VLDB 2026 Research / reviewers in the wild / expert
André Augusto
dblp:352/1200
· DBLP profile ↗
4ranked-venue papers
4as first author
4since 2021 · last 2025
0000-0001-7020-2087ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 3 first-author · 3 since 2021Software engineering, systems software and programming languages · 3 · 3 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | XChainWatcher: Identifying Anomalies in Cross-Chain BridgesabstractCross-chain bridges are a blockchain interoperability middleware that supports the transfer of assets and data across blockchains. However, several of these bridges have vulnerabilities that have caused 3.2 billion dollars in losses since May 2021. Some studies have revealed the existence of these vulnerabilities, but there is little quantitative research available, and there are no safeguard mechanisms to protect bridges from such attacks. Furthermore, no studies are available on the practices of cross-chain bridges that can cause financial losses. We propose XChainWatcher (Cross-Chain Watcher), a modular and extensible logic-driven anomaly detector for cross-chain bridges. It operates in three main phases: (1) decoding events and transactions from multiple blockchains, (2) building logic relations from the extracted data, and (3) evaluating these relations against a set of detection rules. Using XChainWatcher, we analyze data from two previously attacked bridges: the Ronin and Nomad bridges. XChainWatcher successfully identified the transactions that led to losses of $611M and $190M (USD) and surpassed the results obtained by a reputable security firm in the latter. We not only uncover successful attacks, but also reveal other anomalies, such as 37 cross-chain transactions (cctx) that should not have accepted, failed attempts to exploit Nomad, over $7.8M worth of tokens locked on one chain but never released on Ethereum, and $200K lost by users due to inadequate interaction with bridges. We provide the first open dataset of 81,000 cctxs across three blockchains, capturing more than $4.2B in token transfers. André Augusto, Rafael Belchior, Jonas Pfannschmidt, André Vasconcelos 0001, Miguel Correia 0001 |
Middleware | 1 |
| 2024 | Multi-Party Cross-Chain Asset TransfersabstractExisting interoperability mechanisms usually en-compass asset exchanges, asset transfers, and general data transfers. However, most of the solutions based on these mechanisms work only for pairs of permissionless blockchains, falling short in use cases that require more complex business relationships. Furthermore, contrary to existing legacy systems, there is little standardization for cross-domain communication, which multiple players in industry and academia are exploring. We present the Multi-Party Secure Asset Transfer Protocol (MP-SATP), a resilient multi-party asset transfer protocol built on top of the Secure Asset Transfer Protocol (SATP), which is being developed by theInternet Engineering Task Force(IETF). Furthermore, we enhance SATP’s crash recovery mechanism to improve the reliability and performance of our solution. Using MP-SATP, we explain how to perform N -to-N resilient asset transfers in permissioned environments by decoupling them into multiple 1-to-1 asset transfers. Our results show that the latency of the protocol is driven by the latency of the slowest 1-to-1 session and that the use of backup gateways avoids the overhead caused by rollbacks. André Augusto, Rafael Belchior, André Vasconcelos 0001, Miguel Correia 0001, Thomas Hardjono |
ICBC | 1 |
| 2024 | SoK: Security and Privacy of Blockchain InteroperabilityabstractRecent years have witnessed significant advancements in cross-chain technology. However, the field faces two pressing challenges. On the one hand, hacks on cross-chain bridges have led to monetary losses of around 3.1 billion USD, highlighting flaws in security models governing interoperability mechanisms and the ineffectiveness of incident response frameworks. On the other hand, users and bridge operators experience restricted privacy, which broadens the potential attack surface.In this paper, we present the most comprehensive study to date on the security and privacy of blockchain interoperability. We employ a systematic literature review, yielding a corpus of 212 relevant documents, including 58 academic papers and 154 gray literature documents, out of a pool of 531 results. We systematically categorize 57 interoperability solutions based on a novel security and privacy taxonomy. Our dataset, comprising academic research, disclosures from bug bounty programs, and audit reports, exposes 45 cross-chain vulnerabilities, 4 privacy leaks, and 92 mitigation strategies. Leveraging this data, we analyze 18 notable bridge hacks accounting for over 2.9 billion USD in losses, mapping them to the identified vulnerabilities.Our findings reveal that a substantial portion (65.8%) of stolen funds originates from projects secured by intermediary permissioned networks with unsecured cryptographic key operations. Privacy-wise, we demonstrate that achieving unlinkability in cross-chain transactions is contingent on the underlying ledgers providing some form of confidentiality. Our study offers 17 critical insights into the security and privacy of cross-chain systems. We pinpoint promising future research directions, underscoring the urgency of enhancing security and privacy efforts in cross-chain technology. The identified improvements have the potential to mitigate the financial risks associated with bridge hacks, fostering user trust in the blockchain ecosystem and, consequently, wider adoption. André Augusto, Rafael Belchior, Miguel Correia 0001, André Vasconcelos 0001, Luyao Zhang 0001, Thomas Hardjono |
SP | 1 |
| 2023 | CBDC Bridging between Hyperledger Fabric and Permissioned EVM-based BlockchainsabstractThe last few years have seen a steep increase in blockchain interoperability research. Most solutions connect public blockchains, where the main cross-chain use case is token transfer. By-design platform transparency, tamper resistance, and auditability make blockchains a candidate infrastructure for Central Bank Digital Currencies (CBDCs), but bridging CBDCs is an important missing piece in that scenario. In this paper, we leverage an asset transfer protocol, SATP, to define an extendable and dependable blockchain interoperability middleware that can bridge CBDC between Hyperledger Fabric and EVM-based permissioned blockchains. The key interoperation enabler in the solution is a shared asset definition enforced by both sides of the bridge, accompanied by a mapping between Fabric identities and Ethereum addresses for identity management. We implemented our design using Hyperledger Cacti. A preliminary evaluation shows that latency is more influenced by the ledgers than the bridging components. André Augusto, Rafael Belchior, Imre Kocsis, László Gönczy, André Vasconcelos 0001, Miguel Correia 0001 |
ICBC | 1 |