USENIX study flags $574.8M in losses

by

A study presented at USENIX Security ’26 identified 65,340 risky crypto addresses involved in misuse across Ethereum and BNB Smart Chain, with 126,982.94 ETH and 17,726.7 BNB in associated native-token losses.

The researchers valued losses associated with those risky crypto addresses at more than $574.8 million. But the two newly described active attack vectors directly account for about $15.7 million, or 2.7%, of that figure. The full paper also used May 2025 reference prices of $4,408 per ETH and $847 per BNB, rather than each token’s dollar value when the losses occurred.

Infographic comparing $574.8 million in associated losses across 65,340 risky Ethereum and BNB Smart Chain address instances with $15.7 million directly tied to two newly described attack vectors.

Someone just drained long-forgotten dormant Ethereum wallets, and the cause may trace back years
Related Reading

Someone just drained long-forgotten dormant Ethereum wallets, and the cause may trace back years

Hundreds of long-inactive Ethereum wallets were swept into a tagged address while researchers and users still debate whether old keys, weak wallet tooling, or another exposure opened the door.

May 1, 2026 · Liam ‘Akiba’ Wright

How risky crypto addresses become traps

The study separates the problem into contract-account misuse and externally owned account misuse.

Contract-account misuse occurs when someone sends a function call, sometimes with ETH or BNB attached, to an address that has no contract code on the selected network. The transaction can still succeed as a simple transfer without executing the intended function. Funds then sit at that address unless later-deployed code can move them.

That enables the first active vector. An attacker can deploy a contract at a testnet address, wait for users to mistakenly send funds to the corresponding no-code address on mainnet, then exploit deterministic contract addressing to deploy malicious withdrawal code at the same location. The paper identified 469 malicious contracts tied to 3,446.37 ETH and 431.79 BNB in losses.

Externally owned account misuse starts with a public or otherwise exposed private key. Anyone who has the key can control the account, and automated sweepers can race to remove incoming funds.

CryptoBandits malware lets criminals use your USB drive to access crypto wallets – Microsoft warns
Related Reading

CryptoBandits malware lets criminals use your USB drive to access crypto wallets – Microsoft warns

Microsoft says the CryptoBandits malware uses USB shortcuts, clipboard monitoring, and Tor to target wallet workflows before funds move.

Jun 22, 2026 · Liam ‘Akiba’ Wright

The second vector uses EIP-7702 to make that drain more direct. An attacker can use the exposed key to delegate the account to malicious code that forwards a deposit to the attacker in the same transaction. The detailed analysis identified more than 17,200 delegated addresses and losses of 25.86 ETH plus 33.45 BNB.

CryptoSlate Daily Brief

Daily signals, zero noise.

Market-moving headlines and context delivered every morning in one tight read.