loading
Papers Papers/2022 Papers Papers/2022

Research.Publish.Connect.

Paper

Paper Unlock

Authors: Alexander Marsalek 1 ; Edona Fasllija 2 and Dominik Ziegler 3

Affiliations: 1 Secure Information Technology Center Austria, Vienna, Austria ; 2 Institute for Applied Information Processing and Communications (IAIK), Graz University of Technology, Graz, Austria ; 3 Know-Center GmbH, Graz, Austria

Keyword(s): Electroneum Cloud Mining, Cryptocurrency, Impersonation Attack, Image Manipulation.

Abstract: The Electroneum cryptocurrency provides a novel mining experience called “cloud mining”, which enables iOS and Android users to regularly earn cryptocurrency tokens by simply interacting with the Electroneum app. Besides other security countermeasures against automated attacks, Electroneum requires the user to upload selfies with a predefined gesture or a drawing of a symbol as a prerequisite for the activation of the mining process. In this paper, we show how a malicious user can circumvent all of these security features and thus create and maintain an arbitrary number of fake accounts. Our impersonation attack particularly focuses on creating non-existing selfies by relying on Generative Adversarial Network (GAN) techniques during account initialization. Furthermore, we employ reverse engineering to develop a bot that simulates the genuine Electroneum app and is capable of operating an arbitrary number of illegitimate accounts on one Android device, enabling the malicious user to o btain an unfairly large payout. (More)

CC BY-NC-ND 4.0

Sign In Guest: Register as new SciTePress user now for free.

Sign In SciTePress user: please login.

PDF ImageMy Papers

You are not signed in, therefore limits apply to your IP address 3.15.156.140

In the current month:
Recent papers: 100 available of 100 total
2+ years older papers: 200 available of 200 total

Paper citation in several formats:
Marsalek, A.; Fasllija, E. and Ziegler, D. (2020). This Selfie Does Not Exist: On the Security of Electroneum Cloud Mining. In Proceedings of the 17th International Joint Conference on e-Business and Telecommunications - SECRYPT; ISBN 978-989-758-446-6; ISSN 2184-7711, SciTePress, pages 388-396. DOI: 10.5220/0009829303880396

@conference{secrypt20,
author={Alexander Marsalek. and Edona Fasllija. and Dominik Ziegler.},
title={This Selfie Does Not Exist: On the Security of Electroneum Cloud Mining},
booktitle={Proceedings of the 17th International Joint Conference on e-Business and Telecommunications - SECRYPT},
year={2020},
pages={388-396},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0009829303880396},
isbn={978-989-758-446-6},
issn={2184-7711},
}

TY - CONF

JO - Proceedings of the 17th International Joint Conference on e-Business and Telecommunications - SECRYPT
TI - This Selfie Does Not Exist: On the Security of Electroneum Cloud Mining
SN - 978-989-758-446-6
IS - 2184-7711
AU - Marsalek, A.
AU - Fasllija, E.
AU - Ziegler, D.
PY - 2020
SP - 388
EP - 396
DO - 10.5220/0009829303880396
PB - SciTePress