Someone, somewhere, pushed their private key to a public GitHub repository. Then 65,339 other someones did roughly the same thing. A peer-reviewed study accepted to USENIX Security ’26, one of the top academic security conferences in the world, has now catalogued the damage: 65,340 high-risk address instances tied to an estimated $574.8 million in losses across Ethereum and BNB Smart Chain.

The paper, authored by Zhenzhe Shao from Sun Yat-sen University and Zhejiang University, represents one of the most comprehensive audits of blockchain address misuse ever conducted.

What the researchers actually found

The study analyzed over 16.3 million deduplicated private keys extracted from 63,004 public GitHub repositories. The data spanned a full decade, from January 2015 through May 2025, capturing keys that developers, students, and hobbyists had inadvertently (or carelessly) committed to version control.

From that trove, the team identified 65,340 high-risk address instances. Those broke down into two categories: 49,344 cases of contract account (CA) misuse and 15,996 cases of externally owned account (EOA) misuse. Together, the addresses were involved in roughly 2.5 million transactions.