According to crypto market maker Wintermute, malicious Ethereum contracts, dubbed 'CrimeEnjoyors,' designed to exploit weak security and drain wallets, have not been successful in their endeavors. This issue is linked to the Ethereum Improvement Proposal (EIP)-7702, part of the recent Pectra upgrade, which enables regular Ethereum addresses to function as smart contracts temporarily.
This upgrade has simplified user experience but also created a risk of malicious contracts draining funds. Wintermute's research team found that over 97% of EIP-7702 delegations were authorized to multiple contracts using the same code, which are used to automatically drain incoming ETH from compromised addresses. Notably, a wallet lost nearly $150,000 to malicious batched transactions in a phishing attack. Despite the large-scale attempt, the attackers have not gained significant profits, with the CrimeEnjoyors spending approximately 2.88 ETH to authorize around 79,000 addresses.
Wintermute's researcher noted that the stolen ether can be traced by analyzing the code of these contracts, and as of Friday, the intended recipient address had no inbound ETH transfers, a pattern consistent across other CrimeEnjoyors.