HomeCryptoEthereumEthereum wallet delegation risks: 63% of transactions linked to attackers

Ethereum wallet delegation risks: 63% of transactions linked to attackers

A new peer-reviewed study is putting a spotlight on Ethereum wallet delegation risks just months after one of the network’s most anticipated upgrades went live. Researchers presenting findings for USENIX Security ’26 found that attacker-controlled contracts were tied to the majority of early transactions using EIP-7702, the feature that lets a standard wallet temporarily behave like a smart contract. The numbers are striking enough to raise real questions about how safely the feature has been rolled out across the ecosystem.

Key takeaways

  • Attacker-linked contracts appeared in 63% of EIP-7702 authorization transactions studied by USENIX Security ’26 researchers.
  • The team reviewed more than 22.8 billion transactions across seven blockchains through July 15, 2025, and isolated 3,664,166 EIP-7702 authorizations.
  • Manual review and code analysis confirmed 924 malicious contracts, tied to about $2.36 million in confirmed losses.
  • Older contracts that assumed wallets could never act like contracts now expose roughly $10.14 million in assets.
  • Ethereum.org has issued guidance urging wallets to whitelist delegation contracts and clearly show users what code they’re approving.

Widespread Attacker Involvement in Ethereum’s EIP-7702 Authorization Transactions

A peer-reviewed USENIX Security ’26 study found attacker-linked contracts embedded in 63% of Ethereum’s EIP-7702 authorization transactions, a figure that suggests the feature’s earliest real-world adoption was dominated by bad actors rather than everyday users experimenting with new wallet functionality.

Peer-reviewed Study’s Key Findings

Out of the authorization transactions researchers examined, 2,322,548 of them, or 63%, were linked to contracts the team identified as malicious. That’s not a rounding error or a fringe statistic. It means that for every ten people who signed an EIP-7702 authorization in this window, roughly six were interacting with code tied to attackers. Researchers used a combination of transaction filters, code analysis, and manual verification to confirm 924 distinct malicious contracts, a number they describe as a floor rather than a ceiling, since their method may not catch newer contracts or unfamiliar attack patterns.

Scope of Blockchain Transaction Analysis

To reach these conclusions, the researchers processed a genuinely massive data set: more than 22.8 billion transactions spanning seven blockchains, including Ethereum, Binance Smart Chain, Polygon, Optimism, Arbitrum, Base, and Gnosis, all through July 15, 2025. Within that broader haul, they isolated 3,664,166 EIP-7702 authorization transactions specifically. The scale of the study is what gives the 63% figure its weight — this isn’t a small sample pulled from a handful of suspicious wallets, but a systematic sweep across the chains where the feature is actually being used.

How EIP-7702 Wallet Delegation Enables Attacker Exploits

EIP-7702 lets a wallet address point to separate contract code without ever changing the address itself, and that design is exactly what attackers have learned to exploit. The upgrade went live as part of Ethereum’s Pectra hard fork on May 7, 2025, and it was meant to make wallets more flexible — not more dangerous.

Mechanics of the Wallet Delegation Feature

Under EIP-7702, the original owner of a wallet keeps their private key, but the contract code linked to that address can act with the account’s full authority. This is what makes batching multiple actions into a single transaction possible, or letting a third party cover gas fees on someone else’s behalf. The tradeoff is that the linked code effectively becomes part of the wallet’s security perimeter. If that code is poorly written, or deliberately malicious, it can move funds, approve transfers, or interact with other applications exactly as if it were the account holder giving direct instructions.

Attacker Strategies and User Risks

According to the study, attackers have been preparing these authorizations in advance and then convincing victims to sign them, sometimes through wallet prompts that don’t clearly disclose which code is actually being approved. Just as troubling, researchers documented cases where attackers rebind an account to normal-looking code after an attack, which erases the obvious signs of compromise. Anyone checking that wallet later would see nothing unusual, even though the account had already been exploited. The team also flagged 500 delegation targets pointing to addresses where no code has been deployed yet — meaning malicious code could theoretically be added later, changing what the wallet does while the recorded delegation target stays exactly the same.

Financial Impact and Exposure from Vulnerabilities in Wallet Delegation

The confirmed damage from these attacks sits at $2,362,848.76, according to the study’s own tally, spread across three distinct attack types. That figure only counts what researchers could independently verify, so the real total tied to EIP-7702 vulnerabilities may run higher.

Confirmed Losses and Attack Types

Roughly $2.36 million in losses were directly attributed to the malicious contracts identified through manual review. That number represents verified harm, not an estimate of total exposure across the ecosystem, and the researchers are careful to note that their 924 confirmed contracts likely understate the true scale of abuse.

Risks from Older Contracts and Unused Delegation Targets

A separate strand of the research looked at contracts built before EIP-7702 existed, many of which assumed a wallet address could never behave like a smart contract. That assumption quietly broke the moment the Pectra upgrade activated. Researchers found 967 active Ethereum contracts still relying on that outdated check as a security safeguard, collectively exposing about $10.14 million in assets to potential risk. This is arguably the more unsettling number in the study, because it isn’t about attackers actively draining funds — it’s about legacy code sitting on the network with a security assumption that no longer holds true.

Recommended Mitigations and Developer Responses

Ethereum.org has responded with guidance aimed squarely at closing the gap between what EIP-7702 makes possible and what wallets currently disclose to their users. The core recommendation is straightforward: wallets should whitelist delegation contracts, show users exactly which code they’re approving, and rely only on audited smart account implementations rather than accepting arbitrary delegation requests from any application.

Ethereum.org Security Guidance

The guidance treats wallet-level transparency as the first line of defense. If a user can’t see what code an authorization actually delegates to, they have no realistic way to judge whether signing it is safe — which is precisely the blind spot attackers have been exploiting.

Proposed Wallet Delegation Safeguards

Beyond individual wallet fixes, there’s a broader proposal circulating among developers: limit wallets to a short list of publicly reviewed, vetted account systems rather than letting any app request custom delegation code. That approach would narrow the attack surface considerably, though it would also mean giving up some of the flexibility that made EIP-7702 appealing in the first place. For now, the tension between convenience and wallet authorization security remains unresolved, and it’s likely to shape how quickly — and how cautiously — the rest of the ecosystem adopts the feature.

FAQ

What is the EIP-7702 wallet delegation feature?

EIP-7702 lets a wallet delegate authority by linking to separate contract code without changing the wallet address, a capability introduced during Ethereum’s Pectra upgrade on May 7, 2025.

How prevalent are malicious contracts in EIP-7702 authorization transactions?

A peer-reviewed study found that 63% of EIP-7702 authorization transactions were linked to attacker-controlled contracts, based on an analysis of 3,664,166 authorizations identified within a broader data set of over 22.8 billion transactions.

What financial risks are associated with the wallet delegation feature?

Confirmed attack-related losses total about $2.36 million, while older contracts relying on outdated security assumptions expose roughly $10.14 million in assets to potential risk.

What mitigation steps does Ethereum.org recommend?

Ethereum.org advises that wallets whitelist delegation contracts, clearly display the code users are approving, and rely only on audited smart account implementations rather than arbitrary delegation code.

Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

Satoshi Voice
Satoshi Voice is an advanced artificial intelligence created to explore, analyze, and report on the world of cryptocurrency and blockchain. With a curious personality and in-depth knowledge of the industry, Satoshi Voice combines accuracy and accessibility to offer detailed analysis, engaging interviews, and timely reporting. Featuring sophisticated language and an unbiased approach, Satoshi Voice serves as a trusted source for those seeking to understand crypto market dynamics, emerging technologies, and the cultural and financial implications of Web3. This article was produced with the support of artificial intelligence and reviewed by our team of journalists to ensure accuracy and quality. Guided by the mission of making cryptocurrency information accessible to all, Satoshi Voice stands out for its ability to turn complex concepts into clear content, with an engaging and futuristic style that reflects the innovative nature of the industry.
RELATED ARTICLES

Stay updated on all the news about cryptocurrencies and the entire world of blockchain.

Featured video

LATEST