Over 80% of Ethereum’s new EIP-7702 delegations are being hijacked by cloned “CrimeEnjoyor” contracts that sweep compromised wallets, according to Wintermute analysis.
Ethereum’s EIP-7702 upgrade, part of the Pectra hard fork, was intended to enhance user experience by allowing wallets to act like smart contracts but is now widely abused by wallet-draining scripts.
Security firms like Scam Sniffer and SlowMist have issued warnings after reports of users losing up to US$150,000 in a single attack linked to malicious batched transactions.
Users are advised to double-check signature requests and not rush into signing transactions, while wallet providers are urged to implement immediate safeguards for EIP-7702 transactions.