Study Finds $575M Lost Through Ethereum and BNB Chain Address Errors
A brand new educational examine has recognized 65,340 high-risk deal with misuse instances on Ethereum and BNB Chain, linked to about $574.8 million in misplaced crypto.
The analysis exhibits how strange errors involving testnet addresses, reused contract addresses, and uncovered non-public keys can change into everlasting losses, whereas newer instruments equivalent to EIP-7702 give attackers one other technique to exploit them.
Address Mistakes Account for Millions in Losses
The examine, led by researchers from Sun Yat-sen University, Zhejiang University, Peking University, and different establishments, describes two types of deal with misuse: Contract Account (CA) Misuse and Externally Owned Account (EOA) Misuse.
CA Misuse occurs when customers deal with a non-contract deal with as if a wise contract exists there. The researchers discovered 49,344 such instances, involving 22,738.41 ETH and 8,681.41 BNB in losses.
One instance concerned a Uniswap V2 router deal with broadly used on Ethereum’s Sepolia testnet. The deal with had greater than 102,000 views throughout Stack Exchange posts and was used continuously for testing, however on Ethereum mainnet, it had no contract code on the time, but customers nonetheless despatched operate calls and ETH to it. The transactions succeeded as easy transfers, leaving the funds trapped.
EOA Misuse accounted for one more 15,996 instances, which concerned addresses whose non-public keys had been uncovered, usually via public code repositories or developer Q&A websites. The examine discovered losses of 104,224.53 ETH and 9,045.29 BNB.
The researchers examined greater than 10 million candidate addresses and 16 million uncovered non-public keys, then analyzed about 2.5 million transactions on Ethereum and BSC. Manual checks gave the detection system an general precision of 99.11%.
The examine additionally discovered that attackers actively exploit these errors. In 469 CA misuse instances, attackers used cross-chain deal with reuse to put malicious contracts at addresses the place customers had already trapped funds, leading to 3,446.37 ETH and 431.79 BNB in losses.
Another 17,270 instances concerned EIP-7702, which lets an externally owned account delegate execution to a wise contract. The researchers discovered attackers utilizing the mechanism to manage uncovered accounts and routinely redirect incoming funds.
Why Familiar Addresses Can Become a Trap
The findings add a unique kind of threat to the safety issues already affecting crypto this yr. A Blockaid report revealed on August 1 found $1.1 billion stolen throughout 212 incidents throughout the first half of 2026, with three separate assaults that prompted greater than $35 million in losses occurring in in the future in late July.
The deal with misuse examine factors to a much less apparent downside: a transaction can succeed whereas nonetheless producing a loss. Users might assume {that a} profitable transaction means they interacted with the supposed contract, even when the deal with has no code on that exact community.
According to the researchers, individuals should verify the community earlier than utilizing an deal with and depend on official venture documentation whereas preserving take a look at accounts away from manufacturing funds.
They additionally referred to as for wallets to warn customers when an deal with has no contract code on the present chain or has a recognized uncovered non-public key.
The publish Study Finds $575M Lost Through Ethereum and BNB Chain Address Errors appeared first on CryptoPotato.
