🚨 Have 65,000+ high-risk Ethereum addresses been exposed?
What exactly happened to $570 million in assets?
Group: 点击进入玖玖的粉丝群
A newly released USENIX Security '26 research report has once again brought Ethereum and BNB Chain security issues to the forefront.⚠️ Researchers found that on these two chains there are around 65,340 instances of high-risk addresses, associated with losses of approximately 126,982 ETH and 17,727 BNB. Using the reference prices adopted by the study, the total value exceeds $570 million.
But there’s an extremely important detail here: this figure doesn’t mean that all $570 million was stolen in a single type of attack, nor does it represent real-time market loss. The researchers emphasized that this is a conservative lower bound calculated based on specific data and reference prices, and the study mainly counted losses involving ETH and BNB native assets.📊 What’s even more worth attention is that the researchers also extracted a large number of potential private keys from more than 63,000 GitHub code repositories and analyzed them using cross-chain data.
In the end, after manual sampling validation, their detection framework achieved an accuracy rate of 99.11%.
🔥 Among them, two attack methods are especially noteworthy.
First is the use of deterministic contract addresses.
Attackers may test with a particular address first, then, after users mistakenly send assets to the corresponding no-code address on the mainnet, deploy a malicious contract to transfer the funds.
Second is related to EIP-7702.
If an account’s private key has already been leaked, attackers may control the account via malicious delegated code, thereby further transferring the assets in the wallet.
So what this report is really worth focusing on isn’t just the “$570 million” number.
👀 More importantly, as blockchain accounts become increasingly complex, new security risks may emerge as smart contracts, cross-chain addresses, and new account mechanisms evolve.
Especially after account features like EIP-7702 continue to gain adoption, wallet security is no longer just about “keeping the private key safe.”
Click the avatar to watch the livestream + join the Jiuji chat group to get daily strategy🚀
#ETH
What exactly happened to $570 million in assets?
Group: 点击进入玖玖的粉丝群
A newly released USENIX Security '26 research report has once again brought Ethereum and BNB Chain security issues to the forefront.⚠️ Researchers found that on these two chains there are around 65,340 instances of high-risk addresses, associated with losses of approximately 126,982 ETH and 17,727 BNB. Using the reference prices adopted by the study, the total value exceeds $570 million.
But there’s an extremely important detail here: this figure doesn’t mean that all $570 million was stolen in a single type of attack, nor does it represent real-time market loss. The researchers emphasized that this is a conservative lower bound calculated based on specific data and reference prices, and the study mainly counted losses involving ETH and BNB native assets.📊 What’s even more worth attention is that the researchers also extracted a large number of potential private keys from more than 63,000 GitHub code repositories and analyzed them using cross-chain data.
In the end, after manual sampling validation, their detection framework achieved an accuracy rate of 99.11%.
🔥 Among them, two attack methods are especially noteworthy.
First is the use of deterministic contract addresses.
Attackers may test with a particular address first, then, after users mistakenly send assets to the corresponding no-code address on the mainnet, deploy a malicious contract to transfer the funds.
Second is related to EIP-7702.
If an account’s private key has already been leaked, attackers may control the account via malicious delegated code, thereby further transferring the assets in the wallet.
So what this report is really worth focusing on isn’t just the “$570 million” number.
👀 More importantly, as blockchain accounts become increasingly complex, new security risks may emerge as smart contracts, cross-chain addresses, and new account mechanisms evolve.
Especially after account features like EIP-7702 continue to gain adoption, wallet security is no longer just about “keeping the private key safe.”
Click the avatar to watch the livestream + join the Jiuji chat group to get daily strategy🚀
#ETH