Next Article in Journal
Valorization of Spent Coffee Grounds as a Functional Protein Ingredient for Sustainable Aquafeed Production
Next Article in Special Issue
FedMARL-LTI: Federated Multi-Agent Reinforcement Learning with LLM-Compatible Threat Intelligence for Cooperative Cyber Defense
Previous Article in Journal
Closure as a New Beginning: Repurposing Post-Mining Sites into Industrial Eco-Parks Backed by Virtual Power Plants
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
Review

Cybersecurity in Cryptocurrencies and NFTs: A Bibliometric Analysis

by
José-María Oliet-Villalba
,
José-Amelio Medina-Merodio
*,
Mikel Ferrer-Oliva
and
José-Javier Martínez-Herraiz
Departamento de Ciencias de la Computación, Universidad de Alcalá, 28871 Madrid, Spain
*
Author to whom correspondence should be addressed.
Appl. Sci. 2026, 16(4), 1917; https://doi.org/10.3390/app16041917
Submission received: 18 December 2025 / Revised: 5 February 2026 / Accepted: 11 February 2026 / Published: 14 February 2026

Abstract

The rapid growth of cryptocurrencies and non-fungible tokens (NFTs) has expanded technological opportunities, but it has also increased the exposure surface to cyber threats, creating a need for a more precise understanding of the field’s scientific evolution. This study aims to systematically analyse academic output related to cybersecurity and cyber threats within cryptocurrency and NFT ecosystems, identifying central themes, the most influential authors, and emerging trends. A bibliometric methodology was employed, based on the PRISMA 2020 protocol and scientific mapping tools such as SciMAT (v1.1.06) and VOSviewer (v1.6.20), using a corpus of 337 articles published between 2014 and 2025. The findings indicate sustained growth in the literature, a marked geographical and editorial concentration, and the presence of motor themes such as blockchain, cybersecurity, emerging technologies and illegal mining, alongside emerging areas such as intrusion detection. The results also reveal a progressive integration of artificial intelligence techniques in the detection and prevention of attacks. In conclusion, this study provides a comprehensive overview of the state of the art, identifies critical gaps, and underscores the need for interdisciplinary approaches to strengthen security in decentralised environments.

1. Introduction

Cryptocurrencies and non-fungible tokens (NFTs) have gained notable prominence in recent years, driven both by media attention and by the speculative momentum of 2021, when Bitcoin and Ethereum experienced sustained increases and reached all-time highs [1]. Moreover, milestones such as the sale of Beeple’s NFT “Everydays: The First 5000 Days” for USD 69 million [2] reinforced the perception that the adoption of these assets is part of an increasingly inevitable future [3]. In parallel, the underlying blockchain technology experienced a surge in adoption, being presented as a promising solution for critical domains such as education and healthcare [4,5,6].
From a functional perspective, cryptocurrencies propose a decentralised economy in which transactions dispense with financial intermediaries and, consequently, their associated costs and controls [7,8]. Although they entail disadvantages—such as high volatility and limited support from national economies and banking institutions—their uptake by regulated entities has boosted their popularity [9,10]. Studies on the decentralised finance (DeFi) ecosystem identify risks such as smart contract vulnerabilities, regulatory ambiguities, and challenges related to transaction scalability and efficiency, among others [11].
With the widespread adoption of smart contracts, Ethereum expanded the design space towards decentralised applications and programmable markets [12]. NFTs, in turn, introduce a framework in which digital ownership acquires an economic value comparable to that of physical assets, underpinned by a verifiable title system that hinders unauthorised distribution, albeit by no means infallibly [13]. In addition, their use to strengthen authentication processes has produced notable results, including digital licences, electronic identity documents, and reliable signature systems [14,15]. Conversely, studies provide a comprehensive collection and detailed analysis of security incidents affecting NFTs to date, additionally noting differences in expertise between academic and industrial settings [16].
Nevertheless, these assets pose a cybersecurity dilemma. On the one hand, they rely on relatively immature technologies with a still-limited security track record, which can erode users’ trust [17,18]. On the other hand, certain security-related characteristics—particularly the degree of pseudonymity associated with the digital environment—facilitate scenarios conducive to illicit activities, ranging from financial fraud to novel channels for financing criminal or terrorist organisations [19].
Although several works make valuable contributions to the state of the art and propose future directions, none provide, as of the time of this study, a quantitative assessment of the maturity and evolution of research topics in cybersecurity within cryptocurrency and NFT ecosystems. By contrast, this study conceptualises both ecosystems as multifaceted entities that integrate human and technological dimensions, enabling the identification of research lines that have received comparatively less attention during the period analysed. A timely identification of these gaps can support a proactive research strategy in the coming years focused on emerging cybersecurity threats and, in turn, contribute to building trustworthy ecosystems for the use of digital currencies and assets.
Bibliometric mapping has become established as a particularly suitable approach for articles seeking to describe, in a quantitative, systematic, and reproducible manner, the state of research within a field [20]. It enables the development of a domain to be visualised from large volumes of literature by identifying author communities, core publication outlets, and leading countries, as well as thematic clusters and their interrelationships through networks and science mapping techniques (e.g., co-occurrence, bibliographic coupling, or co-citation) [21]. This approach offers clear advantages over purely narrative reviews: it facilitates the objective synthesis of large-scale patterns and helps to reconstruct the domain’s conceptual structure to detect established lines of inquiry, peripheral areas, and research gaps with methodological traceability [21].
Accordingly, the main objective of this work is to conduct a bibliometric study and scientific mapping of the literature produced to date in this research area, so as to serve as a reference for future studies and to contribute to the development of this line of inquiry.
The research questions addressed in this study are as follows:
  • RQ1: How has the number of publications evolved between 2014 and 2025 regarding cybersecurity and cyber threats in cryptocurrencies and NFTs?
  • RQ2: Which authors, countries, journals, and publications have contributed most to the study of cybersecurity and cyber threats in cryptocurrencies and NFTs?
  • RQ3: What are the main topics addressed, and how are they evolving?
  • RQ4: What are the principal emerging topics?
  • RQ5: What are the main clusters identified in the literature?
To address these questions, 337 scholarly articles were analysed. These were retrieved from the Web of Science and Scopus databases and underwent a rigorous screening process following the PRISMA 2020 methodology. The most productive authors and journals were identified and classified according to indicators such as the h-index, total number of publications, citation count, and year of publication.
Subsequently, a keyword co-occurrence analysis was conducted across the selected articles. First, VOSviewer was employed to visualise thematic groupings derived from co-occurrence patterns and to identify research areas. Next, SciMAT was used to produce strategic diagrams based on term co-occurrence, which made it possible to delineate thematic blocks and to distinguish both the most consolidated research lines and those with the greatest potential for further development. Two analyses were conducted using this latter tool. First, the article corpus was segmented into three time periods to visualise the evolution of themes and the emergence of new cybersecurity-related trends. Second, the entire corpus was analysed as a single set in order to assess the maturity level of the different research streams.
The remainder of the paper is organised as follows: Section 2 reviews the literature on cybersecurity in the cryptocurrency and NFT ecosystems; Section 3 details the methodology and study phases; Section 4 presents the results; Section 5 discusses these results; and Section 6 sets out the conclusions of the work.

2. State of the Art

Cryptocurrencies, NFTs, and the blockchain infrastructure underpinning both collectively constitute a new paradigm that enables the digitalisation of systems that were previously not feasible [22]. In economic settings, the possibilities offered by cryptocurrencies support a model of global finance that is decentralised and independent of central authorities, and have been proposed as a potential future alternative to existing currencies [17]. In response to Bitcoin’s early scalability challenges, new systems such as payment channels have been proposed to expedite transactions and move them closer to practical use; however, these solutions are also exposed to attacks [23,24,25].
Moreover, the concept of ownership has acquired new meanings, supported by NFTs and the blockchain, enabling the sale of purely digital assets as if they were physical goods, as well as strengthening digital control over increasingly large logistics chains [5,26,27]. Finally, there has been growing interest in blockchain applications for handling personal data in healthcare and other contexts [28]. An NFT-based authentication framework has been proposed for metaverse users [15], whilst systems based on adaptor signatures and time-lock puzzles enable cross-chain environments for digital asset transactions that are independent of central nodes [29].
The immaturity of the relevant technologies in terms of security has stimulated research into the largely unexplored attack surface of these new ecosystems [30,31]. Attacks targeting cryptocurrencies exhibit a wide range of vectors, from the exploitation of software vulnerabilities to advanced social engineering, thereby requiring diversified defence mechanisms [32,33]. In the phishing domain, studies highlight the existence of malicious phishing websites in the cryptocurrency environment and propose the development of phishing-URL detection models [34]. By contrast, blockchain-based phishing detection frameworks have been shown to be markedly ineffective against contemporary attacker strategies for concealing malicious behaviour [35]. In addition, the security of cryptocurrency exchanges constitutes a critical focus due to their central role in liquidity and market access [36].
With respect to NFTs, the smart contracts on which they rely are subject to numerous vulnerabilities, associated both with code defects and with developers’ limited security expertise, as well as the lack of mature detection tools [37,38]. Research has underscored the need to develop a threat-modelling framework for the NFT ecosystem and has proposed updated frameworks [39].
Cryptocurrency and NFT ecosystems possess inherent characteristics that make them conducive environments for illicit activity [40]. Numerous studies emphasise the need to develop a regulatory framework suited to the decentralised context of these digital assets in response to the proliferation of crimes such as fraud and money laundering [41,42,43]. They also create space for terrorism financing and other criminal activities [44], as well as for ransomware payment channels [45]. Relatedly, the exploitation of these mechanisms for the discreet accumulation of economic resources by terrorist organisations has been documented, via funding routes that evade law enforcement interception efforts [19]. This has motivated initiatives for detecting illicit activity using machine learning (ML) techniques [46]. Furthermore, the economic value of cryptocurrencies has made mining activities—and miners themselves—targets for attacks, alongside a pronounced rise in cryptojacking offences through the use of specialised malware or malicious websites [47,48].
The digital nature of cryptocurrencies translates into a greater impact of cyberattacks, which can entail heightened price volatility and an expansion of exchanges that reverberates across payment companies and the financial and technology sectors [10]. Research examining the impact of the nine largest cryptocurrency cybercrimes on returns and volatility between 2020 and 2022 indicates a direct influence on volatility [49]. Other studies link fluctuations in the value of cryptocurrencies and NFTs to terrorist attacks, observing increases during preparation and financing phases and losses in the post-attack period, thereby evidencing the reach and penetration of criminal and terrorist organisations within cryptocurrency markets [50].

Positioning Relative to Prior Bibliometric Studies in FinTech, DeFi, and Blockchain Security

Recent bibliometric studies have mapped adjacent domains relevant to cryptocurrency and NFT ecosystems, particularly FinTech and digital finance. These works typically emphasise publication growth, influential outlets, and thematic clusters (often via keyword co-occurrence), providing useful macro-level overviews of a fast-expanding research space. However, their framing and retrieval strategies often privilege financial services, inclusion, regulation, and managerial perspectives, which can underrepresent the security-specific knowledge base and its distinct threat-driven vocabulary and evidence structure [51,52].
Within blockchain research, bibliometric reviews have also examined enabling technologies such as smart contracts and highlighted streams linked to standardisation, verification, and security [53]. While this line of mapping clarifies how “smart contract security” emerges as a recognised research stream, it is commonly organised around smart-contract engineering and blockchain applications broadly rather than around a security-first corpus focused on cyberattacks, threat mechanisms, and defensive techniques across cryptocurrency and NFT ecosystems as socio-technical settings [54,55].
Related bibliometric work on blockchain risks has further catalogued negative externalities (e.g., governance, irreversibility, and vulnerabilities), but these syntheses frequently treat security as one dimension among many and do not isolate the cyberthreat literature sufficiently to support fine-grained interpretation of how attack vectors, detection approaches, and defensive strategies co-evolve [56]. In parallel, DeFi-focused bibliometric reviews provide an important bridge between finance and blockchain research, yet they typically target business/economics corpora and therefore tend to overlook the specialised cybersecurity literature concentrated in computer science and security venues [57].
Against this background, the contribution of the present study is to consolidate and map—using a systematic PRISMA-guided retrieval strategy and science mapping—the security-centric literature addressing cyber threats in both cryptocurrency and NFT ecosystems. This design enables a more direct identification of security motor themes, emerging threat areas, and methodological shifts (e.g., increased use of AI-based detection) within the dedicated cyberthreat evidence base, complementing broader fintech/blockchain mappings while addressing their limited granularity on cybersecurity dynamics.

3. Methodology

This study combined a systematic literature review with bibliometric techniques to consolidate evidence on cybersecurity and cyberthreats in NFT environments while offering an integrated snapshot of the knowledge base and prevailing research directions [58,59,60]. Study selection and reporting followed PRISMA 2020 to document identification screening eligibility and inclusion decisions with procedural transparency [61,62].
The methodological design aligned descriptive bibliometric indicators with science mapping to capture both performance patterns and the conceptual configuration of the literature [63,64]. The workflow progressed through auditable stages covering record retrieval dataset consolidation and network construction, thereby supporting traceability and replicability across comparable domains [63,64].
The analysis was executed sequentially on the final NFT corpus to preserve consistency in indicators analytical procedures and visual structures across the tools employed [65,66,67,68]. Prior to network analysis, terminology was normalised and cleaned within the pipeline to improve semantic coherence and comparability among extracted terms [67].
VOSviewer was then applied to explore the structural organisation of the corpus through network visualisations and preliminary clustering configurations facilitating the interpretation of term associations and emergent thematic groupings [65,66,68].
Finally, SciMAT supported an end-to-end co-word analysis including network construction normalisation and strategic mapping using centrality density diagrams and cluster networks. This complemented VOSviewer by enabling a more strategic reading of thematic structure and its internal cohesion within the field [59,67,69,70].

3.1. Data Base Selection and Research Guide

Records were retrieved from Web of Science and Scopus because both index peer-reviewed journals and provide strong citation links and standardised exports. These characteristics support robust and reproducible bibliometric mapping across comparable research domains [71,72].
Web of Science contributes curated coverage while Scopus broadens indexing scope. Their combined use improves retrieval while preserving comparable filtering logic and consistent downstream processing for screening and analysis [73,74].
To minimise the risk of omission, retrieval was complemented through backward and forward citation chasing and targeted checks of key reference lists. This step strengthens coverage when eligibility criteria and screening decisions are applied systematically [75].
Subsequently, datasets were consolidated and duplicate records were identified and removed using Rayyan [76]. Any remaining inconsistencies were resolved through manual verification so that only unique records progressed to the study selection stage.
Search terms targeted cybersecurity research in cryptocurrency and NFT ecosystems with emphasis on attack vulnerabilities and related evidence. The thematic scope is summarised in Figure 1.
To maximise retrieval sensitivity while controlling topical drift, the following query was applied using the same keywords and filters:
(TS = ((‘cryptocurrencies’ OR ‘NFT’ OR ‘non fungible tokens’) AND (‘vulnerab*’ OR ‘cybersecurity’ OR ‘cyber security’ OR ‘attack’)) AND DT = (Article) AND DT = (English))). The asterisk in “vulnerab*” enables the search engine to retrieve any word that contains the letters preceding the asterisk, such as “vulnerabilities”, “vulnerability”, and “vulnerable”.

Eligibility Criteria (Inclusion/Exclusion)

Inclusion criteria. Records were eligible if they (i) were peer-reviewed journal articles, (ii) were published in English, (iii) addressed cybersecurity or cyber threats in cryptocurrency and/or NFT ecosystems (e.g., attacks, vulnerabilities, defensive mechanisms, detection/mitigation), and (iv) were indexed in Web of Science or Scopus with sufficient bibliographic metadata for screening and science mapping.
Exclusion criteria. We excluded (i) non-English publications, and (ii) non-article document types such as conference papers/proceedings, reviews, book chapters, editorials, letters, notes, and short communications. These restrictions were applied at the database search/filtering stage to ensure comparability of metadata and consistent quality screening for the bibliometric and science-mapping workflow. Records without accessible full text were also excluded at the eligibility stage (see PRISMA flow).
The strategy used inclusive security-related terms and restricted results to journal articles and English language to support consistent screening and subsequent analysis [61,62]. The search returned 1015 Web of Science records and 448 Scopus records, resulting in 1463 records.
Study selection and reporting followed PRISMA 2020 and the successive stages are summarised in Figure 2 [77].
Because records were retrieved from two databases, duplicates were removed first. This step excluded 340 items and yielded 1123 unique records for title and abstract screening [76,77].
During screening, 699 records were excluded in line with PRISMA 2020 reporting [77]:
  • 109 addressed NFTs in the medical domain (neurofibrillary tangle).
  • 94 focused on economic and financial aspects only.
  • 42 treated cybersecurity as a secondary aspect.
  • 18 had a structure that prevented evaluation.
  • 436 were tangential to the object of study.
After screening, 424 articles progressed to full text assessment. Before assessment, 37 items were removed due to inaccessible full texts. A further 50 were excluded because cybersecurity remained secondary or the focus did not meet the relevance threshold. The final dataset comprised 337 articles [77].
This corpus was analysed with VOSviewer and SciMAT using consistent metrics and visual structures derived from the same evidence base [65,66,67,68].

3.2. Network Visualisation and Clustering (VOSviewer)

Following terminology normalisation, a network-based analysis was conducted in VOSviewer, a tool extensively adopted for constructing and visualising bibliometric networks and for examining cluster configurations through graph-based layouts that support exploratory inspection of the underlying knowledge structure [65,66,68]. This step provides an additional representation of term relatedness and cluster boundaries, enabling a systematic cross-check of the thematic organisation subsequently derived through co word analysis and science mapping, and thereby reinforcing methodological coherence across analytical stages [63,64]. VOSviewer was selected because it is specifically designed for bibliometric mapping and offers strong interpretability features for network exploration and cluster reading in applied reviews [68,69,78].
The network was constructed using keyword co-occurrence, where links represent the joint appearance of terms across publications [68]. In the resulting visualisation, each node corresponds to a keyword and is labelled with the keyword itself, while node size reflects the relative weight of that keyword in the dataset as captured by its occurrence count under the selected counting method. Spatial proximity captures the strength of relatedness between terms and link thickness indicates association strength based on co-occurrence patterns [65,66,68].
Cluster colours correspond to the partition produced by the software clustering routine, which segments the network into coherent areas based on connection density, facilitating the identification of dominant thematic regions and the assessment of their internal cohesion [65,66,68]. In this stage, clusters were therefore identified automatically by VOSviewer, whereas interpretative cluster labels (when reported in the manuscript) were assigned manually by the authors after inspecting the most central and frequent keywords within each automatically generated cluster. This follows standard practice in bibliometric mapping to preserve transparency between algorithmic partitioning and substantive naming [68,72].
For the VOSviewer setup, the analysis was operationalised as a keyword co-occurrence map to represent the conceptual structure of the corpus through networks of terms that co appear across documents [68,79]. The full counting method was applied because it assigns full weight to each keyword occurrence at the document level, which is appropriate when the objective is to represent the observed presence of terms in the dataset without fractional redistribution [79]. To ensure that retained terms were sufficiently representative and to mitigate noise introduced by single occurrence keywords, the minimum inclusion threshold was set to two documents per keyword, a pragmatic criterion widely used in VOSviewer-based co-occurrence studies to exclude idiosyncratic terms while preserving emerging but recurrent concepts [79,80].
Subsequently, terminology was normalised by consolidating synonyms, spelling variants, and equivalent expressions using a thesaurus file to prevent artificial node fragmentation and to improve cluster validity [71,79,81]. After applying the thesaurus, the final keyword set was reduced accordingly, reflecting the consolidation of equivalent terms into unified descriptors. The thesaurus used for this normalisation process is reported in Appendix A.
Illustrative normalisation examples. To increase transparency, Table 1 provides representative examples of how lexical variants were consolidated (e.g., spelling/hyphenation differences, plural/singular forms, acronyms vs. full expressions). This prevented artificial fragmentation of concept nodes in the co-occurrence networks. The complete mapping table is provided in Appendix A.

3.3. Co-Word Analysis and Thematic Mapping (SciMAT)

A co word analysis was conducted on the final corpus of 337 articles to model the domain conceptual structure through recurring keyword co-occurrence patterns [58,63,64]. The underlying assumption is that keyword co-occurrence represents document content and that co-occurrence intensity approximates conceptual proximity, enabling coherent thematic groupings [58,63,64].
The procedure was implemented in SciMAT because it integrates network construction normalisation clustering and strategic visualisation within a single environment, which supports end-to-end science mapping under consistent settings [59,67]. Operationally, SciMAT supports dataset preparation co-occurrence matrix generation network normalisation theme detection and strategic diagrams based on centrality and density [59,67].
Co-occurrence links were computed at the document level, so each keyword pair contributes once per document. This prevents inflated associations that can arise from within-document repetition and preserves comparable link meaning across the corpus [58,59,67].
Before network generation, terminological harmonisation was applied to reduce lexical dispersion and strengthen semantic consistency. Spelling variants and superficial morphological differences were standardised and equivalent terms were merged when they referred to the same concept in context [59,67]. The terms to be normalised were the same as those used in VOSviewer; therefore, the complete normalisation table is provided in Appendix A.
This preprocessing reduces artificial fragmentation and concentrates evidence under consistent labels, improving cluster interpretability. For transparency, the unit of analysis relied on a unified keyword set combining author terms, indexed terms, and harmonised added terms as supported by SciMAT role settings [59,67].
The network used keywords as the unit of analysis, with authorRole, sourceRole and addedRole enabled [59,67]. The Equivalence Index was selected for normalisation to attenuate frequency driven bias and represent relative association strength between keywords [59,67].
This normalisation is more reliable than raw counts when interpreting network structure and thematic boundaries [58,59,67]. Theme detection applied the Simple Centres algorithm implemented in SciMAT supporting replication under equivalent configuration choices [67].
The SciMAT configuration is summarised as follows:
  • Unit of analysis: Words (authorRole = true, sourceRole = true, addedRole = true)
  • Network type: Co-occurrence
  • Standardisation measure: Equivalence Index
  • Clustering algorithm: Simple Centres
  • Maximum cluster size: 12
  • Minimum cluster size: 3
  • Measure of thematic continuity: Jaccard index
  • Overlap measure: Equivalence Index
In SciMAT, the minimum and maximum cluster size indicate the minimum and maximum number of keywords required for a theme to be retained. This directly regulates thematic granularity and interpretability within the strategic mapping outputs [67,82].
In this study, the minimum was set to 3 to restrict weakly supported clusters and the maximum to 12 to avoid overly broad themes that reduce semantic specificity [59,67,83]. This range is consistent with SciMAT-based studies reporting the same configuration to maintain interpretable partitions [84,85]
In SciMAT, strategic diagram centrality represents a theme interaction with other themes and its structural relevance, while density reflects internal cohesion and thematic consolidation [59,67]. Because the publication window is relatively narrow, mapping was executed as a single period to avoid sparsity-driven discontinuities and to preserve stability for the study objectives [59,67].

4. Results

In this section, several analyses are presented based on the articles obtained following the prior selection process conducted in accordance with the PRISMA 2020 protocol.
In addition to performing the co-word analysis, SciMAT was used to classify the 337 selected articles according to year of publication, number of citations, and the journals in which they were published. This information proved useful for addressing the stated research questions.

4.1. Publishing Activity (RQ1)

To address this question, all articles were grouped and ordered according to their year of publication.
The results are presented in Figure 3 and are discussed below. A growing trend in scientific output is observed over the study period, spanning 2014 to 2025. This upward trend may be linked to the parallel rise in broader interest in cryptocurrencies and NFTs, which became more pronounced from 2020 onwards. This may plausibly be attributed to the sharp increase in the value of two major cryptocurrencies (Bitcoin and Ethereum), as well as the introduction of Ethereum 2.0 in 2022 and the subsequent deployment of smart contracts and NFTs, whose peak in public interest occurred in that same year. It is reasonable to expect that, alongside the interest in and development of these technologies, cybersecurity concerns will also intensify, consolidating cybersecurity as a fundamental aspect of the future of cryptocurrencies, NFTs, and the underlying blockchain technology.

4.2. Authors, Countries and Journals (RQ2)

For the authorship analysis, the most prolific authors within the selected set of articles were identified. Table 2 presents this classification, accompanied by additional information such as each author’s h-index and details of the most-cited article by each author within this sample.
Regarding the origin of the articles, the corpus spans a total of 59 countries, of which the top six account for 61% of the publications. These are China (91), India (31), the United States (28), Canada (20), Australia (18), and South Korea (17).
Table 3 lists the leading journals by number of published articles, including those that published four or more papers. The total number of journals represented in the dataset is 185.
The cumulative number of publications across these 17 journals is 115 articles, representing 34% of the total, which highlights the substantial contribution of these outlets to advancing research on cybersecurity and cyber threats affecting cryptocurrencies and NFTs.

4.3. Connection and Evolution of Themes (RQ3)

To address the research question concerning the main topics covered in the literature and their evolutionary trajectories, three independent and complementary studies were conducted. First, VOSviewer was used to examine the structural relationships among key terms and to identify thematic clusters. Second and third, SciMAT was employed to carry out two analyses: on the one hand, the temporal evolution of the topics studied, and on the other, the thematic maturity and strategic development of the field, the latter underpinned by a keyword co-occurrence (co-word) analysis.

4.3.1. Clustering Analysis (VOSviewer)

A complementary analysis was conducted using VOSviewer, in which thematic clusters were organised on the basis of the relationships among individual topics. This can be seen in the map presented in Figure 4, where seven clusters are identified, representing seven distinct research areas on cybersecurity and cyber threats in the context of cryptocurrencies and NFTs.
Cluster 1 (red): This cluster contains terms related to cybersecurity and criminal activities, as well as technological terms such as ‘machine learning’, ‘artificial intelligence’, and ‘decentralization’. The interrelationships among the terms suggest a strong connection between emerging technologies and their exploitation to carry out illicit activities. The most relevant terms within the cluster are as follows:
  • ‘cybersecurity’: Cybersecurity is one of the objects of study in this research and is a key aspect for consolidating cryptocurrencies and NFTs as a trustworthy ecosystem.
  • ‘cybercrime’: This form of crime uses digital platforms to conduct illicit activities.
  • ‘crime’: Conventional criminal activities have adapted to new technologies, employing new means and identifying new victims.
  • ‘decentralization’: Decentralisation is a design feature of the blockchain technology underpinning cryptocurrencies and NFTs. This feature entails inherent security vulnerabilities.
  • ‘machine learning’: ML and artificial intelligence (AI) have become essential technological tools for securing cryptocurrencies and NFTs.
Cluster 2 (green): This cluster contains terms related to blockchain technology, which constitutes the infrastructure underpinning both cryptocurrencies and NFTs. The most relevant terms are: ‘blockchain’, ‘network architecture’, ‘peer to peer networks’, ‘distributed ledger’, and ‘cryptography’.
  • ‘blockchain’: Represents blockchain technology and is the largest node in the map, reflecting its foundational nature within the domain of study.
  • ‘network architecture’: Blockchain operation is enabled by a specific network architecture designed for that purpose.
  • ‘peer to peer networks’: P2P networks enable blockchain to operate without reliance on a centralised architecture.
  • ‘distributed ledger’: These databases provide essential support for blockchain technology.
  • ‘cryptography’: Cryptography is one of the cybersecurity tools most widely used by blockchain technology.
Cluster 3 (dark blue): This cluster encompasses terms related to different types of cyberattacks, many of which are characteristic of cryptocurrency environments. The most representative terms are ‘malware’, ‘cyber attacks’, ‘computational resources’, ‘cryptomining’, and ‘cryptojacking’.
  • ‘malware’: Refers to malicious software designed to infect systems, control them, and use them illicitly.
  • ‘cyber attacks’: Cyberattacks constitute a critical threat to cryptocurrency and NFT ecosystems.
  • ‘computational resources’: Computational resources are a target for attackers, as they can be exploited to mine additional cryptocurrency.
  • ‘cryptomining’: Cryptomining is a highly significant economic activity through which new cryptocurrency units are obtained.
  • ‘cryptojacking’: Cryptojacking is the most frequent cyberattack in cryptocurrency-mining environments, in which attackers hijack victims’ computing power for their own benefit by mining.
Cluster 4 (yellow): This cluster includes terms related to cryptocurrencies. The most important terms are: ‘cryptocurrency’, ‘privacy’, ‘electronic money’, ‘anonymity’, and ‘public key cryptography’.
  • ‘cryptocurrency’: Cryptocurrencies are one of the research objects of this study.
  • ‘privacy’: privacy is one of the predominant features of cryptocurrencies.
  • ‘electronic money’: Electronic money enables financial transactions to be carried out over the internet.
  • ‘anonymity’: Anonymity is another key property of cryptocurrencies and is subject to considerable debate.
  • ‘public key cryptography’: Asymmetric (public key) cryptography is used in cryptocurrency wallets.
Cluster 5 (purple): this cluster contains terms associated with NFTs. The most important terms are ‘nft’, ‘smart contracts’, ‘ecosystems’, ‘codes (symbols)’, and ‘personal computing’.
  • ‘nft’: NFTs are one of the objects of study in this research.
  • ‘smart contracts’: Smart contracts are the blockchain technology enabling the creation of NFTs and the assignment of ownership.
  • ‘ecosystems’: Refers to the NFT ecosystem, i.e., the environment in which NFTs exist, including marketplaces, ownership systems, and their issuance.
  • ‘codes (symbols)’: Refers to symbol encoding, whereby intelligible information characters are translated into sets of bits or symbols for transmission via communication channels.
  • ‘personal computing’: Refers to personal computers, typically used as a victim or as an attack vector against a third-party system.
Cluster 6 (light blue): This cluster covers topics related to the operating characteristics and vulnerabilities of the most prominent cryptocurrencies: Bitcoin and Ethereum. The main terms are: ‘bitcoin’, ‘ethereum’, ‘proof of work’, ‘consensus mechanism’, and ‘51% attack’.
  • ‘bitcoin’: The most important and best-known cryptocurrency, and the one for which the most security studies have been conducted.
  • ‘ethereum’: The second most important and best-known cryptocurrency, and a platform for decentralised applications enabled through smart contracts.
  • ‘proof of work’: A consensus protocol widely used in Bitcoin and previously in Ethereum.
  • ‘consensus mechanism’: Consensus protocols enable a distributed network to reach agreement to execute transactions or other actions.
  • ‘51% attack’: One of the best-known attacks and vulnerabilities in blockchain networks. It occurs when an attacker controls 51% of the computational power, enabling the blockchain to be rewritten and misused.
Cluster 7 (orange): This cluster encompasses terms related to security and authentication challenges in cryptocurrencies and NFTs. The most important terms are: ‘security’, ‘network security’, ‘authentication’, ‘electronic document identification’, and ‘zero knowledge proofs’.
  • ‘security’: Represents security as a broad concept encompassing all security aspects associated with cryptocurrency and NFT ecosystems.
  • ‘network security’: Refers to the security of the networks that constitute the infrastructure of cryptocurrencies and NFTs.
  • ‘authentication’: Authentication is a fundamental security feature, particularly in electronic money systems and digital ownership contexts.
  • ‘electronic document identification’: Electronic identity document systems have relevant links to both authentication and anonymisation challenges.
  • ‘zero knowledge proofs’: A cryptographic approach that allows a statement to be validated without revealing additional information beyond the statement itself.

4.3.2. Evolution of the Research Themes (SciMAT)

Following the thematic area analysis conducted with VOSviewer, the broad overview it provides was contrasted with an analysis of the temporal evolution of the themes examined in research on cybersecurity and cyber threats in cryptocurrencies and NFTs.
To this end, SciMAT was used to perform the co-word analysis described in Section 3.3. Co-Word Analysis and thematic mapping (SciMAT), dividing the corpus into three time periods. The first corresponds to the pre-boom phase of blockchain technology and spans 2014 to 2020. The second covers 2021 to 2023, coinciding with the adoption and heightened media attention surrounding cryptocurrencies and NFTs. Finally, the third period runs from 2024 to October 2025, when this study was conducted.
This analysis makes it possible to identify the topics addressed and the interrelationships among them. As an output, three strategic diagrams are produced, one for each time period. In each diagram, themes are positioned within a matrix defined by two axes: density and centrality. Density reflects the degree of internal development of each theme, whilst centrality indicates its relevance within the field of study.
An initial observation of the strategic diagram for the 2014–2020 period (Figure 5A) reveals the presence of basic themes, which may reflect the relatively immature state of research on the object of study during that stage. In this diagram, the main thematic foci in relation to cybersecurity are anonymity, cyberattacks and crime, and the economic dimension. Additional themes are also present, such as cryptography and distributed consensus, which are more technical and specialised aspects.
In comparison, the second period (Figure 5B) is far more diverse, with a marked increase in both the number and specificity of the themes represented in the strategic diagram. Research is primarily centred on cryptocurrencies and the security of their ecosystems, with smart contracts emerging as a cross-cutting theme, alongside topics such as authentication and financial fraud detection. Overall, the themes identified suggest that research during this period is closely associated with emerging challenges arising from the adoption of blockchain-based cryptocurrency and NFT ecosystems, particularly within the economic domain.
The third period (Figure 5C) reflects the most recent state of research and retains the more concrete and diversified thematic structure observed in the second period, again indicating a higher volume of scholarly output with regard to the first period. Cybersecurity and vulnerabilities emerge as highly central themes, alongside topics related to machine learning, illicit mining, and digital identity and access control. This may coincide with the maturation of ML technologies, both in terms of strengthening the security of the ecosystems examined in this study and of increasing their susceptibility to exploitation.
Overall, it can be observed that as the temporal axis shifts towards more recent years, both the number and the specificity of the topics investigated increase. This conclusion is reinforced by the temporal distribution of the selected articles (Figure 3), which shows that the first period contains a comparatively smaller number of studies thereby substantially reducing the sample space within which thematic divergence could be observed.

4.3.3. Strategic Diagram (SciMAT)

In the previous section, we examined the evolution of research on cybersecurity and cyber threats in cryptocurrencies and NFTs. This section conducts the co-word analysis again, but this time with the aim of assessing the maturity level of the themes as of the time of this study. To this end, a single corpus of articles was considered, as most of the selected studies were published between 2020 and 2025. This results in a diagram featuring concrete and specialised themes, which is better suited to identifying individual research streams (Figure 6).
This section examines the structure of the strategic diagram in greater depth, which consists of a matrix defined by the density and centrality axes described in Section 4.3.2. Evolution of the research themes (SciMAT).
Accordingly, the matrix is divided into four quadrants according to their position on these axes, and the themes contained in each quadrant share characteristic features:
  • Upper-right quadrant: Motor themes, with high centrality and high density.
  • Upper-left quadrant: Highly developed themes (high density) but with low centrality. Although relevant, they are less connected to the specific research area considered.
  • Lower-right quadrant: Transversal and basic themes, with low density and high centrality. They are priority topics that require further development.
  • Lower-left quadrant: Emerging or declining themes, characterised by low density and low centrality. This quadrant foreshadows the future—or the abandonment—of research lines in the field.
The quadrants are interpreted below, following the order in which they have been listed:
  • Upper-right quadrant: motor themes (high density and centrality)
    Key terms: ‘blockchain’, ‘emerging technologies’, ‘long short-term memory’, ‘cybersecurity’, and ‘illegal mining’.
    Interpretation: These themes occupy the upper-right quadrant because they combine high centrality (i.e., they articulate strong links with multiple other themes) with high density (i.e., they form internally cohesive and well-developed research sub-networks). In substantive terms, this positioning is consistent with their role as the main “organising axes” of the field: “blockchain” provides the enabling infrastructure underpinning both cryptocurrencies and NFTs and therefore co-occurs with a broad range of security, architectural, and threat-related topics. “cybersecurity” functions as the umbrella concern that connects disparate lines of work (attacks, vulnerabilities, protection mechanisms, identity, and trust). “emerging technologies” captures the expansion of the threat surface and the need to assess novel architectures and applications that continuously reshape the ecosystem. At the same time, the presence of “long short-term memory” as a motor theme reflects the consolidation of AI-driven approaches—particularly neural models—within detection and prevention tasks, forming a coherent methodological stream that also bridges to fraud, anomaly detection, and behavioural analysis. Finally, illegal mining appears as a mature and highly developed topic because it represents a concrete, recurrent threat vector that has generated a substantial body of specialised work while remaining sufficiently connected to the broader security discourse to act as a driver of research priorities.
  • Upper-left quadrant: highly developed themes (high density, low centrality)
    Key terms: ‘geometry’, ‘distributed ledger’, and ‘licence’.
    Interpretation: These themes in the upper-left quadrant are considered highly developed because, within the SciMAT framework, they combine high density (strong internal cohesion and well-defined sub-networks of co-occurring keywords) with low centrality (limited connectivity and a reduced structuring influence on the dominant thematic network). This configuration represents the classical signature of mature yet comparatively isolated research streams in strategic co-word mapping. “geometry” exhibits strong intra-cluster links around hardware security and side-channel attacks, as well as around intellectual property protection mechanisms, such as signature and watermarking schemes. “distributed ledger” likewise shows high interconnectivity, with a dense sub-cluster and additional links to applied contexts such as NFT-enabled healthcare traceability and privacy-preserving consensus designs, indicating a technically consolidated line that remained peripheral to the motor themes. “licence” displays a coherent internal core that suggests a specialised and well-articulated discourse on authorisation and secure trading, yet one that was less integrated with the broader cybersecurity keyword backbone.
  • Lower-right quadrant: transversal and fundamental themes (low density, high centrality)
    Key terms: ‘classification (of information)’, ‘authentication’ and ‘peer-to-peer networks’.
    Interpretation: These themes in the lower-right quadrant are interpreted as transversal or basic because they combine high centrality (strong connections to multiple themes) with low density (a comparatively less cohesive internal structure). The latter suggests that the literature addresses them primarily as enabling functions rather than as fully consolidated specialised subfields. Substantively, these themes operate as cross-cutting prerequisites for securing cryptocurrency and NFT ecosystems. “classification (of information)” is closely linked to data processing and analytical pipelines that support multiple security tasks. “authentication” is described as a fundamental security feature in electronic money systems and in digital ownership contexts, which naturally connects it to identity, access control, privacy, and trust. “peer-to-peer networks” reflect the underlying distributed communication substrate on which blockchain and related mechanisms relies, rendering it highly connected to the broader research agenda, even if the associated sub-network remains less mature and more diffuse within this corpus.
  • Lower-left quadrant: emerging or declining themes (low density and centrality)
    Key terms: ‘exchange protocols’, ‘real-world’, ‘intrusion detection’ and ‘vulnerabilities’.
    Interpretation: These themes are positioned in the lower-left quadrant and are characterised as emerging or declining because they exhibited both low centrality (limited connectivity with the dominant thematic network) and low density (weak internal cohesion and comparatively underdeveloped sub-networks of co-occurring keywords). This interpretation was consistent with the strategic mapping logic underpinning co-word analysis and SciMAT. Such a pattern was aligned with themes that represented a relatively specialised or fragmented research line that had not yet consolidated around a stable set of shared concepts. “exchange protocols” reflected a narrow protocol-level concern within exchange ecosystems. “vulnerabilities” functioned as a broad label that, in this corpus, aggregated heterogeneous issues without forming a cohesive cluster. “real-world” captured application- or deployment-oriented challenges that remained weakly integrated into the main organising axes of the field. “intrusion detection” encompassed techniques for identifying anomalous behaviours that extended beyond purely technical aspects, thereby remaining peripheral to central themes such as the use of AI in “long short-term memory”.

4.3.4. Comparative Synthesis of VOSviewer and SciMAT Outputs

The VOSviewer and SciMAT outputs are complementary because they operationalise keyword relations in different ways, even though they are derived from the same screened corpus and the same normalised keyword set. VOSviewer provides an exploratory representation of the conceptual structure through a proximity-based network layout and an algorithmic partition into a small number of clusters that capture broad thematic regions (Figure 4). By contrast, SciMAT constructs themes via co-word clustering under an equivalence-index normalisation and then positions those themes in strategic space (centrality–density), enabling interpretation of maturity and field-level relevance as well as longitudinal change (Figure 5A–C and Figure 6).
These methodological differences explain the observed variation in granularity. VOSviewer’s seven clusters aggregate multiple subtopics into larger “concept regions”, whereas SciMAT typically yields a more fine-grained thematic landscape because its clustering is subsequently interpreted through centrality/density and (in the evolution analysis) across time-slices. In practical terms, VOSviewer is informative for identifying the main neighbourhoods of co-occurring concepts, while SciMAT is informative for determining whether a topic is (i) a motor theme, (ii) developed but peripheral, (iii) basic/transversal, or (iv) emerging/declining in the field’s strategic structure.
Importantly, the two tools converge on the same core knowledge backbone. For example, the VOSviewer cluster organised around “blockchain”, network architecture, peer-to-peer networks, and cryptography corresponds to the high-centrality “blockchain” motor theme in SciMAT, indicating that infrastructure-level concepts remain structurally central across both mappings. Likewise, VOSviewer’s cluster combining cybersecurity/cybercrime with machine learning and AI aligns with SciMAT’s motor themes “cybersecurity” and “long short-term memory”, signalling that AI-enabled detection and security analytics have consolidated as a central methodological stream rather than remaining a peripheral technique.
The tools also provide consistent signals for concrete threat vectors. VOSviewer’s attack-focused cluster including malware, cryptomining, and cryptojacking is mirrored by SciMAT’s “illegal mining” motor theme and its strong connectivity to broader cybersecurity discourse, indicating that resource-hijacking threats represent a mature and recurrent line of investigation. In addition, VOSviewer’s NFT/smart-contract cluster is consistent with SciMAT’s identification of smart-contract-related themes as increasingly cross-cutting in the later periods and as part of the more specialised thematic structure observed after 2021.
At the same time, SciMAT surfaces several specialised but less structurally integrated streams (e.g., themes such as “geometry” or “licence” in the high-density/low-centrality quadrant) that are not necessarily visible as independent regions in the VOSviewer map because they can be absorbed into larger proximity communities or remain below a salience threshold when the representation is constrained to a small number of clusters. This divergence is analytically meaningful: it suggests the presence of technically mature niche threads that are developed internally but not yet strongly connected to the field’s dominant cybersecurity backbone.
Overall, reading the outputs jointly supports a robust interpretation: VOSviewer clarifies the field’s broad conceptual neighbourhoods, while SciMAT identifies (and time-tracks) which of these neighbourhoods function as motor themes, which remain transversal foundations (e.g., authentication/classification), and which are emerging or peripheral. This joint reading reduces the risk of over-interpreting any single clustering scheme and strengthens the validity of the thematic conclusions reported for RQ3.

4.4. Emerging Themes (RQ4)

To identify emerging themes, an in-depth analysis was conducted—using the SciMAT tool—of the cluster associated with the emerging theme ‘intrusion detection’. This cluster is located in the lower-left corner of the strategic diagram shown in Figure 6 and comprises the following nodes:
  • ‘intrusion detection’: This term refers to the detection of intrusions, that is, the identification of anomalous elements within a given context, whether involving the detection of malicious actors or illicit activities.
  • ‘differential privacy’: Differential privacy enables the analysis of a dataset without compromising the privacy of the individuals within it.
  • ‘data mining’: Data mining enables the analysis and processing of large volumes of data through specialised tools in order to uncover patterns and other relevant information.
  • ‘decentralized finance’: DeFi uses blockchain networks to enable an economic system that does not depend on central authorities such as banks.
To strengthen the argument that this topic exhibits an emerging pattern, the temporal distribution of the articles related to it within the selected corpus was analysed. This allowed it to be determined whether research interest in the topic was increasing (i.e., emerging) or declining.
Figure 7 presents the temporal distribution of articles that included the keyword “intrusion detection”. Two relevant factors were observed: first, the very small number of articles associated with this keyword (four out of 337); second, the concentration of these articles in the most recent two years. This pattern could be indicative of an upward trajectory in the academic output on this topic. To complement this perspective, the distribution of this keyword across articles indexed in Scopus was analysed within the context of cryptocurrencies and NFTs, as dedicated tools were provided there to support this type of analysis. The query that was used was as follows: (TS = ((“cryptocurrencies” OR “nft” OR “non fungible tokens”) AND “intrusion detection”)) AND DT = (Article) AND DT = (English).
The temporal distribution of the articles retrieved through the Scopus query mirrored that of the selected corpus (Figure 8), particularly in terms of the concentration of publications in the most recent period (2023–2025) and the upward trend in output.
Overall, the positioning of the theme in the strategic diagram and the temporal distribution of the related academic production allowed the emerging nature of this research topic to be determined.

4.5. Cluster Identification (RQ5)

In this section, each node in the strategic diagram in Figure 6 is examined. Each node corresponds to a concept; the links between nodes indicate term co-occurrences within the analysed articles, and the size of each node is related to the number of documents in which that concept appears.

4.5.1. Blockchain

The central node of this cluster is “blockchain”, as it constitutes its thematic axis. From it, connections extend to nodes associated with a high number of documents, such as “security”, “cryptocurrency”, “network architecture”, and “bitcoin”. The terms comprising the cluster—shown in Figure 9A—relate primarily to technical domains linked to blockchain technology, indicating its use cases and key characteristics.
The nodes exhibit a high degree of interconnectivity, with the links between “cryptocurrency” and “bitcoin” standing out, as well as the connections between “NFT” and “digital assets” and “smart contracts”.
As the enabling infrastructure for cryptocurrency systems and NFT ecosystems, blockchain has seen increased uptake in domestic applications, healthcare, and intelligent transport [22]. However, its exponential adoption and relative immaturity in security terms make it necessary to consider potential threats [86].
Blockchain technology operates on fundamental consensus protocols, such as Proof-of-Work (PoW) and Proof-of-Stake (PoS), designed for distributed networks and inherently susceptible to critical vulnerabilities such as 51% attacks and double spending [87]. Indeed, analyses of computational capacity in networks such as Bitcoin and Crypto Ethereum indicate an increasing concentration of hash-rate power among a very small set of miners, which poses a genuine risk to current blockchains [88]. Selfish Mining-based Denial-of-Service (SDoS) attack strategies enable an adversary with 15% of the mining power to mount a 51% attack, constituting a serious threat to the Bitcoin ecosystem [89].
The NFT ecosystem faces security issues ranging from asset design to their handling within decentralised marketplaces, requiring greater attention and proactive measures [16,39]. Analyses of the new attack surface and the security of NFTs have shown that mounting a specific attack could have a trivial—or even zero—cost [30]. Other studies have examined the inadequate maintenance of the Smart Contract Weakness Enumeration (SWE) list, updating it with 273 vulnerability descriptions and proposing mechanisms for its continuous and iterative maintenance [54].
Analyses of sleepminting attacks have led to the proposal of a prevention system to reduce the number of attacks through the analysis of transactions and their metadata [37]. In parallel, a watermarking technique for smart contracts based on code obfuscation has been proposed, aimed at protecting copyright and reducing the proliferation of vulnerabilities without a significant degradation in performance [90].

4.5.2. Emerging Technologies

The terms comprising the cluster—shown in Figure 9B—address topics linked to emerging technologies, which require new security approaches and raise questions regarding their potential societal impact.
The nodes exhibit a high degree of interconnectivity, with the link between “data integrity” and “confidentiality” standing out, as well as the connections between “digitalization” and “economic analysis” and “human”.
Emerging technologies are accompanied by a new security context, in which their immaturity creates opportunities for malicious actors who are quick to examine this new landscape in search of previously unseen vulnerabilities [91]. Analyses indicate that, although cryptocurrency-based systems offer numerous advantages—such as the removal of intermediaries, low transaction costs, and a globalised monetary system—they also entail risks including vulnerability to cyberattacks, inaccessibility without an internet connection, and high price volatility [8,17,92]. The profitability of double-spending attacks has been investigated in numerous studies [93,94].
In parallel, research has been undertaken to address vulnerabilities within this emerging ecosystem. A systematic analysis was conducted of a Blockchain-enabled IoT Access Control (BIAC) architecture aimed at optimising access-control management in IoT environments through the use of Zero-Knowledge Proofs (ZKPs), with the capability to conceal permissions and preserve the requester’s anonymity [95]. Likewise, a blockchain-based multi-factor authentication system was proposed to implement a distributed authentication mechanism supported by ZKPs [96].
ZeroCross was proposed as a privacy-preserving sidechain-based scheme, designed to enable Monero cross-chain exchange and to guarantee unlinkability, transaction fairness, and confidentiality [97]. For Payment Channel Networks (PCNs), an anonymous multi-hop scheme based on onion routing was developed to address issues stemming from idealised routing assumptions and the privacy limitations of existing PCNs, achieving relationship anonymity and resistance to wormhole attacks, as well as improved computational efficiency relative to comparable alternatives [98].

4.5.3. Filesystem

The terms comprising the cluster—shown in Figure 10A—are technological in nature and refer to systems that make use of a file system.
The nodes exhibit a high degree of interconnectivity. Among the most significant links are those between “trust” and “ipfs”, and between “performance” and “trees (mathematics)”.
Smart contract security represents a critical challenge on platforms such as Ethereum, requiring systematic analysis and the continual updating of taxonomies of known vulnerabilities [30,54].
Studies have proposed an efficient approach for securing smart contracts through a hybrid security analysis that combines symbolic execution and pattern matching, achieving vulnerability detection with a low false-positive rate and surpassing the efficiency of other existing research approaches [99]. In parallel, the application of machine learning (ML)-based forensic detection techniques has been shown to be effective for assessing the likelihood of different types of vulnerabilities in Ethereum-based contracts [100].
Beyond detection, automated vulnerability repair guided by ML and rule-based methods has been presented as an effective solution for protecting the underlying business logic of smart contracts [101].
NFT technology has moved beyond speculative use to become a fundamental component in the development of secure, decentralised solutions for identity management and authentication in complex environments, including the metaverse and healthcare [14,15,96]. Moreover, in the context of the Industrial Internet, a distributed active identity-resolution system based on InterPlanetary File System (IPFS) and NFTs has been proposed to address single points of failure and Distributed Denial-of-Service (DDoS) attack risks arising from the tree-based structure of the Domain Name Server (DNS) architecture, providing secure and reliable identity-resolution services [102].

4.5.4. Long Short-Term Memory

The terms comprising the cluster—shown in Figure 10B—are heterogeneous in nature and primarily relate to economic issues and cyberattacks.
The nodes exhibit a high degree of interconnectivity, with the relationship between “fraud detection” and “banking” standing out.
The contemporary cybercrime landscape has been profoundly shaped by the emergence and proliferation of Bitcoin and other cryptocurrencies, which have been identified as prominent threat vectors that facilitate illicit operations on a global scale [103,104]. Cryptocurrency, such as Bitcoin, Ethereum, and, more recently, Monero, has become the currency of choice for many drug dealers and extortionists. The criminal activities extend to tax evasion, money laundering, Ponzi schemes, and the theft of cryptocurrencies to kidnapping for ransom. As the demand for cryptocurrencies increases, it provides opportunities for criminals to hide behind the presumed privacy and anonymity. Identifying these cryptocurrency-related crimes have posed challenges for law enforcement due to the cross-border nature of transactions, the use of evasion technology to mask the identity of users, and inconsistent regulations. To address the role of cryptocurrencies in criminal activities, the study focused on four research questions: (1) What role do cryptocurrencies such as bitcoin (BTC) play in criminal activities? (2) What factors facilitate cryptocurrency-related criminal activities? (3) What role do politics play in regulating cryptocurrencies? and (4) What are the challenges they pose for regulators and law enforcement? To answer the questions, the study utilised a systematic content review of the news reports, court cases, scholarly articles, online search engines, and commentaries relevant to regulations and reforms. The findings help to understand the current climate of virtual currencies, their use in criminal activities, and the complexities involved in regulating cryptocurrencies [104]. In this context, the strong positive correlation observed between cryptocurrency fraud offences, digital development, and levels of adoption underscores the urgency of understanding which features of cryptocurrencies may entail heightened criminal risk [105]. Research into these offences has benefited from architectures that integrate AI and blockchain for investigation and protection, demonstrating that advanced classifiers such as random forests can achieve high levels of accuracy in fraud detection [106]. Crypto-Aegis, a machine-learning (ML)-based framework, has been proposed as an alternative for detecting and identifying cryptojacking attacks using network traffic alone [107].
In addition, data-driven systems have been developed to detect and analyse specific scams, such as the “Bitcoin Generator Scam”, successfully identifying fraudulent addresses proactively before any transaction is completed [108]. Moreover, at the network layer of permissionless blockchains, network design entails trade-offs between fundamental requirements such as performance, anonymity, and resistance to Denial-of-Service (DoS) attacks, necessitating the development of models that formalise these complex interactions [109].
With respect to DoS attacks, a technique has been explored to deter financially motivated attackers from launching application-layer DDoS attacks by forcing them to mine cryptocurrency in order to carry out the attack, thereby increasing attack costs and yielding negative economic returns for attackers [110]. In addition, a new DoS attack modality that can be executed within Bitcoin’s memory pools (mempools) has been investigated, and prioritisation mechanisms based on fees, transaction age, and transaction size have been proposed to mitigate this attack vector [111].

4.5.5. Illegal Mining

The terms comprising the cluster—shown in Figure 11A—are technological in nature and relate primarily to distributed systems, ML, and malicious behaviour.
The nodes exhibit a high degree of interconnectivity, with the link between “peer-to-peer computing” and “distributed computer systems” standing out, as well as the triad formed by “cryptojacking” in connection with “static analysis” and “natural languages”.
Block mining is an indispensable process within cryptocurrency ecosystems, as it validates new transactions and enables the system to function, offering incentives—frequently in the form of cryptocurrencies—to volunteer participants in exchange for their computational power [112]. These incentives make such systems attractive targets for malicious actors, as the attacks can yield considerable profitability [93,94,113]. In this context, network integrity may be compromised by specific weaknesses in the consensus protocols of these decentralised networks, such as network-partition attacks that affect both PoW and PoS blockchains [114].
Attack profitability is maximised through combined attack models and highly sophisticated mining strategies. Combined attacks such as SelfHolding—which combines selfish mining and the block-withholding attack in Bitcoin—achieve higher expected revenue than the classic selfish-mining attack, even when the attacker’s computational power is relatively small [115]. Similarly, optimal attack strategies such as SDoS can mount a 51% attack with only 15% of the mining power [89].
Detecting these malicious mining strategies requires continuous behavioural analysis of miners. A simple heuristic was presented to detect the presence of selfish-mining attacks and their variants [116]. Supporting this line of work, statistical tests capable of identifying strategic mining behaviours such as selfish mining have been proposed, enabling the detection of anomalous miners and coordinated mining cartels in Monacoin and Bitcoin Cash [117].
Cryptojacking has become a dominant form of resource exploitation, driving the development of detection techniques based on deep learning and advanced predictive models [107,118]. The use of deep-learning techniques to process assembly code was proposed for the detection of evasive cryptojacking, achieving low false-positive and false-negative rates [119]. In a similar vein, a holistic and intelligent system for detecting cryptojacking malware was introduced, based on predictive models employing convolutional neural networks (CNNs), achieving high efficiency and 99% accuracy [47]. The literature also highlights that effective malware detection is crucial, given that many cryptocurrency systems lack adequate algorithms for this purpose [120].

4.5.6. Cybersecurity

The terms comprising the cluster—shown in Figure 11B—are heterogeneous in nature, and the themes they represent are linked to the field of cybersecurity, whether in the form of cyberattacks or detection and protection tools.
The nodes exhibit a high degree of interconnectivity, with the link between “ransomware” and “blockchain forensics” standing out, as well as the connections between “personal computing” and “network traffic analysis” and “attack vector”.
Cybersecurity is an essential consideration in the conceptualisation of any technological ecosystem, and it is especially relevant in digital-asset ecosystems, where a cyberattack can have significant consequences for price volatility and trading volume [10]. In this regard, ransomware has been identified as a dominant form of organised cybercrime, in which criminal groups adopt modern, business-like revenue models; however, blockchain transparency enables effective forensics to trace and monitor these organisations [45,121]. Trends in ransomware attacks have been analysed and detection and prevention systems proposed to mitigate them [122]. Similarly, a machine learning-based system was proposed to analyse and classify Bitcoin payment transactions in order to identify malicious transactions associated with ransomware attacks, achieving models with 99.08% accuracy [123].
The application of AI and ML is highly beneficial for securing complex, emerging technological ecosystems [124]. The literature suggests that AI supports the financial industry both in process optimisation and in fraud detection and cryptocurrency price prediction, whose volatility is exacerbated by cyberattacks [125]. In the domain of malicious-user identification, combining ML with centrality measures provides a robust system for identifying suspicious users based on their reputation score [126]. Moreover, de-anonymising the Bitcoin blockchain has been successfully addressed using supervised ML to predict the type of unidentified entities, with potential applications for cryptocurrency compliance and regulation in society [127].

4.5.7. Geometry

The terms comprising the cluster—shown in Figure 12A—are technological in nature and relate primarily to cryptography, pointing to security uses and schemes that rely on it.
The nodes exhibit a high degree of interconnectivity. In particular, a sub-cluster is formed by the strong relationships among the terms “side channel attack”, “pin”, “hardware”, and “hardware security”. Another significant connection links “signature scheme” with “watermarking”.
Protecting ownership is one of the fundamental aspects of security for cryptocurrencies and digital assets in virtual ecosystems, owing to their online accessibility and the potential for uncontrolled redistribution [128].
Zero-watermarking schemes have been proposed to protect NFT images, resulting in increased resistance to both geometric and non-geometric attacks [129]. Watermarking techniques are also used to protect smart contracts, helping to prevent the proliferation of vulnerabilities while supporting security in distributed environments [90].
Ensuring that cryptocurrency holdings remain under the control of their legitimate owner is, moreover, a key focus of numerous studies. Side-channel attacks enable the extraction of critical cryptographic components from cryptocurrency hardware wallets, potentially remaining undetected by the victim [130,131], while design flaws in hierarchical deterministic wallets enable privilege-escalation attacks [132]. Privacy-preserving signature schemes have been developed to improve the resilience of deterministic-wallet mechanisms and stealth addresses for protecting cryptocurrency exchanges [133].

4.5.8. Distributed Ledger

The terms comprising the cluster—shown in Figure 12B—are technological and heterogeneous in nature, with smaller groups associated with use cases of distributed ledger technology and its characteristics.
The nodes exhibit a high degree of interconnectivity, with a sub-cluster standing out based on the strong relationships among the terms “eclipse attack”, “markov processes”, and “dependability modelling”, and to a lesser extent with “supply chains”.
Decentralised technologies—including distributed databases—can be strengthened through the application of blockchain technology, enabling a transformation in data management and storage models in sectors such as finance and healthcare [6]. The application of NFTs in a verification and management system for second-hand medical equipment has yielded excellent results [5]. The resilience and trustworthiness of the Bitcoin system against eclipse attacks—an inherent risk in distributed systems—has been analysed in numerous studies [134,135,136]. In addition, a specific solution for ownership and supply-chain management of 3D CAD models was described using persistent NFTs on distributed ledgers, with the aim of combating counterfeiting [128]. In another study, an efficient, privacy-preserving consensus protocol—Delegated Proof of Secret Sharing (DPoSS)—was proposed, inspired by distributed secure computation and implemented through verifiable secret sharing [137].

4.5.9. Licence

The terms comprising the cluster—shown in Figure 13A—are heterogeneous in nature, referring to the threats and tools for the cybersecurity of licences, which in this case represent the authority to perform activities, such as managing and selling crypto assets.
The nodes exhibit slight interconnectivity, with a strong link between ‘risk assessment’ and ‘behavioral research’, as well as notable connections linking ‘lattice’ to ‘quantum cryptography’ and ‘secure transactions’.
Cryptocurrencies operate in blockchain systems for mining and trading, characterised by P2P consensus systems and a decentralised architecture. These systems are subject to specific vulnerabilities and require special considerations that extend beyond purely technical aspects, impacting users economically as well [91,138,139]. Research on the “jumping mining attack” has reported the viability of such malicious behaviour in mining systems, resulting in greater profits than those earned by honest miners [140]. Characterisation studies of miners have indicated a growing concentration of hash rate among a very small group of miners, posing a real risk of 51% attacks [88]. The economic impact of these attacks should be considered, as a successful 51% attack can result in total control over the mining chain, allowing the attacker to double-spend, restrict transactions, and effectively control the price of a cryptocurrency [141].
In parallel, the need to protect these high-priority trading environments has driven the development and implementation of modern cryptographic techniques resistant to the new threat posed by quantum attacks [142]. A quantum key distribution-based exchange protocol was proposed to enable secure digital asset exchange between users of heterogeneous decentralised networks [143]. Additionally, the application of two new confidential transaction protocols supported by homomorphic ZKP was studied, designed to offer resistance against quantum attacks [144].

4.5.10. Classification (of Information)

The terms comprising the cluster—shown in Figure 13B—are heterogeneous in nature and refer to the uses of information classification as a tool.
The nodes exhibit moderate interconnectivity, with the link between “criminal activities” and “financial fraud” standing out, as well as the connections linking “machine learning” to “deep learning” and “anomaly detection”.
The literature has examined the effectiveness of classification models for detecting cryptojacking on websites, finding that relatively simple models, such as Random Forest and Logistic Regression, can achieve success rates equal to or higher than those of more advanced algorithms [145]. Efforts to combat this attack have also resulted in the development of holistic and intelligent cryptojacking-malware detection systems that use predictive models, achieving high accuracy [47]. In addition, solutions have been proposed that leverage lightweight microarchitectural changes to trace instructions common to hashing algorithms, enabling an end-to-end detection solution with negligible performance overhead [146].
With respect to other forms of illicit activity, transaction forensics for stolen funds is essential. An analysis of hacking subnetworks has indicated that the key distinction between criminal groups lies in the speed at which funds exit via terminal nodes within the subnetworks, prioritising temporal features over static ones when classifying hacks [147]. Moreover, systems based on graph hyperedge classification techniques have been shown to detect illicit Bitcoin operations with high accuracy and to be robust against adversarial attacks [148]. Furthermore, the use of classification algorithms in Bitcoin and Ethereum for fraud detection has yielded promising results [149,150].

4.5.11. Authentication

The terms comprising the cluster—shown in Figure 14A—are predominantly technological in nature, relating to authentication applications across different systems and associated characteristics.
The nodes exhibit very limited interconnectivity. The connection between “offline” and “zero-knowledge proof” is particularly notable. Another significant linkage connects “privacy” with “cryptocurrency exchange”.
Authentication is a fundamental feature in cryptocurrency and NFT ecosystems, as it is required to ensure the secure management of these digital assets, which in turn requires adapting authentication mechanisms to the decentralised context of blockchain [102]. The integration of cryptographic paradigms such as ZKPs into BIAC and multi-factor authentication (MFA) solutions as privacy mechanisms has yielded promising results [95,96,151]. Malleability-resistant signature schemes have also been proposed to improve the security of cryptocurrency transactions [152].
The application of NFTs to digital identity authentication extends to complex environments such as the metaverse. In this context, a framework using Elliptic Curve Cryptography (ECC) was proposed and rigorously tested with AVISPA, demonstrating resilience against replay and man-in-the-middle (MITM) attacks [15]. Similarly, a secure and lightweight authentication scheme for resource-constrained LoRaWAN nodes links nodes to on-chain NFTs for tracking items in supply chains [153]. This development aligns with the need for robust asset-authentication mechanisms for cyber–physical systems (CPSs), where the DSCoT blueprint uses extended NFTs and smart contracts to generate access codes, achieving promising results of up to 96.69% across cost and efficiency metrics [154].
Finally, the use of blockchain technology enables the processing of private data without compromising the identity of associated users—referred to as differential privacy—which is essential in medical applications and in economic transactions [6,155].

4.5.12. Peer to Peer Networks

The terms comprising the cluster—shown in Figure 14B—are technological and economic in nature.
The nodes exhibit moderate interconnectivity. The link between “financial transactions” and “heuristics” is particularly notable, and the connection between “third parties” and “deanonymization” is also significant.
P2P networks provide the decentralised infrastructure for blockchain, and their decentralised architecture is studied by security professionals on both sides of the attacker–defender spectrum. The obfuscated nature of connections in the Bitcoin P2P network and the difficulty of analysing them may entail more disadvantages than advantages [156]. The Bitcoin P2P protocol lacks a robust cybersecurity model and is vulnerable to several network-layer attacks [157].
In parallel, studies have sought to develop cryptocurrency exchange platforms without the involvement of third parties typical of centralised systems, proposing protocols that provide security while supporting multiple currencies [158]. Concerns about user anonymity in these networks in the face of de-anonymisation attacks have motivated the development of network-level policies such as Dandelion [159], which was subsequently improved through Dandelion++ in later years [160]. However, the anonymity sought by users also enables illicit activities, such as fraudulent financial transactions, which has prompted proposals for intervention by law-enforcement or security agencies when necessary, as well as the development of tools capable of revoking anonymity [46].

4.5.13. Vulnerabilities

The terms comprising the cluster—shown in Figure 15A—are heterogeneous in nature. The nodes exhibit no interconnectivity.
The novelty of blockchain poses challenges for its protection, as the software on which it relies—among other factors—often does not yet reach the level of maturity required to guarantee the security of operations [38]. Experts have proposed incorporating a non-repudiation feature into the “NaCl” networking and cryptography library used in blockchain applications, through the integration of a signature block [161]. In addition, a machine learning-based tool capable of repairing smart contracts at the source-code level has been developed, outperforming earlier tools [101].

4.5.14. Real-World

The terms comprising the cluster—shown in Figure 15B—are heterogeneous in nature.
The nodes exhibit very limited interconnectivity. The linkage between “scalability” and “channel network” is particularly notable. The other existing link connects the nodes “proof of work” and “computational resources”.
The applicability of cryptocurrencies and NFTs in real-world settings entails new cybersecurity considerations from both technical and non-technical perspectives [138]. Cryptocurrency scalability is a crucial factor for practical usability, and research has therefore been conducted to optimise the performance and reliability of PCNs [162]. The decentralised-asset ecosystem—particularly NFTs—is susceptible to novel attacks that exploit protocol design flaws. The sleepminting phenomenon, understood as the transfer of NFTs without consent, has been analysed, and a preventive system has been proposed which, through transaction analysis, can detect and block up to 87% of such attacks [37].
With respect to cryptocurrency exchanges, research has examined ways of making them resilient to cyberattacks, including collision, Sybil, and front-running attacks [163]. Beyond technological aspects, experts have highlighted the need to develop an international legal framework that addresses the risks associated with such exchanges [41].

4.5.15. Intrusion Detection

The terms comprising the cluster—shown in Figure 16—are heterogeneous in nature and refer to the concepts of DeFi and data mining. The nodes exhibit very limited interconnectivity, with the only link being that between “decentralized finance” and “differential privacy”.
The anonymity associated with blockchain networks generally complicates any activity aimed at monitoring them, which in turn affects the detection of malicious acts [44]. Advances in forensic analysis make it possible to examine malware-like attacks based on the traces they leave in network traffic [164]. Analysing transactions on Uniswap enables the identification of patterns associated with different attacks, as well as bot detection, highlighting the need to employ detection mechanisms in DeFi systems [165]. Blockchain data mining has been proposed as a promising approach for anomaly detection [166].

5. Discussion

The publication growth observed between 2014 and 2025 (RQ1) reflects a field that is responding to the accelerated mainstreaming of cryptocurrencies and NFTs, not merely increasing output in parallel with general scientific trends. As these ecosystems expanded and diversified, so did their attack surfaces, particularly through smart contracts, decentralised applications, and the operational complexity of blockchain-based infrastructures. This has reinforced cybersecurity as a necessary layer of research rather than an optional technical add-on, especially as real-world exploitation has evolved alongside market adoption and platform development.
This temporal expansion is also consistent with evidence showing that cybercrime and illicit uses of crypto infrastructures have increased in sophistication, thereby pushing academic research to address security not only as a technical problem but also as an adversarial and economically motivated phenomenon. In this context, the emergence of research waves can be interpreted as connected to periods of innovation and vulnerability discovery, where system novelty often outpaces standardised protection practices, encouraging rapid academic consolidation around security challenges [45,167].
Regarding geographical distribution (RQ2), the corpus spans 59 countries, yet research output is strongly concentrated: the top six countries account for 61% of publications—China (91), India (31), United States (28), Canada (20), Australia (18), and South Korea (17). This pattern indicates that knowledge production in cryptocurrency/NFT cybersecurity is not evenly distributed, but instead anchored in a limited set of national research systems with high capacity in computer science and security engineering [168].
Several drivers may plausibly contribute to this concentration. First, countries with well-funded cybersecurity and computer science ecosystems are more likely to sustain specialised research on adversarial threats in decentralised infrastructures. Second, the topic itself is closely tied to access to technical expertise, compute resources, and cross-disciplinary capabilities (e.g., cryptography, networking, machine learning, and software engineering), which are unevenly distributed across regions. Third, regional innovation ecosystems—such as active blockchain/fintech sectors, exchange infrastructure, and regulatory experimentation—may indirectly shape research salience by increasing exposure to relevant threat models and applied security problems.
At the same time, the observed disparities should be interpreted cautiously because they can be amplified by methodological choices. In particular, the study restricts retrieval to English-language journal articles indexed in Web of Science and Scopus. This design improves comparability for bibliometric mapping, but it can under-represent regions where relevant work is published in non-English outlets, local journals, or conference proceedings (which are common dissemination channels in computer science). Consequently, the geographic distribution reported here should be read as the distribution of indexed, English-language journal output rather than the full global distribution of expertise.
These regional disparities matter substantively for the field’s development. Cyber threats to cryptocurrencies and NFTs are transnational, yet defensive research agendas can become shaped by the data availability, infrastructures, and regulatory contexts of leading publishing regions. Increasing cross-regional collaboration and improving visibility for under-represented regions would likely broaden the empirical basis of the field (e.g., threat prevalence, reporting practices, and security governance approaches), strengthening the generalisability of conclusions and supporting more inclusive security knowledge for decentralised ecosystems.
From a thematic perspective (RQ3), the identification of blockchain and cybersecurity as motor themes can be interpreted as the direct result of infrastructural centrality: blockchain is the substrate enabling decentralised value transfer and tokenisation, and cybersecurity is the cross-cutting constraint that determines whether these systems can operate reliably under adversarial conditions. This explains why these themes exhibit strong connectivity with multiple subtopics (e.g., peer-to-peer networks, smart contract vulnerabilities, fraud detection), since most research questions in the area ultimately depend on blockchain’s operational properties and its exposure to exploitation [12,31].
The prominence of illegal mining as a motor theme can be explained through incentive structures and observability. Illegal mining and cryptojacking convert unauthorised computational access into direct profit, which makes them persistent threats across decentralised infrastructures. This economic clarity increases their research tractability: the behaviour produces measurable traces, supports repeatable detection strategies, and links technical monitoring to broader questions of cybercrime and resource exploitation. As a result, illegal mining becomes both cohesive as a research subfield and strategically important for understanding systemic vulnerabilities [47,48].
The salience of LSTM and related machine-learning methods within the motor themes suggests a structural shift in how threats are conceptualised and mitigated. Rather than focusing only on static vulnerabilities, the literature increasingly treats decentralised threats as dynamic behavioural patterns that require predictive and adaptive modelling. This development is consistent with broader trajectories in cybersecurity research that move toward data-driven monitoring and anomaly detection. In decentralised environments, such approaches are especially attractive because transaction streams are large-scale and time-dependent, while adversarial behaviour evolves rapidly in response to defensive measures [106,108].
Concerning emerging topics (RQ4), the appearance of intrusion detection as an incipient theme reflects a growing need to operationalise security monitoring under decentralisation constraints. Blockchain systems often involve pseudonymity and limited access to user-level ground truth, which restricts traditional investigative and attribution techniques. These conditions encourage the development of detection architectures based on behavioural analysis, data mining, and anomaly detection rather than identity-dependent verification. The association with DeFi also indicates that the research frontier is moving toward protecting composable financial infrastructures where attacks can propagate rapidly across protocols and produce immediate systemic losses [35,116].
At the same time, the immaturity of NFT-focused security work can be inferred from its comparatively fragmented clustering. NFT threats are distributed across multiple layers, including smart contracts, marketplaces, metadata storage, wallet interactions, and social engineering, which reduces thematic cohesion and makes it difficult for the literature to converge on shared threat models and standardised mitigation pipelines. This fragmentation is not simply a lack of attention; it is partly structural, because NFT security challenges often depend on off-chain governance and platform-specific design choices that evolve quickly and resist generalisation [37,39].
Finally, the thematic clusters identified (RQ5) suggest that the field has developed several specialised subdomains, each shaped by distinct technical constraints. Clusters centred on peer-to-peer networks and distributed ledger resilience reflect ongoing concerns about network-level attacks and protocol robustness, which remain foundational in decentralised computing. Work clustered around authentication highlights the need to ensure trustworthy identity and access control in environments where user verification is often externalised or weakened by design. Meanwhile, clusters linked to geometry and watermarking indicate a parallel research trajectory focused on cryptographic assurance and content integrity mechanisms, which are increasingly relevant to NFT ecosystems and digital ownership verification [130,135].
Taken together, these patterns support a synthesis in which cryptocurrency cybersecurity research appears comparatively mature due to stable threat incentives and persistent infrastructural focus, while NFT security remains less consolidated due to multi-layer heterogeneity and platform volatility. The novelty of this study lies in making that distinction explicit through combined science mapping techniques, showing that the literature is not evolving uniformly but along differentiated maturity trajectories. This has practical implications: research efforts are likely to advance fastest where shared datasets, stable attack models, and reproducible monitoring pipelines exist, whereas domains with rapid ecosystem change require integrative frameworks that bridge on-chain and off-chain vulnerabilities and improve evaluation standards for AI-driven detection under privacy constraints [46,149].

6. Conclusions

This bibliometric review provides an integrated and evidence-based synthesis of research on cybersecurity and cyber threats in cryptocurrency and NFT ecosystems. By analysing 337 journal articles published between 2014 and 2025 and applying science mapping techniques (VOSviewer and SciMAT), the study clarifies the field’s intellectual structure, identifies the most influential actors and publication outlets, and characterises the evolution of key themes over time.
Beyond describing publication growth, the study addresses a gap in the literature by offering a quantitative, maturity-oriented assessment capable of distinguishing consolidated research streams from emerging and less cohesive areas. In particular, the strategic mapping results indicate that blockchain, cybersecurity, emerging technologies, and illegal mining operate as motor themes that structure the research agenda. Meanwhile, themes such as authentication and peer-to-peer networks appear as transversal foundations, and intrusion detection is positioned as an emerging research line with increasing relevance in recent years.
The results further suggest that cybersecurity research in cryptocurrency environments is more developed than NFT-focused security research, which remains comparatively fragmented across multiple layers including smart contracts, marketplaces, metadata infrastructures, and user-facing attack vectors. This uneven thematic consolidation indicates that the field is evolving along differentiated trajectories shaped by ecosystem complexity, heterogeneous architectures, and the rapid emergence of new adversarial strategies.
At the same time, several unresolved challenges remain open. First, security approaches face limitations in supporting real-time detection and response, particularly in DeFi contexts where composability and protocol interdependencies amplify systemic exposure. Second, although AI-driven methods are increasingly adopted, the field still lacks standardised evaluation strategies and explainability mechanisms that support transparency, auditability, and operational trust in detection systems. Third, the expansion of cross-chain infrastructures and interoperability protocols introduces additional vulnerability surfaces that cannot be addressed through single-chain security assumptions, calling for updated threat models and empirical validation.
Accordingly, future research should advance along four complementary lines: (i) explainable AI (XAI) for intrusion and anomaly detection under adversarial conditions; (ii) NFT-specific threat taxonomies that consolidate heterogeneous attack vectors into reproducible analytical frameworks; (iii) systematic investigation of cross-chain vulnerabilities and bridge-related attack patterns; and (iv) regulation-aware security frameworks capable of integrating compliance constraints, forensic traceability needs, and privacy-preserving mechanisms within decentralised environments.
Overall, the findings confirm that cybersecurity in cryptocurrencies and NFTs should be approached as a socio-technical and incentive-driven security domain. Progress in this area will require interdisciplinary research combining cryptography, network security, data-driven detection, human factors, and regulatory perspectives to develop security mechanisms that are both technically robust and operationally applicable.

6.1. Theoretical Implications

From a theoretical perspective, this study contributes a maturity-driven conceptualisation of cybersecurity research in cryptocurrency and NFT ecosystems. By distinguishing motor, transversal, isolated, and emerging themes, the science mapping results provide a structured representation of how knowledge is organised across the field and where conceptual consolidation remains limited.
The findings support the need to extend classical cybersecurity frameworks to incorporate decentralised trust assumptions, distributed governance, and incentive-shaped adversarial behaviour. Themes such as illegal mining, strategic attacks on consensus mechanisms, smart-contract vulnerabilities, and DeFi-related risks indicate that attack surfaces in crypto ecosystems are shaped by protocol economics and system design as much as by conventional software and network vulnerabilities.
Furthermore, the increasing prominence of machine learning, graph analysis, and anomaly detection reflects a shift from reactive security perspectives towards adaptive and predictive paradigms. However, this evolution also raises theoretical challenges related to robustness against adversarial manipulation, explainability of detection outcomes, and the reproducibility of AI-driven results across heterogeneous blockchain environments.
Finally, the expanding use of NFTs in authentication, identity, and asset management suggests the need for updated theoretical models of digital ownership, integrity verification, and trust formation. These models must account for the interaction between on-chain mechanisms, off-chain governance structures, and marketplace dynamics that influence how security failures emerge and propagate.

6.2. Practical Implications

From an applied perspective, the findings highlight priority areas for cybersecurity practitioners and ecosystem stakeholders by identifying where threats and research gaps concentrate. For cybersecurity teams, the prominence of illegal mining, cryptojacking, ransomware-related flows, and smart-contract exploitation reinforces the need for continuous monitoring, threat intelligence integration, and detection pipelines capable of operating under high transaction volume and evolving attacker strategies.
For blockchain developers and protocol designers, the identified gaps emphasise the importance of secure-by-design practices, including systematic code auditing, formal verification where feasible, and evaluation frameworks that consider composability risks in DeFi. In addition, cross-chain architectures require security approaches that explicitly define trust boundaries and incorporate bridge-resilience strategies, given the tendency of vulnerabilities to propagate across interconnected environments.
For NFT marketplaces and platform operators, the relative fragmentation of NFT security research indicates that operational protection should address multi-layer risks, including marketplace manipulation, phishing and social engineering, metadata tampering, wallet compromise, and unauthorised asset transfers. In practice, mitigation strategies should combine stronger identity and authentication controls, behavioural fraud detection tailored to NFT transactions, and incident response mechanisms that support traceability and user protection.
Finally, in policy and regulatory contexts, the results suggest that illicit finance, consumer protection, and systemic risk require governance strategies that go beyond ex post enforcement. Regulation-aware security frameworks should integrate forensic capabilities, risk-based monitoring, and privacy-preserving compliance mechanisms. In addition, emerging themes such as intrusion detection and AI-based security indicate the relevance of transparency requirements for automated detection systems, baseline security expectations for exchanges and marketplaces, and cross-jurisdictional coordination mechanisms to address cyber-enabled financial crime.

Stakeholder-Oriented Recommendations Derived from the Bibliometric Evidence

The bibliometric results are directly actionable because they differentiate (i) motor themes that structure the field (e.g., blockchain, cybersecurity, illegal mining, and AI-driven detection), (ii) transversal foundations (e.g., authentication and peer-to-peer networks), and (iii) emerging lines (e.g., intrusion detection), while also indicating that NFT-focused security remains comparatively fragmented. This maturity-oriented evidence can be translated into prioritised actions for different stakeholder groups.
Implications for policymakers and regulators: The concentration of mature research streams around illegal mining/cryptojacking, smart-contract exploitation, and AI-enabled detection suggests that baseline policy should focus on (a) minimum security controls for exchanges, marketplaces, custodians, and bridge operators (e.g., continuous monitoring requirements, vulnerability disclosure processes, incident response readiness), and (b) standardised reporting for on-chain and off-chain security incidents to reduce fragmentation of evidence and enable cross-jurisdictional learning. In addition, because AI-based detection appears as a consolidated methodological stream, governance frameworks should include auditability and transparency expectations for automated risk-scoring and detection systems, including documentation of evaluation procedures and known failure modes under adversarial manipulation.
Implications for developers, protocol designers, and platform operators: The identification of smart-contract-related threats as persistent and cross-cutting supports prioritising secure-by-design engineering across the lifecycle: formal threat modelling before deployment, systematic code review and third-party audits, and (where feasible) formal verification for high-value contract components. Where the literature indicates multi-layer risk (especially for NFTs), platform operators should treat security as a stack that spans contract logic, metadata integrity, marketplace mechanisms, and user-facing attack surfaces (e.g., phishing/social engineering), and implement mitigations accordingly (e.g., hardened signing flows, transaction simulation/warnings, metadata validation, and protection against unauthorised transfers). Finally, because cross-chain architectures amplify risk propagation, bridge design should explicitly define trust boundaries and incorporate resilience mechanisms that assume partial compromise rather than relying on single-chain assumptions.
Implications for cybersecurity professionals and incident responders: The prominence of illegal mining/cryptojacking and the growing consolidation of ML-driven approaches imply that operational teams should invest in (a) continuous telemetry and threat intelligence integration tuned to crypto/NFT infrastructures, (b) detection pipelines that combine signature-based controls with behavioural/anomaly detection, and (c) response playbooks that address both on-chain indicators (transaction patterns, address clustering, laundering signals) and off-chain compromise vectors (wallet compromise, credential theft, malicious dApps, and infrastructure-level intrusion). Given the emerging emphasis on intrusion detection, practitioners should also prioritise evaluation practices that test detection tools under realistic adversarial conditions and across heterogeneous platforms, reducing overfitting to narrow datasets.

6.3. Limitations and Future Lines of Research

One of the main limitations of this study relates to the temporal scope and the way the dataset was analysed. Specifically, the methodological decision to examine the 2014–2025 period as a single unified corpus—rather than splitting it into sub-periods—was motivated by two key considerations: (i) the need to ensure a sufficiently large dataset to support robust co-word and thematic network analysis, and (ii) the thematic continuity observed across the literature during this interval, where cybersecurity challenges in cryptocurrencies and NFTs progressively evolve while maintaining stable conceptual anchors (e.g., fraud, blockchain security, smart contract vulnerabilities, and digital asset authentication).
However, this approach inevitably constrains the capacity to detect temporal shifts in research priorities, emergent topics, and short-lived thematic bursts, particularly in a rapidly changing domain influenced by technological innovation, market dynamics, and evolving regulatory responses. In this regard, while aggregating the full period strengthens overall statistical stability and thematic mapping, it may obscure meaningful transitions in the field—such as changes before and after major market events, high-profile cyberattacks, or the expansion of NFTs into mainstream adoption.
Therefore, future research should complement the present findings through longitudinal or time-sliced bibliometric designs (e.g., 2014–2019, 2020–2022, 2023–2025), enabling the identification of thematic trajectories, topic maturity, and turning points in the evolution of cybersecurity research related to cryptocurrencies and NFTs. Such approaches could provide a more granular understanding of how the intellectual structure of the field changes over time.

Funding

This work has been developed within the “Recovery, Transformation and Resilience Plan”, project C084/23 Ada Byron INCIBE-UAH, funded by the European Union (Next Generation).

Data Availability Statement

The original contributions presented in this study are included in the article. Further inquiries can be directed to the corresponding author.

Conflicts of Interest

The authors declare no conflict of interest.

Appendix A. Keyword Normalisation Mapping Table

LabelReplace by
'currentcurrent
block-chainblockchain
blockchain forensicblockchain forensics
blockchain technologyblockchain
blockchainsblockchain
centralisedcentralized systems
computer crimecybercrime
computing powercomputational resources
consensus algorithmsconsensus mechanism
consensus protocolsconsensus mechanism
cryptocurrenciescryptocurrency
cryptocurrency exchangescryptocurrency exchange
cyber securitycybersecurity
cyber-attackscyber attacks
cyber-crimescybercrime
cybercriminalscybercrime
decentraliseddecentralization
denial-of-service attackdos
electronic cashelectronic money
features extractionfeature extraction
financial servicefinancial services
fraudfinancial fraud
identity authenticationauthentication
machine learning techniquesmachine learning
machine-learningmachine learning
malwaresmalware
metaversesmetaverse
miningcryptomining
natural language processingnatural languages
network layersnetwork architecture
network nodenetwork architecture
network routingnetwork architecture
nftsnft
non-fungible tokennft
non-fungible tokensnft
non-fungible tokens (nfts)nft
nonfungible tokennft
peer to peerpeer to peer networks
privacy preservingprivacy
privacy-preserving techniquesprivacy
public keyspublic key cryptography
quantum computersquantum computing
security analysissecurity
security issuessecurity
security of datasecurity
security requirementssecurity
smart contractsmart contracts
vulnerabilityvulnerabilities
wide area networkswide-area networks
zero-knowledge proofzero-knowledge proofs

References

  1. Amirzadeh, R.; Thiruvady, D.; Nazari, A.; Ee, M.S. Dynamic evolution of causal relationships among cryptocurrencies: An analysis via Bayesian networks. Knowl. Inf. Syst. 2025, 67, 355–370. [Google Scholar] [CrossRef] [Scilit]
  2. Lyubchenko, I. What is Art? NFTs, Beeple, and Art Connoisseurship in the 21st Century. Interact. Film Media J. 2022, 2, 174–190. [Google Scholar] [CrossRef] [Scilit]
  3. Hossaion, S.; Bairagi, M.; Aktar, J.; Honey, U.; Mithy, S.A. The Evolution of Bitcoin: A Historical Analysis and Future Prospects. iRASD J. Econ. 2023, 5, 241–252. [Google Scholar] [CrossRef] [Scilit]
  4. Khan, F.A.; Asif, M.; Ahmad, A.; Alharbi, M.; Aljuaid, H. Blockchain technology, improvement suggestions, security challenges on smart grid and its application in healthcare for sustainable development. Sustain. Cities Soc. 2020, 55, 102018. [Google Scholar] [CrossRef] [Scilit]
  5. Gebreab, S.A.; Salah, K.; Jayaraman, R.; Zemerly, J. Trusted Traceability and Certification of Refurbished Medical Devices Using Dynamic Composable NFTs. IEEE Access 2023, 11, 30373–30389. [Google Scholar] [CrossRef] [Scilit]
  6. Krishnasamy, S. My Holistic Data Share: A WEB3 Data Share Application: Extending Beyond Finance to Privacy-Protected Decentralised Share of Multi-Dimensional Data to Enhance Global Healthcare. Blockchain Healthc. Today 2024, 7, 10-30953. [Google Scholar] [CrossRef] [Scilit]
  7. Baldi, M.; Chiaraluce, F. A trusted cryptocurrency scheme for secure and verifiable digital transactions. First Monday 2017, 22. [Google Scholar] [CrossRef] [Scilit]
  8. Ciarko, M.; Poszwa, G.; Paluch-Dybek, A.; Timur, M.C. Cryptocurrencies as the future of money: Theoretical aspects, blockchain technology and origins of cryptocurrencies. Virtual Econ. 2023, 6, 70–93. [Google Scholar] [CrossRef] [Scilit]
  9. Auer, R.; Farag, M.; Lewrick, U.; Orazem, L.; Zoss, M. Banking in the Shadow of Bitcoin? The Institutional Adoption of Cryptocurrencies. SSRN J. 2023, 10355, 1–25. [Google Scholar] [CrossRef] [Scilit]
  10. Cheraghali, H.; Molnár, P.; Storsveen, M.; Veliqi, F. The impact of cryptocurrency-related cyberattacks on return, volatility, and trading volume of cryptocurrencies and traditional financial assets. Int. Rev. Financ. Anal. 2024, 95, 103439. [Google Scholar] [CrossRef] [Scilit]
  11. Oben, R.J.; Özdamlı, F. Decentralized Finance (DeFi): Benefits, Risks, and Risk Mitigation Strategies. Istanb. Bus. Res. 2024, 53, 455–475. [Google Scholar] [CrossRef] [Scilit]
  12. Chen, H.; Pendleton, M.; Njilla, L.; Xu, S. A Survey on Ethereum Systems Security: Vulnerabilities, Attacks, and Defenses. ACM Comput. Surv. 2020, 53, 1–43. [Google Scholar] [CrossRef] [Scilit]
  13. Wang, Q.; Li, R.; Wang, Q.; Chen, S. Non-Fungible Token (NFT): Overview, Evaluation, Opportunities and Challenges. arXiv 2021, arXiv:2105.07447. [Google Scholar] [CrossRef] [Scilit]
  14. Musamih, A.; Yaqoob, I.; Salah, K.; Jayaraman, R.; Omar, M.; Ellahham, S. Using NFTs for Product Management, Digital Certification, Trading, and Delivery in the Healthcare Supply Chain. IEEE Trans. Eng. Manag. 2024, 71, 4480–4501. [Google Scholar] [CrossRef] [Scilit]
  15. Khan, W.Z.; Siddiqa, A.; Alanazi, F.; Khan, M.K. NFT-Based Digital Identity Authentication Framework for the Metaverse Environments. IEEE Trans. Consum. Electron. 2025, 71, 5699–5707. [Google Scholar] [CrossRef] [Scilit]
  16. Ma, K.; Huang, J.; He, N.; Wang, Z.; Wang, H. SoK: On the security of non-fungible tokens. Blockchain Res. Appl. 2025, 6, 100268. [Google Scholar] [CrossRef] [Scilit]
  17. Fauzi, M.A.; Paiman, N.; Othman, Z. Bitcoin and cryptocurrency: Challenges, opportunities and future works. J. Asian Financ. Econ. Bus. 2020, 7, 695–704. [Google Scholar] [CrossRef] [Scilit]
  18. Byun, H.; Kim, J.; Jeong, Y.; Seok, B.; Gong, S.; Lee, C. A Security Analysis of Cryptocurrency Wallets against Password Brute-Force Attacks. Electronics 2024, 13, 2433. [Google Scholar] [CrossRef] [Scilit]
  19. Farber, S.; Yehezkel, S.A. Financial Extremism: The Dark Side of Crowdfunding and Terrorism. Terror. Political Violence 2024, 37, 651–670. [Google Scholar] [CrossRef] [Scilit]
  20. Pessin, V.Z.; Yamane, L.H.; Siman, R.R. Smart bibliometrics: An integrated method of science mapping and bibliometric analysis. Scientometrics 2022, 127, 3695–3718. [Google Scholar] [CrossRef] [Scilit]
  21. Jing, Y.; Wang, C.; Chen, Y.; Wang, H.; Yu, T.; Shadiev, R. Bibliometric mapping techniques in educational technology research: A systematic literature review. Educ. Inf. Technol. 2024, 29, 9283–9311. [Google Scholar] [CrossRef] [Scilit]
  22. Chen, Y.; Chen, H.; Zhang, Y.; Han, M.; Siddula, M.; Cai, Z. A survey on blockchain systems: Attacks, defenses, and privacy preservation. High-Confid. Comput. 2022, 2, 100048. [Google Scholar] [CrossRef] [Scilit]
  23. Sahoo, S.S.; Hosmane, M.M.; Chaurasiya, V.K. A secure payment channel rebalancing model for layer-2 blockchain. Internet Things 2023, 22, 100822. [Google Scholar] [CrossRef] [Scilit]
  24. Qiao, Y.; Wu, K.; Khabbazian, M. Non-intrusive Balance Tomography Using Reinforcement Learning in the Lightning Network. ACM Trans. Priv. Secur. 2024, 27, 1–32. [Google Scholar] [CrossRef] [Scilit]
  25. Kurt, A.; Akkaya, K.; Yilmaz, S.; Mercan, S.; Shlomovits, O.; Erdin, E. LNGate2: Secure Bidirectional IoT Micro-Payments Using Bitcoin’s Lightning Network and Threshold Cryptography. IEEE Trans. Mob. Comput. 2024, 23, 6027–6044. [Google Scholar] [CrossRef] [Scilit]
  26. Rak, M.; Niemiec, M. Securing Trading Card Game Assets Using Blockchain Technology. Appl. Sci. 2024, 14, 11139. [Google Scholar] [CrossRef] [Scilit]
  27. Hasan, H.R.; Salah, K.; Mayyas, A.; Musamih, A.; Yaqoob, I.; Omar, M.; Jayaraman, R. Using composable NFTs and blockchain for the creation of EV battery digital passports with sustainability and traceability features. Sustain. Futures 2025, 10, 100847. [Google Scholar] [CrossRef] [Scilit]
  28. Rishiwal, V.; Agarwal, U.; Yadav, M.; Alotaibi, A.; Yadav, P.; Tanwar, S. Blockchain-Secure Gaming Environments: A Comprehensive Survey. IEEE Access 2024, 12, 183466–183488. [Google Scholar] [CrossRef] [Scilit]
  29. Chen, Y.; Liu, J.-N.; Yang, A.; Weng, J.; Chen, M.-R.; Liu, Z.; Li, M. PACDAM: Privacy-Preserving and Adaptive Cross-Chain Digital Asset Marketplace. IEEE Internet Things J. 2024, 11, 13424–13436. [Google Scholar] [CrossRef] [Scilit]
  30. Gao, Y.; Saad, M.; Oest, A.; Zhang, J.; Han, B.; Chen, S. Can I Own Your NFTs? Understanding the New Attack Surface to NFTs. IEEE Commun. Mag. 2023, 61, 64–70. [Google Scholar] [CrossRef] [Scilit]
  31. Houy, S.; Schmid, P.; Bartel, A. Security Aspects of Cryptocurrency Wallets—A Systematic Literature Review. ACM Comput. Surv. 2024, 56, 1–31. [Google Scholar] [CrossRef] [Scilit]
  32. Alyami, M.; Alhotaylah, R.; Alshehri, S.; Alghamdi, A. Phishing Attacks on Cryptocurrency Investors in the Arab States of the Gulf. J. Risk Financ. Manag. 2023, 16, 271. [Google Scholar] [CrossRef] [Scilit]
  33. Xia, P.; Guo, Y.; Lin, Z.; Wu, J.; Duan, P.; He, N.; Wang, K.; Liu, T.; Yue, Y.; Xu, G.; et al. WALLETRADAR: Towards automating the detection of vulnerabilities in browser-based cryptocurrency wallets. Autom. Softw. Eng. 2024, 31, 1–33. [Google Scholar] [CrossRef] [Scilit]
  34. He, D.; Liu, Z.; Lv, X.; Chan, S.; Guizani, M. On Phishing URL Detection Using Feature Extension. IEEE Internet Things J. 2024, 11, 39527–39536. [Google Scholar] [CrossRef] [Scilit]
  35. Wen, H.; Fang, J.; Wu, J.; Zheng, Z. Hide and Seek: An Adversarial Hiding Approach Against Phishing Detection on Ethereum. IEEE Trans. Comput. Soc. Syst. 2023, 10, 3512–3523. [Google Scholar] [CrossRef] [Scilit]
  36. Lee, S.A.; Milunovich, G. Digital exchange attributes and the risk of closure. Blockchain Res. Appl. 2023, 4, 100131. [Google Scholar] [CrossRef] [Scilit]
  37. Guidi, B.; Michienzi, A. Delving NFT vulnerabilities, a sleepminting prevention system. Multimed. Tools Appl. 2023, 82, 46065–46084. [Google Scholar] [CrossRef] [Scilit]
  38. Azimi, S.; Golzari, A.; Ivaki, N.; Laranjeiro, N. A systematic review on smart contracts security design patterns. Empir. Softw. Eng. 2025, 30, 1–40. [Google Scholar] [CrossRef] [Scilit]
  39. Liao, P.; Liu, C.; Yin, J.; Wang, Z.; Cui, X. NFT Security Matrix: Towards Modeling NFT Ecosystem Threat. CMES-Comput. Model. Eng. Sci. 2024, 139, 3255–3285. [Google Scholar] [CrossRef] [Scilit]
  40. Ncube, P.T.; Kabwe, R. The regulation of cryptocurrencies to combat money laundering crimes in South African banking institutions. De Jure Law J. 2023, 56, 354–375. [Google Scholar] [CrossRef] [Scilit]
  41. Alekseenko, A.P. Model Framework for Consumer Protection and Crypto-Exchanges Regulation. J. Risk Financ. Manag. 2023, 16, 305. [Google Scholar] [CrossRef] [Scilit]
  42. Kirimhan, D. Importance of anti-money laundering regulations among prosumers for a cybersecure decentralized finance. J. Bus. Res. 2023, 157, 113558. [Google Scholar] [CrossRef] [Scilit]
  43. Lu, O. Cleaning up NFT Laundering Privately: A Proposal for NFT AML Regulation. J. Law Technol. Policy 2023, 2023, 399–422. [Google Scholar]
  44. Anatolii, A.; Shliakhovskyi, O.; Kozii, V.; Fedchak, I. Investigating cryptocurrency financing crimes terrorism and armed aggression. Soc. Leg. Studios 2023, 6, 123–131. [Google Scholar] [CrossRef] [Scilit]
  45. Patsakis, C.; Politou, E.; Alepis, E.; Hernandez Castro, J. Cashing out crypto: State of practice in ransom payments. Int. J. Inf. Secur. 2024, 23, 699–712. [Google Scholar] [CrossRef] [Scilit]
  46. Nicholls, J.; Kuppa, A.; Le-Khac, N.-A. The next phase of identifying illicit activity in Bitcoin. Int. J. Netw. Manag. 2024, 34, e2259. [Google Scholar] [CrossRef] [Scilit]
  47. Almurshid, H.A.; Almomani, I.; Khalifa, M.A.; El-Shafai, W. A Holistic Intelligent Cryptojacking Malware Detection System. IEEE Access 2024, 12, 161417–161439. [Google Scholar] [CrossRef] [Scilit]
  48. Saad, M.; Mohaisen, D. Analyzing In-Browser Cryptojacking. IEEE Trans. Dependable Secur. Comput. 2024, 21, 5448–5460. [Google Scholar] [CrossRef] [Scilit]
  49. Mohamad, A.; Dimitriou, D. From scam to heist: The impact of cybercrimes on cryptocurrencies. Appl. Econ. Lett. 2024, 1–9. [Google Scholar] [CrossRef] [Scilit]
  50. Sezgin, F.S.; Ozdurak, C. Are Crypto Assets Connected to Real World Shocks? The Nexus Between Terrorist Attacks, Bitcoin and NFTs. J. Econ. Policy Res. 2023, 10, 113–132. [Google Scholar] [CrossRef] [Scilit]
  51. Alfawareh, F.S.; Al-Kofahi, M. Analysis of global research trends on FinTech: A bibliometric study. J. Internet Digit. Econ. 2023, 4, 30–49. [Google Scholar] [CrossRef] [Scilit]
  52. Patel, R.; Migliavacca, M.; Oriani, M.E. Blockchain in banking and finance: A bibliometric review. Res. Int. Bus. Financ. 2022, 62, 101718. [Google Scholar] [CrossRef] [Scilit]
  53. Peng, X.; Zhao, Z.; Wang, X.; Li, H.; Xu, J.; Zhang, X. A review on blockchain smart contracts in the agri-food industry: Current state, application challenges and future trends. Comput. Electron. Agric. 2023, 208, 107776. [Google Scholar] [CrossRef] [Scilit]
  54. Chen, J.; Huang, M.; Lin, Z.; Zheng, P.; Zheng, Z. To healthier Ethereum: A comprehensive and iterative smart contract weakness enumeration. Blockchain Res. Appl. 2025, 6, 100258. [Google Scholar] [CrossRef] [Scilit]
  55. Ante, L. Smart contracts on the blockchain—A bibliometric analysis and review. Telemat. Inform. 2021, 57, 101519. [Google Scholar] [CrossRef] [Scilit]
  56. Mahmood, Z.; Asif, M.; Aljuaid, M.; Lodhi, R.N. Beneath the surface: A bibliometric analysis of the hidden risks and costs of blockchain technology. Int. J. Web Inf. Syst. 2023, 19, 280–303. [Google Scholar] [CrossRef] [Scilit]
  57. Romero-Castro, N.; López-Cabarcos, M.Á.; Vittori-Romero, V.; Piñeiro-Chousa, J. Decentralized Finance in Business and Economics Research: A Bibliometric Analysis. Int. J. Financ. Stud. 2025, 13, 211. [Google Scholar] [CrossRef] [Scilit]
  58. Callon, M.; Courtial, J.P.; Laville, F. Co-word analysis as a tool for describing the network of interactions between basic and technological research: The case of polymer chemsitry. Scientometrics 1991, 22, 155–205. [Google Scholar] [CrossRef] [Scilit]
  59. Cobo, M.J.; López-Herrera, A.G.; Herrera-Viedma, E.; Herrera, F. An approach for detecting, quantifying, and visualizing the evolution of a research field: A practical application to the Fuzzy Sets Theory field. J. Informetr. 2011, 5, 146–166. [Google Scholar] [CrossRef] [Scilit]
  60. Giraldo-Giraldo, C.; Rubio-Andrés, M.; Rave-Gómez, E.D.; Gutiérrez-Broncano, S. Evolution of the Concept and Scientific Mapping of Sustainable Human Resource Management S-(HRM). Adm. Sci. 2025, 15, 39. [Google Scholar] [CrossRef] [Scilit]
  61. Yawised, K.; Apasrawirote, D. The synergy of immersive experiences in tourism marketing: Unveiling insightful components in the ‘Metaverse’. J. Destin. Mark. Manag. 2025, 37, 101019. [Google Scholar] [CrossRef] [Scilit]
  62. Zahid, A.; Ferraro, A.; Petrillo, A.; De Felice, F. Exploring the Role of Digital Twin and Industrial Metaverse Technologies in Enhancing Occupational Health and Safety in Manufacturing. Appl. Sci. 2025, 15, 8268. [Google Scholar] [CrossRef] [Scilit]
  63. Carrasco-Garrido, C.; De-Pablos-Heredero, C.; Rodríguez-Sánchez, J.-L. Exploring hybrid telework: A bibliometric analysis. Heliyon 2023, 9, e22472. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  64. Ramos, M.T.; Salgado, M.S.M. Exploring the nexus between sustainability and food events. ESIC Mark. 2024, 54, e321. [Google Scholar] [CrossRef] [Scilit]
  65. Kramar, R. Beyond strategic human resource management: Is sustainable human resource management the next approach? Int. J. Hum. Resour. Manag. 2014, 25, 1069–1089. [Google Scholar] [CrossRef] [Scilit]
  66. Kramar, R. Sustainable human resource management: Six defining characteristics. Asia Pac. J. Hum. Resour. 2022, 60, 146–170. [Google Scholar] [CrossRef] [Scilit]
  67. Cobo, M.J.; López-Herrera, A.G.; Herrera-Viedma, E.; Herrera, F. SciMAT: A new science mapping analysis software tool. J. Am. Soc. Inf. Sci. Technol. 2012, 63, 1609–1630. [Google Scholar] [CrossRef] [Scilit]
  68. van Eck, N.J.; Waltman, L. Software survey: VOSviewer, a computer program for bibliometric mapping. Scientometrics 2010, 84, 523–538. [Google Scholar] [CrossRef] [Scilit]
  69. Haba, H.F.; Bredillet, C.; Dastane, O. Green consumer research: Trends and way forward based on bibliometric analysis. Clean. Responsible Consum. 2023, 8, 100089. [Google Scholar] [CrossRef] [Scilit]
  70. Shen, Z.; Ji, W.; Yu, S.; Cheng, G.; Yuan, Q.; Han, Z.; Liu, H.; Yang, T. Mapping the knowledge of traffic collision Reconstruction: A scientometric analysis in CiteSpace, VOSviewer, and SciMAT. Sci. Justice 2023, 63, 19–37. [Google Scholar] [CrossRef] [Scilit]
  71. Lim, W.M.; Kumar, S.; Donthu, N. How to combine and clean bibliometric data and use bibliometric tools synergistically: Guidelines using metaverse research. J. Bus. Res. 2024, 182, 114760. [Google Scholar] [CrossRef] [Scilit]
  72. Donthu, N.; Kumar, S.; Mukherjee, D.; Pandey, N.; Lim, W.M. How to conduct a bibliometric analysis: An overview and guidelines. J. Bus. Res. 2021, 133, 285–296. [Google Scholar] [CrossRef] [Scilit]
  73. Gavel, Y.; Iselid, L. Web of Science and Scopus: A journal title overlap study. Online Inf. Rev. 2008, 32, 8–21. [Google Scholar] [CrossRef] [Scilit]
  74. Mongeon, P.; Paul-Hus, A. The journal coverage of Web of Science and Scopus: A comparative analysis. Scientometrics 2016, 106, 213–228. [Google Scholar] [CrossRef] [Scilit]
  75. Haddaway, N.R.; Grainger, M.J.; Gray, C.T. Citationchaser: A tool for transparent and efficient forward and backward citation chasing in systematic searching. Res. Synth. Methods 2022, 13, 533–545. [Google Scholar] [CrossRef] [Scilit]
  76. Ouzzani, M.; Hammady, H.; Fedorowicz, Z.; Elmagarmid, A. Rayyan—A web and mobile app for systematic reviews. Syst. Rev. 2016, 5, 210. [Google Scholar] [CrossRef] [Scilit]
  77. Page, M.J.; McKenzie, J.E.; Bossuyt, P.M.; Boutron, I.; Hoffmann, T.C.; Mulrow, C.D.; Shamseer, L.; Tetzlaff, J.M.; Akl, E.A.; Brennan, S.E.; et al. The PRISMA 2020 statement: An updated guideline for reporting systematic reviews. BMJ 2021, 372, n71. [Google Scholar] [CrossRef] [Scilit]
  78. McAllister, J.T.; Lennertz, L.; Atencio Mojica, Z. Mapping A Discipline: A Guide to Using VOSviewer for Bibliometric and Visual Analysis. Sci. Technol. Libr. 2022, 41, 319–348. [Google Scholar] [CrossRef] [Scilit]
  79. van Eck, N.J.; Waltman, L. VOSviewer Manual (Version 1.6.20). Available online: https://www.vosviewer.com/documentation/Manual_VOSviewer_1.6.20.pdf (accessed on 15 January 2026).
  80. Kıllı, M.; Kefe, İ. Bibliometric network mapping of farm accounting studies using a comprehensive dataset. Data Brief 2024, 54, 110288. [Google Scholar] [CrossRef] [Scilit]
  81. Nowakowska, M. A comprehensive approach to preprocessing data for bibliometric analysis. Scientometrics 2025, 130, 5191–5225. [Google Scholar] [CrossRef] [Scilit]
  82. Rivero-Gutierrez, L.; Blanco-González, A.; Cabanelas-Lorenzo, P.; Plaza-Casado, A. Digitalization and internationalization: A bibliometric approach and content analysi. Int. J. Mark. Commun. New Media 2025, 17, 51–79. [Google Scholar] [CrossRef] [Scilit]
  83. Dastane, O.; Haba, H.F. The Landscape of Digital Natives Research: A Bibliometric and Science Mapping Analysis. FIIB Bus. Rev. 2023, 23197145221137960. [Google Scholar] [CrossRef] [Scilit]
  84. Bagheri, B.; Azadi, H.; Soltani, A.; Witlox, F. Global city data analysis using SciMAT: A bibliometric review. Environ. Dev. Sustain. 2024, 26, 15403–15427. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  85. Echchad, M. Ecolabels research: Trends and way forward based on bibliometric analysis. Expert J. Bus. Manag. 2024, 12, 22–32. [Google Scholar]
  86. Ghosh, A.; Gupta, S.; Dua, A.; Kumar, N. Security of Cryptocurrencies in blockchain technology: State-of-art, challenges and future prospects. J. Netw. Comput. Appl. 2020, 163, 102635. [Google Scholar] [CrossRef] [Scilit]
  87. Akbar, N.A.; Muneer, A.; Elhakim, N.; Fati, S.M. Distributed hybrid double-spending attack prevention mechanism for proof-of-work and proof-of-stake blockchain consensuses. Future Internet 2021, 13, 285. [Google Scholar] [CrossRef] [Scilit]
  88. Aponte-Novoa, F.A.; Sandoval-Orozco, A.L.S.; Villanueva-Polanco, R.; Wightman, P. The 51% Attack on Blockchains: A Mining Behavior Study. IEEE Access 2021, 9, 140549–140564. [Google Scholar] [CrossRef] [Scilit]
  89. Wang, Q.; Li, C.; Xia, T.; Ren, Y.; Wang, D.; Zhang, G.; Choo, K.-K.R. Optimal Selfish Mining-Based Denial-of-Service Attack. IEEE Trans. Inf. Forensics Secur. 2024, 19, 835–850. [Google Scholar] [CrossRef] [Scilit]
  90. Huang, T.; Huang, J.; Pang, Y.; Yan, H. Smart contract watermarking based on code obfuscation. Inf. Sci. 2023, 628, 439–448. [Google Scholar] [CrossRef] [Scilit]
  91. Haghighat, A.T.; Shajari, M. Computation integrity assurance for emerging distributed computation outsourcing environments, the case of block withholding attack on Bitcoin pools. IET Inf. Secur. 2020, 14, 553–561. [Google Scholar] [CrossRef] [Scilit]
  92. Castonguay, J.J.; Smith, S. Digital Assets and Blockchain: Hackable, Fraudulent, or Just Misunderstood?*. Account. Perspect. 2020, 19, 363–387. [Google Scholar] [CrossRef] [Scilit]
  93. Jang, J.; Lee, H.-N. Profitable Double-Spending Attacks. Appl. Sci. Basel 2020, 10, 8477. [Google Scholar] [CrossRef] [Scilit]
  94. Grunspan, C.; Perez-Marco, R. On profitability of nakamoto double spend. Probab. Eng. Informational Sci. 2022, 36, 732–746. [Google Scholar] [CrossRef] [Scilit]
  95. Hu, Q.; Dai, Y.; Li, S.; Jiang, T. Enhancing Account Privacy in Blockchain-Based IoT Access Control via Zero Knowledge Proof. IEEE Netw. 2023, 37, 117–123. [Google Scholar] [CrossRef] [Scilit]
  96. Jose Diaz Rivera, J.; Afaq, A.; Song, W.-C. Securing Digital Identity in the Zero Trust Architecture: A Blockchain Approach to Privacy-Focused Multi-Factor Authentication. IEEE Open J. Commun. Soc. 2024, 5, 2792–2814. [Google Scholar] [CrossRef] [Scilit]
  97. Li, Y.; Weng, J.; Li, M.; Wu, W.; Weng, J.; Liu, J.-N.; Hu, S. ZeroCross: A sidechain-based privacy-preserving Cross-chain solution for Monero. J. Parallel Distrib. Comput. 2022, 169, 301–316. [Google Scholar] [CrossRef] [Scilit]
  98. Wang, C.; Ren, Y.; Wu, Z. Multi-hop anonymous payment channel network based on onion routing. IET Blockchain 2024, 4, 197–208. [Google Scholar] [CrossRef] [Scilit]
  99. Kushwaha, S.S.; Joshi, S.; Gupta, A.K. An efficient approach to secure smart contract of Ethereum blockchain using hybrid security analysis approach. J. Discret. Math. Sci. Cryptogr. 2023, 26, 1499–1517. [Google Scholar] [CrossRef] [Scilit]
  100. Lohith, L.; Singh, K.; Chakravarthi, B. Digital forensic framework for smart contract vulnerabilities using ensemble models. Multimed. Tools Appl. 2024, 83, 51469–51512. [Google Scholar] [CrossRef] [Scilit]
  101. Gao, C.; Yang, W.; Ye, J.; Xue, Y.; Sun, J. SGuard+: Machine Learning Guided Rule-Based Automated Vulnerability Repair on Smart Contracts. ACM Trans. Softw. Eng. Methodol. 2024, 33, 1–55. [Google Scholar] [CrossRef] [Scilit]
  102. Huang, T.; Xie, R.; Ren, Y.; Yu, F.R.; Zou, Z.; Han, L.; Liu, Y.; Cheng, D.; Li, Y.; Liu, T. DTAIS: Distributed trusted active identity resolution systems for the Industrial Internet. Digit. Commun. Netw. 2024, 10, 853–862. [Google Scholar] [CrossRef] [Scilit]
  103. Broadhead, S. The contemporary cybercrime ecosystem: A multi-disciplinary overview of the state of affairs and developments. Comput. Law Secur. Rev. 2018, 34, 1180–1196. [Google Scholar] [CrossRef] [Scilit]
  104. Kethineni, S.; Cao, Y. The Rise in Popularity of Cryptocurrency and Associated Criminal Activity. Int. Crim. Justice Rev. 2020, 30, 325–344. [Google Scholar] [CrossRef] [Scilit]
  105. Kovalchuk, O.; Ruslan, R.; Banakh, S. Cryptocurrency Crime Risks Modeling: Environment, E-Commerce, and Cybersecurity Issue. IEEE Access 2024, 12, 50673–50688. [Google Scholar] [CrossRef] [Scilit]
  106. Agarwal, U.; Rishiwal, V.; Tanwar, S.; Yadav, M. Blockchain and crypto forensics: Investigating crypto frauds. Int. J. Netw. Manag. 2024, 34, e2255. [Google Scholar] [CrossRef] [Scilit]
  107. Caprolu, M.; Raponi, S.; Oligeri, G.; Di Pietro, R. Cryptomining makes noise: Detecting cryptojacking via Machine Learning. Comput. Commun. 2021, 171, 126–139. [Google Scholar] [CrossRef] [Scilit]
  108. Badawi, E.; Jourdan, G.-V.; Onut, I.-V. The “Bitcoin Generator” Scam. Blockchain Res. Appl. 2022, 3, 100084. [Google Scholar] [CrossRef] [Scilit]
  109. Neudecker, T.; Hartenstein, H. Network layer aspects of permissionless blockchains. IEEE Commun. Surv. Tutor. 2019, 21, 838–857. [Google Scholar] [CrossRef] [Scilit]
  110. Sasaki, T.; Hernandez-Gañan, C.; Yoshioka, K.; van Eeten, M.; Matsumoto, T. Pay the Piper: DDoS mitigation technique to deter financially-motivated attackers. IEICE Trans. Commun. 2020, 103, 389–404. [Google Scholar] [CrossRef] [Scilit]
  111. Saad, M.; Kim, J.; Nyang, D.; Mohaiseny, D. Contra-∗: Mechanisms for countering spam attacks on blockchain’s memory pools. J. Netw. Comput. Appl. 2021, 179, 102971. [Google Scholar] [CrossRef] [Scilit]
  112. Liu, X.; Huang, Z.; Wang, Q.; Jiang, X.; Chen, Y.; Wan, B. Analyzing Miners’ Dynamic Equilibrium in Blockchain Networks under DDoS Attacks. Electronics 2023, 12, 3903. [Google Scholar] [CrossRef] [Scilit]
  113. Zhu, H.; Chang, X.; Misic, J.; Misic, V.B.; Yang, R. Revisiting FAW attack in an imperfect PoW blockchain system. Peer-to-Peer Netw. Appl. 2022, 15, 2430–2443. [Google Scholar] [CrossRef] [Scilit]
  114. Chen, R.; Li, D.; Zhang, Y.; Liu, Y.; Liu, J.; Guan, Z.; Xie, M.; Wu, Q.; Zhou, J.; Susilo, W. Dissecting Blockchain Network Partitioning Attacks and Novel Defense for Bitcoin and Ethereum. IEEE Trans. Inf. Forensics Secur. 2025, 20, 8613–8627. [Google Scholar] [CrossRef] [Scilit]
  115. Dong, X.; Wu, F.; Faree, A.; Guo, D.; Shen, Y.; Ma, J. Selfholding: A combined attack model using selfish mining with block withholding attack. Comput. Secur. 2019, 87, 101584. [Google Scholar] [CrossRef] [Scilit]
  116. Chicarino, V.; de Albuquerque, C.; Jesus, E.; Rocha, A. On the detection of selfish mining and stalker attacks in blockchain networks. Ann. Telecommun. 2020, 75, 143–152. [Google Scholar] [CrossRef] [Scilit]
  117. Li, S.-N.; Campajola, C.; Tessone, C.J. Statistical detection of selfish mining in proof-of-work blockchain systems. Sci. Rep. 2024, 14, 1–13. [Google Scholar] [CrossRef] [Scilit]
  118. Kale, M.R.; Deepa; Kumar, A.N.; Anantha, N.L.; Rao, V.S.; Godla, S.R.; Thenmozhi, E. Enhancing Cryptojacking Detection Through Hybrid Black Widow Optimization and Generative Adversarial Networks. Int. J. Adv. Comput. Sci. Appl. 2024, 15, 871–884. [Google Scholar] [CrossRef] [Scilit]
  119. Mani, G.; Kim, M.; Bhargava, B.; Angin, P.; Deniz, A.; Pasumarti, V. Malware Speaks! Deep Learning Based Assembly Code Processing for Detecting Evasive Cryptojacking. IEEE Trans. Dependable Secur. Comput. 2024, 21, 2461–2477. [Google Scholar] [CrossRef] [Scilit]
  120. Samara, G.; Al-Mohtaseb, A.; Khafajeh, H.; Alazaidah, R.; Alidmat, O.; Nasayreh, A.; Alzyoud, M.; Al-Shanableh, N. Securing cryptocurrency transactions: Innovations in malware detection using machine learning. Int. J. Data Netw. Sci. 2024, 8, 2055–2066. [Google Scholar] [CrossRef] [Scilit]
  121. Cong, W.; Harvey, C.; Rabetti, D.; Wu, Z.-Y. An Anatomy of Crypto-Enabled Cybercrimes. Manag. Sci. 2025, 71, 3622–3633. [Google Scholar] [CrossRef] [Scilit]
  122. Breese, J.L.; Fox, M.; Vaidyanathan, G. Ransomware: A primer, suggested deterrence and a systems thinking approach. Issues Inf. Syst. 2022, 23, 230–242. [Google Scholar] [CrossRef] [Scilit]
  123. Alsaif, S.A. Machine Learning-Based Ransomware Classification of Bitcoin Transactions. Appl. Comput. Intell. Soft Comput. 2023, 2023, 6274260. [Google Scholar] [CrossRef] [Scilit]
  124. Awadallah, A.; Eledlebi, K.; Zemerly, M.J.; Puthal, D.; Damiani, E.; Taha, K.; Kim, T.-Y.; Yoo, P.D.; Raymond Choo, K.-K.; Yim, M.-S.; et al. Artificial Intelligence-Based Cybersecurity for the Metaverse: Research Challenges and Opportunities. IEEE Commun. Surv. Tutor. 2025, 27, 1008–1052. [Google Scholar] [CrossRef] [Scilit]
  125. Choithani, T.; Chowdhury, A.; Patel, S.; Patel, P.; Patel, D.; Shah, M. A Comprehensive Study of Artificial Intelligence and Cybersecurity on Bitcoin, Crypto Currency and Banking System. Ann. Data Sci. 2024, 11, 103–135. [Google Scholar] [CrossRef] [Scilit]
  126. Mittal, R.; Bhatia, M.P.S. Detection of Suspicious or UnTrusted Users in Crypto-Currency Financial Trading Applications. Int. J. Digit. Crime Forensics 2021, 13, 79–93. [Google Scholar] [CrossRef] [Scilit]
  127. Yin, H.H.S.; Langenheldt, K.; Harlev, M.; Mukkamala, R.R.; Vatrapu, R. Regulating Cryptocurrencies: A Supervised Machine Learning Approach to De-Anonymizing the Bitcoin Blockchain. J. Manag. Inf. Syst. 2019, 36, 37–73. [Google Scholar] [CrossRef] [Scilit]
  128. Mouris, D.; Tsoutsos, N.G. NFTs for 3D Models: Sustaining Ownership in Industry 4.0. IEEE Consum. Electron. Mag. 2024, 13, 13–22. [Google Scholar] [CrossRef] [Scilit]
  129. Peng, Y.; Deng, C.; Li, J.; KinTak, U. Personalized zero-watermark algorithm based on non-uniform weighted reconstruction and WGAN. IET Image Process. 2024, 18, 4862–4872. [Google Scholar] [CrossRef] [Scilit]
  130. Park, D.; Choi, M.; Kim, G.; Bae, D.; Kim, H.; Hong, S. Stealing Keys from Hardware Wallets: A Single Trace Side-Channel Attack on Elliptic Curve Scalar Multiplication Without Profiling. IEEE Access 2023, 11, 44578–44589. [Google Scholar] [CrossRef] [Scilit]
  131. Park, D.; Kim, J.; Kim, H.; Hong, S. Cloning Hardware Wallet Without Valid Credentials Through Side-Channel Analysis of Hash Function. IEEE Access 2024, 12, 132677–132688. [Google Scholar] [CrossRef] [Scilit]
  132. Fan, C.-I.; Tseng, Y.-F.; Su, H.-P.; Hsu, R.-H.; Kikuchi, H. Secure hierarchical Bitcoin wallet scheme against privilege escalation attacks. Int. J. Inf. Secur. 2020, 19, 245–255. [Google Scholar] [CrossRef] [Scilit]
  133. Liu, Z.; Yang, G.; Wong, D.S.; Nguyen, K.; Wang, H.; Ke, X.; Liu, Y. Secure Deterministic Wallet and Stealth Address: Key-Insulated and Privacy-Preserving Signature Scheme with Publicly Derived Public Key. IEEE Trans. Dependable Secur. Comput. 2022, 19, 2934–2951. [Google Scholar] [CrossRef] [Scilit]
  134. Zhou, C.; Xing, L.; Liu, Q. Dependability Analysis of Bitcoin subject to Eclipse Attacks. Int. J. Math. Eng. Manag. Sci. 2021, 6, 469–479. [Google Scholar] [CrossRef] [Scilit]
  135. Zhou, C.; Xing, L.; Liu, Q.; Wang, H. Semi-Markov Based Dependability Modeling of Bitcoin Nodes Under Eclipse Attacks and State-Dependent Mitigation. Int. J. Math. Eng. Manag. Sci. 2021, 6, 480–492. [Google Scholar] [CrossRef] [Scilit]
  136. Benassy, G.; Ooshita, F.; Inoue, M. Eventually consistent distributed ledger despite degraded atomic broadcast. Concurr. Comput. Pract. Exp. 2023, 35, e6199. [Google Scholar] [CrossRef] [Scilit]
  137. Geng, T.; Njilla, L.; Huang, C.-T. Delegated Proof of Secret Sharing: A Privacy-Preserving Consensus Protocol Based on Secure Multiparty Computation for IoT Environment. Network 2022, 2, 66–80. [Google Scholar] [CrossRef] [Scilit]
  138. Ramos, S.; Pianese, F.; Leach, T.; Oliveras, E. A great disturbance in the crypto: Understanding cryptocurrency returns under attacks. Blockchain Res. Appl. 2021, 2, 100021. [Google Scholar] [CrossRef] [Scilit]
  139. Quamara, S.; Singh, A.K. A systematic survey on security concerns in cryptocurrencies: State-of-the-art and perspectives. Comput. Secur. 2022, 113, 102548. [Google Scholar] [CrossRef] [Scilit]
  140. Hu, M.; Chen, J.; Gan, W.; Chen, C.-M. A jumping mining attack and solution. Appl. Intell. 2021, 51, 1367–1378. [Google Scholar] [CrossRef] [Scilit]
  141. Sayeed, S.; Marco-Gisbert, H. Assessing blockchain consensus and security mechanisms against the 51% attack. Appl. Sci. 2019, 9, 1788. [Google Scholar] [CrossRef] [Scilit]
  142. Sadeghi, S.; Chouhan, V.; Aldarwbi, M.; Ghorbani, A.; Chow, A.; Burko, R. Securing financial sector applications in the quantum era: A comprehensive evaluation of NIST’s recommended algorithms through use-case analysis. Expert Syst. Appl. 2025, 288, 128243. [Google Scholar] [CrossRef] [Scilit]
  143. Joshi, S.; Choudhury, A.; Minu, R.I. Quantum blockchain-enabled exchange protocol model for decentralized systems. Quantum Inf. Process. 2023, 22, 1–35. [Google Scholar] [CrossRef] [Scilit]
  144. Alupotha, J.; Boyen, X.; McKague, M. Aggregable Confidential Transactions for Efficient Quantum-Safe Cryptocurrencies. IEEE Access 2022, 10, 17722–17747. [Google Scholar] [CrossRef] [Scilit]
  145. Aponte-Novoa, F.A.; Povedano Álvarez, D.; Villanueva-Polanco, R.; Sandoval-Orozco, A.L.; García Villalba, L.J. On Detecting Cryptojacking on Websites: Revisiting the Use of Classifiers. Sensors 2022, 22, 9219. [Google Scholar] [CrossRef] [Scilit]
  146. Lachtar, N.; Elkhail, A.A.; Bacha, A.; Malik, H. A Cross-Stack Approach towards Defending against Cryptojacking. IEEE Comput. Archit. Lett. 2020, 19, 126–129. [Google Scholar] [CrossRef] [Scilit]
  147. Goldsmith, D.; Grauer, K.; Shmalo, Y. Analyzing hack subnetworks in the bitcoin transaction graph. Appl. Netw. Sci. 2020, 5, 1–20. [Google Scholar] [CrossRef] [Scilit]
  148. Lee, S.; Kim, J.; Seo, M.; Ho Na, S.; Shin, S.; Kim, J. CENSor: Detecting Illicit Bitcoin Operation via GCN-Based Hyperedge Classification. IEEE Access 2024, 12, 152330–152346. [Google Scholar] [CrossRef] [Scilit]
  149. Tripathy, N.; Balabantaray, S.K.; Parida, S.; Nayak, S.K. Cryptocurrency fraud detection through classification techniques. Int. J. Electr. Comput. Eng. 2024, 14, 2918–2926. [Google Scholar] [CrossRef] [Scilit]
  150. Nayyer, N.; Javaid, N.; Akbar, M.; Aldegheishem, A.; Alrajeh, N.; Jamil, M. A New Framework for Fraud Detection in Bitcoin Transactions Through Ensemble Stacking Model in Smart Cities. IEEE Access 2023, 11, 90916–90938. [Google Scholar] [CrossRef] [Scilit]
  151. Garcia-Grau, F.; Herrera-Joancomarti, J.; Josa, A.D. Anonymous Access System with Limited Number of Uses in a Trustless Environment. Appl. Sci. 2024, 14, 8581. [Google Scholar] [CrossRef] [Scilit]
  152. Feng, X.; Ma, J.; Wang, H.; Miao, Y.; Liu, X.; Jiang, Z. An Accessional Signature Scheme with Unmalleable Transaction Implementation to Securely Redeem Cryptocurrencies. IEEE Trans. Inf. Forensics Secur. 2023, 18, 4144–4156. [Google Scholar] [CrossRef] [Scilit]
  153. Sidorov, M.; Khor, J.; Chern Hao Wong, A.; Ying Lee, Y.; Li, J. A Lightweight Authentication Scheme for LoRaWAN Nodes Represented as On-Chain Nonfungible Tokens. IEEE Sens. J. 2024, 24, 28222–28232. [Google Scholar] [CrossRef] [Scilit]
  154. Khalil, U.; Uddin, M.; Malik, O.A.; Ong, O.W. A Novel NFT Solution for Assets Digitization and Authentication in Cyber-Physical Systems: Blueprint and Evaluation. IEEE Open J. Comput. Soc. 2024, 5, 131–143. [Google Scholar] [CrossRef] [Scilit]
  155. van Dam, G.; Kadir, R.A. Hiding payments in lightning network with approximate differentially private payment channels. Comput. Secur. 2022, 115, 102623. [Google Scholar] [CrossRef] [Scilit]
  156. Franzoni, F.; Salleras, X.; Daza, V. AToM: Active topology monitoring for the bitcoin peer-to-peer network. Peer-to-Peer Netw. Appl. 2022, 15, 408–425. [Google Scholar] [CrossRef] [Scilit]
  157. Franzoni, F.; Daza, V. SoK: Network-Level Attacks on the Bitcoin P2P Network. IEEE Access 2022, 10, 94924–94962. [Google Scholar] [CrossRef] [Scilit]
  158. Tian, H.; Xue, K.; Luo, X.; Li, S.; Xu, J.; Liu, J.; Zhao, J.; Wei, D.S.L. Enabling Cross-Chain Transactions: A Decentralized Cryptocurrency Exchange Protocol. IEEE Trans. Inf. Forensics Secur. 2021, 16, 3928–3941. [Google Scholar] [CrossRef] [Scilit]
  159. Venkatakrishnan, S.B.; Fanti, G.; Viswanath, P. Dandelion: Redesigning the Bitcoin Network for Anonymity. Proc. ACM Meas. Anal. Comput. Syst. 2017, 1, 1–34. [Google Scholar] [CrossRef] [Scilit]
  160. Fanti, G.; Bojja Venkatakrishnan, S.B.; Bakshi, S.; Denby, B.; Bhargava, S.; Miller, A.; Viswanath, P. Dandelion++: Lightweight Cryptocurrency Networking with Formal Anonymity Guarantees. Perform. Eval. Rev. 2018, 46, 5–7. [Google Scholar] [CrossRef] [Scilit]
  161. Rasslan, M.; Nasreldin, M.M.; Abdelrahman, D.; Elshobaky, A.; Aslan, H. Networking and cryptography library with a non-repudiation flavor for blockchain. J. Comput. Virol. Hacking Tech. 2024, 20, 1–14. [Google Scholar] [CrossRef] [Scilit]
  162. Zhang, Y.; Yang, D. RobustPay+: Robust Payment Routing with Approximation Guarantee in Blockchain-Based Payment Channel Networks. IEEE/ACM Trans. Netw. 2021, 29, 1676–1686. [Google Scholar] [CrossRef] [Scilit]
  163. Xie, H.; Yan, Z. SPCEX: Secure and Privacy-Preserving Cryptocurrency Exchange. IEEE Trans. Dependable Secur. Comput. 2024, 21, 4404–4417. [Google Scholar] [CrossRef] [Scilit]
  164. Zimba, A.; Wang, Z.; Chen, H.; Mulenga, M. Recent advances in cryptovirology: State-of-the-art crypto mining and crypto ransomware attacks. KSII Trans. Internet Inf. Syst. 2019, 13, 3258–3279. [Google Scholar] [CrossRef] [Scilit]
  165. Choi, N.; Kim, H. Decentralized Exchange Transaction Analysis and Maximal Extractable Value Attack Identification: Focusing on Uniswap USDC3. Electronics 2024, 13, 1098. [Google Scholar] [CrossRef] [Scilit]
  166. Kamisalic, A.; Kramberger, R.; Fister, I., Jr. Synergy of Blockchain Technology and Data Mining Techniques for Anomaly Detection. Appl. Sci. 2021, 11, 7987. [Google Scholar] [CrossRef] [Scilit]
  167. Muradyan, S.; Pcholovsky, N.; Sarbaev, G.; Vinogradova, K.; Vasyukov, V. Cryptocurrency as a priority means of terrorism financing in the digital economy. Rev. Gest. Tecnol.-J. Manag. Technol. 2022, 22, 161–175. [Google Scholar] [CrossRef] [Scilit]
  168. SJR—International Science Ranking. Available online: https://www.scimagojr.com/countryrank.php?area=1700 (accessed on 11 December 2025).
Figure 1. Scope of cybersecurity and cyber threats in cryptocurrency and NFT ecosystems.
Figure 1. Scope of cybersecurity and cyber threats in cryptocurrency and NFT ecosystems.
Applsci 16 01917 g001
Figure 2. Methodology used.
Figure 2. Methodology used.
Applsci 16 01917 g002
Figure 3. Articles published per year.
Figure 3. Articles published per year.
Applsci 16 01917 g003
Figure 4. Cluster diagram obtained with VOSviewer. Each cluster is identified by a unique colour.
Figure 4. Cluster diagram obtained with VOSviewer. Each cluster is identified by a unique colour.
Applsci 16 01917 g004
Figure 5. (A). Strategic analysis (2014–2020). (B). Strategic diagram (2021–2023). (C). Strategic diagram (2024–2025).
Figure 5. (A). Strategic analysis (2014–2020). (B). Strategic diagram (2021–2023). (C). Strategic diagram (2024–2025).
Applsci 16 01917 g005
Figure 6. Strategic diagram obtained with SciMAT.
Figure 6. Strategic diagram obtained with SciMAT.
Applsci 16 01917 g006
Figure 7. Temporal distribution of articles with “intrusion detection” as a keyword.
Figure 7. Temporal distribution of articles with “intrusion detection” as a keyword.
Applsci 16 01917 g007
Figure 8. Temporal distribution of the article set retrieved from Scopus.
Figure 8. Temporal distribution of the article set retrieved from Scopus.
Applsci 16 01917 g008
Figure 9. (A). The ‘blockchain’ cluster. (B). The ’emerging technologies’ cluster.
Figure 9. (A). The ‘blockchain’ cluster. (B). The ’emerging technologies’ cluster.
Applsci 16 01917 g009
Figure 10. (A). The ‘filesystem’ cluster (B). The ‘long short-term memory’.
Figure 10. (A). The ‘filesystem’ cluster (B). The ‘long short-term memory’.
Applsci 16 01917 g010
Figure 11. (A). The ‘illegal mining’ cluster. (B). The ‘cybersecurity’ cluster.
Figure 11. (A). The ‘illegal mining’ cluster. (B). The ‘cybersecurity’ cluster.
Applsci 16 01917 g011
Figure 12. (A). The ‘geometry’ cluster. (B). The ‘distributed ledger’ cluster.
Figure 12. (A). The ‘geometry’ cluster. (B). The ‘distributed ledger’ cluster.
Applsci 16 01917 g012
Figure 13. (A). The ‘licence’ cluster. (B). The ‘classification (of information)’.
Figure 13. (A). The ‘licence’ cluster. (B). The ‘classification (of information)’.
Applsci 16 01917 g013
Figure 14. (A). The ‘authentication’ cluster. (B). The ‘peer to peer’ networks.
Figure 14. (A). The ‘authentication’ cluster. (B). The ‘peer to peer’ networks.
Applsci 16 01917 g014
Figure 15. (A). The ‘vulnerabilities’ cluster. (B). The ‘real-world’ cluster.
Figure 15. (A). The ‘vulnerabilities’ cluster. (B). The ‘real-world’ cluster.
Applsci 16 01917 g015
Figure 16. The ‘intrusion detection’ cluster.
Figure 16. The ‘intrusion detection’ cluster.
Applsci 16 01917 g016
Table 1. Illustrative examples of keyword normalisation (excerpt; full mapping in Appendix A).
Table 1. Illustrative examples of keyword normalisation (excerpt; full mapping in Appendix A).
Original Keyword Variants (as Retrieved)Normalised Keyword (Used in Analysis)
“nfts”, “non-fungible token”, “non-fungible tokens”, “nonfungible token”, non-fungible tokens (nfts)“nft”
“machine-learning”, “machine learning techniques”“machine learning”
“block-chain”, “blockchains”, “blockchain technology”“blockchain”
“computer crime”, “cyber-crimes”, “cybercriminals”“cybercrime”
“privacy preserving”, “privacy-preserving techniques”“privacy”
“network layers”, “network node”, “network routing”“network architecture”
Table 2. Most relevant authors.
Table 2. Most relevant authors.
Author H-Index
(WoS)
Publications (WoS)Article Citations
(WoS)
Year of Publication DOI
Misic, J.31 377 Revisiting FAW attack in an imperfect PoW blockchain system 6 2022 10.1007/s12083-022-01360-1
Misic, V. 27 331 Delay Impact on Stubborn Mining Attack Severity in Imperfect Bitcoin Network 2 2024 10.1109/TNSE.2023.3344158
Salah, K. 52 220 Using composable NFTs and blockchain for the creation of EV battery digital passports with sustainability and traceability features 0 2025 10.1016/j.sftr.2025.100847
Wang, H. 38 214 SoK: On the security of non-fungible tokens 2 2025 10.1016/j.bcra.2024.100268
Yang, W. 2 3 SGuard+: Machine Learning Guided Rule-Based Automated Vulnerability Repair on Smart Contracts 12 2024 10.1145/3641846
Zhang, Y. 5 10 RobustPay+: Robust Payment Routing with Approximation Guarantee in Blockchain-Based Payment Channel Networks 29 2021 10.1109/TNET.2021.3069725
Zheng, Z. 83 596 Adaptive Double-Spending Attacks on PoW-Based Blockchains 7 2024 10.1109/TDSC.2023.3268668
Chen, J. 12 51 A jumping mining attack and solution 3 2020 10.1007/s10489-020-01866-2
Liu, Y. 39 309 DTAIS: Distributed trusted active identity resolution systems for the Industrial Internet 2 2024 10.1016/j.dcan.2023.06.006
Liu, J. 24 190 Dissecting Blockchain Network Partitioning Attacks and Novel Defense for Bitcoin and Ethereum 0 2025 10.1109/TIFS.2025.3585468
Table 3. Most relevant journals.
Table 3. Most relevant journals.
Publisher Number of Articles
IEEE Access 28
IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING 15
COMPUTERS & SECURITY6
PEER-TO-PEER NETWORKING AND APPLICATIONS 6
IEEE Transactions on Information Forensics and Security 6
SENSORS 6
IEEE INTERNET OF THINGS JOURNAL 6
Blockchain: Research and Applications 5
APPLIED SCIENCES-BASEL 5
Applied Sciences (Switzerland) 4
ELECTRONICS 4
IEEE TRANSACTIONS ON NETWORK SCIENCE AND ENGINEERING 4
INTERNATIONAL JOURNAL OF INFORMATION SECURITY 4
INFORMATION SCIENCES 4
Multimedia Tools and Applications 4
CMES—Computer Modeling in Engineering and Sciences 4
Journal of Information Security and Applications 4
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content.

Share and Cite

MDPI and ACS Style

Oliet-Villalba, J.-M.; Medina-Merodio, J.-A.; Ferrer-Oliva, M.; Martínez-Herraiz, J.-J. Cybersecurity in Cryptocurrencies and NFTs: A Bibliometric Analysis. Appl. Sci. 2026, 16, 1917. https://doi.org/10.3390/app16041917

AMA Style

Oliet-Villalba J-M, Medina-Merodio J-A, Ferrer-Oliva M, Martínez-Herraiz J-J. Cybersecurity in Cryptocurrencies and NFTs: A Bibliometric Analysis. Applied Sciences. 2026; 16(4):1917. https://doi.org/10.3390/app16041917

Chicago/Turabian Style

Oliet-Villalba, José-María, José-Amelio Medina-Merodio, Mikel Ferrer-Oliva, and José-Javier Martínez-Herraiz. 2026. "Cybersecurity in Cryptocurrencies and NFTs: A Bibliometric Analysis" Applied Sciences 16, no. 4: 1917. https://doi.org/10.3390/app16041917

APA Style

Oliet-Villalba, J.-M., Medina-Merodio, J.-A., Ferrer-Oliva, M., & Martínez-Herraiz, J.-J. (2026). Cybersecurity in Cryptocurrencies and NFTs: A Bibliometric Analysis. Applied Sciences, 16(4), 1917. https://doi.org/10.3390/app16041917

Note that from the first issue of 2016, this journal uses article numbers instead of page numbers. See further details here.

Article Metrics

Back to TopTop