Understanding End-User Perception of Transfer Risks in Smart Contracts
Authors
Privacy by Design & User ControlPrivacy Perception & Decision-MakingCryptocurrency InvestorsPrivacy Policy Makers
Research Background and Issues
- Problems and Challenges: With the increasing use of blockchain smart contracts, particularly in financial transactions, it is critical for users to understand the risks associated with these systems. However, users' awareness of transfer risks (e.g., being blacklisted) remains limited. The authors observed that users not only lack sufficient understanding of certain real risks but also tend to confuse real risks with false ones.
- Significance: Smart contracts are a fundamental component of decentralized applications. If users cannot comprehend how smart contracts operate and the potential risks involved, it may lead to financial losses and a lack of behavioral trust. This poses a significant barrier to the further development of smart contracts and the blockchain ecosystem.
- Research Motivation and Related Work: The authors aim to address a gap in existing research by focusing on the end users of smart contracts rather than developers. While prior studies have explored users' overall perceptions of blockchain technology or decentralized systems, they have not delved deeply into the understanding of specific contracts and associated risks.
Solution
- Research Methodology: The authors adopted a dual approach: first, conducting a user survey based on the most popular smart contract (USDT on Ethereum) to understand users' risk perceptions; second, performing both automated and manual analyses of the source code of the 78 most active ERC-20 smart contracts on Ethereum to assess the prevalence of transfer risks.
- Innovations:
- Conducted the first large-scale quantitative and qualitative analysis of user perceptions of smart contracts.
- Proposed a classification of transfer risks (e.g., user blacklisting, contract suspension, contract upgrades) and related perception metrics (surprise level, awareness level, risk severity).
- Developed an experimental algorithm for automatically detecting risks in smart contracts.
- Implementation Steps:
- Recruited 110 blockchain-experienced participants for a user survey, covering statistical analysis and free-text responses on perceived risks.
- Conducted a quantitative evaluation of the USDT contract content and its interaction with the MetaMask wallet interface.
- Collected ERC-20 smart contract source codes and performed automated risk detection tasks combined with manual validation.
Research Findings
- Key Results:
- User Perception Results:
- 71.8% of users identified "user blacklisting" and "smart contract upgradeability" as the most severe risks.
- The MetaMask interface used for failed or reduced transactions was deemed insufficiently informative, with only 31.8% of users understanding the reason for "partial fund transfers."
- Source Code Analysis Results: The study found that risks such as user blacklisting and smart contract upgradeability exist in ERC-20 smart contracts but are relatively rare (e.g., each present in 1.3% of contracts). Additionally, three new risks were identified, including "asset destruction" (1.3%) and "transfer restriction changes" (2.6%).
- Automated Detection Capability: The automated risk detection algorithm was highly effective in identifying "contract suspension" functionality, achieving an F1 score of 80%.
- User Perception Results:
- Advantages and Comparisons: This user-focused study expands beyond previous research that primarily concentrated on developer tools, addressing the gap in understanding ordinary users' risk perceptions. Compared to existing studies, this work combines user surveys with smart contract source code analysis, offering a more comprehensive approach.
- Limitations and Future Directions:
- The study is limited to ERC-20 smart contracts and needs to be extended to other types of smart contracts.
- The user survey relies on self-reported data rather than observed behaviors; future research should include behavioral experiments.
- The accuracy of the automated detection method is constrained by function name matching; future work could explore semantic analysis tools.
Conclusion and Recommendations for Future Work
- Key Conclusions: There is a significant gap in the interpretability of smart contract design. Most users are unable to accurately understand the behavior and risks of smart contracts, leading to a lack of trust. Core risks may have profound impacts on user behavior and product trust.
- Recommendations:
- Develop smart contracts and wallet user interfaces that effectively communicate risks to end users.
- Design more interpretable programming languages for source code to help users better understand potential risks in the code.
- Extend user research to other blockchain ecosystems to ensure the generalizability of the findings.
Research Questions / Practical Problems
Question signals indexed for this paper.
help
Research Questions
3- How well do ordinary users understand transfer risks in smart contracts (e.g., USDT contracts)?Category: Privacy-Enhancing TechnologiesSimilar questionsarrow_forward
- Which transfer risks (e.g., user blacklisting, contract upgradability) are most common in ERC-20 smart contracts?Category: Privacy-Enhancing TechnologiesSimilar questionsarrow_forward
- Can automated detection algorithms effectively identify transfer risks in smart contracts?Category: Privacy-Enhancing TechnologiesSimilar questionsarrow_forward
lightbulb
Practical Problems
1- Ordinary users struggle to understand risks in smart contracts, potentially causing financial losses.Category: Privacy-Enhancing TechnologiesSimilar questionsarrow_forward
- 100%
"Don't put all your eggs in one basket": How Cryptocurrency Users Choose and Secure Their Wallets
CHI '24· Privacy by Design & User Control +1
- 80%
Understanding User-Perceived Security Risks and Mitigation Strategies in the Web3 Ecosystem
CHI '24· Privacy by Design & User Control +2
- 75%
SIGCHI Social Impact Award Talk – Making Privacy and Security More Usable
CHI '18· Privacy by Design & User Control +1
- 75%
You 'Might' Be Affected: An Empirical Analysis of Readability and Usability Issues in Data Breach Notifications
CHI '19· Privacy by Design & User Control +1
- 75%
Bits Under the Mattress: Understanding Different Risk Perceptions and Security Behaviors of Crypto-Asset Users
CHI '21· Privacy by Design & User Control +1
- 75%
Human-GDPR Interaction: Practical Experiences of Accessing Personal Data
CHI '22· Privacy by Design & User Control +1
- 75%
Obfuscation Remedies Harms Arising from Content Flagging of Photos
CHI '22· Privacy by Design & User Control +1
- 75%
Understanding Privacy Switching Behaviour on Twitter
CHI '22· Privacy by Design & User Control +1
- 75%
How Language Formality in Security and Privacy Interfaces Impacts Intended Compliance
CHI '23· Privacy by Design & User Control +1
- 75%
The Impact of Risk Appeal Approaches on Users’ Sharing Confidential Information
CHI '24· Privacy by Design & User Control +1
Based on Jaccard similarity of research subtopics & professions (≥60%)
Quick Actions
AdRecommended
Learn AI Coding at CodeNow
open_in_newOpen DOI Link
DOI: https://dl.acm.org/doi/10.1145/3706598.3713887
At a Glance
fact_checkPaper Snapshot
dataset
Source
CHI
calendar_month
Year
2025
emoji_events
Award
No award tagged
group
Authors
4 authors
sell
Subtopics
Privacy by Design & User Control, Privacy Perception & Decision-Making
work
Professions
Cryptocurrency Investors, Privacy Policy Makers
article
Content Status
Full text indexed
hub
Related Papers
10 related papers