Ethereum2026-08-21 15:21:01Security study says 63% of sampled EIP-7702 wallet authorizations were tied to malicious contractsA security paper presented at the USENIX Security Symposium found that 63% of the sampled Ethereum EIP-7702 wallet authorization transactions were linked to malicious contracts controlled by attackers, according to a Techub News report citing NewsBTC. The study said those malicious authorization activities have already resulted in more than $2.3 million in confirmed asset theft. The report said the main issue is not an inherent flaw in Ethereum itself. Instead, it centers on malicious authorizations and a broader wallet attack surface created around the way users approve permissions. EIP-7702, as part of account abstraction, lets externally owned accounts gain more flexible functionality through authorized code execution, but that same flexibility can leave users exposed if they sign harmful authorizations. Researchers said wallet interface design has become a critical layer of defense. They suggested wallets may need clearer warnings, stronger authorization displays, and better simulation tools so users can better understand the risks before signing.1100
PancakeSwap2026-07-23 13:43:00Dormant PancakeSwap LP loses about $2.96 million after signing malicious EIP-7702 approvalA long-inactive PancakeSwap liquidity provider lost about $2.96 million after signing a malicious EIP-7702 approval, according to monitoring by Specter. The attacker removed roughly $1.48 million in BSC-USD liquidity and another $1.48 million in BUSD liquidity that had been supplied by the victim. Specter said the attacker then swapped the BUSD portion into ETH. Of the stolen funds, about $1.46 million has already been deposited into Tornado Cash, while around $1.48 million in USDT remains in the attacker-controlled address. The incident centers on a malicious authorization and involved assets previously deployed on PancakeSwap as liquidity.1380
OP Labs2026-07-22 14:20:14OP Labs Sets 10-Year Post-Quantum Plan to Retire ECDSA Accounts by 2036OP Labs said OP Mainnet and the broader Superchain will phase out ECDSA-based EOAs by January 2036, pushing users toward EIP-7702-powered smart contract accounts designed for post-quantum security.470
Ethereum2026-07-08 13:22:17Ethereum to Launch Major Pectra Upgrade in Q1 2025: EIP-7702 and EOF IntegrationEthereum's upcoming Pectra upgrade, expected in Q1 2025, integrates EVM Object Format and EIP-7702, enabling EOA to act as smart contract wallets temporarily. The upgrade includes ~19 EIPs targeting Layer2 fee reduction and validator efficiency.450
Polymarket2026-06-28 21:31:37Polymarket Users Lose $3.1M PUSD in Front-End Script Attack; Funds Bridged to Ethereum区块链情报公司 AMLBot 监测显示,Polymarket 用户在 Polygon 网络上因前端恶意脚本入侵,被盗走约 310 万美元 PUSD。攻击者利用 EIP-7702 委托执行诱导用户签署授权,随后将资金转换为 USDC.e 并桥接至以太坊,最终兑换为 ETH 并集中存储。目前约 1891.9 枚 ETH 分布在三个新钱包中。此次攻击手法与 2024 年 1inch 的 Lottie Player 库入侵事件类似,均源于第三方脚本被攻破。事件再次警示去中心化应用前端的安全性薄弱环节,用户需警惕恶意授权签名。1920
Polymarket2026-06-28 20:31:31Polymarket Users Lose ~$3.1M PUSD in Front-End Malicious Script Attack on PolygonBlockchain intelligence firm AMLBot has detected a malicious script injection attack targeting Polymarket users on the Polygon network, resulting in the theft of approximately $3.1 million in PUSD stablecoins. Attackers embedded malicious code into the platform's front end, tricking users into signing EIP-7702 delegation transactions that emptied their wallets. The stolen funds were converted to USDC.e via Relay, bridged to Ethereum, swapped for ETH, and consolidated into approximately 1,891.9 ETH across three new wallets. AMLBot draws parallels to the 2024 attack on 1inch, where the Lottie Player library was compromised, leading to front-end contamination.2080
Polymarket2026-06-28 19:31:15Polymarket Users Lose $3.1M in Front-End Script Attack; Technique Mirrors 2024 1inch IncidentAccording to AMLBot monitoring, Polymarket users on Polygon network suffered a front-end malicious script intrusion, losing approximately $3.1 million in PUSD. The attack exploited EIP-7702 delegate execution to trick users into signing malicious authorizations. Stolen funds were converted via Relay to USDC.e, bridged to Ethereum mainnet, and swapped to ETH, currently held as 1,891.9 ETH across three new wallets. The method closely resembles the 2024 1inch attack where the Lottie Player library was compromised to inject wallet-draining scripts, highlighting the persistent threat of third-party front-end dependencies in DeFi.2010
Polymarket2026-06-28 18:01:19Polymarket Users Lose $3.1M PUSD in Front-End Malicious Script Attack; Funds Bridged to EthereumBlockchain intelligence firm AMLBot reported that Polymarket users on Polygon were compromised via a front-end malicious script injection, resulting in the theft of approximately $3.1 million in PUSD. The attacker exploited EIP-7702 delegate execution to trick users into signing authorization transactions, draining wallets of all PUSD. The stolen funds were converted to USDC.e via Relayer, bridged to Ethereum, swapped for ETH, and distributed across three new wallets holding roughly 1,891.9 ETH. The attack mirrors the 2024 1inch incident where the Lottie Player library was compromised, highlighting the growing threat of third-party script attacks on DeFi frontends.2020