Study finds 65,340 risky crypto addresses tied to $574 million in losses

Summary

A study on Ethereum and BNB Smart Chain found 65,340 risky crypto addresses tied to misuse, with associated native-token losses of 126,982.94 ETH and 17,726.7 BNB, valued at over $574.8 million using May 2025 prices. Only about $15.7 million of that total came from two newly described active attack vectors. One vector targets contract-account misuse: funds sent to a no-code address on one network can be stolen later if an attacker deploys malicious code at the deterministic matching address. This accounted for 469 malicious contracts and 3,446.37 ETH plus 431.79 BNB in losses. The second vector targets exposed private keys and uses EIP-7702 delegation to forward deposits to an attacker in the same transaction, affecting more than 17,200 addresses and causing 25.86 ETH plus 33.45 BNB in losses. The dataset was built from GitHub repositories, Stack Exchange data, extracted private keys, transaction-pattern rules, and symbolic execution, with reported precision of 99.11%.