Attackers Dominate Early Adoption of Ethereum's Smart Wallet Feature
Ethereum's new smart wallet feature, EIP-7702, has been widely used by attackers to gain unauthorized access to user accounts. According to a recent study, 63% of all EIP-7702 authorization transactions on Ethereum and six other chains between May 7, 2025, and July 15, 2025, were linked to malicious contracts.
The study, which analyzed over 22.8 billion historical transactions, found that a relatively small set of malicious contracts was responsible for the majority of these attacks. The researchers identified 924 malicious contracts, with 793 targeting externally owned accounts and 124 targeting contract accounts.
The researchers also estimated that attackers had caused $2.36 million in realized losses across the three attack categories. Additionally, they found that about $10.1 million in assets were at potential high risk due to older contracts that assumed programmable EOAs could not exist.
Wallets and monitoring tools need to remember where an account previously pointed and evaluate changes in delegated code. The study's authors recommend making delegation a wallet-controlled installation decision, whitelisting delegation contracts, and displaying the target prominently.