Skip to main content

Investigation Reveals $575M Vanished From Ethereum And BNB Address Flubs 🖤🦇

A fresh academic dive into the blockchain shadows has spotted 65340 high-risk address mix-ups on Ethereum and BNB Chain, tied to roughly 574.8 million dollars in vanished crypto. 🕸️ The research highlights how everyday slip-ups with testnet addresses, reused contracts, and leaked private keys turn into forever losses, while fresh tools like EIP-7702 hand attackers extra sneaky paths.

Address Mistakes Account for Millions in Losses 🖤

The study, led by researchers from Sun Yat-sen University, Zhejiang University, Peking University, and other institutions, describes two forms of address misuse: Contract Account (CA) Misuse and Externally Owned Account (EOA) Misuse. CA Misuse occurs when users treat a non-contract address as if a smart contract lives there. The researchers uncovered 49344 such cases, involving 22738.41 ETH and 8681.41 BNB in losses. 🌑 One striking case involved a Uniswap V2 router address widely used on Ethereum’s Sepolia testnet. The address had more than 102000 views across Stack Exchange posts and was used frequently for testing, but on Ethereum mainnet, it had no contract code at the time, yet users still sent function calls and ETH to it. The transactions succeeded as simple transfers, leaving the funds trapped. EOA Misuse accounted for another 15996 cases, which involved addresses whose private keys had been exposed, often through public code repositories or developer Q&A sites. The study found losses of 104224.53 ETH and 9045.29 BNB. 🔮 The researchers examined more than 10 million candidate addresses and 16 million exposed private keys, then analyzed about 2.5 million transactions on Ethereum and BSC. Manual checks gave the detection system an overall precision of 99.11%. The study also found that attackers actively exploit these mistakes. In 469 CA misuse cases, attackers used cross-chain address reuse to place malicious contracts at addresses where users had already trapped funds, resulting in 3446.37 ETH and 431.79 BNB in losses. 💀 Another 17270 cases involved EIP-7702, which lets an externally owned account delegate execution to a smart contract. The researchers found attackers using the mechanism to control exposed accounts and automatically redirect incoming funds.

Why Familiar Addresses Can Become a Trap 🕯️

The findings add a different type of risk to the security problems already affecting crypto this year. A Blockaid report published on August 1 found 1.1 billion dollars stolen across 212 incidents during the first half of 2026, with three separate attacks that caused more than 35 million dollars in losses occurring in one day in late July. The address misuse study points to a less obvious problem: a transaction can succeed while still producing a loss. Users may assume that a successful transaction means they interacted with the intended contract, even when the address has no code on that particular network. According to the researchers, people ought to check the network before using an address and rely on official project documentation while keeping test accounts away from production funds. 🦇 They also called for wallets to warn users when an address has no contract code on the current chain or has a known exposed private key. 👁️


Just another echo from the void by iconofsin.eth 💖


Maybe you like what i'm doing here and wanna support me via the ethereum blockchain: iconofsin.eth 💖

Leave a Reply