This feature newly introduced in this Altcoin carries the risk of users' Holdings being stolen: Attention is required!

robot
Abstract generation in progress

Wintermute, a trading firm known in the Crypto currency markets, has issued an important security warning regarding the recent "Pectra" hard fork carried out by Ethereum.

According to the company, the feature named EIP-7702 offered as part of the update is primarily being exploited by malicious individuals and user wallets are at risk.

EIP-7702 offers an "account abstraction" feature developed under the leadership of Ethereum co-founder Vitalik Buterin, allowing wallets to temporarily behave like smart contracts. This enables users to perform functions like multi-transaction batching, payment of gas fees by another party, and social identity verification in a single transaction. However, according to data published by Wintermute via Dune Analytics, this capability is being exploited by malicious attackers to drain wallets.

According to Wintermute's analysis, over 80% of EIP-7702 delegations are serving attacks where a simple and short smart contract called "CrimeEnjoyor" is copied and reused across different addresses. This contract automatically transfers assets from compromised wallets with leaked private keys to an address controlled by the attacker.

"The CrimeEnjoyor contract is short, simple, and widely used," said Wintermute. "This copied bytecode currently makes up the majority of all EIP-7702 delegations. It's an ironic and dark picture," he explained.

The blockchain security firm Scam Sniffer recently announced that it detected a malicious transaction linked to a long-known fraudulent service called Inferno Drainer, which caused a loss of approximately $150,000. On the other hand, another security firm, SlowMist, emphasized in its analysis of the vulnerabilities of EIP-7702 that wallet service providers should support such transactions and that it is important for users to clearly display target addresses in the contracts they sign.

*This is not investment advice.

Follow our Telegram group, Twitter account, and Youtube channel for exclusive news, analyses, and on-chain data! Also, start live price tracking by downloading our Android and IOS Applications right away!

View Original
The content is for reference only, not a solicitation or offer. No investment, tax, or legal advice provided. See Disclaimer for more risks disclosure.
  • Reward
  • Comment
  • Share
Comment
0/400
No comments
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate app
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)