Saturday, March 7, 2026
HomeEthereumCrypto investor loses $1M in Uniswap rip-off exploiting Ethereum's EIP-7702

Crypto investor loses $1M in Uniswap rip-off exploiting Ethereum’s EIP-7702


A single phishing assault drained practically $1 million value of tokens from a crypto investor who unknowingly signed a batch of malicious transactions disguised as Uniswap swaps, based on blockchain safety agency Rip-off Sniffer.

In an Aug. 22 publish on X, Yu Xiang, founding father of blockchain safety agency SlowMist, famous that the incident concerned 5 tokens siphoned by means of a transaction exploiting Ethereum’s new EIP-7702 mechanism.

He defined:

“From the attitude of a phished person, it goes like this: the person opens a phishing web site, a pockets signature immediate pops up, the person clicks verify, and with simply that one motion, all worthwhile belongings within the pockets tackle vanish in a snap.”

EIP-7702 was launched within the Pectra improve to streamline the Ethereum person expertise. The function permits a pockets to behave like a brief sensible contract, making it potential to batch a number of transactions, allow gasoline sponsorship, or set spending limits in a single step.

In precept, the delegation is revocable and network-specific. Nonetheless, attackers have discovered methods to weaponize the function in apply.

Crypto market maker Wintermute has warned that the usual’s implementation is being exploited at scale. Its June evaluation confirmed that greater than 90% of EIP-7702 delegations had been linked to malicious contracts.

The agency identified that many of those contracts are easy copy-paste scripts that scan for susceptible wallets and drain their holdings mechanically.

Contemplating this, Rip-off Sniffer and Xiang urged crypto customers to take additional care earlier than signing pockets requests. They beneficial verifying domains, avoiding rushed confirmations, and rejecting signatures that appear unclear or overly broad.

Additionally they acknowledged that a few of the pink flags that might come up embrace requests for limitless token approvals, contract upgrades below EIP-7702, or transaction simulations that don’t match expectations.

Talked about on this article



Supply hyperlink

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Most Popular

Recent Comments