Close Menu
    Facebook X (Twitter) Instagram
    Facebook Instagram YouTube
    Crypto Go Lore News
    Subscribe
    Saturday, August 22
    • Home
    • Market Analysis
    • Latest
      • Bitcoin News
      • Ethereum News
      • Altcoin News
      • Blockchain News
      • NFT News
      • Market Analysis
      • Mining News
      • Technology
      • Videos
    • Trending Cryptos
    • AI News
    • Market Cap List
    • Mining
    • Trading
    • Contact
    Crypto Go Lore News
    Home»Ethereum»Ethereum Wallet Delegation Feature Faces Scrutiny After Attacker Findings
    Ethereum

    Ethereum Wallet Delegation Feature Faces Scrutiny After Attacker Findings

    CryptoExpertBy CryptoExpertAugust 22, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email VKontakte Telegram
    Ethereum Wallet Delegation Feature Faces Scrutiny After Attacker Findings
    Share
    Facebook Twitter Pinterest Email Copy Link
    Ledger


    TLDR

    A peer-reviewed study for USENIX Security ’26 found attacker-linked contracts tied to 63% of Ethereum’s EIP-7702 authorization transactions.
    Researchers tracked 3.66 million authorization transactions across seven chains through July 2025.
    Detected losses totaled $2.36 million, with another $10.14 million in assets exposed through outdated contract defenses.
    Attackers were found rebinding accounts to normal-looking code after attacks, making it harder to spot ongoing risk.
    Researchers and Ethereum developers are now pushing wallets to vet and clearly display any code an account delegates to.

    A new study has found that attackers were behind most of the early activity tied to a new Ethereum wallet feature. The research was peer-reviewed and presented for USENIX Security ’26.

    The feature in question is EIP-7702, which lets a regular Ethereum wallet temporarily act like a smart contract. It went live as part of the Pectra upgrade on May 7, 2025.

    Researchers studied more than 22.8 billion transactions across seven blockchains, including Ethereum, Binance Smart Chain, Polygon, Optimism, Arbitrum, Base, and Gnosis. Within that data, they found 3,664,166 EIP-7702 authorization transactions through July 15, 2025.

    Ledger

    Of those, 2,322,548 transactions, or 63%, were linked to contracts the researchers identified as malicious. The team used transaction filters, code analysis, and manual review to confirm 924 malicious contracts overall.

    How the delegation feature works

    EIP-7702 allows a wallet address to point to separate contract code without changing the address itself. The original owner keeps their private key, but the linked code can act with the full authority of that account.

    This setup lets wallets add features like batching multiple actions into one transaction or letting someone else pay the gas fee. It also means the linked code becomes part of the wallet’s security.

    If that code is faulty or written by an attacker, it can approve transfers, move funds, or interact with apps as if it were the account owner. Researchers say attackers have prepared these authorizations ahead of time and gotten victims to sign them, sometimes through a wallet prompt that does not clearly show which code is being approved.

    What the losses looked like

    The study measured $2,362,848.76 in confirmed losses across three attack types. A separate part of the research looked at older contracts that assumed a wallet address could never behave like a contract.

    That assumption broke once EIP-7702 launched. Researchers found 967 active Ethereum contracts still relying on it as a security check, exposing about $10.14 million in assets to potential risk.

    Researchers also found attackers switching an account back to normal-looking code after an attack. This makes it hard for anyone checking a wallet’s current state to spot that it was compromised earlier.

    They additionally found 500 delegation targets pointing to addresses with no code yet deployed. Code could be added to those addresses later, changing what the wallet actually does while its recorded target stays the same.

    The study’s authors say their method may not catch every malicious contract, especially newer ones or those using different attack methods. The 924 confirmed contracts represent what they were able to verify, not the full scope of abuse.

    In response, Ethereum.org has released guidance recommending wallets whitelist delegation contracts, clearly show users which code they are approving, and rely only on audited smart account implementations. A related proposal calls for wallets to stick to a short list of publicly reviewed account systems rather than letting any application request custom delegation code.



    Source link

    okex
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Telegram Copy Link
    CryptoExpert
    • Website

    Related Posts

    Ethereum

    GnosisDAO Approves Gnosis Chain for Ethereum Economic Zone

    August 21, 2026
    Ethereum

    Bitmine Ethereum Holdings Reach 4.8% of Total ETH Supply

    August 20, 2026
    Ethereum

    Bitmine Nears 5% of Ethereum Supply With 5.82M ETH

    August 19, 2026
    Ethereum

    Ethereum Developers Consider New Privacy Transaction System

    August 18, 2026
    Ethereum

    Ethereum Devs to Narrow 66 Proposals tied to 2027 Hegotá Upgrade

    August 17, 2026
    Ethereum

    Why Ethereum and Solana Supply Growth Could Drop Sharply by 2031: Grayscale

    August 16, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Recommended
    Editors Picks

    Ethereum Wallet Delegation Feature Faces Scrutiny After Attacker Findings

    August 22, 2026

    Paul Ryan’s American Idea Foundation, Digital Asset Plan Canton Benefits Pilot

    August 22, 2026

    Solana Governance Proposals Target Fee Burns And Faster Disinflation

    August 22, 2026

    Treasury ‘Not-QE’ Fuels Bitcoin Rally

    August 22, 2026
    Latest Posts

    We are a leading platform dedicated to delivering authoritative insights, news, and resources on cryptocurrencies and blockchain technology. At Crypto Go Lore News, our mission is to empower individuals and businesses with reliable, actionable, and up-to-date information about the cryptocurrency ecosystem. We aim to bridge the gap between complex blockchain technology and practical understanding, fostering a more informed global community.

    Latest Posts

    Ethereum Wallet Delegation Feature Faces Scrutiny After Attacker Findings

    August 22, 2026

    Paul Ryan’s American Idea Foundation, Digital Asset Plan Canton Benefits Pilot

    August 22, 2026

    Solana Governance Proposals Target Fee Burns And Faster Disinflation

    August 22, 2026
    Newsletter

    Subscribe to Updates

    Get the latest Crypto news from Crypto Golore News about crypto around the world.

    Facebook Instagram YouTube
    • Contact
    • Privacy Policy
    • Terms Of Service
    • Social Media Disclaimer
    • DMCA Compliance
    • Anti-Spam Policy
    © 2026 CryptoGoLoreNews. All rights reserved by CryptoGoLoreNews.

    Type above and press Enter to search. Press Esc to cancel.

    bitcoin
    Bitcoin (BTC) $ 76,995.00
    ethereum
    Ethereum (ETH) $ 2,414.00
    tether
    Tether (USDT) $ 0.999805
    bnb
    BNB (BNB) $ 694.22
    xrp
    XRP (XRP) $ 1.47
    usd-coin
    USDC (USDC) $ 0.999865
    solana
    Solana (SOL) $ 93.29
    tron
    TRON (TRX) $ 0.34486
    figure-heloc
    Figure Heloc (FIGR_HELOC) $ 1.00
    staked-ether
    Lido Staked Ether (STETH) $ 2,265.05