A Novel Feature Extraction and Detection Model for Phishing Scam on Ethereum Using Machine Learning
| dc.contributor.author | Ertam, Fatih | |
| dc.contributor.author | Kucuk, Duzgun | |
| dc.contributor.author | Kilincer, Ilhan Firat | |
| dc.date.accessioned | 2026-08-12T17:11:21Z | |
| dc.date.issued | 2026 | |
| dc.department | Fırat Üniversitesi | |
| dc.description.abstract | The proliferation of phishing scam tokens on the Ethereum blockchain, including honeypot, rug pull, and impersonation schemes, poses a grave threat to financial security. Although earlier studies have documented detection accuracies that exceed 95%, they frequently depend on random train-test partitions. These partitions frequently overestimate real-world performance by disregarding the temporal progression of phishing behaviors. This study addresses the methodological gap by employing a temporally validated evaluation. A labeled dataset comprising 5408 Ethereum token contracts was constructed. This dataset was verified through a two-stage process that integrated cyber threat intelligence and on-chain evidence. A total of 16 discriminative features were extracted, reflecting transaction volume, network structure, and temporal behavior. In lieu of employing random partitioning, temporal validation (70% training, 15% validation, and 15% testing) was adopted to assess generalizability to emerging threats. Six machine learning models (LightGBM, XGBoost, Random Forest, Gradient Boosting, Decision Tree, and MLP) were tuned via GridSearchCV. LightGBM demonstrated optimal performance, attaining 85.59% accuracy, 81.63% F1-score, and 92.02% AUC on temporally held-out data. The feature ablation process yielded the identification of transaction volume as the most discriminative factor, with a corresponding increase in performance of 13.09 points on the performance scale. Conversely, temporal features exhibited a marginal decline in performance, with a decrease of 0.87 points. Temporal validation resulted in a 3.95-point-percentage decrease compared to random splitting, thereby exposing the optimistic bias present in prior studies. Despite the fact that the resulting F1-score of 81.63% falls short of the 85% threshold stipulated in the literature, it is indicative of a realistic deployment expectation. This work underscores the importance of temporal validation for reliable fraud detection research. | |
| dc.description.sponsorship | Scientific Research Projects Coordination Unit of Firat University, Turkiye [ADEP.25.28, TEKF.25.13] | |
| dc.description.sponsorship | This work is supported by the Scientific Research Projects Coordination Unit of Firat University, Turkiye (Project Numbers: TEKF.25.13 andADEP.25.28). | |
| dc.identifier.doi | 10.1002/cpe.70503 | |
| dc.identifier.issn | 1532-0626 | |
| dc.identifier.issn | 1532-0634 | |
| dc.identifier.issue | 1 | |
| dc.identifier.orcid | 0000-0001-8090-4998 | |
| dc.identifier.scopus | 2-s2.0-105024538317 | |
| dc.identifier.scopusquality | Q1 | |
| dc.identifier.uri | https://doi.org/10.1002/cpe.70503 | |
| dc.identifier.uri | https://hdl.handle.net/11508/51121 | |
| dc.identifier.volume | 38 | |
| dc.identifier.wos | WOS:001668039900041 | |
| dc.identifier.wosquality | Q3 | |
| dc.indekslendigikaynak | Web of Science | |
| dc.indekslendigikaynak | Scopus | |
| dc.language.iso | en | |
| dc.publisher | Wiley | |
| dc.relation.ispartof | Concurrency and Computation-Practice & Experience | |
| dc.relation.publicationcategory | Makale - Uluslararası Hakemli Dergi - Kurum Öğretim Elemanı | |
| dc.rights | info:eu-repo/semantics/openAccess | |
| dc.snmz | KA_WoS_20260511 | |
| dc.subject | blockchain fraud | |
| dc.subject | cryptocurrency forensics | |
| dc.subject | feature ablation | |
| dc.subject | phishing detection | |
| dc.subject | temporal validation | |
| dc.title | A Novel Feature Extraction and Detection Model for Phishing Scam on Ethereum Using Machine Learning | |
| dc.type | Article |







