Ethereum Pectra Upgrade Hijacked by Wallet-Draining Attacks Despite User Benefits
Over 80% of
$ETH's new EIP-7702 delegations were used for malicious "sweeper" attacks, Wintermute analysis reveals.
The Pectra upgrade was designed to improve user experience through account abstraction and smart contract functionality.
A single malicious script nicknamed "CrimeEnjoyor" dominated the majority of EIP-7702 implementations.
One victim lost nearly $150,000 through a phishing attack enabled by the upgrade, Scam Sniffer reported.
The feature allows wallets to temporarily behave like smart contracts for batching transactions and sponsoring gas fees.
Ethereum co-founder Vitalik Buterin originally proposed and championed the EIP-7702 specification.
The copy-pasted bytecode automatically sweeps wallets with compromised private keys and sends funds to attackers.
