Researchers at USENIX Security '26 identified 65,340 high-risk cryptocurrency addresses holding an estimated $574.8 million across Ethereum and BNB Chain, according to a presentation at the conference.

The study traced 126,982.94 ether and 17,726.7 BNB tied to the flagged addresses. Researchers detected attack methods involving contract accounts and EIP-7702, an Ethereum protocol feature that allows externally owned accounts to delegate execution authority. The detection mechanism achieved 99.11% precision in identifying the at-risk holdings.

Across total value locked, last 90 days
Across total value locked, last 90 days · MSB Intel data desk

USENIX Security is the flagship academic computer security conference held annually by the USENIX Association. The 2026 presentation is one of the first peer-reviewed assessments of large-scale address vulnerability across two major blockchain networks simultaneously.

MSB Intel

EIP-7702, finalized in Ethereum's Dencun upgrade earlier in 2024, introduced the ability for standard accounts to temporarily delegate their execution context to smart contracts. Researchers flagged this mechanism as a vector for sophisticated attacks when implemented without proper safeguards. The study did not disclose whether the $574.8 million in identified losses occurred or remained potential exposure.

BNB Chain and Ethereum together account for over $2 trillion in total value locked as of mid-2026. The identified addresses represent approximately 0.03 percent of that aggregate, though the precision figure carried minimal false-positive rate.

Academic conferences have published increasing volumes of blockchain security research over the past two years. Industry adoption of these findings remains uneven.

The document to watch is whether Ethereum or BNB Chain implement protocol or client-level guidance based on the USENIX findings within the next six months.