Study links 65,340 Ethereum and BNB Chain address misuse cases to $574.8 million in losses

An academic study identified 65,340 high-risk address misuse cases on Ethereum and BNB Chain that were tied to about $574.8 million in lost crypto, highlighting a quieter but persistent security risk beyond headline hacks. The research separates the problem into Contract Account misuse, where users interact with an address as if smart contract code exists there, and Externally Owned Account misuse, where funds are sent to addresses with exposed private keys. Researchers counted 49,344 Contract Account misuse cases, with losses of 22,738.41 ETH and 8,681.41 BNB, and 15,996 Externally Owned Account misuse cases, with losses of 104,224.53 ETH and 9,045.29 BNB. The study also found active exploitation: attackers used cross-chain address reuse in 469 Contract Account misuse cases to deploy malicious contracts at addresses holding trapped funds, causing 3,446.37 ETH and 431.79 BNB in losses, while 17,270 cases involved EIP-7702, a feature that lets an externally owned account delegate execution to a smart contract, enabling attackers to automatically divert incoming funds from exposed accounts. The researchers examined more than 10 million candidate addresses, 16 million exposed private keys and about 2.5 million transactions on Ethereum and BSC, with manual checks showing 99.11% precision. The findings suggest that a transaction can complete onchain without achieving the user’s intended action, especially when a familiar address is valid on one network but has no contract code on another. The study urges users to verify the network, rely on official project documentation and keep test accounts separate from production funds, while calling on wallets to warn when an address lacks contract code on the current chain or is linked to a known exposed private key.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.