𝐄𝐭𝐡𝐞𝐫𝐞𝐮𝐦 𝐏𝐞𝐜𝐭𝐫𝐚 𝐔𝐩𝐠𝐫𝐚𝐝𝐞 𝐄𝐱𝐩𝐨𝐬𝐞𝐬 𝟗𝟕% 𝐨𝐟 𝐄𝐈𝐏-𝟕𝟕𝟎𝟐 𝐖𝐚𝐥𝐥𝐞𝐭𝐬 𝐭𝐨 𝐀𝐮𝐭𝐨-𝐃𝐫𝐚𝐢𝐧 𝐑𝐢𝐬𝐤 he highly acclaimed Pectra upgrade of Ethereum through EIP-7702 exposes wallets with 97% susceptibility to auto-drain from malicious sweeper https://t.co/j2ZU3FnJCV
PSA: Supply Chain Attack: #Ethereum and #BSc devs upgrade immidietely Malicious npm Packages Target BSC and Ethereum to Drain Crypto Wallets Socket uncovered four malicious npm packages that exfiltrate up to 85% of a victim’s Ethereum or BSC wallet using obfuscated JavaScript.
4.9% eth on cexs but 97% of eip-7702 contracts are crimepilled drain exploits

Ethereum's recent Pectra upgrade, specifically the implementation of EIP-7702 designed to simplify wallet delegation, is being exploited by malicious bots that automatically drain wallets. Security researchers and firms, including Wintermute and others, have identified that over 97% of EIP-7702 delegations are linked to identical malicious contracts known as "CrimeEnjoyor," which facilitate automatic theft of Ethereum from compromised wallets. One reported victim lost $150,000 in a phishing attack related to this vulnerability. Additionally, a supply chain attack involving malicious npm packages targeting both Ethereum and Binance Smart Chain (BSC) wallets has been uncovered, with these packages capable of exfiltrating up to 85% of a victim’s crypto holdings using obfuscated JavaScript. The findings have prompted urgent calls for developers on Ethereum and BSC to upgrade their systems immediately to mitigate these risks.

