
Pectra EIP-7702 Exploit: One Signature, 12,000 Wallets, $48M Gone
$48 million. 12,000 wallets. One signature that looked like a login.
The Scheme: Code Delegation Turned Into a Drain Vector
EIP-7702 introduced a new transaction type — `0x04` — that lets an Externally Owned Account sign an authorization tuple. Once on-chain, the EOA executes calls as if it were the delegated contract until the authorization expires. The exploit: phishing crews convince you to sign that tuple pointing to their drainer contract. You didn't approve a token. You approved becoming the attacker. Old phishing stole one approval at a time. 7702 phishing steals the wallet's behaviour itself.
Old phishing rented a key. 7702 phishing rents the locksmith.
Pectra's EIP-7702 lets a normal wallet temporarily delegate its code to a smart contract. Between April and May 2026, drainer-as-a-service crews weaponized that exact mechanism. Victims signed what looked like a routine sign-in. The signature bonded a malicious contract to their EOA for 24 hours. The contract drained everything in 47 minutes. The wallet wasn't hacked. The wallet was rented out.
The Hard Truth: The Signature Looks Like a Login
The EIP-7702 authorization tuple, when displayed in MetaMask v12.4 and earlier, rendered as a generic 'Sign-in with Ethereum' message. No dollar value. No token list. No transaction simulation warning. SlowMist documented 38 phishing kits between April 7 and May 22, 2026 — each one designed to fire a `0x04` signature from a wallet that had no idea what it was approving. The user thought they were proving wallet ownership. They were handing over the keys to drive.
Once delegated, the malicious contract had a 24-hour window. 12,000 wallets drained across mainnet, Base, Optimism, and Arbitrum. Median time from signature to empty wallet: 47 minutes. The fastest drain on record cleared $1.2M in 11 minutes — including a CryptoPunk fire-sold to Blur three blocks after the authorization landed.
The total: $48.2M in tokens, $7.4M in NFTs, $3.1M in liquid staking derivatives. Recovery rate: 0.4%. Wintermute Research traced the infrastructure to the same crews that ran the April 2026 Phantom Drainer $50M campaign, now upgraded with a 7702 module. They industrialized a feature into a weapon — and shipped the weapon before the wallets shipped the warning.
EIP-7702 didn't break Ethereum. Drainer crews just discovered the feature was loaded.
The Anatomy: Authorization → Delegation → Drain → Off-Ramp
Step 1 — Lure. The victim lands on a cloned phishing site (a fake airdrop claim, a 'gas refund', a 'Pectra migration helper'). The signature request shows a `0x04` authorization tuple. To MetaMask v12.4 it looks like a benign EIP-712 message. No transaction simulation. No dollar value. No red banner.
Step 2 — Delegate. The attacker submits the signed authorization on-chain in a sponsor-paid transaction (gas paid by the crew, not the victim). The victim's EOA is now bonded to the drainer contract for up to 24 hours. Anything that would have been signed now executes drainer logic — and the user never paid a single wei of gas to lose everything.
Step 3 — Drain. The drainer enumerates holdings via on-chain indexers and triggers a single batched `multicall`. ERC-20s swept to a collection wallet. NFTs sold via Blur instant bid. Liquid staking positions unwound through flash-loan unstake. Step 4 — Off-Ramp. Within 60 minutes funds are bridged through Across, swapped on THORChain, and parked in a no-KYC exchange. The blockchain remembers everything. It just can't stop anything.
You signed a 'login.' The attacker rented your wallet for 24 hours. They only needed 47 minutes.
Vocabulary Decoded: The 7702 Drainer Dictionary
Every term below is a real Pectra primitive — weaponized by drainer crews:
"Authorization Tuple" / "0x04 Transaction"
What it is legitimately:
A new Pectra transaction type that lets an EOA sign a tuple `(chainId, address, nonce)` declaring 'this EOA temporarily executes code from `address`'. Designed for gasless transactions, batched swaps, and account abstraction without abandoning self-custody.
How drainer crews weaponized it:
The phishing kit asks you to sign a `0x04` tuple where `address` = drainer contract. The user sees an opaque hex blob in MetaMask v12.4. You didn't approve a token. You appointed a CEO of your wallet for the next 24 hours.
"Set-Code Delegation" (Bonded EOA)
What it is legitimately:
The on-chain effect of a 7702 authorization: the EOA now executes the delegated contract's bytecode whenever it's called. This enables wallets to behave like smart accounts (multicall, session keys, social recovery) without migrating funds.
How it becomes lethal:
When the bonded contract is hostile, every interaction with that EOA — including incoming token transfers, NFT mints, and even gas-station refunds — can trigger drainer logic. The bond persists until the nonce is bumped or the authorization expires. It's a 24-hour management contract. The manager is a thief.
"Sponsored Authorization" (Gasless Trap)
What it sounds like:
A meta-transaction pattern where a relayer pays the gas to broadcast a user's signed authorization. Standard in account abstraction. Convenient for onboarding.
What 7702 drainers actually use it for:
The crew pays the gas to publish your signed authorization. You never see a 'pending transaction' in your wallet. By the time the drainer fires, you've forgotten you signed anything. Gasless isn't free. Someone always pays. With 7702, it's you — just not in ETH.
"Blind Signing" (EIP-712 Spoof)
What it sounds like:
Signing a typed-data message your wallet can parse and display in human-readable form. Used by every DeFi protocol for permits, off-chain orders, and meta-transactions.
What makes 7702 blind-signing devastating:
The phishing kit wraps the `0x04` authorization inside a fake EIP-712 envelope labelled 'Sign in with Ethereum.' MetaMask v12.4 parses the envelope, not the inner authorization. You read the wrapper. The wrapper lies. The blockchain reads the contents.
Every term is real Pectra infrastructure. Every one was turned into a weapon before the wallets caught up.
How the 7702 Drain Pipeline Actually Works
Five stages. Industrial. Repeatable. Documented across 38 phishing kits:
Stage 1: The Bait (Cloned Front-End)
Google Ads for 'Pectra airdrop,' 'EIP-7702 migration tool,' 'Ethereum gas refund.' The first sponsored result is a pixel-perfect clone of a known wallet UI. URL is one character off — `metamask-pectra[.]app` instead of `metamask.io`. You searched for the upgrade. They sold you the downgrade.
The best phishing answers a question you already asked.
Stage 2: The Hook (Fake Sign-In Prompt)
The site requests a 'Sign in with Ethereum' signature to 'verify your wallet for the Pectra airdrop.' MetaMask v12.4 shows a generic SIWE prompt. The hex blob underneath is a `0x04` authorization tuple pointing to the drainer contract. Nobody reads the hex. The attackers know that.
The only thing more dangerous than a malicious transaction is a malicious signature.
Stage 3: The Bond (Sponsored On-Chain Submission)
Within 30 seconds, the crew's relayer publishes your authorization in a sponsored transaction. Your EOA is now executing the drainer's bytecode. You see no 'pending' state in your wallet — because you didn't broadcast anything. They paid the gas. You paid the wallet.
The moment you signed, the rental contract was filed. You just didn't know you were the landlord.
Stage 4: The Sweep (Batched Multicall)
An on-chain bot indexes your holdings. A single `multicall` transaction sweeps ERC-20s, lists NFTs at 80% floor on Blur, and unwinds liquid staking via flash-loan unstake. Median completion: 47 minutes. Fastest documented: 11 minutes. The drainer doesn't steal. It liquidates.
47 minutes. Less time than a Premier League first half.
Stage 5: The Off-Ramp (Cross-Chain Laundry)
Funds bridge through Across or Stargate to a chain with shallow forensics, swap on THORChain native, and land at a no-KYC exchange. By hour 6, the trail forks across 3 chains and 5 destinations. Six hours. Three chains. Zero recoverable funds.
0.4% recovery rate. The other 99.6% is paying for somebody's villa in Phuket.
On-Chain Evidence: Three Documented 7702 Drains
These are anonymized but verified case studies from SlowMist's April–May 2026 dataset. Patterns to recognize:
DApp claim: 'Pectra Genesis Airdrop — verify wallet for 12,000 PCTR tokens' Signature requested: SIWE-style 'Sign in with Ethereum' prompt Underlying payload: 0x04 authorization → 0xDr4iN...c0DE (drainer contract) Time to drain: 23 minutes after signature Loss: 142 ETH + 8 NFTs (CryptoPunks, Pudgy Penguins) fire-sold on Blur
Translation: He chased a free token. He delivered the wallet.
The victim was an active DeFi user with 18 months of experience. He saw 'Sign in with Ethereum' — a pattern he'd used 200+ times — and approved without reading the hex. The drainer waited 23 minutes (long enough to look organic), then executed the multicall. Loss visible only when he tried to swap and saw an empty wallet.
DApp claim: 'Ethereum Foundation Gas Refund Program — claim retroactive refund for past transactions' Signature requested: 'Verify wallet ownership for refund eligibility' Underlying payload: 0x04 authorization tuple, 24-hour validity Time to drain: 11 minutes (fastest documented case) Loss: 380 ETH + 1 CryptoPunk (Punk #4156-class) sold for 65% of floor
Translation: There is no refund. There never was.
Whale wallet. The victim had previously interacted with Ethereum Foundation contracts, so the spoofed page passed the smell test. The drainer prioritized the CryptoPunk because NFT off-ramp via Blur is faster than ERC-20 routing. *11 minutes from signature to liquidation.*
Telegram DM (from spoofed @MetaMask_Support_Bot): 'Hi! We noticed your wallet hasn't migrated to Pectra. Use our official migrator to enable 7702 features safely: [link to phishing site]' Signature requested: 'Enable EIP-7702 features for your wallet' Underlying payload: 0x04 authorization → drainer Time to drain: 41 minutes Loss: 37 ETH + 4 stETH positions unwound via flash loan
Translation: There is no official migrator. The migration is to their wallet.
Social engineering via Telegram. The fake support bot scraped the victim's username from a public 'help me with MetaMask' post. The 'migration' was framed as essential and time-sensitive ('Pectra rolls out in 48 hours'). The user signed within 90 seconds of clicking the link.
Red Flags: 7 Signs You're About to Sign Away Your Wallet
If your wallet doesn't show what 0x04 means, your wallet is the vulnerability.
- The signature request is type `0x04` (or your wallet shows 'Set Code' / 'Authorization'). This is *not* a token approval. It's a delegation. Reject by default unless you've manually verified the contract address.
- The site asks you to 'Sign in with Ethereum' for an airdrop, refund, or 'wallet migration.' Real airdrops never require a signature to claim eligibility. Real refunds don't exist. Real wallet upgrades happen inside the wallet, not on a website.
- The signature payload contains an unfamiliar 42-character contract address. Verify on Etherscan: how old is the contract? How many transactions? Is it verified? A 2-day-old unverified contract = drainer.
- MetaMask shows no transaction simulation, no dollar value, no token list. Modern drainers exploit this gap deliberately. If you can't see what it does, assume it does the worst thing possible.
- The site uses a 'sponsored transaction' or 'we'll pay the gas' UX pattern. Convenience is bait. With 7702, gasless = the attacker is broadcasting your signature, not you.
- You arrived via a Google Ad, Telegram DM, or Twitter/X reply — not a bookmarked URL. 63% of 7702 victims arrived through paid search ads or social DMs. Bookmark your wallet's official URL. Never search for it.
- The site URL has subtle typos: `metamask-pectra[.]app`, `etherescan[.]io`, `1lnch[.]exchange`. Drainer crews register hundreds of typosquats per kit. One character off = pixel-perfect clone with a different destination wallet.
The Numbers: 7702 Drains by the Data
Aggregated from SlowMist, Wintermute Research, and Etherscan tagged contracts (April 7 – May 22, 2026):
12,000 wallets drained
Across Ethereum mainnet (58%), Base (19%), Optimism (12%), Arbitrum (11%). Average loss: $4,825. Median loss: $890. The whales skewed the average — the typical victim lost a holiday, the unlucky ones lost a house.
38 distinct phishing kits
Drainer-as-a-Service. Affiliates paid 30% revenue share to the kit operators. Top 3 kits accounted for 71% of total losses. They franchised the weapon. The franchise model is what scales it.
$58.7M total stolen
$48.2M in tokens, $7.4M in NFTs (Blur fire-sales), $3.1M in liquid staking derivatives (flash-loan unstakes). Recovery: $230K (0.4%). Tether and Circle froze nothing — the funds bridged off Ethereum within 6 hours.
47 minutes median time-to-drain
Fastest documented: 11 minutes. Slowest: 22 hours (drainer waited for the 24-hour window to maximize incoming transfers). The bond was 24 hours. The execution was sub-hour. The damage was permanent.
Confused by the Jargon?
Explore our glossary of 258 crypto scam terms with real-world examples.
Why 12,000 Experienced Users Signed
These weren't beginners. Average victim had 18+ months of DeFi experience. Here's why the kit still worked:
Signature Fatigue
Active DeFi users sign 30-50 prompts per month. Permits, swaps, log-ins, votes. The 51st signature looks identical to the 50th — except this one is a `0x04` to a drainer. Familiarity isn't safety. It's the opposite.
Wallet UI Lag
MetaMask v12.4, the dominant version during the campaign, had no parser for `0x04` tuples. The signature prompt looked like every other SIWE login. The wallet shipped the new permission. It forgot to ship the new warning.
Trusted Entry Points
Victims arrived via Google (the world's most trusted search engine) or via DMs from accounts impersonating MetaMask, Ledger, or the Ethereum Foundation. The entry point felt safe. The destination wasn't.
Invisible Damage Window
The drain doesn't fire when you sign. It fires anywhere from 11 minutes to 22 hours later. By the time funds vanish, victims can't connect the cause (a 'sign-in' from earlier today) to the effect (an empty wallet now). Cause and effect were separated by enough time to make them feel unrelated.
The best phishing doesn't look like phishing. It looks like Tuesday.
Plain English: What 7702 Delegation Actually Is
Forget the hex. Here's what a `0x04` signature does in human terms:
Your Wallet (The House)
Your EOA holds your tokens. You have the only key. Nothing leaves without your signature.
EIP-7702 (The Power of Attorney)
A `0x04` signature is a 24-hour Power of Attorney. You appoint a contract to act as if it were you — moving funds, signing approvals, making swaps — for the next 24 hours.
The Drainer (The Fake Lawyer)
When the contract you appointed is hostile, you've handed Power of Attorney to a thief in a suit. He doesn't break in. He walks in through the front door — because legally, he's you.
Sponsored Authorization (Free Stamp)
The relayer paying gas is the notary stamping the document for free. You didn't pay. You didn't notice. But the document is filed and binding.
Revocation (Cancelling the POA)
You can revoke an active 7702 delegation by bumping the nonce or via your wallet's authorization manager. But if the drainer fires before you revoke, the cancellation arrives at an empty house.
You wouldn't sign a Power of Attorney for a stranger in the street. EIP-7702 is exactly that — except the street is a Google search result.
Protection: 5 Habits That Make You 7702-Proof
Every habit below would have stopped 100% of the documented April–May 2026 drains:
1. Treat every `0x04` signature as a code-delegation, not a login.
If your wallet shows 'Set Code,' 'Authorization,' `EIP-7702`, or an unparsed hex blob — reject by default. Only sign when you've manually verified the target contract address against the protocol's official documentation. No address verification, no signature.
2. Upgrade to a 7702-aware wallet today.
MetaMask v12.5+, Rabby v0.97+, Frame v0.6+, and Ledger Live (May 2026 firmware) all parse `0x04` tuples and show explicit red-banner warnings. If your wallet doesn't show this, you're flying blind on a runway full of drainers.
3. Use a hardware wallet for anything above $1K.
Ledger and Trezor firmware updates (May 2026) display the authorization tuple's target contract on the device screen. A 7702 drain cannot complete without your physical button press confirming the contract address. The button press is the last line of defence.
4. Compartmentalize: hot wallet for dApps, cold wallet for holdings.
Keep $50–$200 max in your dApp-facing wallet. Hold the rest in a cold wallet that never touches phishing surface area. If the hot wallet gets bonded to a drainer, you lose pizza money — not life savings.
5. Audit active delegations weekly.
Use revoke.cash, Etherscan's Authorizations tab, or your wallet's built-in 7702 manager. If you see a delegation you don't remember signing, assume hostile and revoke immediately — bumping the nonce kills the bond.
Key Takeaways
- EIP-7702 is a *permission*, not a transaction — and it's more dangerous than any approval ever was.
- 12,000 wallets drained for $58.7M between April and May 2026, via a single `0x04` signature each.
- The signature looked like 'Sign in with Ethereum.' MetaMask v12.4 had no parser for the underlying authorization.
- Median time-to-drain: 47 minutes. Fastest: 11 minutes. Recovery rate: 0.4%.
- Upgrade your wallet, segregate funds, audit delegations weekly — and treat every `0x04` signature like a 24-hour blank check.
EIP-7702 didn't break the rules.
It wrote a new one — and forgot to tell the wallet to read it out loud.
Frequently Asked Questions
Sources & Citations
Research for this investigation compiled from publicly available blockchain data, security reports, and community documentation.
eips.ethereum.org
wintermute.com
slowmist.com
www.trailofbits.com
Verification: All blockchain transactions and addresses referenced in this article can be independently verified through the linked blockchain explorers. We encourage readers to conduct their own verification.
More Scam Warnings
Continue learning about crypto threats
Phantom Drainer: The $50M Approval Heist Hitting Wallets in 2026
Phishing • 2026-04-30
Drainer-as-a-Service. $1,500/month in Telegram. 6 affiliates drained 31,500 wallets for $50M in 8 months using Permit2 traps and blind-signing exploits.
7 Crypto Wallet Scams Draining Victims in 2026 [With Examples]
Wallet Security • 2026-06-24
Phishing apps stole $4.6B in 2025. See real attack screenshots, fake seed phrase tricks, and the 3-step verification that stops 99% of wallet drains.
Operation Atlantic: $83M Scam 3 Governments Are Hunting
Approval Phishing • 2026-04-12
142 cloned DeFi sites. 14,847 wallets drained. $83M stolen with one 'Approve' button. 3 governments. 6 arrests. 94% of funds unrecoverable.