The Ethereum's Pectra upgrade introduces EIP-7702 allowing users to delegate wallet control via offchain signatures.
However, a flaw in the upgrade can lead to a malicious signature rewriting wallet code and transferring control to an attacker's contract without requiring transaction confirmation.
Security experts warn that even hardware wallets are at risk of exposure if users unwittingly approve delegation messages, which can be difficult to detect due to their format.
Most individual wallets, including cold storage, need immediate updates to handle the new signature type to avoid potential instant and irreversible loss for users.