Pulling Off The Mask: Forensic Analysis of the Deceptive Creator Wallets Behind Smart Contract Fraud

Mingxuan Yao, Runze Zhang, Haichuan Xu, Ryan Chou, Varun Chowdhary Paturi, Amit Kumar Sikder

IEEE Symposium on Security and Privacy 2024 · Day 2 · Continental Ballroom 6

Overview

In the rapidly evolving landscape of blockchain technology, smart contracts have emerged as a powerful tool, yet they also present new vectors for sophisticated fraud. This talk, "Pulling Off The Mask: Forensic Analysis of the Deceptive Creator Wallets Behind Smart Contract Fraud," presented by Mingxuan Yao and his colleagues from the Georgia Tech lab, addresses a critical and often overlooked aspect of smart contract scams: the Deceptive Creator Wallets (DCWs). These wallets are the hidden orchestrators behind vast networks of fraudulent contracts, and their elusive nature renders traditional fund flow tracking methods largely ineffective. The research introduces Coco, a novel forensic analysis tool designed to unmask these DCWs and the full scope of their illicit operations.

Watch on YouTube

Visual summary for Pulling Off The Mask: Forensic Analysis of the Deceptive Creator Wallets Behind Smart Contract Fraud by Mingxuan Yao, Runze Zhang, Haichuan Xu, Ryan Chou, Varun Chowdhary Paturi, Amit Kumar Sikder
Visual summary for Pulling Off The Mask: Forensic Analysis of the Deceptive Creator Wallets Behind Smart Contract Fraud by Mingxuan Yao, Runze Zhang, Haichuan Xu, Ryan Chou, Varun Chowdhary Paturi, Amit Kumar Sikder

Key moments

  1. 0:00 The FBI's challenge: scaling fraud investigations
  2. 2:00 Deceptive Creator Wallets and Coco's forensic approach
  3. 3:55 How Coco uses symbolic analysis to detect dynamic fraud
  4. 5:45 Coco reveals massive scale of fraud: $200M stolen
  5. 7:00 Top 10 DCWs: millions in profit, active since 2017
  6. 7:50 Coco dramatically increases victim identification over traditional methods
  7. 8:20 Collaborations with Etherscan and FBI for fraud mitigation

Pulling Off The Mask: Forensic Analysis of the Deceptive Creator Wallets Behind Smart Contract Fraud

Speakers: Mingxuan Yao; Runze Zhang; Haichuan Xu; Ryan Chou; Varun Chowdhary Paturi; Amit Kumar Sikder, Georgia Tech Lab

Conference: IEEE S&P

YouTube: https://www.youtube.com/watch?v=T_2_ucVTKKc

Overview

In the rapidly evolving landscape of blockchain technology, smart contracts have emerged as a powerful tool, yet they also present new vectors for sophisticated fraud. This talk, "Pulling Off The Mask: Forensic Analysis of the Deceptive Creator Wallets Behind Smart Contract Fraud," presented by Mingxuan Yao and his colleagues from the Georgia Tech lab, addresses a critical and often overlooked aspect of smart contract scams: the Deceptive Creator Wallets (DCWs). These wallets are the hidden orchestrators behind vast networks of fraudulent contracts, and their elusive nature renders traditional fund flow tracking methods largely ineffective. The research introduces Coco, a novel forensic analysis tool designed to unmask these DCWs and the full scope of their illicit operations.

The core problem, as highlighted by the speaker, is the severe scalability challenge faced by law enforcement agencies like the FBI when investigating individual fraud incidents. While victims report scams involving specific fraudulent contracts, tracing stolen funds often leads to dead ends or an overwhelming number of disconnected incidents. The true perpetrators, the DCWs, never directly receive or send stolen funds, making them invisible to conventional investigative techniques. This talk not only exposes the scale of this problem—affecting hundreds of thousands of victims and billions of dollars—but also provides a robust, systematic solution that integrates static and dynamic analysis to reveal the hidden connections between seemingly disparate fraud campaigns.

The significance of this work extends beyond academic curiosity, offering tangible tools and insights for mitigating widespread smart contract fraud. By identifying the root cause—the DCWs—investigators can move from reactive, incident-by-incident responses to proactive, campaign-level mitigation. The collaboration with platforms like Etherscan and agencies like the FBI underscores the real-world impact and immediate applicability of Coco's findings, promising a more effective defense against the pervasive and costly threat of blockchain-based financial deception.

Background

▶ Watch: The FBI's challenge: scaling fraud investigations (0:00)

The genesis of this research lies in a fundamental limitation of traditional cryptocurrency fraud investigations: the inability to scale. As illustrated by the "FBI agent Jake" analogy, an investigator tracking stolen funds might successfully trace a single incident, but this approach quickly breaks down when faced with an onslaught of similar reports. Each incident appears isolated, and the sheer volume of new frauds deploying in seconds far outpaces the weeks it takes to investigate even a handful of cases. The critical missing piece is identifying the orchestrator behind these widespread schemes, a challenge exacerbated by the unique architecture of smart contract fraud.

The key to understanding this challenge lies with the Deceptive Creator Wallet (DCW). A DCW is a digital wallet controlled by a scammer, used exclusively to deploy fraudulent smart contracts. Crucially, these wallets are designed to remain hidden from fund flow analysis. Stolen funds, once transacted to a fraudulent contract, are never routed to or from the DCW itself. This architectural decision by fraudsters ensures that traditional methods, which follow the money trail, hit a blind spot. Investigators like Jake are left helpless, unable to connect individual fraud incidents to a common source, let alone predict or prevent future attacks.

The problem’s existence is rooted in the pseudo-anonymous nature of blockchain transactions and the programmatic capabilities of smart contracts. While all transactions are public, the identities behind wallet addresses remain obscured. Fraudsters leverage this by creating contracts that autonomously manage stolen funds, often redirecting them through complex chains or to multiple, ephemeral recipient addresses. This dynamic behavior further complicates tracing. The motivation for this research, therefore, was to provide investigators with a tool capable of overcoming these inherent limitations, enabling them to first identify the DCW, then uncover all related fraud incidents, and finally, inform proactive mitigation strategies. This pressing need was explicitly recognized through collaboration with the FBI, highlighting the real-world impact and urgency of developing more sophisticated forensic capabilities for blockchain-based crime.

Key Findings

▶ Watch: How Coco uses symbolic analysis to detect dynamic fraud (3:55)

The deployment of Coco against real-world data revealed the staggering scale and sophistication of smart contract fraud orchestrated by Deceptive Creator Wallets (DCWs). The research began by feeding Coco a dataset of 157 fraud contracts reported to Etherscan, a popular Ethereum block explorer. From this initial set, Coco successfully identified 91 distinct DCWs responsible for their deployment, demonstrating its effectiveness in unmasking these hidden orchestrators.

The true impact of these DCWs became evident upon further analysis. The 91 identified DCWs were found to have created an astonishing more than 1 million fraudulent contracts. This finding alone underscores the limitations of traditional, incident-based investigations, as a single DCW could be responsible for an entire ecosystem of scams. The financial ramifications were equally alarming: Coco uncovered that these campaigns had stolen over $2.2 billion. This figure was calculated using historical ETH exchange rates at the time of the fraud, implying that if the perpetrators held onto their illicit gains, their profits would be significantly higher today given the appreciation of Ethereum.

Further analysis of the illicit profit distribution across contracts and DCWs painted a nuanced picture of fraud operations. While many DCWs were highly profitable, making between $1,000 and $1 million and deploying between 1,000 and 1 billion contracts, others operated on a smaller scale, making around 100 ETH with fewer than 100 contracts. This suggests a diverse operational landscape among fraudsters, from large-scale, highly organized campaigns to smaller, perhaps less sophisticated, but still significant, efforts.

A deep dive into the top 10 most profitable DCWs revealed their remarkable longevity and financial success. Fraudulent activities linked to these top perpetrators dated back to September 2017, a mere two years after Ethereum's introduction, indicating a persistent and early adoption of these deceptive tactics. Collectively, these top 10 DCWs alone were responsible for over $1.7 million in illicit profits, demonstrating the long-term, high-value nature of these sophisticated schemes.

Perhaps one of the most compelling findings was the stark contrast between Coco's victim identification capabilities and traditional methods. While conventional fund flow tracking could only identify approximately 15,000 victims from the analyzed incidents, Coco, by integrating its advanced forensic techniques, uncovered nearly 500,000 victims. This nearly 33-fold increase in identified victims dramatically illustrates the hidden scope of smart contract fraud and the necessity of tools like Coco for comprehensive impact assessment. The research team actively collaborated with Etherscan, reporting the 91 DCWs and over 1 million fraudulent contracts, leading to the flagging of these addresses and providing warnings to future users. Furthermore, ongoing collaboration with the FBI aims to leverage these findings for broader fraud mitigation efforts.

Technical Deep Dive

▶ Watch: Coco reveals massive scale of fraud: $200M stolen (5:45)

The core innovation of this research lies in Coco, a sophisticated forensic analysis system designed to "sneeze out" Deceptive Creator Wallets (DCWs). Coco transcends the limitations of traditional fund flow tracking by integrating two powerful analytical paradigms: transaction analysis and bytecode analysis. This combined approach provides a more comprehensive and accurate picture of fraudulent activities and their orchestrators.

Coco operates in three distinct, sequential stages:

  1. Deploying Chain Analysis: Given a single fraudulent contract as input, Coco first performs a deploying chain analysis. This process traces the creation lineage of the contract, effectively identifying the DCW responsible for its initial deployment. This step is crucial because, as established, DCWs do not directly handle stolen funds, making their identification dependent on their contract creation activities.
  1. Implicate Fraud Identification: Once a DCW is identified, Coco moves to uncover all other fraudulent incidents orchestrated by that same wallet. This involves analyzing all contracts created by the identified DCW, thereby revealing entire campaigns of fraud that would otherwise appear as disconnected individual reports.
  1. Capability Analysis: The final and perhaps most innovative stage is capability analysis. This stage delves into the operational mechanisms of the fraudulent contracts to understand their specific deceptive capabilities, which in turn informs precise mitigation strategies.

To illustrate the technical prowess of Coco, consider the example of dynamic recipient resolution, a sophisticated technique used by fraudsters to constantly change where stolen funds are sent. An investigator might observe a fraudulent contract (Fraud Contract 1) moving funds to different recipients over time, leading to confusion. Coco addresses this by employing a multi-faceted approach:

First, Coco performs symbolic analysis on Fraud Contract 1. This involves marking the contract's input, storage variables, and balance as symbolic values. Instead of executing the contract with concrete data, Coco explores all possible execution paths. During this symbolic execution process, Coco meticulously maps accumulated symbolic constraints to a CAP model. The CAP model effectively captures the contract's logic and dependencies, allowing Coco to understand how its behavior is influenced by external factors or internal state.

Through this detailed bytecode exploration, Coco might discover that Fraud Contract 1 is not hardcoding recipient addresses but is instead fetching this crucial information from an on-chain data drop. This data drop could be another smart contract (Fraud Contract 4) or a specific storage slot on the blockchain that is periodically updated by the scammer.

To complete the picture, Coco then re-integrates transaction analysis. This step correlates the insights from symbolic execution with actual on-chain transactions. By analyzing the transactions involving Fraud Contract 1 and the identified on-chain data drop, Coco can pinpoint the "redirection command" – the specific transaction or interaction that updates the recipient information. In the example, Coco would identify that Fraud Contract 4 is defining the recipient information for Fraud Contract 1 through the on-chain data drop.

This capability analysis is paramount for mitigation. Once Coco identifies that a fraud campaign utilizes "dynamic recipient resolution capability," it can advise investigators to monitor transactions invoked by Fraud Contract 4 (the control contract) or directly monitor the specific on-chain data drop. This proactive monitoring allows for the detection of future fraud attempts before victims are even targeted, moving beyond reactive fund tracking to predictive threat intelligence. The entire Coco framework is publicly available, with the code hosted on GitHub, enabling broader adoption and further research in this critical area.

Demo / Proof of Concept

▶ Watch: Coco dramatically increases victim identification over traditional methods (7:50)

While the presentation did not feature a live, interactive demonstration of the Coco tool in action, the speaker effectively illustrated its capabilities through a detailed walkthrough of its analytical process and the results derived from real-world data. The "Jake" analogy, detailing an FBI agent's struggle with dynamic recipient resolution, served as a compelling narrative proof of concept. This scenario highlighted a sophisticated fraud technique that traditional fund flow tracking would miss, demonstrating how Coco's symbolic and bytecode analysis could precisely identify the underlying mechanism (e.g., fetching recipient data from an on-chain data drop controlled by another contract) and provide actionable intelligence for mitigation. The extensive quantitative findings, such as the identification of 91 Deceptive Creator Wallets (DCWs), the uncovering of over 1 million fraudulent contracts, and the revelation of $2.2 billion in stolen funds, further served as a robust, large-scale proof of concept for Coco's effectiveness and its ability to uncover previously hidden fraud networks.

Defensive Implications

▶ Watch: Collaborations with Etherscan and FBI for fraud mitigation (8:20)

The findings from the Coco research offer critical defensive implications for individuals, blockchain platforms, and law enforcement agencies battling smart contract fraud. The most significant shift required is a move away from the traditional, reactive model of tracking stolen funds after the fact. This approach is demonstrably ineffective against sophisticated Deceptive Creator Wallets (DCWs) that intentionally obscure their involvement in fund flows.

Instead, defenders should prioritize the proactive identification of DCWs and the unique capabilities of their deployed fraudulent contracts. Tools like Coco enable this by:

  1. Shifting Focus to Creator Wallets: Security teams and investigators should integrate DCW identification into their threat intelligence frameworks. By identifying the wallets responsible for deploying fraud, they can flag entire campaigns rather than individual contracts, significantly broadening their defensive posture. The collaboration with Etherscan, where 91 DCWs and over 1 million contracts were reported and subsequently flagged, serves as a prime example of this proactive defense in action. These flags provide immediate warnings to potential victims, preventing transactions to known fraudulent addresses.
  1. Implementing Capability-Based Monitoring: The capability analysis performed by Coco is invaluable. For contracts exhibiting "dynamic recipient resolution capability," for instance, defenders should establish monitoring systems that track the identified control contracts (e.g., Fraud Contract 4 in the example) or specific on-chain data drops that dictate the fraudulent contract's behavior. This allows for early detection of changes in recipient addresses or other operational parameters, potentially forewarning of new fraud waves before they fully materialize.
  1. Enhancing Predictive Fraud Detection: The insights gleaned from analyzing DCW patterns, their longevity (some active since 2017), and their operational methods (e.g., self-replicating polymorphic contracts, colluding fraudsters as mentioned in the paper) can be used to build more robust predictive models for fraud. Understanding the "DNA" of a DCW's operations allows for the anticipation of future fraud types and deployment strategies.
  1. Strengthening Collaboration with Law Enforcement and Platforms: The successful collaboration with the FBI and Etherscan highlights the power of shared intelligence. Blockchain analytics firms, security researchers, and block explorers should actively share identified DCWs and their associated fraud campaigns with law enforcement to facilitate investigations and asset recovery. Conversely, law enforcement can leverage such tools and data to build stronger cases against perpetrators, moving beyond individual arrests to dismantling entire fraud organizations.
  1. Educating Users on Sophisticated Scams: While not directly a technical defense, the widespread nature of DCW-orchestrated fraud underscores the need for continuous user education. Users must be aware that even if a contract appears legitimate or functions for a short period, its creator wallet might be linked to a broader, deceptive scheme. Warnings on block explorers, as facilitated by the Coco research, are a critical step in this educational process.

By adopting these defensive implications, the blockchain ecosystem can move towards a more resilient and secure future, where the masks of deceptive creator wallets are pulled off, and their fraudulent operations are systematically mitigated.

Key Takeaways

  • Traditional fund flow analysis is fundamentally inadequate for identifying and mitigating smart contract fraud, as Deceptive Creator Wallets (DCWs) deliberately avoid direct involvement in fund transfers, rendering them invisible.
  • Coco, a novel forensic tool, effectively unmasks DCWs by integrating symbolic bytecode analysis with transaction analysis, providing a comprehensive view of fraud campaigns and their orchestrators.
  • The scale of DCW-orchestrated fraud is immense, with 91 DCWs identified as responsible for deploying over 1 million fraudulent contracts and stealing more than $2.2 billion from nearly 500,000 victims.
  • Proactive mitigation strategies should focus on identifying and monitoring the unique capabilities of fraudulent contracts (e.g., dynamic recipient resolution) and their control mechanisms (e.g., on-chain data drops or specific control contracts), rather than solely tracking stolen funds.
  • Effective fraud mitigation requires strong collaboration between academic researchers, blockchain platforms (like Etherscan), and law enforcement agencies (like the FBI) to share intelligence, flag fraudulent addresses, and prevent future victimizations.
  • The research highlights the sophisticated and long-running nature of blockchain fraud, with some DCWs active since 2017, underscoring the continuous need for advanced analytical tools and intelligence sharing.

About the Speaker(s)

The primary presenter for "Pulling Off The Mask" was Mingxuan Yao, who conducted this research alongside a team of talented colleagues: Runze Zhang, Haichuan Xu, Ryan Chou, Varun Chowdhary Paturi, and Amit Kumar Sikder. All members of the research team are affiliated with the Georgia Tech lab, indicating their expertise in computer science, cybersecurity, and blockchain technology research. Their work is characterized by a strong emphasis on practical application, evidenced by their significant collaborations with real-world entities such as Etherscan, a leading Ethereum block explorer, and the Federal Bureau of Investigation (FBI). This collaboration underscores their commitment to translating academic research into tangible tools and insights for combating sophisticated financial crimes in the blockchain space.

Reviews

Dr. Zero (Offensive Security Researcher) — MUST SEE

This research pulls the mask off the real orchestrators of smart contract fraud: Deceptive Creator Wallets. Coco's novel blend of symbolic and transaction analysis uncovers billions in stolen funds and provides critical, actionable intelligence that traditional fund-flow tracking completely misses. This is how you fight sophisticated fraud at scale.

Heather Calloway (CISO) — MUST SEE

This crucial research effectively unmasks the hidden orchestrators behind smart contract fraud, exposing billions in illicit gains and a systemic failure in traditional investigative approaches. Coco provides a robust, actionable framework for institutions and law enforcement to shift from reactive incident response to proactive, campaign-level mitigation, fundamentally changing how this risk must be managed.

→ Top-rated talks at IEEE Symposium on Security and Privacy 2024

All talks from IEEE Symposium on Security and Privacy 2024