IntegraChain

Market Prices

BTC Bitcoin
$79,581.4 -1.73%
ETH Ethereum
$2,450.3 -2.42%
SOL Solana
$101.81 -1.81%
BNB BNB Chain
$722.7 -0.23%
XRP XRP Ledger
$1.4 -3.39%
DOGE Dogecoin
$0.0847 -2.63%
ADA Cardano
$0.2107 -5.00%
AVAX Avalanche
$7.41 -0.90%
DOT Polkadot
$0.8910 +1.54%
LINK Chainlink
$11.62 -2.27%

Event Calendar

{{年份}}
12
05
halving BCH Halving

Block reward halving event

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

18
03
unlock Sui Token Unlock

Team and early investor shares released

28
03
unlock Arbitrum Token Unlock

92 million ARB released

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

Tools

All →

Altseason Index

41

Bitcoin Season

BTC Dominance Altseason

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$79,581.4
1
Ethereum ETH
$2,450.3
1
Solana SOL
$101.81
1
BNB Chain BNB
$722.7
1
XRP Ledger XRP
$1.4
1
Dogecoin DOGE
$0.0847
1
Cardano ADA
$0.2107
1
Avalanche AVAX
$7.41
1
Polkadot DOT
$0.8910
1
Chainlink LINK
$11.62

🐋 Whale Tracker

🔴
0xdd23...4f55
2m ago
Out
3,534,677 USDC
🔵
0xe842...ed46
5m ago
Stake
4,796 BNB
🔵
0x9712...9e99
1d ago
Stake
16,573 BNB
Industry

65,340 Addresses, $574 Million in Losses, and the Two Attack Vectors No One Talked About

ChainChain
The numbers land like a hammer. 65,340 risky crypto addresses. 126,982.94 ETH and 17,726.7 BNB in associated losses. At May 2025 reference prices, that's $574.8 million. The study from USENIX Security '26 is thorough—63,004 GitHub repositories mined, 16.3 million deduplicated private keys extracted, transaction-pattern rules and symbolic execution across Ethereum and BNB Smart Chain. But the headline figure is a distraction. The two active attack vectors they describe account for only $15.7 million, or 2.7% of the total. The rest is noise from old, forgotten addresses. The spread was real, but the exit was imaginary. I've spent years in the trenches of DeFi trading, building MEV bots and auditing smart contracts. I've seen the same patterns. The market loves a big number. It sells clicks. But the real risk isn't the $574 million sitting in zombie addresses—it's the two mechanisms that keep draining fresh funds today. The paper breaks misuse into two categories: contract-account misuse and externally owned account (EOA) misuse. Both are avoidable. Both are still happening. Contract-account misuse happens when someone sends a function call with ETH or BNB to an address that has no contract code. The transaction succeeds as a simple transfer. Funds land at a dead address—unless later-deployed code can move them. The first active vector exploits deterministic contract addressing. An attacker deploys a contract on a testnet, gets the same address on mainnet, then waits. Users send funds to the no-code address. The attacker deploys malicious withdrawal code at the same location. The paper identified 469 malicious contracts tied to 3,446.37 ETH and 431.79 BNB. That's $15.2 million at current prices. Alpha decays faster than the code that finds it. I once audited a yield farming protocol that had a hardcoded testnet address in its frontend. Users were sending funds to a dead address on mainnet. The developer said, "It's just a test." I told them: "That's a trap." They didn't fix it. Three months later, someone deployed a contract at that address and drained the accumulated funds. The paper confirms this is not an edge case. It's a systematic failure of development hygiene. EOA misuse is the second vector. Exposed private keys—from GitHub, Pastebin, or leaked datasets—let anyone control the account. Automated sweepers race to drain incoming funds. The paper adds a twist: EIP-7702 makes this more direct. An attacker uses the exposed key to delegate the account to malicious code. The code forwards any deposit to the attacker in the same transaction. The study found more than 17,200 delegated addresses, with losses of 25.86 ETH and 33.45 BNB. That's about $500,000. Small compared to the headline, but it's a growing surface. I trust the log, not the hype. The paper claims 99.11% precision for their detection results. They sampled contract-account and pattern-based EOA cases, had two researchers independently judge each detection, and treated addresses derived from public private keys as confirmed. That precision is impressive. But it does not mean the $574.8 million is all actively at risk. Most of that figure comes from old, forgotten addresses—funds that were lost years ago and never moved. The true active threat is the $15.7 million from the two vectors. That's still real money. But it's a different kind of risk. The contrarian angle: the market focuses on price action, not key management. Every day, traders talk about the next altcoin, the next DeFi yield. They ignore the fact that their own security is the weakest link. The paper's dataset includes private keys from GitHub repositories created between January 2015 and May 2025. That's a decade of carelessness. The blind spot is where the money hides. I've seen the aftermath of exposed keys. In 2020, I was running a MEV bot on Ethereum. I found a wallet with a leaked private key that had $50,000 in USDC. I could have swept it. I didn't. But someone else did. That wallet was part of a larger pattern. The paper's findings are a map of that pattern. The real question is: how many of these addresses are still being funded? The paper does not provide a current funded-address count. They began disclosing to wallet developers and exchanges. But without a remediation rate, the problem remains open. What can you do? Check both the address and chain against official sources. Developers should never expose test accounts or hardcoded keys in production. Wallet providers can warn before transactions reach no-code or exposed-key destinations. These are basic steps. The market won't implement them until the losses hit their portfolio. The paper's value is not in the $574 million figure. It's in the two active vectors. They are preventable. They are still happening. The next time you send a transaction to a new address on a new chain, pause. Ask yourself: is this a testnet address? Is this a known exposed key? The bot didn't fail; the market changed rules. I'll leave you with this: 65,340 addresses. Only 2.7% of the losses are from active attacks. The rest is a graveyard of forgotten keys. The market is a system of incentives. The incentive to secure your keys is weaker than the incentive to chase yield. Until that changes, the study will be a cautionary tale, not a turning point. How many of your testnet addresses are still live on mainnet?

Fear & Greed

73

Greed

Market Sentiment

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

💡 Smart Money

0xe03b...22d0
Top DeFi Miner
+$4.8M
67%
0xb158...ec9e
Experienced On-chain Trader
+$1.4M
86%
0xcf1b...c2a4
Experienced On-chain Trader
+$1.7M
70%