Submitted:
01 September 2025
Posted:
02 September 2025
You are already at the latest version
Abstract
Although blockchain has revolutionary potential across diverse areas, it faces significant security vulnerabilities that threaten user assets and information. The primary security issues included smart contract exploits and social engineering attacks. Smart contracts exploit target code vulnerabilities and logic flaws, and social engineering involves fake websites and malicious browser extensions designed to steal user credentials and private keys. This study will analyse two major real-world attacks, the 2025 ByBit hack and the 2021 Poly Network attack. The ByBit attack led to $1,40 billion in losses through social engineering, and the Poly Network resulted in $611 million being stolen by exploiting cross-chain protocol vulnerabilities. Both cases highlight how human errors and technical flaws can lead to severe security breaches. To address these challenges, this study proposes a web browser security solution that has multi-layered protection mechanisms, the Safu Extension. The system integrates phishing website detection, domain whitelisting and blacklisting, and community-based threat reporting. Other than that, it also integrated AI-powered malicious code detection in smart contracts and transaction simulation. A comparative analysis with existing solutions will demonstrate that Safu Extension offers better overall protection by combining automated detection, community intelligence, and a user-friendly interface.
Keywords:
1. Introduction
1.1. Study Background
1.1.1. Key Components and How Blockchain Works
1.1.2. Cyber Attacks on Blockchain
1.2. Problem Identification
1.2.1. Limitations of Existing Systems
Reactive Approach
Biasnesses and False Positives
2. Case Study Analysis
2.1. Bybit Hack
2.1.1. Chronology

Initial Compromisation
Smart Contract Manipulation
Injection of Malicious Code
Execution of the Heist
2.1.2. Lazarus Group
2.1.3. Impact
2.1.4. Lessons Learned
2.2. Poly Network Attack
2.2.1. Chronology and Vulnerability of the Poly Network Attack

Return of Funds and White Hat Recognition
Impact on Poly Network and DeFi Market
Lessons from the Poly Network Exploit
3. Proposed Secure System
- Phishing website detection
- Domain blacklisting
- Community-based threat reporting
- Whitelist functionality
- Real-time URL monitoring
- Malicious Code Detection
- Transaction Simulation
3.1. Security Approach
3.1.1. Phishing Website Detection
Whitelist Functionality and Levenshtein Distance Algorithm
- Insertion
- Deletion
- Permutation

3.1.2. Domain Blacklisting

3.1.3. Community-Based Threat Reporting


3.1.4. Malicious Code Detection in Smart Contract Using LLM
3.1.5. Transaction Simulation
3.2. Architecture

3.2.1. Manifest V3
3.2.2. Background Service Worker
3.2.3. Popup Interface

3.2.4. Dashboard for Details

3.2.5. Multiple Protection Layers
- Blacklist Integration
- Phishing Detection
- Malicious Code Detection
- Community Reports
3.3. Prototype
4. Implementation Challenges & Feasibility
4.1. Practical Challenges
4.1.1. AI Implementation
4.1.2. Maintenance of Whitelisted Domains
4.1.3. Database Safety
4.1.4. Zero-Day Vulnerability
4.2. Potential Limitations
4.2.1. Reliability of Community-Based Reporting
4.2.2. Ethical Considerations
4.2.3. Compatibility Across Web 3.0 Platforms
5. Evaluation & Discussion
5.1. Overview of Existing Solutions
5.1.1. Web3 Antivirus
5.1.2. WalletGuard
5.1.3. AegisWeb3
5.2. Comparative Analysis
5.2.1. Feature Comparison
5.2.2. Benchmarking with Existing Solutions
5.3. Strength and Weaknesses of Proposed Solution
5.3.1. Stengths
Multi-Layered Phishing Defense
Usability and Compatability
5.3.2. Weaknesses
Feasibility and Maintenance of LLM
Performance Overhead and Latency
Reliability of Community-Based Reporting
6. Conclusions
References
- 2025 Data Breach Investigations Report. (2025). Verizon Business. https://www.verizon.com/business/resources/reports/dbir/.
- Abdelghani, T. (2019). Implementation of Defense in Depth Strategy to Secure Industrial Control System in Critical Infrastructures. American Journal of Artificial Intelligence, 3(2), 17. [CrossRef]
- Ahmed, Q. W., Garg, S., Rai, A., Ramachandran, M., Jhanjhi, N. Z., Masud, M., & Baz, M. (2022). AI-Based Resource Allocation Techniques in Wireless Sensor Internet of Things Networks in Energy Efficiency with Data Optimization. Electronics, 11(13), 2071. [CrossRef]
- Ahmed, S. (2025). Enhancing Data Security and Transparency: The Role of Blockchain in Decentralized Systems. International Journal of Advanced Engineering, Management and Science, 11(1), 167–176. [CrossRef]
- An, M., Fan, Q., Yu, H., An, B., Wu, N., Zhao, H., Wan, X., Li, J., Wang, R., Zhen, J., Zou, Q., & Zhao, B. (2023). Blockchain Technology Research and Application: A Literature Review and Future Trends. Journal of Data Science and Intelligent Systems. [CrossRef]
- Attaullah, M., Ali, M., Almufareh, M. F., Ahmad, M., Hussain, L., Jhanjhi, N., & Humayun, M. (2022). Initial stage COVID-19 detection system based on patients’ symptoms and chest X-Ray images. Applied Artificial Intelligence, 36(1). [CrossRef]
- Azeem, M., Ullah, A., Ashraf, H., Jhanjhi, N., Humayun, M., Aljahdali, S., & Tabbakh, T. A. (2021). FOG-Oriented secure and lightweight data aggregation in IOMT. IEEE Access, 9, 111072–111082. [CrossRef]
- B. Lashkari & P. Musilek. (2021). A Comprehensive Review of Blockchain Consensus Mechanisms. IEEE Access, 9, 43620–43652. [CrossRef]
- Basit, A., Zafar, M., Liu, X., Javed, A. R., Jalil, Z., & Kifayat, K. (2021). A comprehensive survey of AI-enabled phishing attacks detection techniques. Telecommunication Systems, 76(1), 139–154. [CrossRef]
- Bell, S., & Komisarczuk, P. (2020). An Analysis of Phishing Blacklists: Google Safe Browsing, OpenPhish, and PhishTank. Proceedings of the Australasian Computer Science Week Multiconference, 1–11. [CrossRef]
- Benhke, R. (2021, November 8). Explained: The Poly Network Hack (August 2021). Halborn. https://www.halborn.com/blog/post/explained-the-poly-network-hack-august-2021.
- BlockSec. (2021, August 12). The Further Analysis of the Poly Network Attack—BlockSec Blog. BlockSec. https://blocksec.com/blog/the-further-analysis-of-the-poly-network-attack.
- Brohi, S. N., Jhanjhi, N., Brohi, N. N., & Brohi, M. N. (2020). Key Applications of State-of-the-Art Technologies to Mitigate and Eliminate COVID-19.pdf. Authorea Preprints. [CrossRef]
- Browne, R. (2021, August 17). Crypto platform hit by $600 million heist asks hacker to become its chief security advisor. CNBC. https://www.cnbc.com/2021/08/17/poly-network-cryptocurrency-hack-latest.html.
- Bybit Interim Investigation Report (p. 8). (2025). Sygnia.
- Carpentier-Desjardins, C., Paquet-Clouston, M., Kitzler, S., & Haslhofer, B. (2025). Mapping the DeFi crime landscape: An evidence-based picture. Journal of Cybersecurity, 11(1), tyae029. [CrossRef]
- CertiK - Bybit Incident Technical Analysis. (2025, February 21). Certik. https://certik.com/resources/blog/bybit-incident-technical-analysis.
- CertiK - Poly Network Exploit. (2022, March 12). Certik. https://certik.com/resources/blog/poly-network-exploit.
- Chainanalysis. (2021, August 12). Poly Network Attacker Returning Funds After Pulling Off Biggest DeFi Theft Ever—Chainalysis. Chainanalysis. https://www.chainalysis.com/blog/poly-network-hack-august-2021/.
- Chen, Z., Hu, Y., He, B., Luo, D., Wu, L., & Zhou, Y. (2025). Dissecting Payload-based Transaction Phishing on Ethereum. Proceedings 2025 Network and Distributed System Security Symposium. Network and Distributed System Security Symposium, San Diego, CA, USA. [CrossRef]
- DappRadar 2022: A Year in Review. (2022, December 22). DappRadar. https://dappradar.com/blog/dappradar-2022-a-year-in-review.
- Das, S. R., Jhanjhi, N. Z., Asirvatham, D., Ashfaq, F., & Abdulhussain, Z. N. (2023, February). Proposing a model to enhance the IoMT-based EHR storage system security. In International Conference on Mathematical Modeling and Computational Science (pp. 503-512). Singapore: Springer Nature Singapore.
- Elatoubi, M. (2023). Phishing in Web 3.0: Opportunities for the Attackers, Challenges for the Defenders. ARIS2 - Advanced Research on Information Systems Security, 3(2), 11–25. [CrossRef]
- England, J. (2021, December 6). Timeline: Poly Network and the curious case of ‘Mr Whitehat.’ FinTech Magazine. https://fintechmagazine.com/crypto/timeline-poly-network-and-curious-case-mr-whitehat.
- Fang, V., & Werlau, P. (2025, February 28). ByBit Billion Dollar Hack - Part 1: Smart Contracts Forensics Timeline. AnChain.AI. https://www.anchain.ai/blog/bybit.
- Federal Bureau of Investigation. (2025, February 26). TraderTraitor: North Korean state-sponsored cyber actors exploit cryptocurrency platforms. Internet Crime Complaint Centre. https://www.ic3.gov/PSA/2025/PSA250226.
- Feng, P., Bi, Z., Yan, L. K. Q., Wen, Y., Peng, B., Liu, J., Yin, C. H., Wang, T., Chen, K., Zhang, S., Li, M., Xu, J., Liu, M., Pan, X., Wang, J., & Niu, Q. (2024). Mastering AI: Big Data, Deep Learning, and the Evolution of Large Language Models -- Blockchain and Applications (No. arXiv:2410.10110). arXiv. [CrossRef]
- Gagliardoni, T. (2021, August 12). The Poly Network Hack Explained. Kudelski Security Research. https://research.kudelskisecurity.com/2021/08/12/the-poly-network-hack-explained/.
- Grassi, P. A., Garcia, M. E., & Fenton, J. L. (2017). Digital identity guidelines: Revision 3. National Institute of Standards and Technology. [CrossRef]
- Hanif, M., Ashraf, H., Jalil, Z., Jhanjhi, N. Z., Humayun, M., Saeed, S., & Almuhaideb, A. M. (2022). AI-Based wormhole attack detection techniques in wireless sensor networks. Electronics, 11(15), 2324. [CrossRef]
- Humayun, M., Jhanjhi, N. Z., Niazi, M., Amsaad, F., & Masood, I. (2022). Securing Drug Distribution Systems from Tampering Using Blockchain. Electronics, 11(8), 1195. [CrossRef]
- Hussain, K., Rahmatyar, A. R., Riskhan, B., Sheikh, M. a. U., & Sindiramutty, S. R. (2024). Threats and Vulnerabilities of Wireless Networks in the Internet of Things (IoT). 2024 IEEE 1st Karachi Section Humanitarian Technology Conference (KHI-HTC), 2, 1–8. [CrossRef]
- Incident Response Plan (IRP) Basics | CISA. (2024, January 31). https://www.cisa.gov/resources-tools/resources/incident-response-plan-irp-basics.
- Jabeen, T., Jabeen, I., Ashraf, H., Jhanjhi, N. Z., Yassine, A., & Hossain, M. S. (2023). An intelligent healthcare system using IoT in wireless sensor network. Sensors, 23(11), 5055. [CrossRef]
- Janik, R. (2025, March 7). ByBit Hack: Exploiting Smart Contracts to Drain Funds - A Deep Dive on How it Happened. Lukka. https://lukka.tech/bybit-hack-deep-dive/.
- Jhanjhi, N. (2024). Comparative analysis of frequent pattern mining algorithms on healthcare data. In 2024 IEEE 9th International Conference on Engineering Technologies and Applied Sciences (ICETAS) (pp. 1-10). IEEE. [CrossRef]
- Jhanjhi, N. Z. (2025). Investigating the influence of loss functions on the performance and interpretability of machine learning models. In S. Pal & Á. Rocha (Eds.), Proceedings of 4th International Conference on Mathematical Modeling and Computational Science. ICMMCS 2025. Lecture Notes in Networks and Systems, vol 1399 (pp. 100-110). Springer. [CrossRef]
- Jun, A. Y. M., Jinu, B. A., Seng, L. K., Maharaiq, M. H. F. B. Z., Khongsuwan, W., Junn, B. T. K., Hao, A. a. W., & Sindiramutty, S. R. (2024). Exploring the Impact of Crypto-Ransomware on Critical Industries: Case Studies and Solutions. Preprint.org. [CrossRef]
- Khan, N. A., Jhanjhi, N. Z., Brohi, S. N., Almazroi, A. A., & Almazroi, A. A. (2021). A secure communication protocol for unmanned aerial vehicles. Computers, Materials & Continua/Computers, Materials & Continua (Print), 70(1), 601–618. [CrossRef]
- Kiyani, F. F., Hamid, B., Humayun, M., Sindiramutty, S. R. a. L., & Chowdhury, S. (2024). Discovery of Influential Publications Using Research Article’s Usage Context. 2024 International Conference on Emerging Trends in Networks and Computer Communications (ETNCC), 1–7. [CrossRef]
- krakenfx. (2021, September 22). Abusing Smart Contracts to Steal $600 million: How the Poly Network Hack Actually Happened. Kraken Blog. https://blog.kraken.com/product/security/abusing-smart-contracts-to-steal-600-million-how-the-poly-network-hack-actually-happened.
- Krishnan, S., Thangaveloo, R., Rahman, S. B. A., & Sindiramutty, S. R. (2021). Smart Ambulance Traffic Control system. Trends in Undergraduate Research, 4(1), c28-34. [CrossRef]
- Linqiang, Y., Sindiramutty, S. R. a. L., Ashraf, H., Muzammal, S. M., Balakrishnan, S. a. P., Gupta, S., & Kavita, N. (2024). Intelligent Household Waste Classification System Based on Machine Learning. 2024 International Conference on Emerging Trends in Networks and Computer Communications (ETNCC), 760–768. [CrossRef]
- Manchuri, A., Kakera, A., Saleh, A., & Raja, S. (2024). pplication of Supervised Machine Learning Models in Biodiesel Production Research - A Short Review. Borneo Journal of Sciences and Technology. [CrossRef]
- Mandvi. (2025, May 7). Simulated Attack Reveals DPRK’s Largest Cryptocurrency Heist via Compromised macOS Developer and AWS Exploits. Cyber Security News. https://cyberpress.org/simulated-attack-reveals-dprks-largest-cryptocurrency-heist/.
- McMillan, R., & Ge, V. H. (2025, March 6). How the Biggest Crypto Hack Ever Nearly Destroyed the World’s No. 2 Exchange. WSJ. https://www.wsj.com/finance/currencies/how-the-biggest-crypto-hack-ever-nearly-destroyed-the-worlds-no-2-exchange-ee273a3a.
- Muzafar, S., & Jhanjhi, N. Z. (2019). Success stories of ICT implementation in Saudi Arabia. In Advances in electronic government, digital divide, and regional development book series (pp. 151–163). [CrossRef]
- Muzammal, S. M., Murugesan, R. K., Jhanjhi, N. Z., & Jung, L. T. (2020). SMTrust: Proposing Trust-Based Secure Routing Protocol for RPL Attacks for IoT Applications. 2020 International Conference on Computational Intelligence (ICCI), 305–310. [CrossRef]
- Ogundokun, R. O., Arowolo, M. O., Damaševičius, R., & Misra, S. (2023). Phishing Detection in Blockchain Transaction Networks Using Ensemble Learning. Telecom, 4(2), Article 2. [CrossRef]
- Peak, B. (2025, March 5). How the Bybit hack happened: Inside the $1.5 billion crypto heist. Cointelegraph. https://cointelegraph.com/learn/articles/how-the-bybit-hack-happened.
- Perdana, A., Aminanto, M. E., & Anggorojati, B. (2024). Hack, heist, and havoc: The Lazarus Group’s triple threat to global cybersecurity. Journal of Information Technology Teaching Cases, 20438869241303941. [CrossRef]
- Po, D. K. (2020). Similarity Based Information Retrieval Using Levenshtein Distance Algorithm. International Journal of Advances in Scientific Research and Engineering (IJASRE), ISSN:2454-8006, DOI: 10.31695/IJASRE, 6(4), Article 4. [CrossRef]
- Poly Network. (2021, September 3). Honour, Exploit, and Code: How we lost 610M dollar and got it back. Poly Network. https://medium.com/poly-network/honour-exploit-and-code-how-we-lost-610m-dollar-and-got-it-back-c4a7d0606267.
- Poly Network. (2023, November 20). The Poly Network Exploit Analysis | by Poly Network | Medium. Medium. https://polynetwork.medium.com/the-poly-network-exploit-analysis-b0a77aff6078.
- Praitheeshan, P., Pan, L., Yu, J., Liu, J., & Doss, R. (2020). Security Analysis Methods on Ethereum Smart Contract Vulnerabilities: A Survey (No. arXiv:1908.08605). arXiv. [CrossRef]
- Ravichandran, N., Tewaraja, T., Rajasegaran, V., Kumar, S. S., Gunasekar, S. K. L., & Sindiramutty, S. R. (2024). Comprehensive Review Analysis and Countermeasures for Cybersecurity Threats: DDoS, Ransomware, and Trojan Horse Attacks. preprint.org. [CrossRef]
- Rekt—Poly Network. (2021, August 11). Rekt. https://www.rekt.news/.
- Rivas, M., Santos, R., & Sanz, J. (2025, March 10). In-Depth Technical Analysis of the Bybit Hack. Ncc Group. https://www.nccgroup.com/us/research-blog/in-depth-technical-analysis-of-the-bybit-hack.
- Riza, A. Z. B. M., Jennsen, L., Anggani, P., Rafeen, A. I., Ruth, P. N. J., Sookun, D., Sookun, V., Yusri, N. a. Z. B. M., Sern, L. J., Luximon, L., Omer, M. L., & Sindiramutty, S. R. (2025). Leveraging Machine Learning and AI to Combat Modern Cyber Threats. Preprints.org. [CrossRef]
- Rodrigues, F. (2025, February 23). Bybit Sees Over $4 Billion ‘Bank Run’ After Crypto’s Biggest Hack. CoinDesk. https://www.coindesk.com/business/2025/02/22/bybit-sees-over-usd4-billion-bank-run-after-crypto-s-biggest-hack.
- Roumani, Y. (2021). Patching zero-day vulnerabilities: An empirical analysis. Journal of Cybersecurity, 7(1), tyab023. [CrossRef]
- Saeed, S., Abdullah, A., Jhanjhi, N. Z., Naqvi, M., & Nayyar, A. (2022). New techniques for efficiently k-NN algorithm for brain tumor detection. Multimedia Tools and Applications, 81(13), 18595–18616. [CrossRef]
- Saini, K. (2025, June 9). Web 1.0, 2.0, 3.0, & 4.0: A Detailed Guide. Simplilearn. https://www.simplilearn.com/what-is-web-1-0-web-2-0-and-web-3-0-with-their-difference-article.
- Schor, L. (2023). What is Safe? [Safe{Wallet}]. https://help.safe.global/en/articles/40869-what-is-safe.
- Seng, Y. J., Cen, T. Y., Raslan, M. a. H. B. M., Subramaniam, M. R., Xin, L. Y., Kin, S. J., Long, M. S., & Sindiramutty, S. R. (2024). In-Depth Analysis and Countermeasures for Ransomware Attacks: Case Studies and Recommendations. Preprints.org. [CrossRef]
- Shah, I. A., Jhanjhi, N. Z., & Laraib, A. (2022). Cybersecurity and blockchain usage in contemporary business. In Advances in information security, privacy, and ethics book series (pp. 49–64). [CrossRef]
- Sindiramutty, S. R., Jhanjhi, N. Z., Tan, C. E., Tee, W. J., Lau, S. P., Jazri, H., Ray, S. K., & Zaheer, M. A. (2024). IoT and AI-Based Smart Solutions for the Agriculture Industry. In Advances in computational intelligence and robotics book series (pp. 317–351). [CrossRef]
- Sindiramutty, S. R., Jhanjhi, N. Z., Tan, C. E., Yun, K. J., Manchuri, A. R., Ashraf, H., Murugesan, R. K., Tee, W. J., & Hussain, M. (2024). Data security and privacy concerns in drone operations. In Advances in information security, privacy, and ethics book series (pp. 236–290). [CrossRef]
- Sindiramutty, S. R., Jhanjhi, N., Tan, C. E., Lau, S. P., Muniandy, L., Gharib, A. H., Ashraf, H., & Murugesan, R. K. (2024). Industry 4.0. In Advances in logistics, operations, and management science book series (pp. 342–405). [CrossRef]
- Sindiramutty, S. R., Prabagaran, K. R. V., Jhanjhi, N. Z., Ghazanfar, M. A., Malik, N. A., & Soomro, T. R. (2024). Security Considerations in Generative AI for web Applications. In Advances in information security, privacy, and ethics book series (pp. 281–332). [CrossRef]
- Sindiramutty, S. R., Prabagaran, K. R. V., Jhanjhi, N. Z., Murugesan, R. K., Brohi, S. N., & Masud, M. (2024). Generative AI in network security and intrusion detection. In Advances in information security, privacy, and ethics book series (pp. 77–124). [CrossRef]
- Sindiramutty, S. R., Tan, C. E., & Wei, G. W. (2024). Eyes in the sky. In Advances in information security, privacy, and ethics book series (pp. 405–451). [CrossRef]
- SlowMist. (2025, February 27). Bybit’s $1.5 Billion Theft Unveiled: Safe{Wallet} Front-End Code Tampered. Medium. https://slowmist.medium.com/bybits-1-5-billion-theft-unveiled-safe-wallet-front-end-code-tampered-84b78f0fa9c2.
- Soltani, R., Zaman, M., Joshi, R., & Sampalli, S. (2022). Distributed Ledger Technologies and Their Applications: A Review. Applied Sciences, 12(15), Article 15. [CrossRef]
- Sun, D., Ma, W., Nie, L., & Liu, Y. (2024). SoK: Comprehensive Analysis of Rug Pull Causes, Datasets, and Detection Tools in DeFi (No. arXiv:2403.16082). arXiv. [CrossRef]
- Sygnia. (2025, March 16). Sygnia’s Investigation into the Bybit Hack: What We Know So Far. Sygnia. https://www.sygnia.co/blog/sygnia-investigation-bybit-hack/.
- Szurdi, J., & Christin, N. (2017). Email typosquatting. Proceedings of the 2017 Internet Measurement Conference, 419–431. [CrossRef]
- The ByBit Hack: What Happened and What It Means for the Crypto Market? (2025, February 26). Virtune. https://www.virtune.com/en/insights/bybit-hack-2025.
- Thummavet, P. (2021, September 2). Poly Network—In-Depth Analysis of the Biggest Heist in DeFi History. Serial Coder. https://www.serial-coder.com/post/poly-network-in-depth-analysis-of-the-biggest-heist-in-defi-history/.
- Tidy, J. (2022, March 31). Ronin Network: What a $600m hack says about the state of crypto. https://www.bbc.com/news/technology-60933174.
- Tong, W., Li, J., Yang, L., Huang, X., Gao, X., & Dong, Z. (2025). A Survey on Blockchain Scalability. In D. He, J. Wu, C. Wang, & H. Huang (Eds.), Blockchain, Metaverse and Trustworthy Systems (pp. 133–146). Springer Nature. [CrossRef]
- Tripathi, G., Ahad, M. A., & Casalino, G. (2023). A comprehensive review of blockchain technology: Underlying principles and historical background with future challenges. Decision Analytics Journal, 9, 100344. [CrossRef]
- TRM Tracks the Poly Network Hack as Attacker Communicates in Real Time. (2021, August 10). TRM Blog. https://www.trmlabs.com/resources/blog/trm-tracks-the-poly-network-hack-as-attacker-communicates-in-real-time-via-input-data.
- Ventures, R. M. (2023, July 6). An In-Depth Analysis of the Recent Exploit in the Poly Network that led to $10m+ being lost! D3ploy. https://medium.com/d3ploy/an-in-depth-analysis-of-the-recent-exploit-in-the-poly-network-that-led-to-10m-being-lost-7eca2922ee3d.
- Waheed, A., Seegolam, B., Jowaheer, M. F., Sze, C. L. X., Hua, E. T. F., & Sindiramutty, S. R. (2024). Zero-Day Exploits in Cybersecurity: Case Studies and Countermeasure. Preprints.org. [CrossRef]
- Wang, Z., Zhu, H., & Sun, L. (2021). Social Engineering in Cybersecurity: Effect Mechanisms, Human Vulnerabilities and Attack Methods. IEEE Access, 9, 11895–11910. IEEE Access. [CrossRef]
- Weiqi, X., Hooi, S. T. C., Sindiramutty, S. R. a. L., Asirvatham, D. a. L., Kumar, D., & Verma, S. (2024). Surface Anomaly Detection Using Machine Learning Technique. 2024 International Conference on Emerging Trends in Networks and Computer Communications (ETNCC), 1–7. [CrossRef]
- Wen, B. O. T., Syahriza, N., Xian, N. C. W., Wei, N. G., Shen, T. Z., Hin, Y. Z., Sindiramutty, S. R., & Nicole, T. Y. F. (2023). Detecting cyber threats with a Graph-Based NIDPS. In Advances in logistics, operations, and management science book series (pp. 36–74). [CrossRef]
- What Are Smart Contracts on Blockchain? | IBM. (2021, July 27). https://www.ibm.com/think/topics/smart-contracts.
- What are web3 transaction simulations? (2025, January 23). Alchemy. https://www.alchemy.com/overviews/transaction-simulation.
- Wilhoit, C., & Dejesus. (2025, May 6). Bit ByBit—Emulation of the DPRK’s largest cryptocurrency heist. Elastic Security Labs. https://www.elastic.co/security-labs/bit-bybit?utm_source=chatgpt.com.
- Wilson, T., Westbrook, T., & John, A. (2021, August 12). Hackers return $260 mln to cryptocurrency platform after massive theft | Reuters. Reuters. https://www.reuters.com/technology/defi-platform-poly-network-reports-hacking-loses-estimated-600-million-2021-08-11/.
- Xiao, Y., Zhang, N., Lou, W., & Hou, Y. T. (2020). A Survey of Distributed Consensus Protocols for Blockchain Networks. IEEE Communications Surveys & Tutorials, 22(2), 1432–1465. IEEE Communications Surveys & Tutorials. [CrossRef]
- Xun, A. T., En, L. a. Z., Shen, L. T., Xin, A. N., Soon, W. H., Jun, W. Z., Ramachandra, H., Xinghao, G., Khant, N. M., Weitao, F., & Sindiramutty, S. R. (2025). Building Trust in Cloud Computing:Strategies for Resilient Security. Preprints.org. [CrossRef]
- Ying, X., Murugesan, R. K., Sindiramutty, S. R., Wei, G. W., Balakrishnan, S., Kumar, D., & Verma, S. (2024). Scene Text Recognition using Deep Learning Techniques. 024 International Conference on Emerging Trends in Networks and Computer Communications (ETNCC), 1–9. [CrossRef]
- Zengeni, I. P., & Zolkipli, M. fadli. (2024). Zero-Day Exploits and Vulnerability Management. Borneo International Journal eISSN 2636-9826, 7(3), Article 3.
- Zhang, M., Zhang, X., Barbee, J., Zhang, Y., & Lin, Z. (2023). SoK: Security of Cross-chain Bridges: Attack Surfaces, Defenses, and Open Problems (No. arXiv:2312.12573). arXiv. [CrossRef]
| Feature | Safu Extension | Web3 Antivirus | WalletGuard | AegisWeb3 |
|---|---|---|---|---|
| Phishing Site Detection | ✓ | ✓ | ✓ | ✓ |
| Malicious Code Detection | ✓ | ✓ | ||
| Centralized Domain Blacklist | ✓ | ✓ | ✓ | ✓ |
| Community-Based Threat Reporting | ✓ | |||
| Proactive Approval Reminders | ✓ | |||
| Transaction Simulation | ✓ | ✓ | ✓ | ✓ |
| Metrics | Web3 Antivirus | WalletGuard | AegisWeb3 | Safu Extension |
|---|---|---|---|---|
| Users Protected | More than 35,000 | More than 50,000 | More than 140,000 | - |
| Losses Prevented | More than $1.5 Million | More than $40 Million | - | - |
| Blacklisted Domains / Phishing sites detected | More than 1.2 Million | More than 15,000 scams stopped | More than 170,000 | Over 320,500 domains blacklisted |
| Scam Contracts Detected | More than 10.1 Million | - | More than 1.2 Million | - |
| Detection Coverage | Fast detection algorithms that covers broad range of threat | 98% of the scams that were detected were not on the existing blocklist | 91.2% coverage on Ethereum-based phishing | Flags domain with more than 0.75 Levenshtein similarity score |
| Transaction Simulation | - | Over 10 Million | - | - |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2025 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (http://creativecommons.org/licenses/by/4.0/).