A brand new tutorial examine has recognized 65,340 high-risk tackle misuse circumstances on Ethereum and BNB Chain, linked to about $574.8 million in misplaced crypto.
The analysis exhibits how abnormal errors involving testnet addresses, reused contract addresses, and uncovered personal keys can change into everlasting losses, whereas newer instruments akin to EIP-7702 give attackers one other solution to exploit them.
Tackle Errors Account for Tens of millions in Losses
The examine, led by researchers from Solar Yat-sen College, Zhejiang College, Peking College, and different establishments, describes two types of tackle misuse: Contract Account (CA) Misuse and Externally Owned Account (EOA) Misuse.
CA Misuse occurs when customers deal with a non-contract tackle as if a wise contract exists there. The researchers discovered 49,344 such circumstances, involving 22,738.41 ETH and eight,681.41 BNB in losses.
One instance concerned a Uniswap V2 router tackle broadly used on Ethereum’s Sepolia testnet. The tackle had greater than 102,000 views throughout Stack Trade posts and was used steadily for testing, however on Ethereum mainnet, it had no contract code on the time, but customers nonetheless despatched perform calls and ETH to it. The transactions succeeded as easy transfers, leaving the funds trapped.
EOA Misuse accounted for an additional 15,996 circumstances, which concerned addresses whose personal keys had been uncovered, usually by public code repositories or developer Q&A websites. The examine discovered losses of 104,224.53 ETH and 9,045.29 BNB.
The researchers examined greater than 10 million candidate addresses and 16 million uncovered personal keys, then analyzed about 2.5 million transactions on Ethereum and BSC. Guide checks gave the detection system an total precision of 99.11%.
The examine additionally discovered that attackers actively exploit these errors. In 469 CA misuse circumstances, attackers used cross-chain tackle reuse to put malicious contracts at addresses the place customers had already trapped funds, leading to 3,446.37 ETH and 431.79 BNB in losses.
One other 17,270 circumstances concerned EIP-7702, which lets an externally owned account delegate execution to a wise contract. The researchers discovered attackers utilizing the mechanism to regulate uncovered accounts and routinely redirect incoming funds.
Why Acquainted Addresses Can Turn into a Entice
The findings add a distinct sort of threat to the safety issues already affecting crypto this 12 months. A Blockaid report revealed on August 1 discovered $1.1 billion stolen throughout 212 incidents throughout the first half of 2026, with three separate assaults that brought on greater than $35 million in losses occurring in someday in late July.
The tackle misuse examine factors to a much less apparent downside: a transaction can succeed whereas nonetheless producing a loss. Customers could assume {that a} profitable transaction means they interacted with the meant contract, even when the tackle has no code on that exact community.
In line with the researchers, folks must verify the community earlier than utilizing an tackle and depend on official venture documentation whereas preserving check accounts away from manufacturing funds.
Additionally they referred to as for wallets to warn customers when an tackle has no contract code on the present chain or has a identified uncovered personal key.
The submit Examine Finds $575M Misplaced By means of Ethereum and BNB Chain Tackle Errors appeared first on CryptoPotato.