Ethereum Pectra Upgrade Hijacked by Wallet-Draining Attacks Despite User Benefits


Over 80% of $ETH's new EIP-7702 delegations were used for malicious "sweeper" attacks, Wintermute analysis reveals.


The Pectra upgrade was designed to improve user experience through account abstraction and smart contract functionality.


A single malicious script nicknamed "CrimeEnjoyor" dominated the majority of EIP-7702 implementations.


One victim lost nearly $150,000 through a phishing attack enabled by the upgrade, Scam Sniffer reported.


The feature allows wallets to temporarily behave like smart contracts for batching transactions and sponsoring gas fees.


Ethereum co-founder Vitalik Buterin originally proposed and championed the EIP-7702 specification.


The copy-pasted bytecode automatically sweeps wallets with compromised private keys and sends funds to attackers.

image
June 01, 2025 at 11:35 PM
46
1
1