CBT Program
Thursday, 17th September 2026
- 08:00 – 08:45 (CEST — UTC+02:00) Workshop Registration
- 08:45 – 09:00 (CEST — UTC+02:00) Opening remarks
- 09:00 – 10:00 (CEST — UTC+02:00)
Joint Keynote (CBT, DPM, CyberICPS, STM, SECAI & TCI)
- Does machine learning compromise the privacy of training data?. Josep Domingo-Ferrer (Universitat Rovira i Virgili).
- Machine learning (ML) models are often trained on personal or otherwise sensitive data. For example, ML models are trained on health data supplied by smartphones or sensitive data coming from IoT sensors. In several jurisdictions, the legal framework for the publication and disclosure of personal data is being extended to ML. This is based on the implicit assumption that disclosing a trained ML model poses a similar privacy risk to the personal data used to train it as directly publishing those data. However, with a trained model, it is necessary to carry out a privacy attack to draw inferences from the training data. In this talk, I examine the main families of privacy attacks against predictive and generative ML, including membership inference attacks (MIAs), property inference attacks, and reconstruction attacks. This analysis shows that most of these attacks appear to be less effective in the real world than might be suggested by a prima facie interpretation of the relevant literature. The talk will conclude by highlighting the role of privacy attacks to assess machine unlearning for privacy, and the potential clash between machine unlearning and blockchain-recorded ML.
- 10:00 – 10:30 (CEST — UTC+02:00) COFFEE BREAK
- 10:30 – 12:30 (CEST — UTC+02:00)
DECENTRALIZED FINANCE Chair: Jordi Herrera Joancomartí (Universitat Autònoma de Barcelona, Catalonia)
- ScamTracer: Proactive DeFi Scam Detection through Integrated On-Chain and Off-Chain Signals. Bahareh Parhizkari, Antonio Ken Iannillo, Ed Zulkoski and Radu State.
- A Light-Client Bridge for Confidential Notes on QBFT Permissioned Ledgers. Pietro Tiberi, Vitangelo Lasorella and Gabriele Marcelli.
- TraceSVM: A Framework for Reverse-Engineering and Analysing Solana's Proprietary AMMs. Florian Klein, Ferdinando Samaria and Frank Stajano.
- Incentives and Market Structure in Intent-Based Exchanges: Evidence from a Solver-Reward Reform. Ruiyang Zhang.
- Pricing the DeFi Tail: Do Protocols or Depositors Price Operational Risk?. Nils Bundi.
- 12:30 – 13:50 (CEST — UTC+02:00) LUNCH BREAK
- 13:50 – 15:20 (CEST — UTC+02:00)
ATTACKS & DEFENSES Chair: Josep Domingo-Ferrer (Universitat Rovira i Virgili, Catalonia)
- Slow and Steady: Preventing MEV with Verifiable Delays. Zeta Avarikioti, Dimitris Karakostas, Karl Kreder and Shreekara Shastry.
- Formalizing PQC Signature Transition: Case of PoW Blockchain Against On-Spend Attack. Kigen Fukuda and Shin'Ichiro Matsuo.
- One-Block-Capped Withholding. Jie Liu.
- 15:20 – 15:40 (CEST — UTC+02:00) COFFEE BREAK
- 15:40 – 17:10 (CEST — UTC+02:00)
PRIVACY Chair: TBC
- Threshold Collaborative Rate Limiting Nullifier Signaling with Membership Privacy. Yağmur Gürel, Uğur Şen and Oğuz Yayla.
- DSphinx: A Decentralized Path Selection for Decentralized Networks. Aurélien Chassagne, Iness Ben Guirat, Jan Tobias Mühlberg, Jean-Michel Dricot and Manuel Mota Leal Dias.
- Proof-of-Uniqueness: Sybil-Resistant Privacy-Preserving Decentralized Identity through Threshold-OPRF and zk-SNARK Registry. Adam Vožda, Martin Perešíni and Ivan Homoliak.
- CBT FAREWELL
- 17:10 – 17:30 (CEST — UTC+02:00) Conference Info
Aims and Scope
Since the emergence of Bitcoin in 2009, a wide array of cryptocurrencies and blockchain-based systems have been introduced, achieving varying degrees of adoption and success. While some of these projects are incremental variations of Bitcoin, others present novel consensus mechanisms, governance models, privacy-enhancing technologies, or explore use cases beyond digital currency—such as decentralized finance (DeFi), non-fungible tokens (NFTs), decentralized autonomous organizations (DAOs), and scalable Layer 2 solutions. Despite these innovations, many proposed systems are released as rapid prototypes or proof-of-concept implementations, often lacking rigorous scientific evaluation.
This workshop aims to serve as a dedicated forum for researchers to critically assess existing systems, explore emerging paradigms such as zero-knowledge proofs, cross-chain interoperability, and sustainable consensus, and propose robust frameworks that contribute to a sound scientific foundation for the ongoing development of blockchain technologies and next-generation decentralized systems.
Topics
The main topics include (but are not limited to):
- Anonymity and privacy in cryptocurrencies
- Blockchain Governance
- Privacy-preserving technologies
- Blockchain based trust systems
- Security analysis of existing cryptocurrencies
- Formal threat models in cryptocurrency systems
- Scalability and Performance Optimization
- Second Layer Solutions
- P2P network cryptocurrencies analysis
- Blockchain-based Identity Management
- Private transactions in blockchain based systems
- New usages of the blockchain technology
- Scalability solutions for blockchain systems
- Interoperability and Cross-Chain Technologies
- Distributed consensus and fault tolerance
- Blockchain Analytics and Forensics
- Blockchain Architecture and Consensus Mechanisms
- On-chain and off-chain code synergies
- Smart Contracts and Decentralized Applications (DApps)
- NFTs (Non-Fungible Tokens) and Digital Assets
- Decentralized Finance (DeFi)
- Blockchain Education and Adoption Challenges
- Post-Quantum Cryptography and Blockchain Security
Program Commitee
PC Chairs:
Victor Garcia-Font Universitat Oberta de Catalunya (UOC)
Jordi Herrera-Joancomartí - Universitat Autònoma de Barcelona (UAB)
Cristina Pérez-Solà - Universitat Autònoma de Barcelona (UAB)
PC Members (temptative list):
- Lennart Ante, Blockchain Research Lab gGmbH
- Daniel Augot, INRIA Saclay--Île-de-France & LIX
- Alex Biryukov, University of Luxembourg
- Rainer Böhme, University of Innsbruck
- Jeremy Clark, Concordia University
- Mauro Conti, Padova University
- Vanesa Daza, Universitat Pompeu Fabra
- Co-Pierre Georg, Deutsche Bundesbank
- Dongning Guo, Northwestern University
- Hannes Hartenstein, Karlsruhe Institute of Technology
- Ethan Heilman, Boston University
- Dorjan Hitaj, Sapienza University of Rome
- Xiapu Luo, The Hong Kong Polytechnic University
- Shin'Ichiro Matsuo, Georgetown University
- Pedro Moreno-Sanchez, IMDEA Software Institute
- Guillermo Navarro-Arribas, Autonomous University of Barcelona
- Charmaine Ndolo, Dresden University of Technology
- Mohammad Pishdar, KU Leuven
- Friman Sánchez, Universitat Oberta de Catalunya
- Weidong Shi, University of Houston
- Hitesh Tewari, Trinity College Dublin
- Dimitrios Vasilopoulos, SnT University of Luxembourg
- Edgar Weippl, University of Vienna
Call for papers
Regular and short papers: Papers must be original and not
submitted for publication elsewhere. Authors are invited to submit
their manuscripts following the LNCS Proceedings Manuscript style.
Papers are limited to 16 pages (full papers), or 8 pages (short
papers) including references and appendices. Paper must be
submitted in PDF format using
the
ESORICS 2026 submission entry at easychair and selecting the
10th Cryptocurrencies and Blockchain Technology workshop
Double blind review: CBT requires anonymized submissions
— please make sure that submitted papers contain no author names
or obvious self-references.
Accepted conference papers will be published by Springer in the LNCS
collection. At least one author of each accepted paper is required to
cover a full registration and present their work at the workshop;
otherwise the paper will not be included in the proceedings.
Venue
The workshop will be held in Rome, Italy, in collaboration with the 31th annual European Symposium on Research in Computer Security, ESORICS 2026. More information on accommodation and venue will be available at the ESORICS 2026 website
Registration
Information about the registration is available at the ESORICS 2026 website.
Kindly use this link to register for the workshop (CBT 2026). Some important information follows:
- At least one regular registration (e.g., a non-student registration) has to be made for each accepted paper at the workshop.












