EIP-7702 Smart Wallet Security Exploit
EIP-7702 delegation feature creates new attack vectors that enable automated fund draining and pose widening security risks to Ethereum users
Too little corroboration in the last 3 days to call a trend (4 articles). Watching for it to gain traction.
Still mostly niche and specialist coverage — not yet picked up broadly by mainstream press.
"Attacker-linked contracts were associated with 2,322,548 of the 3,664,166 EIP-7702 authorization transactions it observed across seven chains through July 15, 2025. That is 63% of the historical transaction volume in the researchers' dataset."
"EIP-7702 breaks the old assumption that msg.sender == tx.origin reliably identifies a plain EOA or blocks contract-mediated behavior. The researchers identified 967 active Ethereum contracts in a subset using that check as a flash-loan defense and estimated that about $10.1 million in assets were at potential high risk."
"Attackers could prepare authorization fields off-chain and ask a victim to sign, and a wallet might reduce the decision to a high-level account-upgrade prompt while obscuring the contract address or code receiving authority."
"Ethereum's official guidance warns that malicious EIP-7702 delegation can give hostile contract code control over assets. A separate USENIX Security '26 study found more than 63% of analyzed EIP-7702 authorization transactions were associated with malicious EOA-targeted attacks, identifying 924 malicious contract accounts across seven supported chains."