Non-Fungible Tokens (NFTs) have emerged as a way to collect digital art as well as an investment vehicle. Despite having been popularized only recently, NFT markets have witnessed several high-profile (and high-value) asset sales and a tremendous growth in trading volumes over the last year. Unfortunately, these marketplaces have not yet received much security scrutiny. Instead, most academic research has focused on attacks against decentralized finance (DeFi) protocols and automated techniques to detect smart contract vulnerabilities. To the best of our knowledge, we are the first to study the market dynamics and security issues of the multi-billion dollar NFT ecosystem. In this paper, we first present a systematic overview of how the NFT ecosystem works, and we identify three major actors: marketplaces, external entities, and users. We perform an in-depth analysis of the top 8 marketplaces (ranked by transaction volume) to discover potential issues associated with such marketplaces. Many of these issues can lead to substantial financial losses. We also collected a large amount of asset and event data pertaining to the NFTs being traded in the examined marketplaces. We automatically analyze this data to understand how the entities external to the blockchain are able to interfere with NFT markets, leading to serious consequences, and quantify the malicious trading behaviors carried out by users under the cloak of anonymity.
翻译:“非易变 Tokens”(NFTs)已成为收集数字艺术和投资工具的一种方法。尽管最近才被普及,但NFT市场也出现了若干高知名度(和高价值)资产销售和去年交易量的大幅增长。不幸的是,这些市场还没有得到很多安全监督。相反,大多数学术研究侧重于对分散化金融(DeFi)协议和自动技术的袭击,以发现智能合同脆弱性。据我们所知,我们首先研究的是数十亿美元的NFT生态系统的市场动态和安全问题。我们首先对NFT生态系统如何运作进行系统化的概述,我们确定了三大行为者:市场、外部实体和用户。我们深入分析了8个顶级市场(按交易量排列),以发现与这类市场有关的潜在问题。其中许多问题可能导致巨大的财政损失。我们还收集了大量与NFTTs在所审查的市场上交易有关的资产和事件数据。我们自动分析这一数据,以便了解这些实体如何通过恶意交易方式从外部交易到NFT的市场。我们通过诚实的公开性交易方式,从而了解这些实体如何将风险量化。