Analysts warn of $1.5M phishing exploit tied to Ethereum’s new EIP-7702

來源 Cryptopolitan

Analysts have sounded the alarm about a vulnerability linked to the relatively new Ethereum Improvement Proposal (EIP-7702) feature following a phishing attack that cost one investor over a million. 

Anti-fraud service Scam Sniffer has noted an increase in phishing scams where attackers target addresses upgraded under the new EIP-7702 standard.

The EIP-7702 feature, which was introduced as part of the Pectra upgrade from May, is designed to enhance wallet functionality by allowing Externally Owned Accounts (EOAs) to temporarily behave like smart contracts.

This feature encourages optimization by allowing multiple operations to be executed within a single transaction, thereby improving efficiency for legitimate users. However, the feature has reportedly opened them up to new exploitation windows.

There have been at least three victims this month

The latest unfortunate victim reportedly lost a total of $1.54 million after signing EIP-7702 phishing batch transactions that contained multiple token transfers and NFT approval operations. Part of those funds has reportedly been bridged to Mainnet via Relay Protocol.

Security analysts warn about EIP-7702 flaw after user loses $1.54M in single phishing attack
Exploiters bridged the stolen funds to Mainnet via Relay Protocol. Sourcce: @realScamSniffer (X/Twitter)

The case comes two days after Scam Sniffer announced that another investor had lost $1M in tokens and NFTs after signing phishing batch transactions disguised as Uniswap swaps.

That exploit came weeks after the anti-fraud service reported that an EIP-7702 upgraded address lost $66k to the same group using the same exploit.

These schemes involve a fraudulent DeFi interface that is typically designed to mimic platforms like Uniswap. The victims were prompted to approve transactions that at first glance appeared routine, but in reality, were authorized hidden transfers.

Upon approval, attackers would drain the wallet almost instantly, siphoning crypto and NFTs.

According to Scam Sniffer, many users are still in the dark about the risks linked to EIP-7702 because it is a recent development. Since the malicious transactions are usually structured to appear normal, unsuspecting users are vulnerable.

Security experts have reported EIP-7702 exploits since June

Scam Sniffer has confirmed that phishing attacks targeting EIP-7702 upgraded addresses have gone up, indicating a growing trend. However, it is not a new trend, as security experts have been reporting incidents for months now.

In June, Wintermute researchers revealed exploiters have targeted several unsuspecting crypto wallets with “automated sweeper” attacks, this time, using “delegate contracts”– a new feature launched as part of the EIP 7702.

In a series of tweets shared via its official X handle, Wintermute claimed its research team had discovered that over 80% of all EIP-7702 delegations were authorized to multiple contracts using the same exact code. They called them sweepers and reported that they are used to automatically drain incoming ETH from compromised addresses.

The malicious attempts by hackers to drain ETH from wallets have continued despite the Ethereum Foundation’s one trillion dollar security program, which it announced on May 14.

To be safe, Scam Sniffer has urged users to be cautious and vigilant when approving batch transactions and to verify interfaces carefully before signing anything.

Fake DeFi platforms designed to mimic legitimate ones have been tagged as one of the most common attack vectors in the crypto sector, and the introduction of batch transactions, though proven to improve user experience for legitimate applications, has added complexity while increasing the chance of an exploit.

The best way to get ahead of the issue is to use only trusted applications and triple-check permissions granted during every transaction, batched or not.

Sign up to Bybit and start trading with $30,050 in welcome gifts

免責聲明:僅供參考。 過去的表現並不預示未來的結果。
placeholder
日幣匯率貶值逼近149!日本央行升息前景不定,聯準會降息難了?比起日本央行升息,短期內美元/日圓走勢更取決於聯準會降息前景。
作者  Tony Chou
8 月 22 日 週五
比起日本央行升息,短期內美元/日圓走勢更取決於聯準會降息前景。
placeholder
8月25日財經早餐:鮑威爾「妥協」放鴿!美元、美債殖利率下挫,以太幣大漲近15%聯准會主席鮑威爾上周五(8月22日)在傑克森霍爾全球央行年會上發表講話,稱由於貨幣政策處於緊縮區間,當前基準情形預期和風險平衡的轉變使我們可能需要調整政策立場。鮑威爾釋放明顯的轉鴿信號,稱業市場正處於奇怪的平衡狀態,存在迅速演變成裁員急劇增加及失業率急升的可能,暗示就業下行風險大於通脹上行風險。交易員押注聯准會9月減息的機會率由講話前約65%攀升至超過85%。
作者  Insights
6 小時前
聯准會主席鮑威爾上周五(8月22日)在傑克森霍爾全球央行年會上發表講話,稱由於貨幣政策處於緊縮區間,當前基準情形預期和風險平衡的轉變使我們可能需要調整政策立場。鮑威爾釋放明顯的轉鴿信號,稱業市場正處於奇怪的平衡狀態,存在迅速演變成裁員急劇增加及失業率急升的可能,暗示就業下行風險大於通脹上行風險。交易員押注聯准會9月減息的機會率由講話前約65%攀升至超過85%。
placeholder
台股大漲446點站回24200 魏哲家澄清疑慮 台積電飆漲30元台股今(25)日開紅盤氣勢如虹,大盤強漲446點,最高來到24263點。上櫃、電子與金融類股同步揚升。電子權值股表現強勁,截至上午約9點20分,台積電大漲30元,暫報1165元;鴻海上漲4.5元,來到207元;廣達漲4.5元,暫報263元;聯發科漲30元,來到1395元;台達電漲14元,暫報678元。
作者  財富進化論
2 小時前
台股今(25)日開紅盤氣勢如虹,大盤強漲446點,最高來到24263點。上櫃、電子與金融類股同步揚升。電子權值股表現強勁,截至上午約9點20分,台積電大漲30元,暫報1165元;鴻海上漲4.5元,來到207元;廣達漲4.5元,暫報263元;聯發科漲30元,來到1395元;台達電漲14元,暫報678元。
placeholder
「雪紅阿姨」王者歸來?宏達電6天4漲停,誰在接盤!佳世達跟漲暗藏外資佈局近期台股在震盪整理中,兩股科技標的卻憑藉熱門題材 「殺出重圍」:佳世達(2352)靠無人機業務獲外資持續加碼,股價創近半年新高;宏達電(2498)則因 AI 智慧眼鏡頭材點燃資金熱情,短短 6 天拉出 4 個議停板,成為市場熱漲的焦點。對一般投資人來說,這兩股的強勢表現背後,既有題材紅利,也藏著需要留意的經營與投資風險。
作者  投資-槓把子
1 小時前
近期台股在震盪整理中,兩股科技標的卻憑藉熱門題材 「殺出重圍」:佳世達(2352)靠無人機業務獲外資持續加碼,股價創近半年新高;宏達電(2498)則因 AI 智慧眼鏡頭材點燃資金熱情,短短 6 天拉出 4 個議停板,成為市場熱漲的焦點。對一般投資人來說,這兩股的強勢表現背後,既有題材紅利,也藏著需要留意的經營與投資風險。
placeholder
佳世達爆量衝漲停 外資追捧AI醫療題材 散戶跟不跟?投資慧眼Insights-佳世達今日爆出7萬張大量,股價觸及漲停!
作者  投資指南針
1 小時前
投資慧眼Insights-佳世達今日爆出7萬張大量,股價觸及漲停!
goTop
quote