← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[DEEP DIVE] EIP-7702 Hits 156M Authorizations, 48% Crime-Linked

Zephyra|May 22, 2026|BPF
EXECUTIVE SUMMARY

Ethereum's EIP-7702 smart account standard has crossed 156 million authorizations and 22 million live smart accounts across EVM chains since its activation on May 7, 2025, according to BundleBear data as of May 2026. The upgrade, which shipped as part of the Pectra hard fork — the largest in Ethe...

"From the perspective of a phished user, it goes like this: the user opens a phishing website, a wallet signature prompt pops up, the user clicks confirm, and with just that one action, all valuable assets in the wallet address vanish in a snap." — Yu Xian, Founder of SlowMist

Executive Summary

Ethereum's EIP-7702 smart account standard has crossed 156 million authorizations and 22 million live smart accounts across EVM chains since its activation on May 7, 2025, according to BundleBear data as of May 2026. The upgrade, which shipped as part of the Pectra hard fork — the largest in Ethereum's history at 11 EIPs — allows Externally Owned Accounts (EOAs) to temporarily function as smart contracts, enabling transaction batching, gas sponsorship, and programmable spending limits without requiring users to migrate to new addresses.

The adoption numbers, however, carry a material caveat. Wintermute, the algorithmic trading firm, tagged 768,275 of 1,580,930 early EIP-7702 activations — 48% — as crime-linked in its Dune Analytics dashboard. The firm's research team identified a single copy-pasted bytecode contract, dubbed "CrimeEnjoyor," as the dominant vector. That contract auto-sweeps funds from wallets whose private keys have been compromised, and its clones now account for the majority of all EIP-7702 delegations by volume. Documented individual losses range from $146,551 to $1.54 million per incident.

The data presents a split outcome: EIP-7702 is simultaneously the most consequential Ethereum user-experience upgrade since the Merge and the largest new attack surface for phishing operators since approval-based token drains. The economic implications for wallet infrastructure providers, DeFi protocols, and institutional custodians are significant.

Table of Contents

  1. What EIP-7702 Changes
  2. Adoption by the Numbers
  3. The CrimeEnjoyor Epidemic
  4. Attack Mechanics
  5. Documented Losses
  6. Institutional Response
  7. Wallet Provider Landscape
  8. Economic Value Implications
  9. Key Takeaways
  10. Conclusion

What EIP-7702 Changes

EIP-7702, co-authored by Vitalik Buterin and the original authors of EIP-3074, introduced a new transaction type that allows EOAs to set their account code by delegating to an existing smart contract. The delegation is temporary — it applies per-transaction — and the private key owner retains full control of the account. The practical effects:

  • Transaction batching: Multiple operations execute in a single transaction. A user can approve a token and swap it in one click instead of two.
  • Gas sponsorship: Applications can pay gas fees on behalf of users, removing the requirement to hold ETH for transaction fees.
  • Programmable guardrails: Spending caps, session keys, and social recovery mechanisms become available to standard EOA wallets.
  • Alternative authentication: Biometric verification, passkeys, and multi-factor signing replace sole reliance on private key custody.

The upgrade shipped as part of the Pectra hard fork on May 7, 2025. Pectra combined the Prague execution layer and Electra consensus layer updates into a single deployment containing 11 EIPs — the highest count of any Ethereum hard fork to date. EIP-7251, which raised the validator maximum effective balance from 32 ETH to 2,048 ETH, and EIP-7691, which doubled average blob throughput for Layer 2 rollups, were included in the same release.

Adoption by the Numbers

BundleBear's EIP-7702 tracker, the primary aggregation source for on-chain smart account activity, reports the following as of the week ending May 11, 2026:

| Metric | Value | |---|---| | Total EIP-7702 authorizations | 156,278,138 | | Total set-code transactions | 65,064,655 | | Live smart accounts | 22,056,869 |

Weekly active smart accounts by chain (week of May 11, 2026):

| Chain | Weekly Active Accounts | |---|---| | BNB Chain | 1,760,656 | | Ethereum | 644,085 | | Polygon | 316,298 | | Base | 312,448 | | Arbitrum | 222,972 | | Optimism | 13,453 | | Gnosis | 2,783 | | Unichain | 1,133 |

Across EVM chains broadly, approximately 62 million smart accounts have been deployed, with Coinbase Smart Wallet and Safe leading in market share. Cumulative paymaster gas sponsorship — where dApps and infrastructure teams subsidize user gas fees — has reached approximately $180 million since Pectra activation, according to BundleBear.

Since Pectra mainnet activation, approximately 14 million EOAs have signed at least one EIP-7702 authorization. The figure represents a fraction of Ethereum's total active address base but exceeds the entire user count of most standalone DeFi protocols.

The CrimeEnjoyor Epidemic

Wintermute's research team launched a dedicated Dune Analytics dashboard to track EIP-7702 delegation patterns shortly after Pectra went live. The findings were described by the firm's researchers as a "wild & depressing chart."

By September 2025, Wintermute had catalogued 1,580,930 EIP-7702 activations and tagged 768,275 — 48% — as crime-related. The "crime" tag designates delegate contracts that auto-sweep funds from compromised externally owned accounts. The dominant contract, labeled "CrimeEnjoyor" by researchers, is short, simple, and widely reused. According to Wintermute: "This one copy-pasted bytecode now accounts for the majority of all EIP-7702 delegations."

An earlier snapshot from May 30, 2025 — just 23 days after activation — showed an even higher ratio, with 97% of all delegations pointing to malicious sweeper contracts. The percentage subsequently declined as legitimate wallet providers (OKX, WhiteBIT, MetaMask) rolled out their own EIP-7702 implementations, diluting the share of criminal activity in the aggregate count. Average daily EIP-7702 transactions settled at approximately 6,285, representing 0.37% of total Ethereum transaction volume.

The mechanism is straightforward: attackers obtain private keys through traditional phishing, malware, or social engineering. They then use EIP-7702 to delegate the compromised EOA to a CrimeEnjoyor contract, which automatically and immediately sweeps all incoming and existing token balances. The upgrade's batching capability means the entire drain executes in a single atomic transaction, giving victims no opportunity to intervene once the delegation is signed.

Attack Mechanics

EIP-7702 phishing attacks follow a three-stage pattern, according to security firms Scam Sniffer and SlowMist:

Stage 1 — Lure: The victim visits a fraudulent DeFi interface that mimics legitimate platforms (Uniswap is the most common impersonation target). The site presents what appears to be a routine swap or approval transaction.

Stage 2 — Delegation signing: The wallet prompts the user to sign an EIP-7702 authorization. Because most wallet interfaces in 2025 did not surface delegation targets clearly, the transaction appeared identical to a standard approval. The victim clicks confirm.

Stage 3 — Atomic drain: The signed authorization delegates the EOA to a malicious contract. That contract executes a batched transaction — multiple token transfers, NFT approvals, and balance sweeps — in a single atomic operation. Funds move to the attacker's address within the same block.

The batching feature, designed to improve user experience by reducing multi-step transaction friction, becomes the attack's force multiplier. A pre-EIP-7702 wallet drain required separate transactions for each token, giving observant users or security tools time to detect and revoke approvals. Post-7702, the entire wallet empties in one transaction.

Documented Losses

Individual incidents reported by security firms since activation:

| Date | Loss | Details | Source | |---|---|---|---| | May 2025 | $146,551 | Single wallet drained via batch delegation | Scam Sniffer | | June 2025 | $66,000 | Delegation phishing on fake DeFi interface | SlowMist | | August 2025 | ~$1,000,000 | Five tokens siphoned via fake Uniswap swap | Scam Sniffer / SlowMist | | 2026 | $1,540,000 | wstETH, cbBTC, and other tokens drained in single batch transaction | Scam Sniffer |

The $1.54 million incident is the largest single EIP-7702 phishing loss documented to date. The victim authorized a batch transaction on a fraudulent DeFi interface containing multiple token transfers and NFT approval operations. Wrapped staked ETH (wstETH), Coinbase-wrapped Bitcoin (cbBTC), and several other assets were extracted in a single block.

Aggregate losses attributable specifically to EIP-7702 delegation phishing are difficult to isolate from broader crypto phishing statistics. Chainalysis estimated that social engineering and phishing were responsible for $290 million in losses across all crypto in Q1 2026 — the single largest attack category. The EIP-7702 vector is a subset of that figure, though the exact share is not publicly quantified.

Institutional Response

Wintermute built and publicly released the most granular tracking tool — a Dune dashboard that classifies every EIP-7702 delegation by contract type (legitimate service, unknown, or crime). The dashboard is multichain, covering Ethereum, BNB Chain, Base, and other L1/L2s with 7702 support.

SlowMist issued guidance urging wallet providers to "quickly support EIP-7702 transactions and prominently display the target contract to reduce phishing attack risk."

0xKofi, a Base protocol engineer, offered a technical clarification that has shaped the debate: "These wallets were not hacked using 7702. The hacker obtained the private keys without [7702]." The distinction is material — EIP-7702 does not create a new key-compromise vector. It amplifies the damage from existing key compromises by enabling atomic, batched fund extraction. The private key leakage occurs upstream through conventional phishing, clipboard malware, or social engineering.

GoPlus Security corroborated Wintermute's findings, independently reporting that over 90% of observed EIP-7702 delegations were linked to malicious contracts.

The Ethereum Foundation has not implemented protocol-level countermeasures. The security burden has shifted to wallet providers, who are expected to implement delegation-target display, transaction simulation, and warning systems at the interface layer.

Wallet Provider Landscape

Wallet integration of EIP-7702 has proceeded along two tracks:

Immediate adopters: OKX, WhiteBIT, Ambire, and Trust Wallet enabled EIP-7702 features shortly after Pectra activation. Within the first week, 11,000 legitimate EIP-7702 authorizations were recorded on mainnet, with exchange wallets leading.

Cautious integrators: MetaMask, Rainbow, and Rabby delayed full deployment pending security audits and regulatory clarity. MetaMask ultimately shipped its Smart Accounts Kit, allowing users to switch their existing EOA to a smart account without migrating funds or changing addresses. The approach leverages EIP-7702's backward-compatible design — users keep their on-chain history while gaining batching and gas abstraction.

Embedded wallets — those built directly into dApps rather than operating as standalone applications — have been the fastest adoption vector. These benefit from EIP-7702 because the dApp controls the transaction flow end-to-end, reducing the phishing surface relative to browser-extension wallets operating across arbitrary websites.

Fireblocks, the institutional custody platform, published a "Security First Approach to EIP-7702" framework for MPC wallet providers, addressing how multi-party computation signing integrates with the new delegation model.

Economic Value Implications

The economic dynamics of EIP-7702 adoption reshape value distribution across Ethereum's fee stack in several ways:

Gas sponsorship as a cost center: The $180 million in cumulative paymaster sponsorship represents a new category of protocol-level subsidy. DApps and infrastructure teams are absorbing gas costs that users previously paid directly. This shifts the fee burden from end users to application operators — a model familiar in Web2 but novel in blockchain economics. The sustainability of this subsidy depends on whether sponsored users generate sufficient protocol revenue (trading fees, lending interest, platform fees) to offset the gas expenditure.

Reduced transaction count, maintained fee revenue: Batching consolidates what were previously 2-5 separate transactions into single operations. This reduces on-chain transaction count but does not necessarily reduce total gas consumed, since the batched transaction performs equivalent computation. Validators and block builders see similar fee revenue per unit of user activity but from fewer discrete transactions.

Security infrastructure as a growth sector: The phishing epidemic has created demand for transaction simulation, delegation monitoring, and automated revocation services. Firms like Wintermute, Scam Sniffer, SlowMist, and GoPlus Security have expanded their product offerings in direct response. The security tooling layer is accumulating economic value that would not exist absent the EIP-7702 attack surface.

Institutional custody complexity: EIP-7702 adds a new dimension to institutional custody — delegation authorization management. Custodians must now audit not only token approvals but also account-level code delegations. This creates compliance overhead and potential regulatory questions, particularly for entities operating under the GENIUS Act's stablecoin custody requirements, where reserve management may involve smart-account-enabled wallets.

Key Takeaways

  • EIP-7702 has crossed 156 million authorizations and 22 million live smart accounts, with 3.27 million weekly active accounts across eight EVM chains.
  • Wintermute tagged 48% of early EIP-7702 activations (768,275 of 1,580,930) as crime-related. The ratio was 97% in the first 23 days before legitimate adoption diluted it.
  • The "CrimeEnjoyor" contract — a single piece of copy-pasted bytecode — accounts for the majority of malicious delegations by volume.
  • Documented individual losses range from $66,000 to $1.54 million. The attack vector amplifies existing key compromises via atomic batch execution, not through a novel key-extraction method.
  • Wallet providers, not the Ethereum protocol itself, bear the security burden. Interface-layer defenses — delegation target display, transaction simulation, and warning prompts — are the primary mitigation.
  • Gas sponsorship via paymasters has reached $180 million cumulative, creating a new subsidy layer in Ethereum's fee economy.
  • Institutional custodians face additional complexity: delegation authorization management sits alongside traditional token approval auditing.

Conclusion

EIP-7702 represents a clear technical improvement to Ethereum's account model. The user-experience benefits — batching, gas abstraction, programmable security — are measurable and real. But the upgrade also demonstrates a persistent pattern in blockchain development: protocol-layer improvements that expand functionality simultaneously expand the attack surface, and the security response consistently lags the exploitation timeline.

The 48% crime-tag ratio is declining as legitimate adoption scales, but the absolute volume of malicious delegations continues to grow. The CrimeEnjoyor contract and its clones operate in the open, on-chain and traceable, yet they persist because the defense is distributed across hundreds of wallet providers with uneven security implementations.

The economic value created by EIP-7702 — in gas sponsorship, smart account infrastructure, and security tooling — is substantial and growing. Whether that value accrues primarily to users, infrastructure operators, or the security remediation industry depends on how quickly wallet interfaces close the delegation-display gap that phishing operators currently exploit. The data, twelve months after activation, suggests the gap is narrowing but not closed.

Sources & References

  1. BundleBear EIP-7702 Metrics Dashboard — Live on-chain smart account and authorization data across EVM chains
  2. Wintermute EIP-7702 Dune Dashboard — Delegation classification and crime-tag tracking
  3. Protos: 48% of Ethereum EIP-7702 Uses Linked to Crime, Says Wintermute — Wintermute research findings on delegation exploitation
  4. Cryptopolitan: Security Analysts Warn About EIP-7702 Flaw After User Loses $1.54M — Documentation of largest individual EIP-7702 phishing loss
  5. CryptoSlate: Crypto Investor Loses $1M in Uniswap Scam Exploiting EIP-7702 — Yu Xian (SlowMist) analysis of $1M delegation phishing attack
  6. CryptoNews Australia: Ethereum's EIP-7702 Exploited by CrimeEnjoyor Wallet-Sweeping Scam — CrimeEnjoyor contract analysis and Wintermute findings
  7. The Block: Smart Wallet Adoption Surges After Pectra Upgrade — Early adoption metrics post-Pectra activation
  8. Unchained Crypto: Ethereum EIP-7702 Brings New Risks, Wintermute Says — 0xKofi clarification on attack attribution
  9. Circle: How the Pectra Upgrade Is Unlocking Gasless USDC Transactions with EIP-7702 — Gas sponsorship and paymaster infrastructure
  10. Fireblocks: Security First Approach to EIP-7702 — Institutional MPC custody integration framework