Investors lost 1 million USD in just 1 click on a fake Uniswap.

robot
Abstract generation in progress

A phishing attack caused a cryptocurrency investor to lose nearly 1 million USD after inadvertently signing a series of malicious transactions disguised as swaps on Uniswap, according to a report by blockchain security firm Scam Sniffer.

On August 22, Yu Xiang – the founder of SlowMist – stated that the incident involves 5 types of tokens that were stolen through transactions exploiting Ethereum's new EIP-7702 mechanism.

He explained: "From the perspective of the attacked user, the process occurs as follows: they open a phishing website, a wallet signing dialog appears, they click confirm, and with just that one action, all valuable assets in the wallet disappear immediately."

EIP-7702 and new risks

EIP-7702 was introduced in the Pectra upgrade to enhance the Ethereum user experience. This feature allows wallets to function as a temporary smart contract, enabling multiple transactions to be executed simultaneously, allowing for gas fee sponsorship or setting spending limits in just one step.

In principle, this power of attorney can be revoked and only applies within a specific network. However, in practice, attackers have found ways to exploit this mechanism.

Security Community Alert

Market maker Wintermute warns that the deployment of this standard is being widely exploited. An analysis from June by the company showed that over 90% of EIP-7702 authorizations are related to malicious contracts. Many contracts are just simple copy-paste code, automatically scanning and withdrawing assets from vulnerable wallets.

Scam Sniffer and Yu Xiang recommend that users exercise caution before signing requests from wallets. Preventive measures include: carefully checking the domain name, not confirming hastily, and refusing ambiguous signatures or those with excessively broad scopes.

Some warning signs include: requests for unlimited spending permissions, upgrading contracts according to EIP-7702, or simulating transactions that do not meet expectations.

Thach Sanh

UNI0.06%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 6
  • Repost
  • Share
Comment
0/400
MengQingqiuvip
· 17h ago
Hold on tight, we're about to da moon 🛫
View OriginalReply0
MengQingqiuvip
· 17h ago
Hold on tight, we're about to da moon 🛫
View OriginalReply0
MengQingqiuvip
· 17h ago
Hold on tight, we're about to da moon 🛫
View OriginalReply0
MengQingqiuvip
· 17h ago
Hold on tight, we're about to da moon 🛫
View OriginalReply0
MengQingqiuvip
· 17h ago
Hold on tight, we're about to da moon 🛫
View OriginalReply0
MengQingqiuvip
· 17h ago
Just go for it💪
View OriginalReply0
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)