Pectra lets hackers drain wallets with just an offchain signature
By: cryptosheadlines|2025/05/11 22:00:13
0
Share
Airdrop Is Live CaryptosHeadlines Media Has Launched Its Native Token CHT. Airdrop Is Live For Everyone, Claim Instant 5000 CHT Tokens Worth Of $50 USDT. Join the Airdrop at the official website, CryptosHeadlinesToken.com Ethereum’s latest network upgrade, Pectra, introduced powerful new features aimed at improving scalability and smart account functionality — but it also opened a dangerous new attack vector that could allow hackers to drain funds from user wallets using only an offchain signature.Under the Pectra upgrade, which went live on May 7 at epoch 364032, attackers can exploit a new transaction type to take control of externally owned accounts (EOAs) without requiring the user to sign an onchain transaction.Arda Usman, a Solidity smart contract auditor, confirmed to Cointelegraph that “it becomes possible for an attacker to drain an EOA’s funds using only an offchain signed message (no direct onchain transaction signed by the user).”At the center of the risk is EIP-7702, a core component of the Pectra upgrade. The Ethereum Improvement Proposal introduces the SetCode transaction (type 0x04), which enables users to delegate control of their wallet to another contract simply by signing a message.If an attacker obtains this signature — say, via a phishing site — they can overwrite the wallet’s code with a small proxy that forwards calls to their malicious contract.“Once the code is set,” Usman explained, “the attacker can invoke that code to transfer out the account’s ETH or tokens—all without the user ever signing a normal transfer transaction.”Source: Vladimir S. | Officer’s NotesRelated: Ethereum Pectra upgrade adds new featuresWallets can be altered with offchain signatureYehor Rudytsia, onchain researcher at Hacken, noted that this new transaction type introduced by Pectra allows arbitrary code to be installed on the user’s account, essentially turning their wallet into a programmable smart contract.“This tx type allows the user to set arbitrary code (smart contract) to be able to execute operations on the user’s behalf,” Rudytsia said.Before Pectra, wallets could not be modified without a transaction signed directly by the user. Now, a simple offchain signature can install code that delegates complete control to an attacker’s contract.“Pre-Pectra, users needed to send transaction (not sign message) to allow their funds to be moved... Post-Pectra, any operation may be executed from the contract which user approved via SET_CODE,” Rudytsia explained.The threat is real and immediate. “Pectra activated May 7, 2025. From that moment, any valid delegation signature is actionable,” Usman warned. He added that smart contracts relying on outdated assumptions, such as using tx.origin or basic EOA-only checks, are particularly vulnerable.Wallets and interfaces that fail to detect or properly represent these new transaction types are most at risk. Rudytsia warned that “wallets are vulnerable if they do not analyze Ethereum’s transaction types,” especially transaction type 0x04.He emphasized that wallet engines must clearly display delegation requests and flag any suspicious addresses.This new form of attack can be easily executed through common offchain interactions like phishing emails, fake DApps, or Discord scams.“We believe it will be the most popular attack vector regarding these breaking changes introduced by Pectra,” Rudytsia said. “From now on, users have to carefully validate what they are going to sign.”Source: NoirRelated: Pectra features already in use: Ethereum EIP-7702 wallets roll outHardware wallets are not safer anymoreHardware wallets are no longer inherently safer, Rudytsia said. He added that hardware wallets from now on are at the same risk as hot wallets from the perspective of signing malicious messages. “If done—all the funds are gone in a moment.”There are ways to stay safe, but they require awareness. “Users should not sign the messages they do not understand,” Rudytsia advised. He also urged wallet developers to provide clear warnings when users are asked to sign a delegation message.Special caution should be taken with new delegation signature formats introduced by EIP-7702, which are not compatible with existing EIP-191 or EIP-712 standards. These messages often appear as simple 32-byte hashes and may bypass normal wallet warnings.“If a message includes your account nonce, it’s probably affecting your account directly,” Usman warned. “Normal sign-in messages or offchain commitments don’t usually involve your nonce.”Adding to the risk, EIP-7702 allows for signatures with chain_id = 0, meaning the signed message can be replayed on any Ethereum-compatible chain. “Understand it can be used anywhere,” Usman said.While multisignature wallets remain more secure under this upgrade, thanks to their requirement for multiple signers, single-key wallets — hardware or otherwise — must adopt new signature parsing and red-flagging tools to prevent potential exploitation.Alongside EIP-7702, Pectra also included EIP-7251, which raised Ethereum’s validator staking limit from 32 to 2,048 ETH, and EIP-7691, which increases the number of data blobs per block for better layer-2 scalability.Magazine: Bitcoin eyes ‘crazy numbers,’ JD Vance set for Bitcoin talk: Hodler’s Digest, May 4 – 10Source link
You may also like

Who is footing the bill for the $64 billion accounting frenzy?
Affected by Bitcoin falling below $60,000, publicly listed companies heavily invested in this asset are facing huge paper losses and valuation discounts, and their debt structure and accounting standards may trigger structural liquidity risks in the future.

Global Launch: As predictions become the most scarce asset in the AI era, Manadia is defining the next generation of the value internet
The trusted AI prediction ecosystem Manadia, which has secured $7 million in funding from well-known institutions like OKX, will globally launch in June. The core token UMXM has already been listed on multiple mainstream platforms, inviting you to seize the new blue ocean of the trillion-level predi...

Morning Report | CoinEx becomes a key hub for Iran to evade sanctions, involving over $3.8 billion in funds; Kalshi seeks a new round of financing, with a valuation potentially rising to $40 billion
Overview of Important Market Events on June 25

Why do cryptocurrency projects always like to change their names?
In many cases, the old names of encryption projects have no competitive advantage, only historical baggage.

From the white-haired stock god to the billionaire fund mogul, the smart people shorting Nvidia are all getting rich using the same framework
Give up on heavily investing in Nvidia's "nine major bottlenecks"! This article analyzes the underlying logic behind top AI investors making billions: physical infrastructure such as electricity, HBM, and optical interconnects are the true keys to wealth in AI hardware.

Morning News | The draft amendment to the People's Bank of China Law aims to clarify the legal status of digital renminbi; South Korea will transfer about 40 unregistered virtual asset service providers to law enforcement agencies
Overview of Important Market Events on June 24

The cryptocurrency industry has entered the "Show Me" era: merely relying on vision is no longer enough
The awareness level of the audience in the cryptocurrency industry—including media, institutions, and retail investors—is steadily increasing, and this trend has become a foregone conclusion.

Interpreting the Ethereum Foundation's new structure: Reaffirming self-sovereignty amid institutional trends
The Ethereum Foundation has announced a new five-layer working framework, clarifying the focus of future development and reaffirming its commitment to decentralized core values amidst the wave of institutionalization.

Former SpaceX engineer reconstructs the financial execution system using first principles
Plan Execution Lab completes angel round financing for Singapore family office, with a valuation of 50 million USD.

Tidal Investment: We still have a positive outlook on the AI industry chain, but the reasons have changed
The intense financing by tech giants has triggered a panic of "AI peak," but the soaring capital expenditures of the five major cloud vendors and the bottlenecks in physical infrastructure indicate that the AI investment cycle is far from over; the second half of this grand performance has just begu...

Standard Chartered Bank sings a 50x rhapsody again, aiming for AAVE to reach 3500 USD
The throne of DeFi lending still exists, but the foundation beneath the throne needs to undergo a reconstruction or reinforcement.

The interim executive director of the Ethereum Foundation speaks out: What is our mission?
"We are here to strengthen defenses against where Ethereum has already become or may become extractive, comprehensive, or susceptible to cartel or state control, or influenced by tools of surveillance or coercion from authoritarian regimes."

Why does OKX want to start a new company with the parent company of the New York Stock Exchange?
ICE and OKX established OKXICE, symbolizing the relationship between traditional finance and the crypto market is transitioning from "tentative cooperation" to "infrastructure-level integration."

Why Is PAXG Price Different From Gold? 5 Reasons Crypto Traders Should Know
Why is PAXG different from gold? Learn the 5 key reasons PAXG and XAUT prices can trade above or below spot gold, including liquidity, funding rates, futures basis, and weekend trading effects.

WEEX OpenAPI 101: 5 Powerful Modules, AI Trading Tools, and Grab Up to 70% Revenue Opportunities
Learn how WEEX OpenAPI connects traders, developers, AI agents, and trading platforms. Discover WEEX API features, Binance-compatible integration, automated trading workflows, revenue opportunities, and ecosystem possibilities.

Interview with NDV Founder Jason Huang: Popping the AI Bubble and the Myth of Microstrategy, Seeking the Ultimate Ace in the Crypto Market
Exclusive Interview with NDV Founder Jason Huang: MicroStrategy's coin selling triggered a stampede, BTC has fallen into a liquidity squeeze, and the current market has not yet bottomed out, patiently waiting for a "FTX-level" iconic panic event to clear.

Morning Report | Former Ethereum Foundation researcher establishes Ethlabs; EU Parliament Economic Committee passes digital euro regulatory proposal
Overview of Important Market Events on June 23

Dragonfly partner Haseeb: The fastest-growing companies in the future may all be stuck at 149 people
The pricing of large models is actually an "AI tax": it shackles large enterprises with computing power constraints, slows down automation, but turns subscriptions into a subsidy for small teams' innovative dividends. By capping the scale at under 149 people, startups can continuously experiment wit...
Who is footing the bill for the $64 billion accounting frenzy?
Affected by Bitcoin falling below $60,000, publicly listed companies heavily invested in this asset are facing huge paper losses and valuation discounts, and their debt structure and accounting standards may trigger structural liquidity risks in the future.
Global Launch: As predictions become the most scarce asset in the AI era, Manadia is defining the next generation of the value internet
The trusted AI prediction ecosystem Manadia, which has secured $7 million in funding from well-known institutions like OKX, will globally launch in June. The core token UMXM has already been listed on multiple mainstream platforms, inviting you to seize the new blue ocean of the trillion-level predi...
Morning Report | CoinEx becomes a key hub for Iran to evade sanctions, involving over $3.8 billion in funds; Kalshi seeks a new round of financing, with a valuation potentially rising to $40 billion
Overview of Important Market Events on June 25
Why do cryptocurrency projects always like to change their names?
In many cases, the old names of encryption projects have no competitive advantage, only historical baggage.
From the white-haired stock god to the billionaire fund mogul, the smart people shorting Nvidia are all getting rich using the same framework
Give up on heavily investing in Nvidia's "nine major bottlenecks"! This article analyzes the underlying logic behind top AI investors making billions: physical infrastructure such as electricity, HBM, and optical interconnects are the true keys to wealth in AI hardware.
Morning News | The draft amendment to the People's Bank of China Law aims to clarify the legal status of digital renminbi; South Korea will transfer about 40 unregistered virtual asset service providers to law enforcement agencies
Overview of Important Market Events on June 24
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com


