Ethereum’s new smart wallet feature used mostly by attackers in early days

Ethereum’s new smart wallet feature used mostly by attackers in early days

Attackers dominated early use of Ethereum’s EIP-7702 feature

A new study found that 63% of early transactions using Ethereum’s EIP-7702 smart wallet feature were linked to malicious contracts. The feature, introduced in May 2025, allows regular Ethereum wallets to temporarily act like smart wallets by delegating control to external code.

Researchers analyzed over 3.6 million EIP-7702 authorization transactions across seven blockchains through July 15, 2025. They identified 2.3 million transactions tied to attacker-controlled contracts, leading to confirmed losses of $2.36 million.

Key findings from the study

  • 63% of 3.66 million EIP-7702 transactions were linked to malicious contracts.
  • 924 malicious contracts were detected and manually reviewed.
  • $2.36 million in confirmed losses from attacks.
  • An additional $10.14 million in assets may be at risk due to outdated security assumptions.
  • The study did not measure how many individual wallets were affected or current attack rates.

How EIP-7702 works and why it’s risky

EIP-7702 is a feature that lets regular Ethereum wallets (called externally owned accounts or EOAs) temporarily delegate control to smart contract code. This allows users to access advanced features like batch transactions without changing their wallet address.

The risk comes from the delegated code gaining full control over the wallet’s actions. If the code is malicious, it can make transactions, approve spending, or interact with apps as if it were the wallet owner. Attackers can trick users into signing authorization requests that look safe but actually give control to harmful contracts.

The study found that attackers reused malicious contracts repeatedly, which inflated the transaction count without necessarily affecting more users.

What the study confirmed

  • 63% of early EIP-7702 transactions were linked to malicious contracts.
  • 924 malicious contracts were identified and manually verified.
  • $2.36 million in losses were confirmed across three types of attacks.
  • An estimated $10.14 million in assets may be vulnerable due to outdated security checks in older contracts.
  • Attackers sometimes switched wallets back to benign code after an attack, making detection harder.

What remains unclear

  • The study did not determine how many individual wallets were affected by these attacks.
  • It did not measure the current rate of attacks in 2026.
  • The total number of malicious contracts may be higher than the 924 detected, as some may have evaded the researchers’ methods.
  • It is unclear how many wallets and apps have adopted recommended security practices since the study was completed.

Why this matters for Ethereum users

EIP-7702 was designed to make Ethereum wallets more flexible and powerful. However, the study shows that attackers quickly exploited the feature before many users and wallet providers could implement proper safeguards.

The findings highlight the need for wallets to carefully vet any code that users delegate control to. Users should be cautious when signing authorization requests and ensure they understand what they are approving. The study also warns that older smart contracts with outdated security assumptions may now be vulnerable.

New guidance from Ethereum.org recommends whitelisting trusted delegation contracts, displaying the target clearly, and avoiding arbitrary delegation on hardware wallets. These steps could help reduce the risk of future attacks.

Sources

YA
Written by

Yasir Arafat

Owner & Developer
View all posts

Yasir Arafat is a software developer and the founder of Newisty, covering web development, software, online tools and digital technology. He also oversees Newisty's publishing, technical development and editorial process.


Comments (0)

Leave a comment
Your comment will appear publicly after submission.
No comments yet. Be the first to comment!