Non-Fungible Tokens (NFTs) have emerged as a way to collect digital art as well as an investment vehicle. Despite having been popularized only recently, over the last year, NFT markets have witnessed several high-profile (and high-value) asset sales and a tremendous growth in trading volumes. However, these marketplaces have not yet received much scrutiny. Most academic researchers have analyzed decentralized finance (DeFi) protocols, studied attacks on those protocols, and developed automated techniques to detect smart contract vulnerabilities. To the best of our knowledge, we are the first to study the market dynamics and security issues of the multi-billion dollar NFT ecosystem. In this paper, we first present a systematic overview of how the NFT ecosystem works, and we identify three major actors: marketplaces, external entities, and users. We study the design of the underlying protocols of the top 8 marketplaces (ranked by transaction volume) and discover security, privacy, and usability issues. Many of these issues can lead to substantial financial losses. During our analysis, we reported 5 security bugs in 3 top marketplaces; all of them have been confirmed by the affected parties. Moreover, we provide insights on how the entities external to the blockchain are able to interfere with NFT markets, leading to serious consequences. We also collect a large amount of asset and event data pertaining to the NFTs being traded in the examined marketplaces, and we quantify malicious trading behaviors carried out by users under the cloak of anonymity. Finally, we studied the 15 most expensive NFT sales to date, and discovered discrepancies in at least half of these transactions.
翻译:非易变 Tokens (NFTs) 已成为收集数字艺术和投资工具的一种方法。尽管直到最近才被普及,但去年,NFT市场也出现了若干高知名度(和高价值)资产销售和贸易量的大幅增长。然而,这些市场还没有得到很多审查。大多数学术研究人员分析了分散化的金融(DeFi)协议,研究了对协议的攻击,并开发了自动技术以发现智能合同脆弱性。据我们所知,我们首先研究了数十亿美元的NFT生态系统的市场动态和安全问题。我们首先系统地概述了NFT生态系统是如何运作的,我们确定了三大行为者:市场、外部实体和用户。我们研究了8大市场的基本协议的设计(按交易量排列),发现了安全、隐私和可用性问题。其中许多问题可能导致巨大的金融损失。在我们的分析中,我们报告了3个顶级市场中的5个安全漏洞;所有这些问题都得到了受影响方的确认。在本文中,我们首先对NFT生态系统如何运作进行了系统化的概述,最后,我们分析了15个风险交易实体是如何在交易中是如何实现的。我们所研究的。