MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Font ResizerAa
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Reading: Account abstraction angst: how the Pectra upgrade made life easier for hackers | ForkLog
Share
Font ResizerAa
MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Search
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Have an existing account? Sign In
Follow US
© Market Alert News. All Rights Reserved.
  • bitcoinBitcoin(BTC)$77,833.00-1.23%
  • ethereumEthereum(ETH)$2,318.40-2.92%
  • tetherTether(USDT)$1.000.02%
  • rippleXRP(XRP)$1.43-1.35%
  • binancecoinBNB(BNB)$637.57-1.09%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$85.46-2.76%
  • tronTRON(TRX)$0.3292320.15%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.04-0.01%
  • dogecoinDogecoin(DOGE)$0.096762-0.70%
Smart Contracts

Account abstraction angst: how the Pectra upgrade made life easier for hackers | ForkLog

Last updated: August 19, 2025 9:10 am
Published: 8 months ago
Share

Beyond a boost to Ethereum’s price, the May Pectra upgrade brought expanded functionality and improvements to the ecosystem. Among other things, it enhanced account abstraction (AA): a new type of transaction appeared, allowing ordinary addresses to function as smart-contract wallets.

On the one hand, the changes broadened AA’s use cases and simplified the user experience; on the other, they gave hackers a way to drain victims’ wallets with a single signature. Here is how criminals are exploiting the new weaknesses — and how to protect your funds.

Concerns about account abstraction’s risks were raised even before Pectra went live on mainnet. The original component was EIP-3074, which would “delegate control over EOA to a smart contract”. The idea was dropped in favour of what seemed a safer alternative at the time, EIP-7702 from Vitalik Buterin.

EIP-3074 was criticised for handing virtually full control over a wallet to the smart contract that received delegation. This would allow attackers to empty a user’s balance with one signature.

Traditional EOAs, once a wallet is connected to a protocol, require approval for every subsequent transaction. For example, on a DEX any trading action must be signed manually. EIP-3074 removed that need via the opcodes AUTH and AUTHCALL, but accounts became more vulnerable to malicious protocols.

The rejected proposal handed control over an external address to a smart contract, whereas its replacement, EIP-7702, added smart-contract code to the EOA. The initiative introduced a new transaction type, user_operation, and provided for permission revocation and compatibility with future AA upgrades.

Even Buterin spoke of critical shortcomings, including trust and centralisation risks:

“It seems that any proposal that aims to use EIP-3074 via ‘privilege de-escalation’ (also known as additional keys) will face a similar problem.”

He was right: moving code to the account level did not stop phishing attacks; if anything, it made them easier.

Smart accounts allow complex actions within a single transaction, support spend limits, autopayments and paying gas in a native token instead of ETH. But what if hackers create a protocol that simply sends all your funds to their wallet — and all it takes is one signature?

According to a Dune dashboard by Wintermute, since Pectra activated on May 7, delegations of EOAs to smart contracts have exceeded 140,000. Among known platforms, WhiteBIT, OKX Wallet and MetaMask lead by authorisations.

The total number of smart contracts with delegation capability is 218.

On May 20, analysts at GoPlus Security recorded one of the first AA phishing incidents. They analysed a suspicious smart contract and found that upon signing it instantly executed a function to auto-transfer assets from the victim’s wallet to the attackers’ address.

On-chain data show the smart contract received about 300 authorisations.

“A sophisticated theft mechanism. This complex attack leverages users’ trust in the new EIP-7702,” GoPlus noted.

The Wintermute dashboard also categorises delegator contracts. At present, about 72.8% are “crimes”. The second-largest category (15%) relates to retail wallets, and the third (9%) to “services”.

On May 24, ScamSniffer reported an AA-phishing victim who lost about $146,000 in cryptocurrencies due to “malicious batch transactions”.

Meanwhile, a Web3 researcher found that the AngelFerno hacking group had added EIP-7702 support to a drainer it sells. The malware can simultaneously withdraw up to ten different coins with one signature on Ethereum, BNB Chain and Gnosis.

There are no universal ways to counter attackers when moving to a smart wallet — just as with traditional blockchain phishing. Still, cybersecurity experts agree on one thing: vigilance helps.

Possible recommendations:

GoPlus Security also noted that leading wallets such as MetaMask have already added risk warnings for EIP-7702. When interacting with a suspicious protocol, the app will display a corresponding notice.

As users adopt enhanced wallet functions, attackers have spotted new ways to profit. That does not mean EIP-7702 is a failure — its strengths remain, not least a simplified UX.

Interacting with blockchains has always come with personal responsibility for safeguarding assets, but account abstraction demands more vigilance than ever. Keep the risks and basic cybersecurity rules in mind if you plan to turn your wallet into a smart contract.

Read more on forklog.com

This news is powered by forklog.com forklog.com

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook

Like this:

Like Loading...

Related

Technology and the Future of Real Estate: How Innovation Is Reshaping the Market in 2025 | investingLive
As Bitcoin Dominance Declines Pepeto Is Set To Benefit, Here is Why
Ethereum (ETH) Crashes Over 10% After $4700 Milestone, Investors Gravitating Toward a Viral DeFi Crypto – Cryptopolitan
Stay updated with the latest GateToken price in USD. Explore live GT to USD conversion, market capitalization, and historical price charts for GateToken.
LLMs work better together in smart contract audits – IT Security News

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article Best Crypto Presale 2025 — MAGACOIN FINANCE Stands Out Amid ETH & Stablecoin Growth
Next Article 7 Best Cryptos To Watch In 2025 As MoonBull’s Whitelist Attracts Whale Attention – South Africa Today
© Market Alert News. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Prove your humanity


Lost your password?

%d