Pectra lets hackers drain wallets with just an offchain signature
By: cryptosheadlines|2025/05/11 22:00:13
0
Share
Airdrop Is Live CaryptosHeadlines Media Has Launched Its Native Token CHT. Airdrop Is Live For Everyone, Claim Instant 5000 CHT Tokens Worth Of $50 USDT. Join the Airdrop at the official website, CryptosHeadlinesToken.com Ethereum’s latest network upgrade, Pectra, introduced powerful new features aimed at improving scalability and smart account functionality — but it also opened a dangerous new attack vector that could allow hackers to drain funds from user wallets using only an offchain signature.Under the Pectra upgrade, which went live on May 7 at epoch 364032, attackers can exploit a new transaction type to take control of externally owned accounts (EOAs) without requiring the user to sign an onchain transaction.Arda Usman, a Solidity smart contract auditor, confirmed to Cointelegraph that “it becomes possible for an attacker to drain an EOA’s funds using only an offchain signed message (no direct onchain transaction signed by the user).”At the center of the risk is EIP-7702, a core component of the Pectra upgrade. The Ethereum Improvement Proposal introduces the SetCode transaction (type 0x04), which enables users to delegate control of their wallet to another contract simply by signing a message.If an attacker obtains this signature — say, via a phishing site — they can overwrite the wallet’s code with a small proxy that forwards calls to their malicious contract.“Once the code is set,” Usman explained, “the attacker can invoke that code to transfer out the account’s ETH or tokens—all without the user ever signing a normal transfer transaction.”Source: Vladimir S. | Officer’s NotesRelated: Ethereum Pectra upgrade adds new featuresWallets can be altered with offchain signatureYehor Rudytsia, onchain researcher at Hacken, noted that this new transaction type introduced by Pectra allows arbitrary code to be installed on the user’s account, essentially turning their wallet into a programmable smart contract.“This tx type allows the user to set arbitrary code (smart contract) to be able to execute operations on the user’s behalf,” Rudytsia said.Before Pectra, wallets could not be modified without a transaction signed directly by the user. Now, a simple offchain signature can install code that delegates complete control to an attacker’s contract.“Pre-Pectra, users needed to send transaction (not sign message) to allow their funds to be moved... Post-Pectra, any operation may be executed from the contract which user approved via SET_CODE,” Rudytsia explained.The threat is real and immediate. “Pectra activated May 7, 2025. From that moment, any valid delegation signature is actionable,” Usman warned. He added that smart contracts relying on outdated assumptions, such as using tx.origin or basic EOA-only checks, are particularly vulnerable.Wallets and interfaces that fail to detect or properly represent these new transaction types are most at risk. Rudytsia warned that “wallets are vulnerable if they do not analyze Ethereum’s transaction types,” especially transaction type 0x04.He emphasized that wallet engines must clearly display delegation requests and flag any suspicious addresses.This new form of attack can be easily executed through common offchain interactions like phishing emails, fake DApps, or Discord scams.“We believe it will be the most popular attack vector regarding these breaking changes introduced by Pectra,” Rudytsia said. “From now on, users have to carefully validate what they are going to sign.”Source: NoirRelated: Pectra features already in use: Ethereum EIP-7702 wallets roll outHardware wallets are not safer anymoreHardware wallets are no longer inherently safer, Rudytsia said. He added that hardware wallets from now on are at the same risk as hot wallets from the perspective of signing malicious messages. “If done—all the funds are gone in a moment.”There are ways to stay safe, but they require awareness. “Users should not sign the messages they do not understand,” Rudytsia advised. He also urged wallet developers to provide clear warnings when users are asked to sign a delegation message.Special caution should be taken with new delegation signature formats introduced by EIP-7702, which are not compatible with existing EIP-191 or EIP-712 standards. These messages often appear as simple 32-byte hashes and may bypass normal wallet warnings.“If a message includes your account nonce, it’s probably affecting your account directly,” Usman warned. “Normal sign-in messages or offchain commitments don’t usually involve your nonce.”Adding to the risk, EIP-7702 allows for signatures with chain_id = 0, meaning the signed message can be replayed on any Ethereum-compatible chain. “Understand it can be used anywhere,” Usman said.While multisignature wallets remain more secure under this upgrade, thanks to their requirement for multiple signers, single-key wallets — hardware or otherwise — must adopt new signature parsing and red-flagging tools to prevent potential exploitation.Alongside EIP-7702, Pectra also included EIP-7251, which raised Ethereum’s validator staking limit from 32 to 2,048 ETH, and EIP-7691, which increases the number of data blobs per block for better layer-2 scalability.Magazine: Bitcoin eyes ‘crazy numbers,’ JD Vance set for Bitcoin talk: Hodler’s Digest, May 4 – 10Source link
You may also like

In the name of charity, for the benefit of the family: How the Trump family turned charity into profit?
This set of "beautiful rhetoric and value return to one's own people" has not stopped at charitable foundations; it has now almost been transferred intact to American Bitcoin.

Will Gold Break $4,500 After Tonight's Fed Decision? What XAUT and PAXG Traders Need to Know
The Federal Reserve announces its June rate decision tonight. Could gold break $4,500 next? Explore the latest gold price prediction, key Fed scenarios, and what they mean for XAUT and PAXG traders.

Cursor, why did you get on Musk's spaceship?
SpaceX set a record with its IPO, spending a staggering $60 billion to acquire the popular AI programming unicorn Cursor just four days later. Musk is using the ultimate puzzle of "super computing power + top coding engine" to propel the market value skyrocketing, surpassing Amazon in one fell swoop...

Morning Report | DeepSeek completes over $7 billion in financing, with a valuation exceeding $50 billion; Musk's personal wealth has surpassed the total market value of Bitcoin
Overview of Important Market Events on June 16

SharpLink CEO: How to understand that Ethereum developers have just surpassed 1 million?
The most important question in the cryptocurrency industry is not which chain is the fastest, but rather where top builders choose to build in the long term. Ethereum has just surpassed one million cumulative developers; what does this number mean?

Morning Report | MiCA grace period expires on July 1; Kalshi's trading volume in the first week of the World Cup breaks $5.1 billion, setting a record
Overview of Important Market Events on June 15

The foundation of SpaceX's trillion-dollar valuation: Who is dividing Musk's annual capital expenditure of tens of billions?
SpaceX Supply Chain Revealed: The Invisible Gold Mine Behind the Trillion-Dollar "Space Dream," from Nvidia's Computing Power Monopoly to China's Sole Supplier of Special Materials, these overlooked water-selling talents are the true wealth creation engine.

How to exit after asset tokenization?
Currently, three models have emerged, aimed at providing instant exit routes for tokenized real-world assets. Their differences lie in: who holds the funds required for exit, how efficiently the funds operate, and the extent to which this model can be scaled across different asset types.

The stablecoin positioning battle escalates: When compliance is just a ticket to entry, will USD1 become the biggest winner?
How does the GENIUS Act reshape the stablecoin landscape?

A16Z: The sun bears witness, SpaceX is worth 7.5 trillion
A deep analysis of Musk's ultimate grand vision: how SpaceX, xAI, and Tesla are deeply intertwined, using space AI data centers and Starships to gradually turn the sci-fi fantasies of Mars colonization and multi-planetary civilization into reality.

Mergers and acquisitions in the cryptocurrency market are exceptionally active
Behind the rise in mergers and acquisitions is a sluggish financing market, declining project valuations, and increased pressure for startup teams to exit. However, it also indicates that the cryptocurrency industry has not lost its capital vitality, but is completing resource reorganization in anot...

Concerns Behind the Binance Customer Service Controversy
As the user base expands to the scale of Binance today, relying on the personal efforts of the founder and a few employees to fill process gaps has become an unsustainable arrangement.

SpaceX Stock Prediction After the IPO: Can SPCX Reach $200 Before QQQ Inclusion?
SpaceX stock has become one of the hottest trades of 2026. Can SPCX reach $200 before QQQ inclusion? Discover the latest SpaceX stock prediction, analyst targets, Bitcoin exposure, and the key catalysts that could move SpaceX stock after its historic IPO.

Congratulations to Carl Moon on His Historic Ferrari Challenge Le Mans Podium Triumph
Crypto influencer and racing enthusiast Carl Moon finished third in the Ferrari Challenge Le Mans Coppa Shell class, marking his best result of the year. As his racing partner and sponsor, WEEX celebrates this remarkable achievement and continues to lead crypto’s journey beyond boundaries, uniting the innovation of digital assets with the passion of motorsport.

Can the CLARITY Act Become Law by July 4? Everything You Need to Know About the Final Battle
The CLARITY Act has cleared a major Senate hurdle, but the hardest battle is still ahead. With the July 4 deadline approaching, can the White House finally pass its biggest crypto regulation bill? Find the clues in our exclusive analysis below.

France vs Senegal World Cup 2026: Mbappe’s New Era Begins Against a Historic Rival
France vs Senegal World Cup 2026 preview: Can Mbappe lead France past Senegal after the shocking 2002 World Cup defeat? Full team news, predicted lineups, key battles, and WEEX's exclusive match prediction.

What is the connection between Huang Zheng of Pinduoduo and blockchain?
From Pinduoduo's "reverse insurance" to blockchain's smart contracts, this article explains how Huang Zheng's underlying logic uses "certainty" rules to reshape the flow of wealth for ordinary people.

Morning Report | Prediction market platforms like Kalshi and Polymarket jointly sue Kentucky over 14.25% trading tax; Bridgewater founder discusses decision-making in the AI era: principled thinking should run parallel to AI, human insight remains irre...
Overview of Important Market Events on June 15
In the name of charity, for the benefit of the family: How the Trump family turned charity into profit?
This set of "beautiful rhetoric and value return to one's own people" has not stopped at charitable foundations; it has now almost been transferred intact to American Bitcoin.
Will Gold Break $4,500 After Tonight's Fed Decision? What XAUT and PAXG Traders Need to Know
The Federal Reserve announces its June rate decision tonight. Could gold break $4,500 next? Explore the latest gold price prediction, key Fed scenarios, and what they mean for XAUT and PAXG traders.
Cursor, why did you get on Musk's spaceship?
SpaceX set a record with its IPO, spending a staggering $60 billion to acquire the popular AI programming unicorn Cursor just four days later. Musk is using the ultimate puzzle of "super computing power + top coding engine" to propel the market value skyrocketing, surpassing Amazon in one fell swoop...
Morning Report | DeepSeek completes over $7 billion in financing, with a valuation exceeding $50 billion; Musk's personal wealth has surpassed the total market value of Bitcoin
Overview of Important Market Events on June 16
SharpLink CEO: How to understand that Ethereum developers have just surpassed 1 million?
The most important question in the cryptocurrency industry is not which chain is the fastest, but rather where top builders choose to build in the long term. Ethereum has just surpassed one million cumulative developers; what does this number mean?
Morning Report | MiCA grace period expires on July 1; Kalshi's trading volume in the first week of the World Cup breaks $5.1 billion, setting a record
Overview of Important Market Events on June 15
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com


