EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Ethereum and BNB chain address errors caused US$574.8 million in crypto asset losses

2026-08-17 12:36:25
Bookmark

Academic research reveals that Ethereum and BNB chain address errors caused nearly US$574.8 million in cryptocurrency losses

A comprehensive academic study traced that cryptocurrency losses caused by Ethereum and BNB chain address errors reached nearly US$574.8 million, highlighting the significant risks faced by users of these two blockchains. The analysis identified 65,340 high-risk events, showing that assets were often sent to wrong or unsafe accounts, while transactions were still confirmed as successful.

Researchers found widespread contract abuse

Research teams from universities such as Sun Yat-sen University, Zhejiang University and Peking University conducted in-depth discussions on the root causes of these losses. The research team focused on two major issues: contract account abuse and externally owned account abuse. Research results show that contract account abuse usually occurs when users assume a contract exists at an address. This assumption is particularly prone to error when switching networks, because an address containing code on one blockchain may not function as expected on another blockchain.

Research documented 49,344 cases of contract address abuse, resulting in losses of 22,738.41 ETH and 8,681.41 BNB. Since most blockchain transactions are confirmed even if the target address lacks the correct contract code, users are often unaware that their assets have been trapped or mistransferred.

A well-known example involves the Uniswap V2 router address, which appears on Ethereum's Sepolia test network, but lacks the contract code on the Ethereum main network. Despite this, users continue to send function calls and ETH to the address, making their cryptocurrency inaccessible.

Attackers exploit such incidents to deploy malicious contracts on previously abused addresses. In 469 analysis cases, this cross-chain address reuse behavior resulted in an additional loss of 3,446.37 ETH and 431.79 BNB. This strategy allows criminals to take advantage of a user's previous mistakes and turn them into proactive theft.

Researchers have found that thousands of contract addresses reused across blockchains have become targets for attackers. By deploying malicious contracts at these addresses, criminals intercept user funds who mistakenly believe they are interacting with trusted smart contracts.

Key breach and EIP-7702 extended user vulnerability

Externally owned account abuse also played a significant role in the recorded losses. The study found that in 15,996 cases, exposed private keys-often posted on code warehouses, tutorials or Q & A forums-allowed attackers to monitor and steal accounts immediately after users deposited funds.

These compromised accounts received a total of 104,224.53 ETH and 9,045.29 BNB. The researchers analyzed more than 10 million potential addresses and 16 million exposed private keys, verifying approximately 2.5 million transactions on the Ethereum and BNB chains. Its accuracy in detecting affected accounts is as high as 99.11%.

Security risks have been further exacerbated by the introduction of EIP-7702, which allows externally owned accounts to delegate enforcement rights to smart contract code. This allows attackers to automatically control compromised accounts and reroute future deposits without human intervention. The research team documented 17,270 such cases in which malicious commissions helped criminals control and steal exposed wallets.

These vulnerabilities, along with broader blockchain security vulnerabilities, continue to surface. According to Blockaid, a total of 212 incidents occurred in the first half of 2026, with $1.1 billion stolen, and losses in a single day sometimes exceeding $35 million. Unlike major hacking attacks, many Ethereum address errors manifest as ordinary confirmed transactions, making them more difficult to detect and process in a timely manner.

Emphasis on user education and proactive monitoring tools

Researchers emphasize that users should strictly obtain wallet addresses from official project documents and maintain the separation of test accounts and production accounts. Enhanced wallet software and monitoring systems can also help prevent risks. Specifically, the wallet is programmable to proactively issue an alert when a user attempts to send funds to an address where a contract code is detected missing on the chain, or an address known to be associated with the exposed private key.

In the rapidly changing cryptocurrency market, where sudden altcoin listings or Federal Reserve decisions can change the landscape in seconds, efficient and secure monitoring becomes crucial. Continuously switching between different applications such as charts, news and portfolio tracking can cost investors high prices. As a result, more and more traders are adopting privacy-first solutions, such as CryptoAppsy, which provides integrated real-time charts, smart price reminders, specific token-specific news, and key macroeconomic data without the need to register an account, and all functions are done within one interface.

Research shows that conducting thorough on-chain inspections and improving wallet alerts can significantly reduce the risk of irreversible loss due to Ethereum address errors, and urges users to exercise caution before confirming critical transactions.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP