A brand new tutorial research has recognized 65,340 high-risk handle misuse circumstances on Ethereum and BNB Chain, linked to about $574.8 million in misplaced crypto.
The analysis reveals how bizarre errors involving testnet addresses, reused contract addresses, and uncovered personal keys can turn into everlasting losses, whereas newer instruments equivalent to EIP-7702 give attackers one other option to exploit them.
Tackle Errors Account for Hundreds of thousands in Losses
The research, led by researchers from Solar Yat-sen College, Zhejiang College, Peking College, and different establishments, describes two types of handle misuse: Contract Account (CA) Misuse and Externally Owned Account (EOA) Misuse.
CA Misuse occurs when customers deal with a non-contract handle as if a sensible contract exists there. The researchers discovered 49,344 such circumstances, involving 22,738.41 ETH and eight,681.41 BNB in losses.
One instance concerned a Uniswap V2 router handle extensively used on Ethereum’s Sepolia testnet. The handle had greater than 102,000 views throughout Stack Alternate posts and was used steadily for testing, however on Ethereum mainnet, it had no contract code on the time, but customers nonetheless despatched operate calls and ETH to it. The transactions succeeded as easy transfers, leaving the funds trapped.
EOA Misuse accounted for an additional 15,996 circumstances, which concerned addresses whose personal keys had been uncovered, usually by public code repositories or developer Q&A websites. The research discovered losses of 104,224.53 ETH and 9,045.29 BNB.
The researchers examined greater than 10 million candidate addresses and 16 million uncovered personal keys, then analyzed about 2.5 million transactions on Ethereum and BSC. Guide checks gave the detection system an total precision of 99.11%.
The research additionally discovered that attackers actively exploit these errors. In 469 CA misuse circumstances, attackers used cross-chain handle reuse to position malicious contracts at addresses the place customers had already trapped funds, leading to 3,446.37 ETH and 431.79 BNB in losses.
One other 17,270 circumstances concerned EIP-7702, which lets an externally owned account delegate execution to a sensible contract. The researchers discovered attackers utilizing the mechanism to regulate uncovered accounts and robotically redirect incoming funds.
Why Acquainted Addresses Can Change into a Entice
The findings add a special sort of threat to the safety issues already affecting crypto this yr. A Blockaid report printed on August 1 discovered $1.1 billion stolen throughout 212 incidents throughout the first half of 2026, with three separate assaults that prompted greater than $35 million in losses occurring in in the future in late July.
The handle misuse research factors to a much less apparent downside: a transaction can succeed whereas nonetheless producing a loss. Customers might assume {that a} profitable transaction means they interacted with the supposed contract, even when the handle has no code on that specific community.
In accordance with the researchers, individuals should verify the community earlier than utilizing an handle and depend on official mission documentation whereas retaining check accounts away from manufacturing funds.
In addition they known as for wallets to warn customers when an handle has no contract code on the present chain or has a recognized uncovered personal key.
The submit Examine Finds $575M Misplaced By means of Ethereum and BNB Chain Tackle Errors appeared first on CryptoPotato.

