Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands

    August 13, 2026

    Trezor Customer Data Exposed in Shipping Partner Breach

    August 13, 2026

    Dogs can tell fear from sadness — and scientists saw it in their brains

    August 13, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands
    • Trezor Customer Data Exposed in Shipping Partner Breach
    • Dogs can tell fear from sadness — and scientists saw it in their brains
    • So Much Solar: Digging Into the List of Every US Power Plant That Went Online This Year
    • How AAU Failed to Protect Young Athletes From Sexual Abuse — ProPublica
    • ‘Harry Potter’ fans reportedly forced energy project’s relocation to avoid Dobby’s grave
    • Turkiye lays out ‘mechanisms’ of defence pact with Pakistan, Saudi Arabia | Recep Tayyip Erdogan News
    • The Best Samsung Galaxy S26 Cases (2026): S26, S26+, and S26 Ultra
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, August 13
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Crypto & Blockchain

    Risky crypto addresses: USENIX study flags $574.8M in losses

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 13, 2026 Crypto & Blockchain No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A study presented at USENIX Security ’26 identified 65,340 risky crypto addresses involved in misuse across Ethereum and BNB Smart Chain, with 126,982.94 ETH and 17,726.7 BNB in associated native-token losses.

    The researchers valued losses associated with those risky crypto addresses at more than $574.8 million. But the two newly described active attack vectors directly account for about $15.7 million, or 2.7%, of that figure. The full paper also used May 2025 reference prices of $4,408 per ETH and $847 per BNB, rather than each token’s dollar value when the losses occurred.

    Infographic comparing $574.8 million in associated losses across 65,340 risky Ethereum and BNB Smart Chain address instances with $15.7 million directly tied to two newly described attack vectors.

    Someone just drained long-forgotten dormant Ethereum wallets, and the cause may trace back yearsSomeone just drained long-forgotten dormant Ethereum wallets, and the cause may trace back years
    Related Reading

    Someone just drained long-forgotten dormant Ethereum wallets, and the cause may trace back years

    Hundreds of long-inactive Ethereum wallets were swept into a tagged address while researchers and users still debate whether old keys, weak wallet tooling, or another exposure opened the door.

    May 1, 2026 · Liam ‘Akiba’ Wright

    How risky crypto addresses become traps

    The study separates the problem into contract-account misuse and externally owned account misuse.

    Contract-account misuse occurs when someone sends a function call, sometimes with ETH or BNB attached, to an address that has no contract code on the selected network. The transaction can still succeed as a simple transfer without executing the intended function. Funds then sit at that address unless later-deployed code can move them.

    That enables the first active vector. An attacker can deploy a contract at a testnet address, wait for users to mistakenly send funds to the corresponding no-code address on mainnet, then exploit deterministic contract addressing to deploy malicious withdrawal code at the same location. The paper identified 469 malicious contracts tied to 3,446.37 ETH and 431.79 BNB in losses.

    Externally owned account misuse starts with a public or otherwise exposed private key. Anyone who has the key can control the account, and automated sweepers can race to remove incoming funds.

    CryptoBandits malware lets criminals use your USB drive to access crypto wallets – Microsoft warnsCryptoBandits malware lets criminals use your USB drive to access crypto wallets – Microsoft warns
    Related Reading

    CryptoBandits malware lets criminals use your USB drive to access crypto wallets – Microsoft warns

    Microsoft says the CryptoBandits malware uses USB shortcuts, clipboard monitoring, and Tor to target wallet workflows before funds move.

    Jun 22, 2026 · Liam ‘Akiba’ Wright

    The second vector uses EIP-7702 to make that drain more direct. An attacker can use the exposed key to delegate the account to malicious code that forwards a deposit to the attacker in the same transaction. The detailed analysis identified more than 17,200 delegated addresses and losses of 25.86 ETH plus 33.45 BNB.

    CryptoSlate Daily Brief

    Daily signals, zero noise.

    Market-moving headlines and context delivered every morning in one tight read.

    5-minute digest 100k+ readers

    Free. No spam. Unsubscribe any time.

    Whoops, looks like there was a problem. Please try again.

    You’re subscribed. Welcome aboard.

    Together, the two active vectors account for 3,472.23 ETH and 465.24 BNB. The rest of the paper’s aggregate covers the broader set of detected contract-account and exposed-key misuse rather than those two attacks alone.

    To build the dataset, the team mined 63,004 GitHub repositories created from January 2015 through May 2025 and used an April 2025 Stack Exchange archive. It extracted more than 16.3 million deduplicated private keys from GitHub, derived their addresses and combined direct key matches with transaction-pattern rules and lightweight symbolic execution on Ethereum and BNB Smart Chain.

    Cardano’s wallet hack exposed the user layer holding its on-chain government togetherCardano’s wallet hack exposed the user layer holding its on-chain government together
    Related Reading

    Cardano’s wallet hack exposed the user layer holding its on-chain government together

    Cardano’s governance model depends on ordinary ADA holders participating, and the SecondFi exploit shows how much that model depends on secure wallet UX.

    Jul 9, 2026 · Gino Matos

    The authors reported 99.11% precision for their overall address-misuse detection results. They randomly sampled the inferred contract-account and pattern-based EOA cases, had two researchers independently judge whether each detection matched the study’s definitions, and separately treated addresses derived from public private keys as confirmed. The precision figure measures detection accuracy, not whether the full dollar estimate was directly caused by the two active vectors.

    The researchers said they began disclosing the findings to wallet developers and exchanges and tried to contact affected projects. However, the paper does not provide a complete remediation rate or a current funded-address count for all 65,340 instances.

    Users can reduce the immediate risk by checking both the address and chain against official sources. Developers should keep test accounts and hardcoded keys out of production, while wallet providers can warn before transactions reach no-code or exposed-key destinations.

    574.8M addresses Crypto flags losses risky study USENIX
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Trezor Customer Data Exposed in Shipping Partner Breach

    Bitcoin Adoption Enters Portfolios and Retirement Accounts

    Bat virus fragments turn up in fertilizer sold in Thai markets, study finds

    CEO of Crypto Lender Delio Gets 15 Years Over $49M Fraud

    Goldman Sachs’ $2.25B NEOS Deal Hands It Ready-Made Bitcoin Income ETF Business

    SpaceXAI Wants Grok Bot to Do Your Job—But It Needs Access to Your Accounts

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands

    August 13, 2026

    Trezor Customer Data Exposed in Shipping Partner Breach

    August 13, 2026

    Dogs can tell fear from sadness — and scientists saw it in their brains

    August 13, 2026

    So Much Solar: Digging Into the List of Every US Power Plant That Went Online This Year

    August 13, 2026
    Latest Posts

    Evacuated villagers in Cairngorms allowed home after wildfire threat lifts | Wildfires

    July 25, 2026

    The Fraternal Order Of Police Supports The Clarity Act.

    July 25, 2026

    How Synthetic Identity Fraud is Coming for Machine Identities

    July 25, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands

    August 13, 2026

    Trezor Customer Data Exposed in Shipping Partner Breach

    August 13, 2026

    Dogs can tell fear from sadness — and scientists saw it in their brains

    August 13, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.