Skip to content Skip to sidebar Skip to footer

Research: 65,340 High-Risk Addresses on Ethereum and BNB Chain, Losses Exceed $574.8 Million

Research presented at USENIX Security ’26 revealed that 65,340 high-risk addresses associated with exploitation on Ethereum and BNB Chain are linked to losses exceeding $574.8 million.

The security study classified the types of accounts and methods through which losses occurred by examining historically used addresses and their associated transactions. Researchers linked losses of 126,982.94 ETH on the Ethereum side and 17,726.7 BNB on the BNB Chain to high-risk addresses.

In the study’s detailed table, data was categorized on the Ethereum mainnet and BSC under headings of GitHub and Stack Exchange sources, as well as contract account (CA) and externally owned account (EOA) exploitation. Thus, address, transaction, and loss statistics were displayed according to different sources and account types.

Wu Blockchain source image

Two Attack Methods Linked to $15.7 Million in Losses

The research highlighted two attack vectors that directly caused approximately $15.7 million in losses. In the first method, contract accounts and pre-determinable deterministic contract addresses were exploited. This approach allowed attackers to access funds by taking advantage of how contract accounts operate.

The second attack vector was based on the exploitation of the EIP-7702 feature. Compromised accounts were directed to execute malicious code, which enabled the transfer of account balances. Since EIP-7702 allows accounts to execute certain functions via contract code, malicious redirections posed a direct risk of fund transfers.

To identify the addresses, historical data from GitHub repositories was examined, and more than 16.3 million unique private keys were extracted. The study reported that detections made using this data achieved a 99.11 percent accuracy rate.

Tüm gelişmelerden ve paylaşımlardan haberdar olmak için Telegram kanalımıza katılın!