Analysts warn of $1.5M phishing exploit tied to Ethereum’s new EIP-7702

来源 Cryptopolitan

Analysts have sounded the alarm about a vulnerability linked to the relatively new Ethereum Improvement Proposal (EIP-7702) feature following a phishing attack that cost one investor over a million. 

Anti-fraud service Scam Sniffer has noted an increase in phishing scams where attackers target addresses upgraded under the new EIP-7702 standard.

The EIP-7702 feature, which was introduced as part of the Pectra upgrade from May, is designed to enhance wallet functionality by allowing Externally Owned Accounts (EOAs) to temporarily behave like smart contracts.

This feature encourages optimization by allowing multiple operations to be executed within a single transaction, thereby improving efficiency for legitimate users. However, the feature has reportedly opened them up to new exploitation windows.

There have been at least three victims this month

The latest unfortunate victim reportedly lost a total of $1.54 million after signing EIP-7702 phishing batch transactions that contained multiple token transfers and NFT approval operations. Part of those funds has reportedly been bridged to Mainnet via Relay Protocol.

Security analysts warn about EIP-7702 flaw after user loses $1.54M in single phishing attack
Exploiters bridged the stolen funds to Mainnet via Relay Protocol. Sourcce: @realScamSniffer (X/Twitter)

The case comes two days after Scam Sniffer announced that another investor had lost $1M in tokens and NFTs after signing phishing batch transactions disguised as Uniswap swaps.

That exploit came weeks after the anti-fraud service reported that an EIP-7702 upgraded address lost $66k to the same group using the same exploit.

These schemes involve a fraudulent DeFi interface that is typically designed to mimic platforms like Uniswap. The victims were prompted to approve transactions that at first glance appeared routine, but in reality, were authorized hidden transfers.

Upon approval, attackers would drain the wallet almost instantly, siphoning crypto and NFTs.

According to Scam Sniffer, many users are still in the dark about the risks linked to EIP-7702 because it is a recent development. Since the malicious transactions are usually structured to appear normal, unsuspecting users are vulnerable.

Security experts have reported EIP-7702 exploits since June

Scam Sniffer has confirmed that phishing attacks targeting EIP-7702 upgraded addresses have gone up, indicating a growing trend. However, it is not a new trend, as security experts have been reporting incidents for months now.

In June, Wintermute researchers revealed exploiters have targeted several unsuspecting crypto wallets with “automated sweeper” attacks, this time, using “delegate contracts”– a new feature launched as part of the EIP 7702.

In a series of tweets shared via its official X handle, Wintermute claimed its research team had discovered that over 80% of all EIP-7702 delegations were authorized to multiple contracts using the same exact code. They called them sweepers and reported that they are used to automatically drain incoming ETH from compromised addresses.

The malicious attempts by hackers to drain ETH from wallets have continued despite the Ethereum Foundation’s one trillion dollar security program, which it announced on May 14.

To be safe, Scam Sniffer has urged users to be cautious and vigilant when approving batch transactions and to verify interfaces carefully before signing anything.

Fake DeFi platforms designed to mimic legitimate ones have been tagged as one of the most common attack vectors in the crypto sector, and the introduction of batch transactions, though proven to improve user experience for legitimate applications, has added complexity while increasing the chance of an exploit.

The best way to get ahead of the issue is to use only trusted applications and triple-check permissions granted during every transaction, batched or not.

Sign up to Bybit and start trading with $30,050 in welcome gifts

免责声明:仅供参考。 过去的表现并不预示未来的结果。
placeholder
Tesla股价10年大涨百倍的启示-未来特斯拉股价走势如何?特斯拉股票怎么买?经过2022年至今全球股灾的洗礼,Tesla股价拉回一段,但是自挂牌以来累计的涨幅仍然超过百倍,堪称这十年来全球新能源科技发展下的最大赢家。
作者  Mitrade
6 月 09 日 周一
经过2022年至今全球股灾的洗礼,Tesla股价拉回一段,但是自挂牌以来累计的涨幅仍然超过百倍,堪称这十年来全球新能源科技发展下的最大赢家。
placeholder
净利润翻倍但股价狂泻,亚马逊Q4财报“罪不至此”?TradingKey - 美国科技巨头亚马逊Amazon(AMZN.US)于2月7日周四盘后公布了喜忧参半的2024年第四季业绩。营收和盈利超预期,但财测逊色、资本支出飙高,重挫盘后股价一度跌逾7%。亚马逊这份成绩单亮点不少,比如削减成本措施奏效、净利润几乎翻倍增长、云计算部门连续三个季度保持19%的增长率、电子商务业务在假日季表现强劲等。然而,投资人尤其关注的AI增长前景和资本支出令人唏嘘:一边
作者  TradingKey
2 月 07 日 周五
TradingKey - 美国科技巨头亚马逊Amazon(AMZN.US)于2月7日周四盘后公布了喜忧参半的2024年第四季业绩。营收和盈利超预期,但财测逊色、资本支出飙高,重挫盘后股价一度跌逾7%。亚马逊这份成绩单亮点不少,比如削减成本措施奏效、净利润几乎翻倍增长、云计算部门连续三个季度保持19%的增长率、电子商务业务在假日季表现强劲等。然而,投资人尤其关注的AI增长前景和资本支出令人唏嘘:一边
placeholder
瑞波币价格预测:在与美国证券交易委员会提交3亿美元瑞波币国库申请后,XRP可能延续反弹瑞波币(XRP)价格在测试 $2.27 的阻力位后停滞不前。该代币在周三撰写时徘徊在约 $2.24,整体加密货币市场情绪低迷。
作者  FXStreet
6 月 05 日 周四
瑞波币(XRP)价格在测试 $2.27 的阻力位后停滞不前。该代币在周三撰写时徘徊在约 $2.24,整体加密货币市场情绪低迷。
placeholder
8.18精选策略分享:比特币、以太币、WTI原油、联合健康(UNH)技术分析本周五(8月22日)鲍威尔出席杰克森霍尔(Jackson Hole)全球央行年会,市场关注鲍威尔是否会借此机会反驳当前过高的降息预期。美联储正陷入两难困境。一方面,关税措施导致的生产者物价指数(PPI)超预期上涨,预示着输入性通胀风险正在累积;另一方面,就业市场降温和制造业低迷又增加了经济下行压力。此外,美联储公布7月货币政策会议纪要、美俄乌三方会晤有望举行同样值得关注。
作者  Insights
8 月 18 日 周一
本周五(8月22日)鲍威尔出席杰克森霍尔(Jackson Hole)全球央行年会,市场关注鲍威尔是否会借此机会反驳当前过高的降息预期。美联储正陷入两难困境。一方面,关税措施导致的生产者物价指数(PPI)超预期上涨,预示着输入性通胀风险正在累积;另一方面,就业市场降温和制造业低迷又增加了经济下行压力。此外,美联储公布7月货币政策会议纪要、美俄乌三方会晤有望举行同样值得关注。
placeholder
8月25日财经早餐:鲍威尔“妥协”放鸽!美元、美债收益率下挫,以太币大涨近15%美联储主席鲍威尔上周五(8月22日)在杰克森霍尔全球央行年会上发表讲话,称由于货币政策处于紧缩区间,当前基准情形预期和风险平衡的转变使我们可能需要调整政策立场。鲍威尔释放明显的转鸽信号,称业市场正处于奇怪的平衡状态,存在迅速演变成裁员急剧增加及失业率急升的可能,暗示就业下行风险大于通胀上行风险。交易员押注美联储9月减息的机会率由讲话前约65%攀升至超过85%。
作者  Insights
1 小时前
美联储主席鲍威尔上周五(8月22日)在杰克森霍尔全球央行年会上发表讲话,称由于货币政策处于紧缩区间,当前基准情形预期和风险平衡的转变使我们可能需要调整政策立场。鲍威尔释放明显的转鸽信号,称业市场正处于奇怪的平衡状态,存在迅速演变成裁员急剧增加及失业率急升的可能,暗示就业下行风险大于通胀上行风险。交易员押注美联储9月减息的机会率由讲话前约65%攀升至超过85%。
goTop
quote