EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

New study: Ethereum address error caused $575 million in cryptocurrency losses

2026-08-17 12:36:55
Bookmark

Ethereum address errors expose cross-chain transfer risks

Private key leakage and EIP-7702 amplification user threat

Ethereum address errors have been linked to 65,340 high-risk cases, causing nearly US$574.8 million in losses on Ethereum and BNB Chain.

Contract account misuse involved 49,344 cases, with a total of 22,738.41 ETH and 8,681.41 BNB being sent to addresses missing the expected code.

Private key leaks resulted in 15,996 account misuse cases involving 104,224.53 ETH and another 9,045.29 BNB on two blockchains.

Researchers identified 17,270 cases of EIP-7702 in which malicious commissions helped attackers control exposed accounts and redirect deposits.

An academic study linked Ethereum address errors and similar lapses on BNB Chain to nearly $574.8 million in losses. Researchers identified 65,340 high-risk cases involving contract addresses, exposed accounts, and cross-chain reuse. Many transactions complete successfully despite users sending assets to the wrong target or unsafe account. This makes the problem more difficult to detect than a failed transfer. The research team includes scholars from Sun Yat-sen University, Zhejiang University, Peking University and other universities. Their work traces the misuse of cryptocurrency addresses on Ethereum and BNB smart chains, and demonstrates how EIP-7702 helps attackers seize exposed accounts and automatically redirect funds into them.


Incorrect Ethereum address exposes cross-chain transfer risk

Researchers divided the problem into contract account misuse and external account misuse. Contract account misuse occurs when a user assumes that a contract exists at a familiar address. This assumption may fail when users switch networks. The same hexadecimal address may have workable code on the test network, but nothing on the main network.

This study documented 49,344 independent contract misuse cases involving 22,738.41 ETH and 8,681.41 BNB. These Ethereum address errors look like routine operations. The transfer may be confirmed even if the expected contract function is never performed. The network simply views the call as a basic payment to an address without code.

A shared Uniswap V2 router address illustrates this danger. Developers have used it on Ethereum's Sepolia test site, and related Stack Exchange posts have attracted more than 102,000 views. However, the address does not have a contract code on the Ethereum main network. The user still submits the function call with ETH attached. The chain accepts these transactions as simple transfers, resulting in assets being locked up.

Attackers monitor addresses affected by misuse of cryptocurrency addresses. The team identified 469 contract cases involving deliberate cross-chain address reuse. The attacker deployed malicious contracts on the target chain where users had previously mistransferred funds. These incidents resulted in losses of 3,446.37 ETH and 431.79 BNB. This approach turns previous mistakes into opportunities for proactive theft.

These findings suggest that Ethereum address errors require chain-specific inspections. An identifiable address does not in itself confirm the existence of an expected contract. Users must verify both the selected network and the deployed bytecode before signing a transaction.


Private key disclosure and EIP-7702 amplification of user threats

Ethereum address errors also include external account misuse. The study identified 15,996 cases related to online disclosure of private keys. Developers sometimes publish private keys in code warehouses, tutorials, or Q & A posts. Attackers can monitor these accounts and transfer funds as soon as they arrive.

These exposed accounts received 104,224.53 ETH, while the associated BNB Chain loss reached 9,045.29 BNB. Researchers examined more than 10 million candidate addresses and 16 million leaked private keys. They then reviewed approximately 2.5 million transactions on the Ethereum and BNB smart chains. Manual verification showed that the overall accuracy of the detection system was 99.11%.

EIP-7702 expands the dangers surrounding Ethereum address errors. This upgrade allows external accounts to delegate execution to smart contract code. Researchers found an additional 17,270 cases where attackers used the mechanism to target exposed accounts. Malicious delegation achieves automatic control and redirects subsequent deposits without repeated manual operations.

These losses coexist with broader security damage recorded in 2026. According to Blockaid,$1.1 billion was stolen in 212 incidents in the first half of the year. In one day in late July, three separate attacks each caused more than $35 million in damage. Unlike visible vulnerability attacks, cryptocurrency address misuse may look like an ordinary confirmed transaction.

Researchers urge users to obtain addresses from official project documents. Test accounts and production wallets should also remain separate. Wallet can mark addresses missing contract codes on the current chain. Wallets can also issue warnings when a known leaked private key controls a target address. Such checks will prevent Ethereum address errors before users approve irreversible transfers.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP