Attackers drove 63% of early use of Ethereum’s new smart wallet feature

Ethereum's shortcut to smart wallet behavior arrived with a new trust problem: a wallet can make a regular address programmable without moving the user's assets, while the delegated code gains power to act with that account's authority.
A peer-reviewed study released for USENIX Security '26 found that attacker-linked contracts were associated with 2,322,548 of the 3,664,166 EIP-7702 authorization transactions it observed across seven chains through July 15, 2025. That is 63% of the historical transaction volume in the researchers' dataset.
The authors tied a relatively small set of malicious contracts to repeated authorizations and described some attacker-controlled activity as likely practice or proof-of-concept testing during an early, exploratory phase.
The figure measures transactions, while distinct-wallet prevalence and the current 2026 attack rate sit outside the study's scope.
Why attackers dominated the early authorization count
Ethereum activated Pectra, including EIP-7702, on May 7, 2025. The final specification introduced a type-4 transaction that lets an externally owned account set a pointer to deployed contract code.
… Continue reading the full article at the original source below.


