Ethereum Pectra Upgrade is Largely Benefitting Crypto Theft Gangs

Source Beincrypto

Ethereum’s recently introduced smart wallet feature, EIP-7702, is under scrutiny after blockchain security researchers uncovered cybercriminals’ misuse of it. Following the Pectra upgrade, several wallet providers have begun integrating EIP-7702 features.

Analysts at Wintermute, a crypto trading firm, noted that attackers used 97% of EIP-7702 wallet delegations to deploy contracts designed to drain funds from unsuspecting users.

Hackers Use Ethereum’s EIP-7702 to Automate Mass Wallet Drainings

EIP-7702 temporarily allows externally owned accounts (EOAs) to operate as smart contract wallets. The upgrade enables features like transaction batching, spending limits, passkey integration, and wallet recovery—all without changing wallet addresses.

While these upgrades aim to enhance usability, malicious actors are leveraging the standard to speed up fund extractions.

Instead of moving ETH manually from each compromised wallet, attackers now authorize contracts that automatically forward any received ETH to their own addresses.

“No doubt attackers are one of the early adopters of new capabilities. 7702 was never meant to be a silver bullet and it does have great use cases,” Rahul Rumalla, Chief Product Officer at Safe, said.

Wintermute’s analysis shows that most of these wallet delegations point to identical codebases designed to “sweep” ETH from compromised wallets.

Ethereum's EIP-7702 Transactions Delegate Approval.Ethereum’s EIP-7702 Transactions Delegate Approval. Source: Dune

These sweepers automatically transfer any incoming funds to attacker-controlled addresses. Out of nearly 190,000 delegated contracts examined, more than 105,000 were linked to illicit activity.

Koffi, a senior data analyst at Base Network, explained that over a million wallets interacted with suspicious contracts last weekend.

He clarified that attackers didn’t use EIP-7702 to hack the wallets but to streamline theft from wallets with already exposed private keys

The analyst furthered that one standout implementation includes a receive function that triggers ETH transfers the moment funds land in the wallet, eliminating the need for manual withdrawal.

Yu Xian, founder of blockchain security firm SlowMist, confirmed that the perpetrators are organized theft groups, not typical phishing operators. He noted that EIP-7702’s automation capabilities make it particularly attractive for large-scale exploits.

“The new mechanism EIP-7702 is used most by coin stealing groups (not phishing groups) to automatically transfer funds from wallet addresses with leaked private keys/mnemonics,” he stated.

Despite the scale of the operation, there are no confirmed profits so far.

Ethereum EIP 7702 Malicious Actors' Address.Ethereum EIP 7702 Malicious Actors’ Address. Source: Dune

A researcher at Wintermute noted that attackers have spent about 2.88 ETH authorizing over 79,000 addresses. One address alone executed nearly 52,000 authorizations, yet the target address has not received any funds.

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
Ripple (XRP) Price Sees a Surge, Solana Targets $600 in 2025 as Investors Increase Focus on New AltcoinThe cryptocurrency market is showing renewed momentum as Ripple (XRP) experiences a significant price surge, and Solana (SOL) sets its sights on a bold $600 target by 2025. Meanwhile, a rising altcoin, Lightchain AI, is capturing investor attention with its innovative ecosystem and strong presale performance, making it a compelling choice for forward-looking investors. Ripple […]
Author  Cryptopolitan
Jan 15, Wed
The cryptocurrency market is showing renewed momentum as Ripple (XRP) experiences a significant price surge, and Solana (SOL) sets its sights on a bold $600 target by 2025. Meanwhile, a rising altcoin, Lightchain AI, is capturing investor attention with its innovative ecosystem and strong presale performance, making it a compelling choice for forward-looking investors. Ripple […]
placeholder
What Crypto Whales are Buying For May 2025Crypto whales are making bold moves heading into May 2025, and three tokens are standing out: Ethereum (ETH), Artificial Superintelligence Alliance (FET), and Onyxcoin (XCN).
Author  Beincrypto
Apr 21, Mon
Crypto whales are making bold moves heading into May 2025, and three tokens are standing out: Ethereum (ETH), Artificial Superintelligence Alliance (FET), and Onyxcoin (XCN).
placeholder
Analysts Highlight 4 Reasons Why ETH Price Could Rebound Strongly in MayEthereum (ETH) has declined for five consecutive months. However, it enters May with rising optimism.
Author  Beincrypto
May 07, Wed
Ethereum (ETH) has declined for five consecutive months. However, it enters May with rising optimism.
placeholder
Ethereum Price Ready to Surge—$2,000 Level Could Be Within ReachEthereum price started a fresh increase above the $1,800 zone. ETH is now rising and attempting a move above the $1,850 resistance. Ethereum started a fresh recovery wave above the $1,820 resistance.
Author  NewsBTC
May 08, Thu
Ethereum price started a fresh increase above the $1,800 zone. ETH is now rising and attempting a move above the $1,850 resistance. Ethereum started a fresh recovery wave above the $1,820 resistance.
placeholder
Ethereum Price Explodes Past $2,200 with 25% Surge—Momentum Builds FastEthereum price started a fresh surge above the $2,000 zone. ETH is now up over 25% and consolidating gains near the $2,200 zone. Ethereum started a fresh surge above the $2,000 resistance.
Author  NewsBTC
May 09, Fri
Ethereum price started a fresh surge above the $2,000 zone. ETH is now up over 25% and consolidating gains near the $2,200 zone. Ethereum started a fresh surge above the $2,000 resistance.
goTop
quote