treated as variables rather than concrete numbers, allowing Coco to explore all possible execution paths of the contract's bytecode. During this symbolic execution process, Coco meticulously maps accumulated symbolic constraints to a CAP model (Constraint Accumulation and Propagation model). This model captures the logical relationships and conditions under which different parts of the contract's code execute.
In the example of dynamic recipient resolution, Coco's symbolic execution might discover that Contract 1 is not hardcoding the recipient address. Instead, it's fetching the recipient information from an on-chain data drop. This data drop itself might be controlled by another contract, say Fraud Contract 4. Coco's analysis reveals that Fraud Contract 4 is defining or updating the recipient information for Fraud Contract 1 through this on-chain data mechanism. This is a critical insight: the recipient is dynamic and controlled externally.
Following symbolic analysis, Coco performs transaction analysis to complete the picture. It observes actual transactions that interact with these contracts and the on-chain data drop. This allows Coco to identify the specific "redirection command" and its origin (e.g., a transaction from Fraud Contract 4 updating the data drop) that dictates where funds are sent. By combining symbolic exploration of potential behaviors with concrete transaction data, Coco can definitively determine the mechanism of dynamic recipient resolution.
This deep technical understanding of a contract's capabilities allows Coco to inform specific mitigation steps. For instance, if dynamic recipient resolution is identified, Coco can advise monitoring transactions invoked by the "defining" contract (Fraud Contract 4) or directly monitoring the on-chain data drop for changes. This shifts mitigation from a reactive response to individual fraud incidents to a proactive monitoring of the underlying control mechanisms, enabling the detection of future frauds before they claim new victims. The integration of these analytical layers—deploying chain, implicit fraud, and capability analysis via symbolic execution—provides a robust and comprehensive framework for dissecting the anatomy of smart contract fraud.
Demo / Proof of Concept
▶ Watch: Uncovering 500K victims; collaboration with EtherScan and FBI (8:00)
While the presentation did not feature a live, interactive demonstration of the Coco framework in action, it effectively showcased the tangible results and impact of its application through real-world collaborations. The "proof of concept" was manifested in the successful deployment and evaluation of Coco against a dataset of reported fraud contracts and the subsequent actions taken by industry partners.
Specifically, the talk highlighted the collaboration with Etherscan, where Coco's findings were directly integrated into their platform. An example was shown of a flagged fraud contract on Etherscan, displaying a prominent warning message to potential users, stating, "This address has been flagged as a fraudulent address. Users are advised to never interact with this contract." This visual evidence serves as a clear demonstration of Coco's output being utilized to protect users in real-time.
The impact of this collaboration was significant: Coco reported 91 DCWs and over 1 million associated fraud contracts to Etherscan. The immediate action taken by Etherscan to flag these addresses represents a powerful validation of Coco's ability to identify and expose large-scale fraud infrastructure. Furthermore, the ongoing collaboration with the FBI, detailed through an email chain screenshot indicating meetings and joint efforts, further solidifies Coco's real-world utility and its potential to influence law enforcement strategies against cybercrime. These practical applications and protective measures, rather than a direct software demonstration, served as the primary proof of concept for Coco's effectiveness.
Defensive Implications
▶ Watch: Future research directions and Coco's public availability (9:50)
The insights and capabilities offered by Coco provide a robust foundation for enhancing defensive strategies against smart contract fraud, moving beyond reactive measures to proactive prevention and disruption. The key defensive implications can be categorized for various stakeholders:
- For Blockchain Explorers and Platforms (e.g., Etherscan):
- Proactive Flagging: Platforms should integrate tools like Coco to automatically identify and flag DCWs and the vast networks of fraudulent contracts they deploy. This warning system can significantly deter potential victims by making the malicious nature of addresses immediately apparent.
- Enhanced Reporting Mechanisms: Leverage Coco's ability to link disparate fraud incidents to a single DCW. This allows for more comprehensive reporting and blacklisting of entire fraud campaigns rather than just individual contract addresses.
- Early Warning Systems: By analyzing the capabilities of new contracts deployed by known or suspected DCWs, platforms can potentially predict and flag new fraud schemes even before they become widely active.
- For Law Enforcement and Regulatory Bodies (e.g., FBI):
- Targeted Investigations: Coco provides investigators with the ability to identify the true orchestrators (DCWs) of fraud, enabling more effective targeting of criminal enterprises rather than chasing individual transactions.
- Campaign Disruption: Understanding the full scope of a DCW's operations (over 1 million contracts in some cases) allows for comprehensive disruption efforts, potentially leading to the arrest of perpetrators and recovery of larger sums of stolen funds.
- Intelligence Gathering: The capability analysis, especially regarding dynamic recipient resolution and self-replicating polymorphic contracts (mentioned as "more in the paper"), offers critical intelligence on evolving fraud tactics, aiding in the development of countermeasures.
- Victim Identification: Identifying a significantly higher number of victims (e.g., 500,000 vs. 15,000) allows for broader outreach, support, and potential restitution efforts.
- For Smart Contract Developers and Auditors:
- Security Best Practices: Understanding how fraudsters utilize dynamic capabilities (like on-chain data drops for recipient resolution) can inform developers about potential attack vectors to avoid in legitimate contracts.
- Vulnerability Detection: While Coco focuses on malicious contracts, its symbolic execution techniques could inspire tools to identify similar "dynamic control" patterns in legitimate contracts that might be exploitable if not properly secured.
- For Individual Users and Investors:
- Increased Awareness: The research highlights the sophistication of modern smart contract fraud. Users should be extremely cautious of investment opportunities promising unrealistic returns and always verify contract addresses through reputable block explorers.
- Trust No One (TNO): Even seemingly legitimate contracts can be part of a larger fraud network. Users should look for warnings on block explorers and exercise extreme diligence before interacting with any new or unfamiliar contract.
- Proactive Monitoring Strategies:
- Monitor DCW Deployments: Instead of waiting for fraud reports, security teams can monitor for new contract deployments from identified or suspicious DCWs.
- Track Dynamic Control Points: If a fraud mechanism relies on an on-chain data drop or a specific "defining contract" to control fund redirection, these points become critical monitoring targets. Any suspicious transactions interacting with these control points could signal an imminent fraud event.
By shifting the focus from individual incidents to the underlying infrastructure and operational capabilities of fraud campaigns, Coco empowers defenders with the intelligence needed to mitigate current threats and anticipate future ones, ultimately making the blockchain ecosystem safer.
Key Takeaways
- Traditional fund flow analysis is inadequate for combating sophisticated smart contract fraud, as deceptive creator wallets (DCWs) rarely interact directly with stolen funds, making them invisible to traditional methods.
- Coco revolutionizes fraud investigation by combining deploying chain analysis with symbolic bytecode execution, enabling the identification of DCWs, the full scope of their fraud campaigns, and their operational capabilities.
- The scale of smart contract fraud is immense: Coco uncovered over $200 million stolen from almost 500,000 victims by just 91 DCWs, which collectively deployed over 1 million fraudulent contracts.
- Dynamic recipient resolution is a key fraud technique: Coco's capability analysis revealed how fraudsters use external on-chain data drops and other contracts to dynamically change fund recipients, making static analysis ineffective.
- Proactive mitigation is possible: By understanding fraud capabilities, defenders can monitor specific control points (e.g., data drops, defining contracts) to detect and prevent future frauds before they occur.
- Collaboration with industry and law enforcement is crucial: Coco's successful integration with Etherscan for flagging millions of fraudulent addresses and ongoing collaboration with the FBI demonstrate its real-world impact and potential for widespread adoption.
About the Speaker(s)
The research presented in "Pulling Off The Mask" was a collaborative effort by a team of researchers from Georgia Tech Lab, including Mingxuan Yao, Runze Zhang, Haichuan Xu, Ryan Chou, Varun Chowdhary Paturi, and Amit Kumar Sikder. While specific individual titles and affiliations beyond Georgia Tech Lab were not detailed in the transcript, the collective expertise of the team highlights a strong academic background in security research. Mingxuan Yao was the primary presenter for this talk, representing the team's work. Their research focuses on advanced forensic analysis techniques for smart contract fraud, aiming to develop scalable solutions for identifying and mitigating sophisticated threats within the blockchain ecosystem. The collaboration with entities like Etherscan and the FBI underscores their commitment to translating academic research into practical, impactful security solutions for the real world.
Reviews
Dr. Zero (Offensive Security Researcher) — MUST SEE
This research presents Coco, a critical forensic framework that unmasks deceptive creator wallets (DCWs) orchestrating large-scale smart contract fraud. By combining deployment chain analysis with symbolic bytecode execution, Coco reveals the full scope of campaigns and their dynamic capabilities, demonstrating a profound impact on victim identification and proactive mitigation. This is exactly the kind of substantive work needed to combat sophisticated on-chain threats.
Heather Calloway (CISO) — STRONG ACCEPT
This research critically exposes the systemic nature of smart contract fraud, demonstrating how traditional investigative methods fail against sophisticated deceptive creator wallets. Coco provides a powerful, scalable framework for proactive identification and disruption of large-scale fraud campaigns, offering clear operational value for platforms and law enforcement.
→ Top-rated talks at IEEE Symposium on Security and Privacy 2024