Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnWeb3SquareMore
Trade
Spot
Buy and sell crypto with ease
Margin
Amplify your capital and maximize fund efficiency
Onchain
Going Onchain, without going Onchain!
Convert
Zero fees, no slippage
Explore
Launchhub
Gain the edge early and start winning
Copy
Copy elite trader with one click
Bots
Simple, fast, and reliable AI trading bot
Trade
USDT-M Futures
Futures settled in USDT
USDC-M Futures
Futures settled in USDC
Coin-M Futures
Futures settled in cryptocurrencies
Explore
Futures guide
A beginner-to-advanced journey in futures trading
Futures promotions
Generous rewards await
Overview
A variety of products to grow your assets
Simple Earn
Deposit and withdraw anytime to earn flexible returns with zero risk
On-chain Earn
Earn profits daily without risking principal
Structured Earn
Robust financial innovation to navigate market swings
VIP and Wealth Management
Premium services for smart wealth management
Loans
Flexible borrowing with high fund security
Ethereum’s EIP-7702 Under Threat: Hackers Automate Crypto Theft Through New Smart Wallet Features

Ethereum’s EIP-7702 Under Threat: Hackers Automate Crypto Theft Through New Smart Wallet Features

CoinotagCoinotag2025/05/30 16:00
By:Marisol Navaro
  • Following recent enhancements in Ethereum, a new exploit is emerging as hackers utilize the EIP-7702 feature to drain wallets with stolen keys.

  • This alarming trend underscores how cybercriminals are swiftly adopting Ethereum’s innovations for illicit activities.

  • Research indicates that over 100,000 smart contracts are now associated with these malicious practices, raising significant security concerns.

The emergence of Ethereum’s EIP-7702 feature is being exploited by hackers to automate theft from compromised wallets, posing significant security risks to users.

Hackers Use Ethereum’s EIP-7702 to Automate Mass Wallet Drainings

EIP-7702 allows externally owned accounts (EOAs) to function as smart contract wallets. By enabling features like transaction batching and wallet recovery, this upgrade significantly enhances usability. However, it also creates opportunities for malicious actors to expedite fund extraction, turning a useful technology into a tool for crime.

Prior to EIP-7702, transferring Ethereum manually from compromised wallets required time and effort. Now, attackers merely authorize contracts that promptly forward any incoming Ethereum to their own addresses, effectively automating their heist operations.

“Although the intent behind EIP-7702 is positive, its misuse highlights the need for enhanced security measures,” stated Rahul Rumalla, Chief Product Officer at Safe.

A recent study by Wintermute shows that a staggering 97% of wallet delegations involving EIP-7702 have been utilized for deploying contracts specifically designed to drain Ethereum from unsuspecting users.

Ethereum’s EIP-7702 Under Threat: Hackers Automate Crypto Theft Through New Smart Wallet Features image 0

This alarming trend indicates that out of approximately 190,000 delegated contracts analyzed, more than 105,000 are linked to malicious activities. Koffi, a senior analyst at Base Network, revealed that over a million wallets interacted with questionable contracts recently, illustrating the scale of the issue.

Importantly, Koffi clarified that while these wallets may be exploited, they weren’t compromised via EIP-7702; the attackers simply leveraged already exposed private keys.

In contentious clarification, Koffi stated:

“These wallets were not hacked using 7702. The hacker obtained the private keys without doing anything related to 7702. Since they have the keys, they could transfer money out of these wallets by making regular transactions from each one.”

—Kofi (@0xKofi) May 31, 2025

This implementation drastically reduces the transaction time required for withdrawn funds, allowing criminals to capitalize on any incoming ETH instantly. Yu Xian, founder of the cybersecurity firm SlowMist, emphasized that these organized theft groups are not typical phishing operations, noting that the automated nature of EIP-7702 allows for large-scale exploits.

“The new mechanism EIP-7702 is primarily leveraged by coin-stealing entities, facilitating rapid transfers from wallets with compromised private keys or mnemonics,” he elaborated.

Despite the extensive operations facilitated by these features, data suggests that the attackers have not yet turned a profit, indicating either delays in execution or challenges in successfully retrieving funds.

Ethereum’s EIP-7702 Under Threat: Hackers Automate Crypto Theft Through New Smart Wallet Features image 1

A researcher from Wintermute reported that approximately 2.88 ETH has been allocated to authorize more than 79,000 addresses involved in this illicit activity. Notably, one address was accountable for nearly 52,000 authorizations, but the target address has not received any ETH thus far, further complicating the analysis of these attacks.

Conclusion

As Ethereum continues to evolve with innovative features like EIP-7702, the rapid adaptation by malicious entities highlights the urgent need for enhanced security and monitoring. Users are advised to remain vigilant and consider implementing additional protective measures to safeguard their investments from potential breaches.

In Case You Missed It: Bitcoin May Face Deeper Pullback as It Struggles to Retain December 2024 All-Time Highs
0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Locked for new tokens.
APR up to 10%. Always on, always get airdrop.
Lock now!

You may also like

Vitalik: Minimalism Is Key to Ethereum L2 Success

Vitalik Buterin urges Layer 2 projects to embrace minimalism and rely on Ethereum’s core security for long-term success.Leverage Ethereum’s Security, Don’t Reinvent ItA Call to L2 Builders: Focus on What Matters

Coinomedia2025/07/16 19:40
Vitalik: Minimalism Is Key to Ethereum L2 Success

2 Billion USDT Minted at Tether Treasury Today

Tether Treasury has minted 2 billion USDT today, as reported by Nansen. Here's what it could mean for the crypto market.Why Does This Matter for Crypto Investors?What Comes Next?

Coinomedia2025/07/16 19:40
2 Billion USDT Minted at Tether Treasury Today

Bitcoin Peak Signal Absent: Bull Run Still Young

The key Bitcoin Peak Signal hasn’t appeared yet, suggesting the current bull run may still have room to grow.Still Early in the Bull RunWhat to Watch Next

Coinomedia2025/07/16 19:40
Bitcoin Peak Signal Absent: Bull Run Still Young