Bitcoin

Bitcoin

$ 62,776.00

BTC (24h)

-1.50%
Etherum

Ethereum

$ 1,873.83

ETH (24h)

-0.80%
BNB

Binance

$ 605.15

BNB (24h)

-1.10%
XRP

XRP

$ 1.00

XRP (24h)

-0.90%
Cryptocurrency News

$574.8M at Risk Across 65,000 Compromised Ethereum and BNB Wallets

A USENIX Security 2026 study recognized 65,340 high-risk address misuses across Ethereum and BNB Smart Chain. This links them to losses of 126,982.94 ETH and 17,726.7 BNB in native tokens. Researchers assessed those losses at more than $574.8 million, using reference prices rather than market prices at the time of individual transactions.

Researchers extracted 16.3 million private keys from 63,004 GitHub repositories for their cross-chain analysis dataset and developed a framework that achieved 99.11% precision after manual sampling validation. The researchers divided address misuse into two categories: contract account misuse and externally owned account misuse. Contract account misuse happens when users treat an address without deployed contract code as a contract address. 

The study identified 49,344 such cases, resulting in losses of 22,738.41 ETH and 8,681.41 BNB. EOA misuse contains addresses whose private keys have been revealed or show strong on-chain signs of compromised control. Researchers identified 15,996 instances of EOA misuse, resulting in losses of 104,244.53 ETH and 9,045.29 BNB. More than 95% of EOA misuse came from the GitHub-exposed key subtype.

10.3 million unique candidate addresses and 16.3 million private keys were retraced after deduplication across multiple GitHub repositories created between January 2015 and May 2025. The context also incorporated data from Ethereum Stack Exchange and Stack Overflow before assessing transactions on Ethereum and BNB Smart Chain. The team manually checked the results but did not verify every one of those 65,340 instances, so while the model is precise, the claims of accuracy aren’t universally verified. The author also mentioned possible heuristic false positives and incomplete data. So, there’s a significant level of concern that everyone needs to exercise here. 

Two Newly Described Attack Vectors Account for $15.7M 

The study describes the two novel identified attack routes that together account for roughly $15.7 million in losses, based on the paper’s reference prices. The first attack exploits deterministic contract address creation. Attackers can promote a contract address on testnet and wait for users to send mainnet funds to the same address, even though no contract code has been embedded. Attackers can later deploy withdrawal code to the same location. Researchers linked 469 malicious contracts to losses of 3446.37 ETH and 431.79 BNB.

The second attack involves EIP-7702, an account whose private keys have already been revealed. Attackers can assign those EOAs to malicious code that can automatically sweep incoming funds. The study identified 17,246 cases. This resulted in losses of 25.86 Ethereum and 33.45 BNB. EIP-7702 security issues have also extended beyond the newly discussed attack vector. Ethereum’s official guidance warns that unauthorized EIP-7702 delegation can give hostile contract code control over assets.

The researchers valued the losses using reference final prices of $4,408 per ETH and $847 per BNB, rather than prices of individual transactions. The researchers mentioned the figure as a conservative lower bound because the analysis covers only native ETH and BNB on the two networks. ERC-20 tokens, NFTs, and other blockchain networks are excluded from the headline loss calculation.

As a result, the 126,982.94 ETH and 17,726.7 BNB figures should be viewed as measured native-token losses within the study’s defined scope, rather than an estimate of all losses resulting from address misuse. The authors recommended wallet warnings for known revealed keys and cross-chain contract mismatches, better secret management for developers, and clearer address-to-network documentation. They also suggested considering chain identifiers in future contract address derivation. The recommendations remain proposals from the researchers and do not signify adopted changes to the Ethereum or BNB chain protocols. The team plans to extend this research to extra chain and token types in the future, potentially broadening the picture of losses associated with high-risk address misuse.

Amitesh Dhar

Amitesh Dhar is a writer and editor at Coin News Span, bringing years of experience in digital publishing and content creation to the world of cryptocurrency and blockchain. Known for his clear writing and analytical approach, Amitesh is dedicated to making complex tech topics accessible and engaging for all readers. With a strong background in editorial roles at platforms such as CharlieIntel, and Sportskeeda, he combines technical know-how with editorial excellence to ensure every article is accurate, insightful, and up-to-date.