Ethereum, BNB Address Misuse Losses Hit $574.8M as Security Shifts
AI-summarised brief · reviewed before publication
Researchers disclosed that $574.8 million was lost through address misuse on Ethereum and BNB Chain, according to a USENIX Security paper. The analysis identified 65,340 high‑risk cases spanning roughly 2.5 million transactions, including 49,344 contract accounts and 15,996 externally owned accounts (EOAs). Misused contracts generated losses of 22,738.41 ETH and 8,681.41 BNB, while EOAs suffered 104,244.53 ETH and 9,045.29 BNB losses, largely from publicly exposed private keys. GitHub‑related addresses alone accounted for 103,402.53 ETH and 8,521.07 BNB in thefts. A highlighted incident involved the UniswapV2Router02 address on Sepolia, where an attacker deployed a malicious contract and withdrew 3.78 ETH after users mistakenly sent funds. The study’s detection system achieved 99.11 % precision, yet over 85 % of flagged GitHub addresses remain unused. Concurrently, Ethereum announced it will abandon the custom Poseidon hash function in favor of standard algorithms such as SHA or BLAKE2s, citing recent advances in proof‑system efficiency.
💡 Why It Matters
- · The findings expose a massive, quantifiable risk from reusable or publicly shared addresses, urging developers and users to overhaul key‑management practices before further cross‑chain losses occur.