Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnWeb3SquareMore
Trade
Spot
Buy and sell crypto with ease
Margin
Amplify your capital and maximize fund efficiency
Onchain
Going Onchain, without going Onchain!
Convert & block trade
Convert crypto with one click and zero fees
Explore
Launchhub
Gain the edge early and start winning
Copy
Copy elite trader with one click
Bots
Simple, fast, and reliable AI trading bot
Trade
USDT-M Futures
Futures settled in USDT
USDC-M Futures
Futures settled in USDC
Coin-M Futures
Futures settled in cryptocurrencies
Explore
Futures guide
A beginner-to-advanced journey in futures trading
Futures promotions
Generous rewards await
Overview
A variety of products to grow your assets
Simple Earn
Deposit and withdraw anytime to earn flexible returns with zero risk
On-chain Earn
Earn profits daily without risking principal
Structured Earn
Robust financial innovation to navigate market swings
VIP and Wealth Management
Premium services for smart wealth management
Loans
Flexible borrowing with high fund security
Ethereum’s Pectra Update Feature EIP-7702 Becomes a Tool for Wallet Drainers

Ethereum’s Pectra Update Feature EIP-7702 Becomes a Tool for Wallet Drainers

CoinEditionCoinEdition2025/06/01 16:00
By:Abdulkarim Abdulwahab

Over 80% of EIP-7702 delegations are linked to malicious wallet-draining bots. Ethereum’s Pectra upgrade enables smart contract-like wallet behavior. Experts call for stronger private key security and user interface improvement.

  • Over 80% of EIP-7702 delegations are linked to malicious wallet-draining bots.
  • Ethereum’s Pectra upgrade enables smart contract-like wallet behavior.
  • Experts call for stronger private key security and user interface improvement.

Scammers are exploiting Ethereum’s new EIP-7702 feature to drain funds from wallets with compromised private keys. The upgrade, introduced on May 7 as part of Ethereum’s Pectra update, has already been linked to over 12,000 transactions involving suspicious contracts.

EIP-7702: Wallet Flexibility Feature Now an Attack Vector

EIP-7702 was developed to improve Ethereum wallet usability. It allows standard wallets to temporarily function like smart contracts, enabling features such as gas sponsorship, spending limits, and transaction batching. While the EIP-7702 feature is optional for users to activate, it has seen rapid adoption, unfortunately, by malicious actors.

Related: Ethereum’s EIP-7702 Brings Native Abstraction to Wallets With Caveats

Wintermute, a blockchain security firm, reports that more than 80% of EIP-7702 delegations are being used to enable “sweeper” contracts. These automated contracts target wallets with leaked private keys and move funds instantly to the attacker’s wallet.

The ‘CrimeEnjoyor’ Contract Behind Most Attacks

According to Wintermute’s research, a single contract, nicknamed “CrimeEnjoyor”, is responsible for the majority of wallet-draining activity. The contract’s code is simple and widely copied, making it easy for scammers to replicate.

Wintermute publicly decoded the contract’s bytecode to help wallet developers and users identify suspicious delegations. They aim to raise awareness and prompt faster community response in flagging malicious activity.

One Exploit Drained $150,000 in One Click

In one incident highlighted by the security firm Scam Sniffer, a user lost nearly $150,000 in a single batched transaction. The theft was linked to the “Inferno Drainer” scam—a well-known toolkit used by phishing groups.

Wintermute says 97% of all EIP-7702 delegations so far use nearly identical code, indicating widespread misuse of the feature.

Experts: Private Key Leaks Remain Core Vulnerability

While EIP-7702’s design is not inherently flawed, experts agree that it enables faster, cheaper automated attacks once a wallet’s private key is compromised. Taylor Monahan, a well-known crypto security advocate, stressed that the core issue is ongoing private key leakage across the ecosystem.

Security researchers are urging wallet providers to clearly display delegation targets to users. Without this transparency, users may unknowingly authorize malicious contracts.

Blockchain security firm SlowMist warned that phishing gangs have already adapted to exploit EIP-7702. As a result, wallet providers and users must remain vigilant.

Related: Can the Biggest Ethereum Upgrade Since the Merge Spark an ETH Price Rally?

Wintermute has called on the Ethereum community to report known malicious contracts and increase visibility into delegation mechanics. Their findings suggest that stronger safeguards and more transparent wallet interfaces are now critical to user safety.

Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

New spot margin trading pair — HOLO/USDT!

Bitget Announcement2025/09/12 07:46

FUN drops by 32.34% within 24 hours as it faces a steep short-term downturn

- FUN plunged 32.34% in 24 hours to $0.008938, marking a 541.8% monthly loss amid prolonged bearish trends. - Technical breakdowns, elevated selling pressure, and forced liquidations highlight deteriorating market sentiment and risk-off behavior. - Analysts identify key support below $0.0080 as critical, with bearish momentum confirmed by RSI (<30) and MACD indicators. - A trend-following backtest strategy proposes short positions based on technical signals to capitalize on extended downward trajectories.

Bitget-RWA2025/09/12 06:14
FUN drops by 32.34% within 24 hours as it faces a steep short-term downturn

OPEN has dropped by 189.51% within 24 hours during a significant market pullback

- OPEN's price plummeted 189.51% in 24 hours to $0.8907, marking its largest intraday decline in history. - The token fell 3793.63% over 7 days, matching identical monthly and yearly declines, signaling severe bearish momentum. - Technical analysts cite broken support levels and lack of bullish catalysts as key drivers of the sustained sell-off. - Absence of stabilizing volume or reversal patterns leaves the market vulnerable to further downward pressure.

Bitget-RWA2025/09/12 06:14
OPEN has dropped by 189.51% within 24 hours during a significant market pullback

New spot margin trading pair — LINEA/USDT!

Bitget Announcement2025/09/11 10:04