A thorough investigation by USENIX Security ’26 has revealed 65,340 addresses on Ethereum and BNB Smart Chain classified as high risk, tying them to losses exceeding 126,982.94 ETH and 17,726.7 BNB.
Summary
- A comprehensive analysis uncovered 65,340 high-risk addresses on Ethereum and BNB Chain.
- Overall losses have reached approximately 126,982.94 ETH and 17,726.7 BNB, amounting to more than $574.8 million.
- For cross-chain analysis, researchers accessed 16.3 million private keys from 63,004 GitHub repositories.
- The detection system achieved a remarkable 99.11% accuracy following manual validation across the two blockchain networks.
- Two newly identified attack vectors exploited deterministic contract addresses and leveraged EIP-7702’s delegated account control features.
The study, shared at the 35th USENIX Security Symposium held in Baltimore, estimates the financial losses at over $574.8 million.
To put this number in perspective, the researchers calculated token losses based on reference prices of $4,408 for each ETH and $847 for each BNB, rather than using prices from the actual transaction times. They note that their findings represent a “conservative lower bound” because the analysis focuses solely on native ETH and BNB, potentially overlooking other less apparent losses.
Misuse of Ethereum Addresses: Risks in Contracts and Key Exposure
The study categorizes “Address Misuse” into two distinct types. The first, Contract Account misuse, occurs when users mistakenly treat a regular address as a contract address, often due to its use in different network contexts. Researchers reported 49,344 such cases, which led to losses amounting to 22,738.41 ETH and 8,681.41 BNB.
The second type, Externally Owned Account (EOA) misuse, involves addresses with compromised private keys or evident signs of control breaches. The study identified 15,996 instances of EOA misuse, which resulted in losses of 104,244.53 ETH and 9,045.29 BNB. Notably, over 95% of the losses in EOA misuse stem from instances where keys were exposed on GitHub.
Two New Attack Strategies Resulting in Roughly $15.7 Million Losses
The first attack method involves the creation of deterministic contract addresses. In this scenario, attackers promote a contract address on a test network, waiting for users to mistakenly send mainnet funds to this no-code address. Subsequently, they deploy withdrawal code at that same address. Researchers tracked 469 malicious contracts linked to a loss of 3,446.37 ETH and 431.79 BNB.
The second method exploits EIP-7702 against accounts with already compromised private keys. Attackers delegate these EOAs to malicious scripts that automatically siphon incoming funds. The paper reports 17,270 such instances, resulting in losses of 25.86 ETH and 33.45 BNB. Considering the reference values provided by the research, these two newly identified attack vectors account for approximately $15.7 million in losses.
Clarifying the 99.11% Precision Rate
The research team analyzed data from 63,004 GitHub repositories created between January 2015 and May 2025, uncovering 10.3 million unique candidate addresses and 16.3 million private keys after deduplication. They also utilized data from Ethereum Stack Exchange and Stack Overflow before examining transactions on both the Ethereum and BNB networks.
After manual sampling, the researchers reported an impressive detection precision of 99.11%. However, this does not imply that every one of the 65,340 cases was individually verified. The authors acknowledge potential heuristic false positives and gaps in the data, emphasizing that ERC-20 tokens, NFTs, and other chains were not included in the overall loss estimates.
Concerns About EIP-7702 Security Are Growing
The official guidance from Ethereum raises alarms regarding malicious EIP-7702 delegations, which may grant hostile contract code control over assets. A different study presented at USENIX Security ’26 highlighted that over 63% of analyzed EIP-7702 authorization transactions were linked to hostile actions targeting EOAs, identifying 924 malicious contract accounts across seven different chains.
Earlier reports indicated that EIP-7702 delegations were associated with automated wallet-draining actions following Ethereum’s Pectra upgrade. In related incidents, roughly $3.1 million was drained from Polymarket users due to phishing attacks and malicious delegated executions.
The researchers advocate for enhanced wallet warnings regarding known exposed keys and discrepancies between cross-chain contracts, improved secret management techniques for developers, and clearer documentation of address-to-network mappings. They also suggest considering chain identifiers in future methods for deriving contract addresses. These recommendations are suggestions for future research rather than immediate changes to Ethereum or BNB Chain protocols.
The team intends to expand their research to include additional chains and token categories in future projects. For now, the reported losses of 126,982.94 ETH and 17,726.7 BNB should be understood as the measured losses within the defined scope of the study, while the estimated total of $574.8 million serves as a standard valuation reference.
