A new academic study found 65,340 address misuse cases on Ethereum (ETH) and BNB Chain, linking them to more than $574.8 million in crypto losses.
Key Points:
- Researchers found 49,344 contract-account misuse cases and 15,996 exposed-account cases across Ethereum and BNB Chain.
- Losses totaled about 127,000 ETH and 17,700 BNB (BNB), while the detection system reached 99.11% precision.
- Attackers exploited cross-chain address reuse and EIP-7702 to capture funds sent to unsafe addresses.
Ethereum Address Losses
Published in the Proceedings of the 35th USENIX Security Symposium, the study drew on data gathered by researchers from Sun Yat-sen University, Zhejiang University, Peking University and other institutions. It identified 49,344 contract-account misuse cases involving 22,738.41 ETH and 8,681.41 BNB, plus 15,996 externally owned account cases involving 104,244.53 ETH and 9,045.29 BNB.
The problem often began with copied test addresses. A Uniswap V2 router address used on Ethereum’s Sepolia testnet appeared in Stack Exchange posts with more than 102,000 views, but the same address had no contract code on mainnet at the time.
Those transactions did not fail. With no executable code at the destination, attempted function calls were processed as ordinary transfers, leaving attached ETH trapped instead of reverting as users expected.
The researchers examined roughly 2.5 million transactions across Ethereum and BNB Smart Chain and reported 99.11% overall precision for their detection system. Private-key exposure created a separate danger.
Also Read: CZ Moves $965K To Giggle Academy As Binance Founder Shifts Focus To Education
Ethereum EIP-7702 Risks
Attackers did more than wait for mistakes. In 469 contract-account misuse cases, they reused cross-chain addresses to deploy malicious contracts where funds had become trapped, producing losses of 3,446.37 ETH and 431.79 BNB.
Another 17,270 cases involved EIP-7702. The proposal lets an externally owned account delegate execution rights to a smart contract. Researchers found attackers using exposed keys to delegate compromised accounts to malicious contracts that automatically swept incoming funds, causing losses of 25.86 ETH and 33.45 BNB.
The researchers urged users to verify the active network, use official project documentation and keep test accounts separate from production funds.
They also recommended warnings when a wallet detects an address with no contract code on the current chain or a known exposed private key.
EIP-7702 arrived with Ethereum’s Pectra upgrade to give externally owned accounts more flexible smart contract capabilities through delegated execution. That can turn an exposed private key from an old operational mistake into a faster, automated attack path.
Read Next: OpenAI’s $40B Annualized Revenue Builds Case For Wall Street Debut





