Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [ACTIVE] · [TECHNOLOGY]
2 clusters · 3 sources · 3 days · First seen · Last updated
Cryptocurrency address misuse and financial losses
Overview
Academic researchers from Sun Yat-sen, Zhejiang, and Peking universities have released a study identifying approximately $574.8 million in cryptocurrency losses resulting from address misuse on the Ethereum and BNB Chain networks.
The study categorizes the vulnerabilities into two primary types. Contract Account (CA) misuse involved 49,344 instances where users sent assets to addresses lacking deployed contract code, often due to cross-platform or network switching inconsistencies. This accounted for losses of roughly 22,738 ETH and 8,681 BNB.
Externally Owned Account (EOA) misuse involved 15,996 cases, largely driven by the exposure of private keys. One report noted that researchers extracted 16.3 million private keys from over 63,000 GitHub repositories. Further analysis highlighted 17,270 instances involving EIP-7702, where malicious delegation allowed attackers to seize exposed accounts and automatically redirect deposits.
Entities
BNB Chain · Ethereum · USENIX Security · GitHub · Zhejiang University
Timeline
-
2 days ago
[TECHNOLOGY] 2 sourcesEthereum and BNB Chain address errors linked to $575M in lossesA study by university researchers links Ethereum and BNB Chain address errors and account misuse to approximately $574.8 million in lost cryptocurrency assets.
-
5 days ago
[TECHNOLOGY] 2 sourcesUSENIX study finds $574.8M lost to crypto address misuseA USENIX Security study reveals that cryptocurrency address misuse on Ethereum and BNB Chain has led to over $574.8 million in losses, driven by contract account errors and exposed private keys.
Sources
ambcrypto.com · bitcoinethereumnews.com · blockonomi.com