A peer-reviewed study presented at the 35th USENIX Security Symposium in Baltimore on August 12-14, 2026, identified 65,340 high-risk cryptocurrency addresses on Ethereum and BNB Smart Chain tied to estimated losses of 126,982.94 ETH and 17,726.7 BNB — valued at $574.8 million at reference prices...
"Private key hacks aren't a cryptography failure — they're a key-management failure the industry keeps mislabeling." — Leo Fan, CEO, Cysic
A peer-reviewed study presented at the 35th USENIX Security Symposium in Baltimore on August 12-14, 2026, identified 65,340 high-risk cryptocurrency addresses on Ethereum and BNB Smart Chain tied to estimated losses of 126,982.94 ETH and 17,726.7 BNB — valued at $574.8 million at reference prices. The researchers extracted 16.3 million private keys from 63,004 public GitHub repositories created between January 2015 and May 2025, constructing what amounts to the largest empirical dataset of leaked blockchain credentials to date.
The findings arrive as CertiK's H1 2026 Hack3d report shows wallet compromise generated $444.5 million in losses across just 33 incidents — more than any other attack category — and as CoinDesk reported that private key compromises account for approximately 40% of the $16.69 billion in cumulative crypto hack losses. Smart contract exploits, once the dominant attack vector, are declining in both frequency and severity. The threat has shifted from code to credentials.
The paper, titled "Lost in Blockchain Address Misuse: Hidden Cross-Platform Risks and Their Security Impact," was authored by nine researchers from Sun Yat-sen University, Peking University, Zhejiang University, the University of Electronic Science and Technology of China, The Hong Kong Polytechnic University, and Lingnan University.
The researchers mined 63,004 GitHub repositories created between January 2015 and May 2025. After deduplication, they extracted 10.3 million unique candidate addresses and 16.3 million private keys. They also incorporated data from Ethereum Stack Exchange and Stack Overflow. The detection framework achieved 99.11% precision following manual sampling validation across both blockchain networks analyzed.
The scale of credential leakage is notable. Developers routinely commit private keys to public repositories during testing, prototyping, or deployment. Many of these keys control addresses that have subsequently received real funds. The study limited its analysis to native tokens (ETH and BNB) — losses from ERC-20 tokens, NFTs, and other chains were excluded, suggesting the true financial exposure is materially higher.
The study classifies address misuse into two categories:
Contract Account (CA) Misuse — 49,344 instances. Users treat addresses without deployed code as contract addresses. Funds sent to these addresses become inaccessible or exploitable. Losses in this category totaled 22,738.41 ETH and 8,681.41 BNB.
Externally Owned Account (EOA) Misuse — 15,996 instances. Private keys for these addresses are either directly exposed on GitHub or show strong on-chain signatures of compromised control. Losses totaled 104,244.53 ETH and 9,045.29 BNB. Over 95% of EOA losses originated from GitHub-exposed keys, according to the study.
The disparity is instructive: EOA misuse accounts for fewer instances but generates 82% of the ETH losses. A leaked private key provides direct, permanent access to all funds held by the associated address. There is no recovery mechanism.
Additionally, the researchers identified 469 malicious contracts exploiting deterministic contract address generation, resulting in losses of 3,446.37 ETH and 431.79 BNB.
The study documents a third, emerging category: misuse of EIP-7702 delegated account control, with 17,270 cases identified. Financial losses in this category were modest — 25.86 ETH and 33.45 BNB — but the researchers flagged the mechanism as a growing risk vector.
EIP-7702, deployed as part of Ethereum's Pectra upgrade, allows externally owned accounts to temporarily attach smart contract code during transactions. This flexibility introduces a new class of vulnerabilities. According to SlowMist, a QNT reserve pool lost 1,988.5 QNT (approximately 54.93 ETH) in April 2026 due to misconfigured admin delegation under EIP-7702. The admin identity was held by an EOA, and the batch execution contract lacked proper access controls.
Research by Wintermute in May 2025 found that over 97% of all EIP-7702 delegations were authorized to multiple contracts using identical code. This pattern suggests systematic deployment of delegation templates without individualized security review. When such configurations are compromised, attackers gain full account privileges.
The USENIX authors note that EIP-7702 is relatively new and its security implications remain "understudied" — a measured assessment given the limited loss data but growing adoption.
The USENIX findings fit a pattern documented across multiple industry sources. CoinDesk reported on June 29, 2026, that private key compromises account for approximately 40% of all crypto hack losses — roughly $6.68 billion of the cumulative $16.69 billion stolen from blockchain projects.
The February 2025 Bybit hack remains the defining case study. Attackers compromised a third-party software supply chain, injected malicious wallet code, and executed unauthorized Ethereum transactions valued at approximately $1.5 billion. The cryptographic primitives were sound. The failure was operational — credential management, supply chain integrity, and key storage.
Wish Wu, co-founder and CEO of Pharos, noted that "most blockchain infrastructure was originally built for a single-user, single-key model," a design that conflicts with basic security principles in multi-party, multi-context operational environments. The attack surface has expanded to include cloud platforms, development tools, CI/CD pipelines, and even social media accounts used for team coordination.
Monthly incident counts escalated from 18 in January 2026 to 57 in June 2026, according to CryptoNews.net. The trend reflects not necessarily an increase in attacker sophistication but an expansion of the attack surface as more organizations bring crypto operations into production environments with inadequate key management practices.
CertiK's Hack3d report for H1 2026 recorded $1.316 billion in gross losses across 344 incidents. On a like-for-like basis (excluding the Bybit incident from H1 2025), losses increased approximately 28% year-over-year.
Wallet compromise was the costliest attack category: $444.5 million across 33 incidents, averaging $13.47 million per event. Two incidents dominated — the Kelp DAO RPC compromise ($291 million) and the Drift Protocol breach ($285 million), both in April 2026 — together accounting for nearly 44% of all H1 losses.
For comparison, code vulnerability exploits produced $151.59 million across 204 incidents, averaging $740,000 per event. Phishing generated $366.31 million across 63 incidents.
The shift is structural. Smart contract auditing has matured — CertiK analyzed 100.8 million contracts in the period and flagged 4.24 million as scam-related. But the attack vector has migrated upstream, from code to infrastructure, from smart contracts to signing keys. Recovery rates remain poor: $115.31 million was frozen or returned in H1 2026, representing just 8.8% of gross losses.
TRM Labs provided a complementary dataset: $972 million across 207 hacks in H1 2026, with North Korean actors responsible for 66% of losses.
The economic implications extend beyond direct theft. Every private key leak on GitHub represents a permanent, unrevocable compromise. Unlike API keys or database passwords, blockchain private keys cannot be rotated for an existing address. Any funds sent to a compromised address — even years after the key was leaked — are immediately accessible to the attacker.
The 16.3 million leaked keys represent a standing inventory of exploitable credentials. Even if the majority control empty wallets, the tail risk is substantial. The study found that 65,340 addresses had received funds despite their keys being publicly available — a 0.4% hit rate on candidate addresses that nonetheless produced $574.8 million in losses.
For institutions building on-chain treasury operations, the findings underscore a fundamental infrastructure cost that is rarely accounted for in economic models: the cost of key management. Hardware security modules, multi-party computation wallets, geographic signer distribution, and regular key rotation ceremonies represent material operational expenses. Organizations that underinvest in these capabilities absorb the difference as unpriced risk.
The security industry has converged on several countermeasures:
Multi-party computation (MPC) wallets distribute key material across multiple parties so that no single entity holds a complete private key. Adoption is growing among institutional custodians but remains limited among smaller protocols and individual developers.
Account abstraction with social recovery replaces the single-key model with programmable access control, allowing wallet recovery through pre-designated guardians rather than a single seed phrase.
Hardware wallet enforcement removes private keys from software environments entirely. CertiK's H1 report recommended protecting private keys through hardware infrastructure, distributing signers across jurisdictions, and adding controls for large transfers.
GitHub secret scanning has expanded. GitHub itself flags committed secrets, and third-party services such as GitGuardian monitor repositories for exposed credentials. A 2025 Google-GitGuardian study found 2,622 valid certificates exposed through GitHub leaks. However, the USENIX data suggests that existing scanning tools failed to prevent 16.3 million private keys from remaining publicly accessible across a decade of repository history.
None of these solutions address the retroactive problem: keys already leaked cannot be un-leaked. The only remediation is to identify compromised addresses and avoid sending funds to them — a task the USENIX study's detection framework, at 99.11% precision, partially enables.
The USENIX study quantifies what security practitioners have argued for years: the primary vulnerability in blockchain systems is not the cryptography or the smart contracts — it is the operational infrastructure surrounding private key management. The 16.3 million keys sitting in public GitHub repositories represent a decade of accumulated credential debt. The $574.8 million in documented losses represents only the native-token exposure on two chains during one study period.
CertiK's H1 2026 data and the CoinDesk analysis of cumulative losses confirm the pattern at industry scale. Wallet compromise, not code exploitation, is the dominant and growing attack vector. The economic cost is not limited to stolen funds; it includes the institutional overhead of proper key management, the reputational damage of breaches, and the systemic risk of concentrated credential exposure.
The cryptography works. The key management does not.