USENIX Security2026Top-tier venue
Lost in Blockchain Address Misuse: Hidden Cross-Platform Risks and Their Security Impact
Zhenzhe Shao, Jiashuo Zhang, Zihao Li, Daoyuan Wu, Chong Chen, Yiming Shen, Lingfeng Bao, Yanlin Wang, Jiachi Chen
Abstract
Blockchain systems, such as Ethereum, employ an account-based model, where each account is uniquely identified by an address. As the fundamental interface for user interaction and asset security, addresses are critical but also pose significant risks when misused. In this paper, we systematically reveal and analyze a class of risks termed Address Misuse , which includes two categories: Contract Account (CA) Misuse and Externally Owned Account (EOA) Misuse . Specifically, CA Misuse arises when users mistakenly treat non-contract addresses (NCAs) as CAs, while EOA Misuse occurs when users interact with EOAs whose private keys are exposed. For each category, we reveal the underlying mechanisms and also introduce previously undisclosed attack vectors that enable attackers to exploit these vulnerabilities for profit. To evaluate their prevalence and impacts, we first construct a dataset from GitHub and Stack Exchange, which contains addresses of various blockchain networks. This dataset includes 10 million candidate addresses for misuse analysis and 16 million exposed private keys. We then perform a large-scale on-chain analysis of their associated transactions on Ethereum and BSC. By combining heuristic rules, transaction pattern analysis, and symbolic execution, we identify 65,340 high-risk address instances, with associated asset losses amounting to about 127k ETH and 17.7k BNB, equivalent to over $574.8M. We evaluate the accuracy of our detection methods to ensure the reliability of the results, achieving an overall precision of 99.11%. Besides, our empirical evaluation also reveals two novel, previously undisclosed attack vectors, providing real-world evidence of how attackers actively exploit users' address misuse for profit.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 9e034fdb-655b-4a76-8dcf-5b61c6bb89e5Builds on16
- Making Smart Contracts SmarterLoi Luu, Duc-Hiep Chu, Hrishi Olickel, Prateek Saxena et al.CCS 2016 · 2,306 citations
- Flash Boys 2.0: Frontrunning in Decentralized Exchanges, Miner Extractable Value, and Consensus InstabilityPhilip Daian, Steven Goldfeder, Tyler Kell, Yunqi Li et al.S&P 2020 · 607 citations
- Quantifying Blockchain Extractable Value: How dark is the forest?Kaihua Qin, Liyi Zhou, Arthur GervaisS&P 2022 · 336 citations
- High-Frequency Trading on Decentralized On-Chain ExchangesLiyi Zhou, Kaihua Qin, Christof Ferreira Torres, Duc Viet Le et al.S&P 2021 · 243 citations
- The Art of The Scam: Demystifying Honeypots in Ethereum Smart ContractsChristof Ferreira Torres, Mathis Steichen, Radu StateUSENIX Security 2019 · 239 citations
Related papers
- Revealing the Dark Side of Smart Accounts: An Empirical Study of EIP-7702 Incurred Risks in Blockchain EcosystemMingyuan Huang, Han Liu, Shuo Yang, Daoyuan Wu et al.USENIX Security 2026
- Blockchain Address PoisoningTaro Tsuchiya, Jin-Dong Dong, Kyle Soska, Nicolas ChristinUSENIX Security 2025
- Characterizing Ethereum Address Poisoning AttackShixuan Guan, Kai LiCCS 2024 · 4 citations
- Interface Illusions: Uncovering the Rise of Visual Scams in Cryptocurrency WalletsGuoyi Ye, Geng Hong, Yuan Zhang, Min YangWWW 2024 · 7 citations
- Smart Contract Vulnerabilities: Vulnerable Does Not Imply ExploitedDaniel Perez, Benjamin LivshitsUSENIX Security 2021 · 150 citations
