Study Finds $575M Lost Through Ethereum and BNB Chain Address Errors

A new academic study has identified 65,340 high-risk address misuse cases on Ethereum and BNB Chain, linked to about $574.8 million in lost crypto.
The research shows how ordinary mistakes involving testnet addresses, reused contract addresses, and exposed private keys can become permanent losses, while newer tools such as EIP-7702 give attackers another way to exploit them.
Address Mistakes Account for Millions in Losses
The study, led by researchers from Sun Yat-sen University, Zhejiang University, Peking University, and other institutions, describes two forms of address misuse: Contract Account (CA) Misuse and Externally Owned Account (EOA) Misuse.
CA Misuse happens when users treat a non-contract address as though a smart contract exists there. The researchers found 49,344 such cases, involving 22,738.41 ETH and 8,681.41 BNB in losses.
One example involved a Uniswap V2 router address widely used on Ethereum’s Sepolia testnet. The address had more than 102,000 views across Stack Exchange posts and was used frequently for testing, but on Ethereum mainnet, it had no contract code at the time, yet users still sent function calls and ETH to it. The transactions succeeded as simple transfers, leaving the funds trapped.
… Continue reading the full article at the original source below.



