"Please Verify": How Human Behavior Undermines Blockchain Security
- š¤ Speaker: Taro Tsuchiya, Carnegie Mellon University š Website
- š Date & Time: Tuesday 15 July 2025, 14:00 - 15:00
- š Venue: Webinar & LT2, Computer Laboratory, William Gates Building.
Abstract
Humans are a critical link to the security of any complex system, and blockchains are no exception. Sometimes, even basic assumptions are not met in practice; we observed that some service providers or users do not properly check transactions, whether purposefully (for latency benefits) or inadvertently (due to operational mistakes). These unexpected behaviors pose new challenges to blockchain security. The first part of this talk will examine a network layer vulnerability – a āblockchain amplification attack.ā Some Ethereum nodes appear to sidestep transaction validations to achieve lower latency, making them vulnerable to a flood of invalid transactions. We quantify its attack damage through mathematical modeling, network monitoring, and local simulation, and compare it with the potential economic gains of latency reduction. The second part focuses on a wallet-level attack – āblockchain address poisoning.ā Attackers generate addresses resembling the victimās recipientās address to fool the victim into sending their assets to the attacker by mistake. We develop a detection algorithm to scan two years of Ethereum and Binance Smart Chain (BSC), characterize attack patterns, extrapolate large attack groups, and bound the attackerās computational capability through measurement and simulation. We will also discuss our initiatives to make our research accessible to end users.
Zoom link: https://us02web.zoom.us/j/85980496815?pwd=z3tmHabXUSHbPgCe6VrSDq3WoIOi0R.1
Series This talk is part of the Computer Laboratory Security Seminar series.
Included in Lists
- All Talks (aka the CURE list)
- bld31
- Cambridge talks
- Computer Laboratory Security Seminar
- Department of Computer Science and Technology talks and seminars
- Interested Talks
- School of Technology
- Security-related talks
- Trust & Technology Initiative - interesting events
- Webinar & LT2, Computer Laboratory, William Gates Building.
- yk449
Note: Ex-directory lists are not shown.
![[Talks.cam]](/static/images/talkslogosmall.gif)



Tuesday 15 July 2025, 14:00-15:00