A pair of alarming security disclosures on Aug. 13, 2026, underscored what analysts are calling a systemic private-key crisis across the crypto ecosystem. A study presented at USENIX Security '26 identified 65,340 risky crypto addresses involved in misuse across Ethereum and BNB Smart Chain, with associated losses of 126,982.94 ETH and 17,726.7 BNB, valued at more than $574.8 million using May 2025 reference prices of $4,408 per ETH and $847 per BNB.
Researchers described two active attack vectors. The first exploits contract-account misuse, where users send function calls or funds to addresses with no deployed contract code. Attackers can deploy a contract at a testnet address and later use deterministic contract addressing to deploy malicious withdrawal code at the corresponding mainnet address. The study linked 469 malicious contracts to 3,446.37 ETH and 431.79 BNB in losses. The second vector uses externally owned account misuse and EIP-7702, allowing an attacker with an exposed private key to delegate the account to malicious code and forward deposits in the same transaction. More than 17,200 delegated addresses were identified, with losses of 25.86 ETH and 33.45 BNB. Together, the two active vectors accounted for 3,472.23 ETH and 465.24 BNB, or about $15.7 million of the broader $574.8 million aggregate.
To build the dataset, the team mined 63,004 GitHub repositories created between January 2015 and May 2025, extracted more than 16.3 million deduplicated private keys, and combined direct key matches with transaction-pattern rules and lightweight symbolic execution. The authors reported 99.11% precision for overall address-misuse detection and said they began disclosing findings to wallet developers and exchanges.
Separately, blockchain analytics platform Lookonchain reported that a private key compromise drained more than $26 million from three wallets linked to the whale TLBL. The trader had already lost $24 million in a 2024 phishing attack, bringing combined losses to about $50.3 million. Security firm PeckShield said the stolen assets included approximately $6.3 million in aWBTC, $5.1 million in DAI, $4.7 million in WBTC and $2.6 million in ETH. After the hack, the attacker converted part of the funds into roughly 20 million DAI and about 3,000 ETH, valued at around $5.64 million, and distributed them across four addresses.
The incidents fit within a wider escalation. A Blockaid report published Aug. 1 said hackers stole $1.1 billion across 212 attacks in the first half of 2026, with private key misuse responsible for roughly $790 million, or nearly 75% of all stolen funds. Monthly incidents increased from 18 in January to 57 in June. Data from Nominis put cumulative losses at approximately $1.65 billion for the first seven months of 2026, with April the worst month at $578 million from exploits on Kelp DAO and Drift Protocol, and July second at $242 million, including $116 million from a Coldcard hardware wallet firmware vulnerability.