According to monitoring by the SlowMist security team, a QNT reserve pool was maliciously attacked due to a design flaw in the EIP-7702 account, resulting in a loss of about 1988.5 QNT (approximately 54.93 ETH). The root cause of the vulnerability lies in the fact that the management rights of this QNT reserve pool are held by an external account (EOA), which delegated its code to a contract via the EIP-7702 mechanism. The functions of that contract are completely open to any external caller and lack necessary permission checks. This arbitrary call vulnerability allowed the attacker to directly extract QNT tokens from the reserve pool. Currently, the attack transaction has been confirmed on-chain, and SlowMist reminds related protocols and users to pay attention to the security of the implementation of the new features in EIP-7702.
