Ethereum wallet delegation risks: 63% of transactions linked to attackers

A new peer-reviewed study is putting a spotlight on Ethereum wallet delegation risks just months after one of the network’s most anticipated upgrades went live. Researchers presenting findings for USENIX Security ’26 found that attacker-controlled contracts were tied to the majority of early transactions using EIP-7702, the feature that lets a standard wallet temporarily behave like a smart contract. The numbers are striking enough to raise real questions about how safely the feature has been rolled out across the ecosystem.
Key takeaways
- Attacker-linked contracts appeared in 63% of EIP-7702 authorization transactions studied by USENIX Security ’26 researchers.
- The team reviewed more than 22.8 billion transactions across seven blockchains through July 15, 2025, and isolated 3,664,166 EIP-7702 authorizations.
- Manual review and code analysis confirmed 924 malicious contracts, tied to about $2.36 million in confirmed losses.
- Older contracts that assumed wallets could never act like contracts now expose roughly $10.14 million in assets.
- Ethereum.org has issued guidance urging wallets to whitelist delegation contracts and clearly show users what code they’re approving.
Widespread Attacker Involvement in Ethereum’s EIP-7702 Authorization Transactions
A peer-reviewed USENIX Security ’26 study found attacker-linked contracts embedded in 63% of Ethereum’s EIP-7702 authorization transactions, a figure that suggests the feature’s earliest real-world adoption was dominated by bad actors rather than everyday users experimenting with new wallet functionality.
… Continue reading the full article at the original source below.

