Crypto investor loses $1M in Uniswap scam exploiting Ethereum’s EIP-7702


The only phishing attack exhausted tokens worth almost $ 1 million from the Kryptovice investor who unknowingly signed a dose of harmful transactions masked as Support Swaps, according to Blockchain SCAM Sniffer.

At 22nd August post On X, Yu Xiang, founder of the security firm Blockchain Slowmist, noted that the incident included five tokens of siphon Ethereum’s New EIP-7702 mechanism.

Explained:

“From the Phisted user’s point of view, it looks like this: the user opens the phishing site, the pacific signature appears, the user clicks on the confirmation, and only with one event, all valuable assets at the wallet will disappear.”

EIP-7702 was introduced in Upgrade Simplify the Ethereum user experience. This feature allows your wallet to act as a temporary intelligent contract, allowing more transactions to allow gas sponsorship, or set expenditure limits in one step.

The delegation is basically canceled and specific to the network. However, attackers found ways to practice this function.

The creator of the Wintermute market is to have warned that the implementation of the standard is used on a scale. Her June analysis showed that more than 90% of the EIP-7702 delegations were associated with harmful contracts.

The company pointed out that many of these contracts are simple scripts of copying and indentations that seek vulnerable wallets and automatically release their shares.

With regard to this, Scam Sniffer and Xiang urged crypt users to pay special care before signing the wallet request. They recommended verification of domain names, avoided the hurried confirmation and refused signatures that seem unclear or too wide.

They also said that some of the red flags that could arise include requirements for unlimited token approval, EIP-7702 contracts, or transaction simulations that do not match expectations.

Stated in this article



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *