Bitget App
Trade smarter
Open
HomepageSign up
Bitget>
News>
Wintermute warns Pectra upgrade leaves Ethereum users at risk of automated attacks

Wintermute warns Pectra upgrade leaves Ethereum users at risk of automated attacks

The Block2025/05/31 16:00
By: By Zack Abrams
ETH-2.18%
Quick Take An update included in Ethereum’s recent “Pectra” upgrade, intended to improve ease-of-use for users, has mostly been used by automated “sweeper” attacks to drain unsuspecting wallets, according to an analysis by Wintermute. Over 80% of EIP-7702 delegations, one function introduced in the upgrade, were devoted to a single malicious script, Wintermute found. One user lost nearly $150,000 to a phishing attack enabled by the script, according to blockchain security firm Scam Sniffer.
Wintermute warns Pectra upgrade leaves Ethereum users at risk of automated attacks image 0

A recent Ethereum upgrade has mostly been used by malicious attackers seeking to drain wallets, according to an analysis by crypto trading firm Wintermute. 

EIP-7702, an account-abstraction upgrade included in Ethereum's recent "Pectra" hard fork , is designed to improve ease of user experience by allowing wallets to temporarily behave like smart contracts, batching multiple actions, sponsoring gas fees, using passkey or social-authentication, or implementing spending limits in a single transaction. EIP-7702 was initially proposed and championed by Ethereum co-founder Vitalik Buterin. 

However, over 80% of EIP-7702 delegations were authorized to multiple contracts with copy-pasted versions of the same basic code, which automatically "sweeps" wallets with leaked keys and sends the contents to the attacker who deployed the contract, according to Wintermute's Dune dashboard . Wintermute nicknamed the contract "CrimeEnjoyor."

"The CrimeEnjoyor contract is short, simple, and widely reused," Wintermute wrote on X. "This one copy-pasted bytecode now accounts for the majority of all EIP-7702 delegations. It’s funny, bleak, and fascinating at the same time."

Blockchain security firm Scam Sniffer recently identified a wallet that lost nearly $150,000 through a malicious batched transaction with links to the Inferno Drainer scam-as-a-service, a longtime nuisance in the crypto security space. 

Security firm SlowMist also detailed the risks of EIP-7702 adoption in a recent analysis . "Wallet service providers should quickly support EIP-7702 transactions and, when users sign delegations, should prominently display the target contract to reduce the risk of phishing attacks," SlowMist wrote. 

"As we predicted, the phishing gangs have caught up," wrote SlowMist founder Yu Xian on X . "Everyone should be vigilant, be careful that the assets in your wallet will be taken away."

Though EIP-7702 introduces a new way for automated attacks, security expert Taylor Monahan said the key issue was the underlying compromise of users' private keys. 

"It's not actually a 7702 issue, its the same issue crypto has had since day one: end users struggle to secure their private keys," Monahan told the Block. "7702 just unlocks a bunch of cool abilities that make sweeping addresses more cost efficient and less tedious." 


Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

Wall Street’s “hottest phrase”: Run it hot! Betting on “fiscal and monetary easing”

The core logic of the "Run it hot" strategy is that tax cuts and interest rate reductions will jointly "heat up" the economy, thereby triggering a new wave of growth.

ForesightNews2025/09/15 14:03
Taking Over from $CARDS? A Detailed Explanation of the Pokémon Card RWA Trading Platform Phygitals

Can Phygitals bring the Pokémon card craze into the crypto world?

深潮2025/09/15 13:25
Data Insights: The Status of Local Stablecoins in Southeast Asia in Q2 2025

Local stablecoins are crucial.

深潮2025/09/15 13:24

Trending news

More
1
Wall Street’s “hottest phrase”: Run it hot! Betting on “fiscal and monetary easing”
2
Taking Over from $CARDS? A Detailed Explanation of the Pokémon Card RWA Trading Platform Phygitals

Crypto prices

More
Bitcoin
Bitcoin
BTC
$114,821.59
-0.42%
Ethereum
Ethereum
ETH
$4,525.17
-2.02%
XRP
XRP
XRP
$3.03
-0.33%
Tether USDt
Tether USDt
USDT
$1
+0.00%
Solana
Solana
SOL
$236.19
-3.58%
BNB
BNB
BNB
$919
-1.28%
USDC
USDC
USDC
$1
+0.05%
Dogecoin
Dogecoin
DOGE
$0.2648
-6.46%
TRON
TRON
TRX
$0.3441
-1.30%
Cardano
Cardano
ADA
$0.8680
-2.51%
How to sell PI
Bitget lists PI – Buy or sell PI quickly on Bitget!
Trade now
Become a trader now?A welcome pack worth 6200 USDT for new users!
Sign up now
Trade smarter