Ethereum Wallet Delegation Feature Tainted by Malicious Contracts
A recent study on Ethereum's EIP-7702 wallet delegation feature has highlighted significant security risks. The researchers found that attacker-controlled contracts were tied to 63% of early transactions using this feature, which allows a standard wallet to temporarily behave like a smart contract.
The study analyzed over 22.8 billion transactions across seven blockchains and isolated 3,664,166 EIP-7702 authorization transactions. Manual review and code analysis confirmed 924 malicious contracts, tied to about $2.36 million in confirmed losses.
The researchers also found that older contracts, which assumed wallets could never act like contracts, now expose roughly $10.14 million in assets. Ethereum.org has issued guidance urging wallets to whitelist delegation contracts and clearly show users what code they're approving.