
WLFI holders are being targeted by a series of phishing attacks exploiting EIP-7702 on Ethereum, according to Yu Xian (SlowMist). The 'delegate contract' mechanism allows bad actors to sweep Tokens as soon as victims deposit ETH or receive WLFI.
EIP-7702 allows regular accounts to temporarily behave like smart contract wallets to authorize execution and batch transactions. When the private key is exposed, the attacker can pre-install a malicious delegate contract at the wallet address and seize WLFI as soon as a transaction occurs.
MAIN CONTENT
Phishing EIP-7702 is currently sweeping WLFI Tokens from wallets with leaked private keys, according to SlowMist.
Mechanism: embedding a delegate contract, taking over execution rights, withdrawing gas and WLFI as soon as the victim deposits funds or transfers.
Recommendations: cancel/overwrite EIP-7702 authorization, transfer Tokens out of the compromised wallet, be wary of fake contracts and fake support channels.
What is WLFI?
WLFI is the Token of World Liberty Financial, backed by Donald Trump, which began trading on Monday morning with a total supply of 24.66 billion Tokens.
The launch of WLFI attracted significant attention, leading to scam campaigns targeting the community. During the initial trading phase, new Tokens are often the target of 'sweeper bots' and fake contracts, making holders particularly cautious.
Why are WLFI holders being attacked?
According to Yu Xian (SlowMist), hackers are exploiting EIP-7702 to pre-embed addresses controlled by hackers into victims' wallets and 'snatch' WLFI as soon as deposits or transactions occur.
In posts on X, Xian describes a recurring scam technique: the bad actor obtains the private key through phishing, then attaches a malicious delegate contract to the corresponding address. When the victim deposits ETH for gas or when WLFI arrives in the wallet, the bot automatically executes the withdrawal command.
"Met another player with multiple addresses that lost all WLFI. Looking at the theft method, it was exploiting the malicious delegate contract 7702, with the prerequisite being the leak of the private key."
– Yu Xian, Founder of SlowMist, Monday, source: X (https://x.com/evilcos/status/1962534941901902057)
What is EIP-7702?
EIP-7702 is a proposal that allows external accounts to temporarily behave like smart contract wallets, authorizing execution rights and batch transactions to smooth the user experience.
According to the specifications of EIP-7702, the delegation mechanism helps to aggregate and automate operations, but also opens up risk surfaces if the private key is leaked or the delegate contract is abused. In that case, the attacker can take over execution rights to sign and send unauthorized commands on behalf of the victim. Source: EIP-7702 (Ethereum, 2024).
How does phishing EIP-7702 work?
The attacker embeds a delegate contract into the victim's address and waits for the moment to deposit ETH or receive WLFI to activate the sweep of Tokens.
The common process observed: 1) private key stolen via phishing, 2) malicious delegate contract attached, 3) when a transaction occurs, this contract takes over execution rights, 4) gas and Tokens are withdrawn immediately. According to Xian, even when the victim tries to transfer the remaining Tokens, the gas deposited can also be transferred away.
"As soon as you attempt to transfer the remaining Tokens, such as WLFI in the Lockbox contract, the amount of gas you deposit will be automatically transferred away."
– Yu Xian, Founder of SlowMist, 31/8, source: X (https://x.com/evilcos/status/1962118451285385720)
What signs indicate that a wallet may have a malicious delegate contract embedded?
Typical signs include ETH deposited for gas being withdrawn immediately, or WLFI being transferred out as soon as it arrives in the wallet, even though you haven't performed any actions.
Sweeper bots often run continuously, monitoring addresses that have been embedded with delegates. When they detect a sufficient balance, they trigger a withdrawal transaction. If you see transactions originating from your wallet without your signature, or strange commands related to delegation/execution, assume that the wallet has been compromised.
What to do when the wallet has been compromised?
Xian recommends canceling or replacing the embedded EIP-7702 authorization and transferring Tokens out of the compromised wallet as soon as possible.
If access is still available, move WLFI to a new safe wallet and consider transacting on a low gas fee network to reduce the 'window' for scanning. With the authorization already embedded, you may need to perform a technical transaction to overwrite the authorization with your own configuration, then withdraw the assets immediately. If you're not confident, it's advisable to seek support from a reputable security team.
Why are participants in the WLFI whitelist/presale at high risk?
According to reports on the WLFI forum, the wallet used for whitelisting must be used for the presale, making it difficult for those who have previously leaked their private keys to switch to a safe wallet.
A user named Anton reported that many others are experiencing similar issues due to the implementation of the airdrop/presale: when the Token is sent to the exposed wallet, bots will 'sweep' immediately before the wallet owner can transfer to a safe wallet. He also suggested that the WLFI team consider direct transfers to wallets specified by users. Source: WLFI forum.
What is the WLFI community facing?
Many users have reported loss or risk of losing WLFI on the official project forum.
A user named hakanemiratlas mentioned that his wallet was hacked since last October, and he could only transfer 20% of WLFI to a new wallet while 'racing' against the hacker; the remaining 80% is stuck and may be transferred away as soon as unlocked. These cases highlight the extreme time pressure when the wallet has been embedded with malicious authorization.
What scams emerged around the WLFI launch?
Before and after the WLFI launch, many fake contracts and phishing schemes emerged targeting the community.
Bubblemaps records 'bundled clones' that mimic contracts of familiar projects, tricking users into signing incorrect addresses. The WLFI team also warns against contacting support via direct messages on any platform, only using emails from the official domain. Source: Bubblemaps; WLFI forum.
How to minimize risks with EIP-7702 and new Tokens?
The general principle is to isolate risks and reduce permissions, avoiding having a single wallet that serves as whitelist, presale, and long-term storage.
Consider: using a new wallet exclusively for airdrop/presale; thoroughly checking contracts, authorization rights, and transaction history before signing; transferring WLFI to a cold wallet or another wallet immediately upon receipt; avoiding depositing a large amount of ETH into suspicious wallets; following official channels to verify domains, contracts, and security guidelines.
What warnings has WLFI issued?
The WLFI team states that they do not provide support through direct messages; users need to check that emails come from the official domain before responding.
Impersonating the team via DM is a common tactic to lure users into signing transactions or revealing seed phrases. The community should closely follow the official channels published by WLFI and promptly report any suspicious cases. Source: WLFI forum.
Statements and sources referenced
This article uses findings and warnings from Yu Xian (SlowMist) posted on X about phishing EIP-7702, specifying EIP-7702 from Ethereum, and information about users/WLFI team from the official forum, along with notes from Bubblemaps regarding fake contracts.
"This is clearly a classic example of phishing EIP-7702: the private key is leaked, and the bad actor embeds a delegate contract into the victim's wallet address."
– Yu Xian, Founder of SlowMist, 31/8, source: X (https://x.com/evilcos/status/1962118451285385720)
Frequently Asked Questions
What is phishing EIP-7702?
This is a technique that exploits the execution authorization of EIP-7702. When the private key is leaked, the bad actor embeds a malicious delegate contract and automatically sweeps Tokens/gas as soon as a transaction occurs. Source: Yu Xian, SlowMist.
How to know if my WLFI wallet has been embedded with authorization?
If the ETH deposited for gas disappears immediately, or if WLFI is transferred out instantly without your signature, it is very likely that the wallet has been embedded with a malicious delegate contract. Stop depositing more funds and take emergency action.
Can I save WLFI from a compromised wallet?
Possibly, if access is still available: overwrite/cancel the EIP-7702 authorization and immediately transfer Tokens to a new wallet. This needs to be done quickly to avoid the bot sweeping. Refer to Yu Xian's recommendations.
Does WLFI have any official support channels?
WLFI confirms that they do not provide support via DM. They only respond to emails from the project's official domain, checking carefully before replying. Source: WLFI forum.
How to avoid fake contracts when trading WLFI?
Always verify contract addresses from official channels, be wary of 'bundled clones', test small transactions first, and separate the wallet used for presale from long-term storage wallets. Source: Bubblemaps, WLFI forum.
Source: https://tintucbitcoin.com/tin-tac-khai-thac-eip-7702-chiem-wlfi/
Thank you for reading this article!
Please Like, Comment, and Follow TinTucBitcoin to stay updated with the latest news about the cryptocurrency market and not miss any important information!
