Wintermute said Ethereum’s Pectra upgrade has already been abused as a tool for wallet-draining activity through EIP-7702, the new feature that lets externally owned accounts temporarily behave like smart-contract wallets. The firm’s analysis, echoed by other security researchers, is that criminals are using the delegation mechanism not to hack wallets directly, but to automate theft from wallets whose private keys or seed phrases have already been compromised. EIP-7702 was introduced with Pectra to improve wallet usability by enabling features such as transaction batching, gas sponsorship, passkey support, and wallet recovery without changing wallet addresses. Security concern comes from the same delegation capability: if a user is tricked into signing a malicious authorization, an attacker-controlled contract can execute draining logic, including automatically forwarding any incoming ETH or tokens out of the wallet. Wintermute’s findings suggest the abuse is already being used at scale, making EIP-7702 an immediate security and user-protection issue rather than only a future theoretical risk.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on Pectra

Comments