EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Research: Ethereum and BNB chain address errors caused $575 million in losses

2026-08-17 12:37:06
Bookmark

New study: Address misuse on the Ethereum and BNB chains leads to approximately US$574 million in losses

A new academic study found 65340 high-risk address misuse cases on the Ethereum and BNB chains, involving approximately US$574 million in cryptocurrency losses. The study shows that common errors involving test net addresses, reused contract addresses, and exposed private keys can cause permanent damage, while new tools such as EIP-7702 provide new avenues for attackers to exploit them.

Address errors cause millions of dollars in losses

This study, led by researchers from Sun Yat-sen University, Zhejiang University, Peking University and other institutions, described two forms of address misuse: contract account misuse and external account misuse.

Contract account misuse refers to when a user uses a non-contract address as an address with a smart contract. Researchers found 49344 such cases, involving the loss of 22,738.41 ETH and 8,681.41 BNB. One example involves Ethereum Sepolia testing the widely used Uniswap V2 router address on the Internet. The address was viewed more than 102,000 times in Stack Exchange posts and frequently used for testing, but on the Ethereum main website, the address did not have a contract code at the time, and users still sent it function calls and ETH. The transaction was successfully executed in the form of a simple transfer, and the funds were trapped as a result.

There were another 15996 cases of misuse of external accounts where the private keys of these addresses were exposed, usually through public code warehouses or developer question and answer websites. The study found that the resulting losses amounted to 104,224.53 ETH and 9,045.29 BNB.

The researchers examined more than 10 million candidate addresses and 16 million exposed private keys, and then analyzed approximately 2.5 million transactions on Ethereum and BSC. After manual inspection, the overall accuracy rate of the detection system reached 99.11%.

Research also found that attackers proactively exploit these errors. In 469 contract account misuse cases, the attacker used cross-chain address reuse to deploy malicious contracts at addresses where users had trapped funds, resulting in the loss of 3,446.37 ETH and 431.79 BNB. Another 17270 cases involved EIP-7702, a mechanism that allows external accounts to delegate enforcement rights to smart contracts. Researchers found that attackers used this mechanism to control exposed accounts and automatically transfer transferred funds away.

Why familiar addresses become traps

These findings add another type of risk to the security issues that have affected cryptocurrencies this year. A report released on August 1 showed that a total of 212 security incidents occurred in the first half of 2026, with $1.1 billion stolen. Among them, three incidents occurred in one day at the end of July alone, causing more than $35 million in losses each. attack.

Address misuse research points to a less obvious problem: a transaction may be executed successfully but still result in a loss. Users may think that a successful transaction means they interact with the expected contract when in fact the address has no code at all on a particular network.

Researchers note that people should check the Internet before using addresses and rely on official project documents, while isolating test accounts from production funds. They also called on wallets to warn users when there is no contract code on the current chain of addresses, or when the private key is known to be exposed.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP