Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnWeb3SquareMore
Trade
Spot
Buy and sell crypto with ease
Margin
Amplify your capital and maximize fund efficiency
Onchain
Going Onchain, without going Onchain!
Convert
Zero fees, no slippage
Explore
Launchhub
Gain the edge early and start winning
Copy
Copy elite trader with one click
Bots
Simple, fast, and reliable AI trading bot
Trade
USDT-M Futures
Futures settled in USDT
USDC-M Futures
Futures settled in USDC
Coin-M Futures
Futures settled in cryptocurrencies
Explore
Futures guide
A beginner-to-advanced journey in futures trading
Futures promotions
Generous rewards await
Overview
A variety of products to grow your assets
Simple Earn
Deposit and withdraw anytime to earn flexible returns with zero risk
On-chain Earn
Earn profits daily without risking principal
Structured Earn
Robust financial innovation to navigate market swings
VIP and Wealth Management
Premium services for smart wealth management
Loans
Flexible borrowing with high fund security
SlowMist Issues Security Alert on Potential New Risks Following Ethereum Pectra Upgrade

SlowMist Issues Security Alert on Potential New Risks Following Ethereum Pectra Upgrade

BlockBeatsBlockBeats2025/05/08 12:38
Show original

On May 8, the security company SlowMist issued a reminder about potential new risks brought by the new features after the Ethereum Pectra upgrade:

For users: Private key protection should always be a top priority. Be aware that the contract code at the same contract address on different chains may not always be the same. Understand the details of the delegation target before proceeding;

 

For wallet providers: Check whether the delegation chain matches the current network, and remind users of the risks associated with using delegation signatures with chainID 0, as such signatures may be replayed on different chains. Display the target contract when users sign a delegation to reduce the risk of phishing attacks;

 

For developers: Ensure permission checks are performed during wallet initialization (e.g., verifying the signature address through ecrecover), and follow the namespace formula proposed in ERC-7201 to mitigate storage conflicts. Do not assume that tx.origin is always an externally owned account (EOA); using msg.sender == tx.origin as a means to defend against reentrancy attacks will no longer be effective. Ensure that the target contract delegated by the user implements the necessary callback functions to ensure compatibility with mainstream tokens.

 

For centralized trading platforms: Conduct tracking checks on deposits to reduce the risk of false deposits from smart contracts.

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!