USENIX Security '26 Study Links 65,340 High-Risk Addresses to $574.8M in Cryptocurrency Losses
Key Takeaways
- •Research presented at USENIX Security '26 identified more than 65,340 high-risk addresses on Ethereum and BNB Chain tied to losses exceeding $574.8 million.
- •The study identified contract account misuse and EIP-7702-related vulnerabilities as the two primary attack vectors exploited by malicious actors.
- •EIP-7702, introduced through Ethereum's Pectra upgrade, allows externally owned accounts to delegate execution to smart contract code but has inadvertently created new exploitable attack surfaces.
- •Ethereum and BNB Chain together account for a substantial share of global smart contract activity, making vulnerabilities on either platform broadly consequential.
- •The findings are expected to prompt increased regulatory scrutiny and drive developer community discussions on strengthening security protocols and smart contract standards.

A study presented at USENIX Security '26 has uncovered significant vulnerabilities in the cryptocurrency ecosystem, identifying more than 65,340 high-risk addresses across Ethereum and BNB Chain. According to the research, these addresses are associated with an estimated $574.8 million in total losses.
The findings were shared on X (formerly Twitter) by cryptocurrency commentator @WuBlockchain, drawing attention to what researchers describe as systemic security gaps requiring urgent action.
Study Details
The USENIX Security '26 research reveals that 65,340 addresses across the two blockchain networks are tied to abusive activities resulting in losses exceeding $574.8 million. The study identified two primary attack vectors: contract account misuse and vulnerabilities related to EIP-7702, an Ethereum improvement proposal.
EIP-7702 was introduced as part of Ethereum's Pectra upgrade and allows externally owned accounts (EOAs) to temporarily delegate execution to smart contract code. While the proposal aims to expand wallet functionality and support account abstraction, the study's findings suggest that its deployment has also introduced new attack surfaces that malicious actors can exploit. The identification of EIP-7702-related vulnerabilities alongside more conventional contract misuse highlights how protocol-level changes can create unintended security consequences even as they expand platform capabilities.
According to the researchers, the scale of these findings underscores systemic risks present within the Ethereum ecosystem and the broader cryptocurrency landscape.
Background and Context
Ethereum is a decentralized blockchain platform that enables developers to build and deploy smart contracts and decentralized applications (dApps). BNB Chain, formerly known as Binance Smart Chain, is another major blockchain network widely used for decentralized applications and digital asset transactions. Together, the two networks represent a substantial portion of global smart contract activity, making security vulnerabilities on either platform consequential for a large share of users and developers. Both networks have previously experienced high-profile exploits, including flash loan attacks, bridge compromises, and rug pulls, placing the study's findings within a broader pattern of recurring security challenges that the industry has faced as total value locked in DeFi protocols has grown.
The USENIX Security conference is a long-running academic venue dedicated to addressing security-related challenges in technology. The conference has a history of featuring peer-reviewed research on emerging threats, making it a prominent forum for presenting findings on blockchain vulnerabilities.
Implications
The reported losses tied to high-risk addresses may prompt increased scrutiny from regulators and could influence how stakeholders assess risk when interacting with potentially vulnerable platforms. The study's findings are also likely to drive discussions within the developer community regarding improvements to security protocols and smart contract standards, particularly as proposals like EIP-7702 continue to reshape account-level functionality on Ethereum.
The full study was presented at USENIX Security '26 and shared via X by @WuBlockchain.
Source: Coinfomania