Hackers Claimed 63% of Ethereum's New Smart Wallet Feature Before Real Users Even Showed Up

Before everyday users ever got a real chance to adopt Ethereum's new smart wallet upgrade, attackers had already made it their own, driving 63% of all early authorization transactions through malicious contracts.

Researchers analyzing Ethereum's EIP-7702, the protocol feature designed to give standard wallets smart contract capabilities, found that the majority of its earliest on-chain activity was not organic adoption. It was exploitation. The damage? A confirmed $2.36 million in losses tied directly to attacker-linked contracts.

What Is EIP-7702 and Why Does It Matter

EIP-7702 is one of the most significant Ethereum upgrades in recent memory. It lets regular externally owned accounts, the wallets most people use every day, temporarily behave like smart contracts. That means features like transaction batching, gas sponsorship, and session-based permissions become available to mainstream users without needing a full account migration.

In theory, this is the bridge between crypto power users and the next hundred million adopters.

In practice, attackers got there first.

How the Attack Worked

Researchers tied the majority of historical EIP-7702 authorization transactions to contracts flagged as attacker-controlled. The attack surface is straightforward and brutal: because EIP-7702 allows a wallet to delegate its logic to an external contract, a user tricked into signing a malicious delegation essentially hands over control of their wallet.

No phishing link required in the traditional sense. One bad signature is enough.

The $2.36 million in measured losses represents confirmed, traceable damage. The actual exposure across wallets that delegated to suspicious contracts but haven't been drained yet is an open question, and that uncertainty is exactly what makes this so dangerous right now.

Why This Should Alarm Every Ethereum Holder

EIP-7702 is new. Most users have no mental model for delegation-based attacks. The interface looks like a standard approval. The consequences are not standard at all.

When a new primitive launches on Ethereum, the security community and the attacker community race to understand it simultaneously. This data confirms attackers won the first lap by a significant margin, 63% to be exact.

The pattern mirrors early DeFi exploit waves, where novel mechanisms were stress-tested by bad actors before auditors and users caught up.

What to Watch and What to Do

If you use an Ethereum wallet and have interacted with any EIP-7702 delegation prompts, verify which contracts your wallet has authorized immediately. Revoke anything unfamiliar using on-chain tools like Revoke.cash.

For traders and DeFi participants, watch for any protocol announcing EIP-7702 integration over the next 60 days. Adoption will accelerate, and so will the attack surface. Security audits specifically covering delegation logic are not optional, they are the minimum bar.

Ethereum's smart wallet future is coming. The question is whether users arrive before the exploiters finish setting up.