An empirical analysis of security and privacy risks in android cryptocurrency wallet apps

Muhammad Ikram, Dali Kaafar, I Wayan Budi Sentana*

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference proceeding contributionpeer-review

3 Citations (Scopus)

Abstract

A cryptocurrency wallet app is a piece of software that manages, stores, and generates private keys of cryptocurrency accounts. With the provision of services such as easy access to transaction history, and checking account balance besides transmissions of new transactions in distributed networks such as Blockchains, cryptocurrency wallet apps gain unprecedented popularity which in turn attracts malicious actors to attack users resulting in loss of cryptocurrency assets and leakage of sensitive user data. This paper presents the first large-scale study of Android cryptocurrency wallet apps. We surveyed apps on Google Play to detect and extract meta-data and application packages of 457 cryptocurrency wallet apps. We perform several passive and active measurements designed to investigate the security and privacy features to study the behavior of cryptocurrency wallet apps. Our analysis includes investigating cryptocurrency wallet apps’ third-party embedding, malware presences, and exfiltration of users’ sensitive data to third-parties. Our study reveals vulnerabilities and privacy issues in cryptocurrency apps including the insecure use of HTTP to serve transactions.
Original languageEnglish
Title of host publicationApplied cryptography and network security
Subtitle of host publication21st International Conference, ACNS 2023, Kyoto, Japan, June 19–22, 2023, proceedings, part II
EditorsMehdi Tibouchi, XiaoFeng Wang
Place of PublicationCham
PublisherSpringer, Springer Nature
Pages699-725
Number of pages27
ISBN (Electronic)9783031334917
ISBN (Print)9783031334900
DOIs
Publication statusPublished - 2023
Event21st International Conference on Applied Cryptography and Network Security - Kyoto, Japan, Kyoto, Japan
Duration: 19 Jun 202322 Jun 2023
Conference number: 21
https://sulab-sever.u-aizu.ac.jp/acns2023/

Publication series

NameLecture Notes in Computer Science
PublisherSpringer
Volume13906
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference21st International Conference on Applied Cryptography and Network Security
Abbreviated titleACNS
Country/TerritoryJapan
CityKyoto
Period19/06/2322/06/23
Internet address

Keywords

  • Cryptocurrency Wallet
  • Static Analysis
  • Dynamic Analysis
  • User-review Analysis

Fingerprint

Dive into the research topics of 'An empirical analysis of security and privacy risks in android cryptocurrency wallet apps'. Together they form a unique fingerprint.

Cite this