$3.55 Million in Unclaimed Bridge Funds Moved Through Ethereum Wallet via EIP-7702
Bridged assets claimed and transferred through a single Ethereum wallet
On October 9, an Ethereum address funded through Tornado Cash claimed and transferred approximately $3.55 million in previously unclaimed bridge assets (services that move digital tokens between different blockchains) through wallet 0x4943. The transfers used two EIP-7702 account delegations, a relatively new Ethereum upgrade that lets a wallet controlled by a private key hand execution authority to another address that can submit transactions on its behalf.
Key numbers and transaction details
- First transaction (4:13:47 p.m. ET): About 499,865 USDT, 325,587 USDC, 500,048 DAI, and 0.9953 ETH moved from Agglayer through wallet 0x4943 to address 0x24a9. The assets were worth roughly $1.33 million.
- Second transaction (4:24:59 p.m. ET): About 2.22 million USDT moved from NEAR's Rainbow Bridge through the same wallet to the same recipient, worth approximately $2.22 million.
- Funding source: About 0.09783 ETH was sent to 0x24a9 from Tornado Cash's 0.1 ETH pool earlier the same day at 3:32:59 p.m. ET.
- All three transactions were submitted by address 0x24a9.
What BlockSec says about the onchain record
BlockSec Phalcon, a security research firm that flagged the transfers, noted that the onchain data confirms the delegations and authorizations were cryptographically valid. However, the firm stated that the blockchain record does not establish whether the wallet owner signed the transactions knowingly, was tricked into signing them, or had the private key compromised.
After the Rainbow Bridge claim, 0x24a9 also submitted a transaction that cleared 0x4943's EIP-7702 delegation in the same Ethereum block, removing the authority it had been granted.
A researcher had notified the wallet owner days earlier
On October 4, onchain researcher stuckfunds.eth sent a public message to the wallet owner advising that funds were still claimable from both Agglayer and NEAR's Rainbow Bridge. The message included the instruction: 'Claim it yourself from this wallet,' according to the transaction record.
What is confirmed versus what remains uncertain
Confirmed: The transactions occurred, the delegation authorizations were valid onchain, the recipient address submitted all transactions, and the funding address had received ETH from Tornado Cash shortly before the claims.
Still unclear: Whether the original owner of wallet 0x4943 intentionally authorized the delegation, was deceived into signing it, or had the private key stolen. No public statement from the wallet owner has been reported.
Why this matters
EIP-7702 introduces a new attack surface: because an account can delegate execution authority to another address, a compromised or tricked wallet owner could unknowingly let a third party execute transactions on their behalf. The valid cryptographic signatures make it difficult to prove wrongdoing onchain, even when the underlying circumstances may involve social engineering or a stolen key.