Since Bitcoin appeared in 2009, over 6,000 different cryptocurrency projects have followed. The cryptocurrency world may be the only technology where a massive number of competitors offer similar services yet claim unique benefits, including scalability, fast transactions, and security. But are these projects really offering unique features and significant enhancements over their competitors? To answer this question, we conducted a large-scale empirical analysis of code maintenance activities, originality and security across 592 crypto projects. We found that about half of these projects have not been updated for the last six months; over two years, about three-quarters of them disappeared, or were reported as scams or inactive. We also investigated whether 11 security vulnerabilities patched in Bitcoin were also patched in other projects. We found that about 80% of 510 C-language-based cryptocurrency projects have at least one unpatched vulnerability, and the mean time taken to fix the vulnerability is 237.8 days. Among those 510 altcoins, we found that at least 157 altcoins are likely to have been forked from Bitcoin, about a third of them containing only slight changes from the Bitcoin version from which they were forked. As case studies, we did a deep dive into 20 altcoins (e.g., Litecoin, FujiCoin, and Feathercoin) similar to the version of Bitcoin used for the fork. About half of them did not make any technically meaningful change - failing to comply with the promises (e.g., about using Proof of Stake) made in their whitepapers.
翻译:自2009年Bitcoin出现以来,已有超过6000个不同的加密货币项目。加密货币世界可能是众多竞争者提供类似服务的唯一技术,但其中约有3/4的人可能已经消失,或者被报告为骗局或不活动。我们还调查了Bitcoin11个安全漏洞是否也在其他项目中补齐了。我们发现,510个基于C语言的加密货币项目中,80%的项目至少有一个未加插的弱点,解决脆弱性的平均时间是237.8天。在510个白金项目中,有大约一半在过去6个月没有更新;两年多以来,大约3/4个这类项目已经消失,或者被报告为骗局或不活动。我们还调查了Bitcoin11个安全漏洞是否也与其他项目相补。我们发现,510个基于C语言的加密货币项目中,有80%的项目至少有1个未加插的弱点,而解决脆弱性的平均时间是237.8天。在510个白金项目中,我们发现至少有157个正币项目可能已经从Bitcoin消失了,大约3个。我们只用不到一半的纸质。