Original author: lightclients
Original source: twitter
Compiled by: MetaCat
After EIP-3074, a single incorrect signature will be able to drain the balance on your Ethereum account.
Yes, it is real.
EIP-3074 co-authors here! Let me calm this concern for now before things get even more out of control.
First of all: I am not aware of any wallet that currently supports signing unprefixed data. This means that no wallet currently supports EIP-3074. No matter how many control panels you browse or how many advanced features you turn on. It is not possible to sign EIP-3074 messages right now.
The message you sign to the "login" dapp is using a completely different standard than EIP-3074, based on EIP-191. This adds the following data to the message you sign:
0x19 <0x45 (E)> <thereum Signed Message:\n" + len(message)> <data to sign
This is why it is impossible to trick someone logged into a dapp into actually signing a valid Ethereum transaction.
Transactions are prefixed with a single-byte value:
0x01 - 2930 tx0x02 - 1559 tx0x03 - 4844 tx
For more information, see: https://github.com/ethereum/execution-specs/tree/master/lists/signature-types
EIP-3074 plans to use the prefix 0x04. This will disambiguate it from all other types of signable data in Ethereum. Wallets must actively choose to allow users to sign these messages.
To understand how a wallet integrates EIP-3074, it could create a situation where users are more vulnerable to exploitation. To understand this, we need to make sure we understand how EIP-3074 signatures work.
The authentication message that builds the signature has the following fields. Importantly, it includes a caller address. This is the only address that AUTH considers the signature valid.

For an account to have a depleted balance, both of the following must be true:
1) The wallet needs to allow the user to sign to any invoker address,
2) The user must not verify whether the invoker is trustworthy.
This means that there will be no problem if the user executes any of them.
We hope that wallet software understands that EIP-3074 invokers are more like extensions of wallet software code than contracts. Wallets should not allow users to freely run arbitrary code and access their pk (private keys); similarly, they should not allow users to arbitrarily delegate their Ethereum accounts.
Therefore, if wallet software does not securely integrate EIP-3074, and users do not verify the callers they are interacting with, delegation to malicious callers is possible. However, this can still be revoked by sending a single tx from the EOA. This will revoke all "in-progress" AUTH signatures.
At the very least, wallet software should make signing an EIP-3074 message a big deal, just like exporting your private keys is a big deal.
Assuming a wallet securely integrates 3074, it is still possible for an account to be compromised. This is a fundamental property of batch transactions. It allows you to easily send multiple operations, just as it allows an attacker to trick you into sending a batch of assets to an address they control.
Wallet software must clearly display every operation you are signing. That way, it is easy to notice "I only intended to make one transaction, but this signature request made me make a dozen more transactions." If batching is done via blind signing, this cannot be detected.
Yes, EIP-3074 places a lot of trust in wallets. However, we already safely trust them with our private keys! There is no higher level of trust.
EIP-3074 can be safely integrated and used. If any wallet has questions about how to do this, please feel free to contact us. As the authors of EIP-3074, we are currently considering how we can best help with the next phase of the standard's development.
We've spent a lot of time over the past few years developing what-if scenarios about how it could be used and abused. We're excited to see these ideas start to make it into production. But we also recognize that this is the hardest part.
To summarize the concerns about a single bad signature draining your Ethereum account balance after EIP-3074:
- Currently the wallet does not support EIP-3074 type signatures, which follow a new format.
- The caller field in the EIP-3074 signature is very important. A bad caller could steal your funds.
- The wallet needs to ensure that the caller address is trusted. This is similar to how wallets currently prevent arbitrary code execution.
- Batching transactions in EIP-3074 still opens up a world where malicious actors can trick you into signing a transaction that transfers assets. Wallets need to clearly display what happens when signing an EIP-3074 message.
- Yes, we have a high level of trust in wallets, but users have entrusted their private keys to them, and that is the highest level of trust.

EIP-3074 given EIP-4337
EIP-3074 is a very good thing for Account Abstraction providers because it is very beneficial to our customers.
- ERC-4337 is the best way to introduce new users to the crypto space.
- EIP-3074 is the best way to onboard existing users to Smart Accounts.
