World Liberty Financial’s WLFI token, a governance asset for the Trump‑backed DeFi project, has become the focus of a wave of wallet-draining attacks tied to Ethereum’s recent Pectra upgrade and its new EIP‑7702 account abstraction feature. Security firm SlowMist’s founder Yu Xian reports that attackers are abusing EIP‑7702-style “smart wallets” by deploying malicious delegate contracts into wallets whose private keys were already compromised in earlier phishing incidents. When victims later receive WLFI or deposit ETH for gas, bots automatically trigger these delegate contracts to transfer all available assets—WLFI and other tokens—to attacker-controlled addresses, leaving users unable to rescue most of their funds. The issue is not a direct protocol-level bug in Ethereum itself, but a “classic EIP‑7702 phishing exploit” that leverages Pectra’s new capability for externally owned accounts to temporarily act as smart contracts, making it easier for attackers to persist control once a key is leaked. WLFI holders have been hit particularly hard, with reports of entire balances stolen across multiple addresses belonging to the same user and only partial recoveries possible in fast “races” against hijacking bots. SlowMist and other researchers warn that once a private key is compromised, the attacker can continuously re‑exploit the wallet via these embedded delegation contracts, creating a risk of total asset loss unless users promptly cancel or overwrite the malicious contract and migrate funds to a fresh address. The WLFI team, which had already been battling numerous scams and cloned contracts around the token launch, has reiterated that it never contacts users via direct messages and urges holders to verify official email domains and harden their wallet security to avoid further phishing‑driven compromises.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on Ethereum Upgrade

Comments