Security study says 63% of sampled EIP-7702 wallet authorizations were tied to malicious contracts
A security paper presented at the USENIX Security Symposium found that 63% of the sampled Ethereum EIP-7702 wallet authorization transactions were linked to malicious contracts controlled by attackers, according to a Techub News report citing NewsBTC. The study said those malicious authorization activities have already resulted in more than $2.3 million in confirmed asset theft. The report said the main issue is not an inherent flaw in Ethereum itself. Instead, it centers on malicious authorizations and a broader wallet attack surface created around the way users approve permissions. EIP-7702, as part of account abstraction, lets externally owned accounts gain more flexible functionality through authorized code execution, but that same flexibility can leave users exposed if they sign harmful authorizations. Researchers said wallet interface design has become a critical layer of defense. They suggested wallets may need clearer warnings, stronger authorization displays, and better simulation tools so users can better understand the risks before signing.








