Understanding End-User Perception of Transfer Risks in Smart Contracts

Privacy by Design & User ControlPrivacy Perception & Decision-MakingCryptocurrency InvestorsPrivacy Policy Makers

Research Background and Issues

  • Problems and Challenges: With the increasing use of blockchain smart contracts, particularly in financial transactions, it is critical for users to understand the risks associated with these systems. However, users' awareness of transfer risks (e.g., being blacklisted) remains limited. The authors observed that users not only lack sufficient understanding of certain real risks but also tend to confuse real risks with false ones.
  • Significance: Smart contracts are a fundamental component of decentralized applications. If users cannot comprehend how smart contracts operate and the potential risks involved, it may lead to financial losses and a lack of behavioral trust. This poses a significant barrier to the further development of smart contracts and the blockchain ecosystem.
  • Research Motivation and Related Work: The authors aim to address a gap in existing research by focusing on the end users of smart contracts rather than developers. While prior studies have explored users' overall perceptions of blockchain technology or decentralized systems, they have not delved deeply into the understanding of specific contracts and associated risks.

Solution

  • Research Methodology: The authors adopted a dual approach: first, conducting a user survey based on the most popular smart contract (USDT on Ethereum) to understand users' risk perceptions; second, performing both automated and manual analyses of the source code of the 78 most active ERC-20 smart contracts on Ethereum to assess the prevalence of transfer risks.
  • Innovations:
    1. Conducted the first large-scale quantitative and qualitative analysis of user perceptions of smart contracts.
    2. Proposed a classification of transfer risks (e.g., user blacklisting, contract suspension, contract upgrades) and related perception metrics (surprise level, awareness level, risk severity).
    3. Developed an experimental algorithm for automatically detecting risks in smart contracts.
  • Implementation Steps:
    1. Recruited 110 blockchain-experienced participants for a user survey, covering statistical analysis and free-text responses on perceived risks.
    2. Conducted a quantitative evaluation of the USDT contract content and its interaction with the MetaMask wallet interface.
    3. Collected ERC-20 smart contract source codes and performed automated risk detection tasks combined with manual validation.

Research Findings

  • Key Results:
    1. User Perception Results:
      • 71.8% of users identified "user blacklisting" and "smart contract upgradeability" as the most severe risks.
      • The MetaMask interface used for failed or reduced transactions was deemed insufficiently informative, with only 31.8% of users understanding the reason for "partial fund transfers."
    2. Source Code Analysis Results: The study found that risks such as user blacklisting and smart contract upgradeability exist in ERC-20 smart contracts but are relatively rare (e.g., each present in 1.3% of contracts). Additionally, three new risks were identified, including "asset destruction" (1.3%) and "transfer restriction changes" (2.6%).
    3. Automated Detection Capability: The automated risk detection algorithm was highly effective in identifying "contract suspension" functionality, achieving an F1 score of 80%.
  • Advantages and Comparisons: This user-focused study expands beyond previous research that primarily concentrated on developer tools, addressing the gap in understanding ordinary users' risk perceptions. Compared to existing studies, this work combines user surveys with smart contract source code analysis, offering a more comprehensive approach.
  • Limitations and Future Directions:
    1. The study is limited to ERC-20 smart contracts and needs to be extended to other types of smart contracts.
    2. The user survey relies on self-reported data rather than observed behaviors; future research should include behavioral experiments.
    3. The accuracy of the automated detection method is constrained by function name matching; future work could explore semantic analysis tools.

Conclusion and Recommendations for Future Work

  • Key Conclusions: There is a significant gap in the interpretability of smart contract design. Most users are unable to accurately understand the behavior and risks of smart contracts, leading to a lack of trust. Core risks may have profound impacts on user behavior and product trust.
  • Recommendations:
    1. Develop smart contracts and wallet user interfaces that effectively communicate risks to end users.
    2. Design more interpretable programming languages for source code to help users better understand potential risks in the code.
    3. Extend user research to other blockchain ecosystems to ensure the generalizability of the findings.

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/papers/chi/188433/2025

AdRecommended

Learn AI Coding at CodeNow

open_in_newOpen DOI Link
DOI: https://dl.acm.org/doi/10.1145/3706598.3713887
At a Glance

Paper Snapshot

fact_check
dataset
Source
CHI
calendar_month
Year
2025
emoji_events
Award
No award tagged
group
Authors
4 authors
sell
Subtopics
Privacy by Design & User Control, Privacy Perception & Decision-Making
work
Professions
Cryptocurrency Investors, Privacy Policy Makers
article
Content Status
Full text indexed
hub
Related Papers
10 related papers