Crypto2Community
HomeCrypto NewsReviewsGuidesGamblingTradingPress Release

Crypto 2 Community

  • About Us
  • Editorial Policy
  • Why Trust Us
  • Contact Us
  • Privacy Policy
  • Submit a Press Release

Cryptocurrency

  • Best Cryptos to Buy Now
  • Best Crypto Exchanges
  • How To Buy Cryptocurrency
  • Best Crypto Wallets
  • Best Altcoins to Buy

Gambling

  • Best Bitcoin Casinos
  • Best Ethereum Casinos
  • Best Crypto Live Casinos
  • Best Crypto Faucet Casinos
  • Provably Fair Bitcoin Casinos

Best Platforms

  • eToro Review
  • BC.Game Review
  • Jackbit Review
  • Metaspins Review
  • CryptoLeo Review

© 2026 Crypto2Community.com

CAUTION: The content presented on this platform is not intended as financial guidance, and we lack the authorization to offer investment advice. Any material found on this website should not be construed as an endorsement or recommendation of any specific trading strategy or investment decision. The information provided herein is of a general nature, and therefore it is essential to evaluate it in the context of your objectives, financial circumstances, and requirements.

Investment activities involve speculation and entail inherent risks to your capital. This website is not intended for utilization in jurisdictions where the described trading or investment activities are prohibited, and it should only be accessed by individuals who are legally permitted to do so. Depending on your country or state of residence, your investment may not be eligible for investor protection, hence it is advisable to conduct thorough research independently or seek appropriate guidance. While this website is accessible to you free of charge, please note that we may receive commissions from the companies featured on this site.

Disclosure: 18+ Rules regarding online gambling vary from country to country, please ensure you are following them and gamble responsibly. The content on this website is provided for entertainment purposes only. We may utilise affiliate links within our content, and receive commission.

Home/Crypto News
Crypto News

Wintermute Flags Surge in EIP-7702 Wallet Exploit After Ethereum Pectra Upgrade

Author
Austin Mwendia
Austin Mwendia
Crypto Writer
Fact Checked by Joshua Downes
Last updated: June 2, 2025
Cryptocurrency trading is speculative and your capital is at risk when you trade. We may earn affiliate commissions from some of the products on this page - at no extra cost to you.
TweetShareLinkedIn0
Wintermute Flags Surge in EIP-7702 Wallet Exploit After Ethereum Pectra Upgrade

Highlights:

  • Ethereum users are facing wallet draining attacks after the Pectra upgrade added the EIP-7702 feature.
  • Wintermute warns about the wallet exploit and injects messages into risky smart contracts.
  • Security teams have urged better tools to detect threats as wallet-draining scams spread.

Scammers are targeting Ethereum users after the network’s Pectra upgrade added EIP-7702. Through this feature, wallet owners can give control to smart contracts for some transactions. Although users can choose whether to use it, it has already attracted both users and attackers quickly.

Advertisement

Banner

Wintermute, a crypto market-making firm, reports that attackers are now using EIP-7702 to take ETH from wallets with exposed private keys. A kind of malicious contract, nicknamed a “sweeper,” captures any ETH users deposit to a compromised address and sends it to the attacker. Since the Pectra upgrade went live on May 7, users have initiated more than 12,000 EIP-7702 transactions, many of which show similar suspicious patterns.

While EIP-7702 brings new convenience, it also introduces new risks

Our Research team found that over 97% of all EIP-7702 delegations were authorized to multiple contracts using the same exact code. These are sweepers, used to automatically drain incoming ETH from compromised… pic.twitter.com/xHp7zr4hC9

— Wintermute (@wintermute_t) May 30, 2025

Wintermute reported that more than 97% of these EIP-7702 delegations use nearly identical code. This strongly suggests that attackers created most of these contracts for the same malicious purpose. Although the feature aims to offer flexible wallet functions, attackers are copying and reusing a single bytecode structure to drain funds from vulnerable addresses.

Wintermute Responds to EIP-7702 Wallet Exploit with Contract Warning Injection

To combat the EIP-7702 wallet exploit, Wintermute developed a tool called “CrimeEnjoyor.” Using this tool, Wintermute now marks on-chain verified malicious Ethereum contracts with visible warnings. When users access these contracts, they now find a clear notice saying that the contract is used to move ETH out of wallets and that they should not send any ETH.

The developers managed this by turning Ethereum Virtual Machine (EVM) bytecode into Solidity code that people can read. Developers made the code public to make sure the warning messages appeared in them. With this reminder, Wintermute aims to make it less likely for unsuspecting users to fall for malicious contracts.

Wintermute reported that a large number of EIP-7702 delegations are now tied to a single bytecode copy. The system helps users fully understand contracts and reduces the risks that automatic sweepers exploit. They believe that by tagging such contracts, any suspicious activity can be spotted more easily.

Even though EIP-7702 is a good feature, the lack of built-in confirmation has made it tough for users to identify safe contracts. If private keys become exposed, the contracts are capable of removing the newly deposited ETH from the wallet without further commands.

Security Firms Highlight Risk as Wallet Drainers Spread Across Ethereum

Security researchers have documented losses linked to the EIP-7702 feature. One Ethereum user lost over $146,000 after signing multiple malicious batched transactions on May 23. The incident was linked to a scam known as Inferno Drainer, which is often used in phishing campaigns.

🚨 After analysis, we found that the phishing case is a new phishing trick, carried out by the well-known phishing group #InfernoDrainer.

🧵 Unlike typical phishing, the delegated address is not a phishing address, but MetaMask: EIP-7702 Delegator… https://t.co/OpJg73XwzT pic.twitter.com/3dJOeltgMT

— SlowMist (@SlowMist_Team) May 27, 2025

Firms like Scam Sniffer and SlowMist have pointed out that attackers are quickly able to use EIP-7702 to their advantage. They want the Ethereum community to do more to explain how contract delegation works. Moreover, they want the community to add better warnings for users. Wintermute urged users and builders to bring attention to any suspicious contracts they encounter.

Apart from EIP-7702, the Pectra upgrade brought other changes as well. EIP-725 increased the amount of ETH validators can stake from 32 to 2,048. In addition, EIP 7691 aims to help the layer-2 networks on Ethereum by increasing data blob limits and lowering transaction fees.

eToro Platform

Best Crypto Exchange

  • Over 90 top cryptos to trade
  • Regulated by top-tier entities
  • User-friendly trading app
  • 30+ million users
9.9

5 Stars

Visit eToro

eToro is a multi-asset investment platform. The value of your investments may go up or down. Your capital is at risk. Don’t invest unless you’re prepared to lose all the money you invest. This is a high-risk investment, and you should not expect to be protected if something goes wrong.

Advertisement

Banner

Tags

EIP-7702 Wallet ExploitEthereumPectra UpgradeWintermute
Austin Mwendia
Author

Austin Mwendia

Austin Mwendia is a passionate crypto journalist with three years of experience. He has contributed to various media outlets, covering blockchain technology, market analysis, and financial trends. He is committed to educating readers and expanding the adoption of blockchain and decentralized finance.

View full profile ›

ℹ️About Crypto2Community's Editorial Process

Crypto2Community's editorial policy is centered on delivering thoroughly researched, accurate, and unbiased content. We uphold strict editorial policy and sourcing standards, and each page undergoes diligent review by our team of top crypto industry experts and seasoned editors. This process ensures the integrity, relevance, and value of our content for our readers.

More by this author:

  • Crypto Weekly Market Wrap May 25 – Policy Shifts, Treasury Moves & Security Breaches
  • Bitcoin Demand Falls to Lowest Level as Market Sentiment Turns Bearish
  • Blockaid Flags $3M SquidRouterModule Exploit Draining 86 Gnosis Safes

Related Articles:

Crypto Weekly Market Wrap May 25 – Policy Shifts, Treasury Moves & Security Breaches
Crypto Weekly Market Wrap May 25 – Policy Shifts, Treasury Moves & Security Breaches
Crypto News•Weekly Crypto Market Wrap11 hours ago
Raymond Munene
By Raymond Munene5/25/2026
Bitcoin Demand Falls to Lowest Level as Market Sentiment Turns Bearish
Bitcoin Demand Falls to Lowest Level as Market Sentiment Turns Bearish
Crypto News13 hours ago
Chinedu Agbakwusi
By Chinedu Agbakwusi5/25/2026
Blockaid Flags $3M SquidRouterModule Exploit Draining 86 Gnosis Safes
Blockaid Flags $3M SquidRouterModule Exploit Draining 86 Gnosis Safes
Crypto News13 hours ago
Austin Mwendia
By Austin Mwendia5/25/2026

Advertisement

Banner

Advertisement

Banner

🔥Latest offers

Play Now

9.85 Stars

🔥 Get up to 60% with all rewards

Claim Bonus

9.65 Stars

💸 300% deposit bonus up to 20,000 USD

Visit eToro

9.95 Stars

Best Crypto Exchange 2025

Virtual currencies are highly volatile. Your capital is at risk.

Visit KuCoin

9.55 Stars

Trading features & low fees

Popular Topics

  • Sei Price Prediction 2025, 2030, 2040
  • Uniswap Price Prediction 2025, 2030, 2040
  • Near Protocol Price Prediction 2025, 2030, 2040
  • Loopring Price Prediction 2025, 2030, 2040
  • Chainlink Price Prediction 2025, 2030, 2040

Trending News

  • Crypto Weekly Market Wrap May 25 – Policy Shifts, Treasury Moves & Security Breaches
  • Bitcoin Demand Falls to Lowest Level as Market Sentiment Turns Bearish
  • Blockaid Flags $3M SquidRouterModule Exploit Draining 86 Gnosis Safes
  • Ethereum Price Analysis – Staking and Institutional Demand Fuel Bullish Outlook Toward $3,000
  • Bitcoin Price Prediction – Weak Institutional Demand Puts BTC at Risk of Drop Toward $65K
  • Tether, Georgia Move to Bring Georgian Lari On-Chain with GEL₮ Stablecoin
  • Top Cryptos to Watch Today, May 25 – BNB, Tron, Hyperliquid
  • Socket Warns TrapDoor Malware Is Targeting Crypto Developers
  • Coinbase CEO Outlines Eight Crypto Upgrades Needed to Fix Global Finance
  • Why the Crypto Market is Down Today?
  • Bitcoin ETFs Bleed $1.26B, But Santiment Says the Signal Is Not Clearly Bearish
  • Grayscale Files Third S-1 Amendment with SEC for HYPE ETF
  • SEC Approves Nasdaq QBTC Bitcoin Index Options for Wall Street Traders
  • Grayscale Names Top Blockchains Set to Benefit From U.S. Crypto Clarity
  • ECB Resists Euro Stablecoins Push Over Bank Stability Concerns
  • Best Memecoins to Purchase Today, May 23 – BONK, PEPE, SIREN
  • Bank of America Holds $53M in Crypto ETF Exposure, BlackRock’s IBIT Takes the Lead
  • BlackRock Moves Over $150M in BTC and ETH to Coinbase Prime
  • THORChain Restart Vote Opens as ADR028 Sets Exploit Recovery Path
  • Sui Removes Gas Fees for USDC and Six Other Stablecoins on Mainnet