Crypto
Home›Crypto›Market Structure›Attackers accounted for 63% of early EIP-7702 smart wa…
Attackers accounted for 63% of early EIP-7702 smart wallet authorizations
A USENIX Security study found 2.32 million of 3.66 million EIP-7702 authorization transactions linked to attacker-controlled contracts, with $2.36 million in measured losses.
A peer-reviewed study released for USENIX Security 26 has raised concerns about Ethereum’s newer smart wallet behavior enabled by EIP-7702, finding that attacker-linked contracts were behind the majority of early authorization transactions. The research examined activity across seven chains through July 15, 2025, and reported 2,322,548 of 3,664,166 EIP-7702 authorization transactions were associated with attacker-linked contracts, or 63% of the observed volume.
The study links a relatively small set of malicious contracts to repeated authorizations and characterizes some attacker-controlled activity as likely practice or proof-of-concept testing during the feature’s early exploratory phase. It also estimates $2.36 million in losses tied to the observed activity.
EIP-7702, part of Ethereum’s Pectra upgrade, activated on May 7, 2025. It introduces a type-4 transaction that lets an externally owned account set a pointer to deployed contract code without changing the account’s address, allowing delegated code to execute in the account’s context.
According to the study, the design enables wallet behaviors associated with smart accounts, such as batched calls and sponsored transactions, without requiring users to migrate to a new address. The researchers caution that buggy or hostile delegation targets could act with the account’s authority and say applications should not rely on requesting arbitrary user authorization signatures because there is no safe generic interface for users to assess code with unrestricted access.
Latest closeEthereum $2,387.70 ▲2.6%