Decomposing Ponzi Schemes: Multi-aspect Lifecycle Analysis for Detecting Fraudulent Smart Contracts
Yizhou Chen, Zeyu Sun, Guoqing Wang, Dan HaoSmart contracts have enabled decentralized financial applications, enabling trustless and transparent asset management. However, their programmability also expands the attack surface, allowing adversaries to encode fraudulent economic behaviors directly into contract logic. Among these threats, Smart Contract Ponzi Schemes (SCPS) represent a particularly harmful class of on-chain financial fraud, in which malicious developers mimic legitimate decentralized finance applications to extract unlawful value from users. Existing detection approaches using static analysis or deep learning often fail to capture SCPC-specific behaviors, while LLMs suffer from hallucinations and lack supervision. To address these limitations, we propose PonziLicle, a novel framework that enhances SCPC detection by systematically modeling the lifecycle behaviors of Ponzi schemes. Specifically, we analyze the typical life cycle of SCPCs and identify five behavioral perspectives that are closely tied to their structure: fund flow, profit logic, referral mechanism, withdrawal control, and camouflaged naming. For each perspective, we design tailored prompts and utilize LLMs to generate fine-grained, perspective-specific code explanations. To mitigate hallucinations, we employ static analysis to extract reliable, contract-level signals aligned with these perspectives, which are then used to calibrate and refine the LLM-generated explanations. Finally, we integrate the smart contract source code, static signals, and calibrated explanations to train a deep learning classifier for SCPC detection. Experimental results on 6,946 real-world smart contracts show that PonziLicle outperforms 7 state-of-the-art SCPC detection methods, achieving an F1-score of 0.958, with an increase of 10.26% to 122.31%.