A USENIX Security study found that address misuse across Ethereum and BNB Chain has produced losses of over $574.8 million in ETH and BNB. Researchers traced the losses to contract accounts that lack code on the mainnet and to private keys exposed publicly, including on GitHub.
Researchers behind a study titled "Lost in Blockchain Address Misuse: Hidden Cross-Platform Risks and Their Security Impact," published by USENIX Security, identified 65,340 cases of high-risk address misuse involving approximately 2.5 million transactions. The losses came to 17,726.7 BNB and 126,982.94 ETH combined.
Using May 2025 prices of $4,408 per ETH and $847 per BNB, the researchers calculated the losses at over $574.8 million.
Contract account misuse adds millions in losses
Of the total, 49,344 high-risk addresses and roughly 1.6 million transactions were tied to Contract Account (CA) misuse, resulting in losses of 22,738.41 ETH and 8,681.41 BNB. Cases sourced from GitHub alone involved 21,160 BNB Chain addresses and 26,908 Ethereum addresses, tied to losses of 7,513.66 BNB and 19,229.40 ETH.
As a case study, researchers pointed to the UniswapV2Router02 address 0xC532…4008 on Sepolia, which recorded approximately 158,775 transactions by August 2025. The same address had no contract code on the Ethereum mainnet, yet 88 transactions were still sent to it. An attacker deployed a malicious smart contract at that address on October 6, 2024 and withdrew 3.78 ETH that users had mistakenly sent there.
Exposed private keys behind EOA losses
Separately, the study found 15,996 high-risk Externally Owned Account (EOA) addresses tied to about 910,000 transactions, with losses of 9,045.29 BNB and 104,244.53 ETH. Publicly exposed private keys were the main cause, and GitHub-related cases alone accounted for 103,402.53 ETH and 8,521.07 BNB.
One example cited was the Truffle test address 0x627…3Ef57, whose publicly accessible private key lets attackers instantly drain any funds sent there by mistake. Even so, over 85% of the addresses gathered from GitHub have not yet been misused, while the researchers' detection system reached 99.11% precision.
The finding lines up with an earlier AMBCrypto report that put Ethereum-related address poisoning losses at approximately $62 million between late 2025 and early 2026.
Source: AMBCrypto
Trading involves risk.