Proactive Detection of Malicious Activities in Decentralized Finance Through Analysis of Behavioral Attack Patterns
Bahareh Parhizkari · Open Repository and Bibliography (University of Luxembourg) · 2026
Decentralized finance has emerged as one of the most prominent applications of blockchain technology, enabling financial services through smart contracts without centralized intermediaries. However, the rapid growth of DeFi has been accompanied by a substantial increase in security incidents, resulting in significant financial losses. Existing security mechanisms have improved the detection of malicious activities in blockchain ecosystems; nevertheless, many approaches focus on exploit transactions or malicious behaviors that become observable shortly before or during attack execution. In modern DeFi environments, where attacks can be completed within a single transaction and an increasing number of transactions are submitted through private transaction infrastructures, the opportunity for effective intervention may be severely limited. This dissertation is motivated by the observation that malicious activities often leave detectable traces before exploit execution. It investigates the hypothesis that meaningful indicators of malicious intent emerge throughout multiple stages of the DeFi attack lifecycle and can be leveraged to identify security threats before attacks are executed. To examine this hypothesis, the dissertation explores several complementary sources of security intelligence. First, it demonstrates that information available during attacker preparation activities can be used to identify potential victim addresses before exploit execution, thereby increasing the time available for defensive actions. Second, it presents a deployment-time detection approach that identifies malicious smart contracts using features extracted from contract bytecode and deployment-related information. The proposed approach achieves an F1-score of 0.84 and an ROC-AUC of 0.95, demonstrating that deploymenttime artifacts contain valuable predictive security signals. Third, the dissertation investigates whether behavioral characteristics observed during the evolution of DeFi projects can provide early indicators of security risk and introduces a framework for estimating attack likelihood using on-chain behavioral signals. The results show that elevated risk levels can often be identified months before compromise. Finally, the dissertation examines the role of external information sources in fraud detection and demonstrates that integrating on-chain and off-chain information improves the identification of fraudulent projects, achieving an F1-score of 0.89. The findings presented throughout this dissertation consistently indicate that valuable security signals emerge before exploit transactions become observable on-chain. These signals can be observed during attacker preparation activities, smart contract deployment, project evolution, and broader ecosystem behaviors. Collectively, the results demonstrate that proactive threat detection in DeFi is feasible and that meaningful opportunities for mitigation exist before exploit execution occurs. By shifting the focus from attack detection during execution to the identification of early-stage indicators of malicious intent, this dissertation contributes toward more proactive and resilient security mechanisms for Decentralized finance ecosystems.