Demystifying Web3 Centralization: The Case of Off-Chain NFT Hijacking

Felix Stöger*, Anxin Zhou, Huayi Duan, Adrian Perrig

*Corresponding author for this work

Research output: Chapters, Conference Papers, Creative and Literary WorksRGC 32 - Refereed conference paper (with host publication)peer-review

1 Citation (Scopus)

Abstract

Despite the ambitious vision of re-decentralizing the Web as we know it, the Web3 movement is facing many hurdles of centralization which seem insurmountable in the near future, and the security implications of centralization remain largely unexplored. Using non-fungible tokens (NFTs) as a case study, we conduct a systematic analysis of the threats posed by centralized entities in the current Web3 ecosystem. Our findings are concerning: almost every interaction between a user and a centralized entity can be exploited to hijack NFTs or cryptocurrencies from the user, through network attacks practical today. We show that many big players in the ecosystem are vulnerable to such attacks, placing large financial investments at risk. Our study is a starting point to study the pervasive centralization issues in the shifting Web3 landscape. © 2024, International Financial Cryptography Association.
Original languageEnglish
Title of host publicationFinancial Cryptography and Data Security - 27th International Conference, FC 2023, Revised Selected Papers
EditorsFoteini Baldimtsi, Christian Cachin
PublisherSpringer, Cham
Pages182-199
ISBN (Electronic)9783031477515
ISBN (Print)9783031477508
DOIs
Publication statusPublished - 2024
Event27th International Conference on Financial Cryptography and Data Security (FC 2023) - Bol, Brač, Croatia
Duration: 1 May 20235 May 2023
https://fc23.ifca.ai/

Publication series

NameLecture Notes in Computer Science
Volume13951
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference27th International Conference on Financial Cryptography and Data Security (FC 2023)
Abbreviated titleFC23
Country/TerritoryCroatia
CityBol, Brač
Period1/05/235/05/23
Internet address

Fingerprint

Dive into the research topics of 'Demystifying Web3 Centralization: The Case of Off-Chain NFT Hijacking'. Together they form a unique fingerprint.

Cite this