EIP-7702 attacks explained
Ethereum's Pectra upgrade let a normal wallet temporarily act like a smart contract. Drainers immediately turned that into a new one-signature exploit that old approval checks can't see.
Scan your wallet: free Watch 24/7 on Telegram
Public address only. No wallet connection. Nothing to sign.
What EIP-7702 actually does
EIP-7702 lets an ordinary wallet (an EOA) sign an 'authorization' that delegates its execution to code living at another address, turning it into a smart-contract-like account for as long as the delegation stands. It's meant for legitimate account-abstraction upgrades, batched transactions, sponsored gas, without moving to a new address.
How a drainer abuses the authorization
A phishing page dresses the same signature up as a claim, upgrade, or 'account verification' step. Sign it, and your wallet's execution is now delegated to the attacker's contract. There's no separate approval per token to sign, the delegated code can act as your account and move whatever it holds.
Why old defenses miss it
Approval scanners watch for approve() and Permit calls touching token allowance storage. A 7702 authorization does neither, so revoking approvals afterward changes nothing. A delegation signed with chainId 0 is valid on every chain at once, a hallmark of a delegation built for mass draining rather than a single legitimate app.
How Guardian catches it before you sign
Veriql's Guardian decodes any authorizationList in a pending request, flags a chainId-0 (every-chain) delegation as a drainer hallmark, and throws a full-screen STOP before you sign, regardless of what the destination contract's code does. Since Pectra shipped, the large majority of observed 7702 delegations outside known apps have been malicious, so treat any surprise delegation prompt as a stop sign.
FAQ
Does revoking my token approvals undo a malicious 7702 delegation?
No. A delegation doesn't touch allowance storage, so there's nothing there to revoke. Undoing it means signing a new authorization from that same wallet that points delegation back at nothing, not always practical if the wallet is fully compromised, which is why moving remaining assets to a fresh wallet is the safer default.
Is EIP-7702 itself dangerous?
No: it's a legitimate Ethereum upgrade. The risk is identical to every other drainer pattern: getting tricked into signing something for someone else's contract. The signature is just newer, so fewer tools were watching for it at first.