Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    MicroStrategy Stock Mirrors Bitcoin's Wildest Swings 7 Times BTC Moved MSTR
    MicroStrategy Stock Mirrors Bitcoin’s Wildest Swings: 7 Times BTC Moved MSTR
    Beyond Bitcoin Treasuries How Hyperliquid’s Revenue-Backed HYPE Is Creating Self-Funding Corporate Balance Sheets
    Beyond Bitcoin Treasuries: How Hyperliquid’s Revenue-Backed HYPE Is Creating Self-Funding Corporate Balance Sheets
    The Unresolved Debate Reignites: Is Bitcoin a Pyramid Scheme?
    The Unresolved Debate Reignites: Is Bitcoin a Pyramid Scheme?
    Exclusive Coinbase Says No Other International Launch For 12 Months, India Is the Bet
    Exclusive: Coinbase Says No Other International Launch For 12 Months, India Is the Bet
    Crypto PACs Reshape US Elections: Trump's Pro-Crypto Agenda Takes Shape
    Crypto PACs Reshape US Elections: Trump’s Pro-Crypto Agenda Takes Shape
  • Opinion
    OpinionShow More
    The CLARITY Act War Starts Jamie Dimon Vs Armstrong
    The CLARITY Act War Starts: Jamie Dimon Vs Armstrong
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino?
    CoinSwitch on TMKOC India Saw a ₹100 Crypto Pitch, But Not the Risks Behind It_
    CoinSwitch on TMKOC: India Saw a ₹100 Crypto Pitch, But Not the Risks Behind It
    Bitcoin Pizza Day Was Never Really About Pizza
    Bitcoin Pizza Day Was Never Really About Pizza
    The CLARITY Act The Final Hand — Everyone's Bluffing, Nobody's Folding, and Thursday Changes Everything
    The CLARITY Act: The Final Hand — Everyone’s Bluffing, Nobody’s Folding, and Thursday Changes Everything
  • Learn
    • Explained
    • How To
    • Insights
  • Podcasts
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Podcasts
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Ethereum News

Pectra Upgrade Has Put Ethereum Wallets on “Auto-drain” Risk: Wintermute

Written By:
Gopal Solanky

Last updated: June 2, 2025 5:38 PM
Published 2025-06-02
Share
Last updated: June 2, 2025 5:38 PM
Published 2025-06-02
Pectra Upgrade Has Put Ethereum Wallets on “Auto-drain” Risk Wintermute

The recent Ethereum Pectra upgrade—which introduced smart wallets, validator limit increase and multiple other upgrades to the network— has inadvertently exposed user wallets to a severe “auto-drain” risk. The research, carried out by the Wintemute team, discloses that 97% of these upgrade delegations are tied to malicious “sweeper” contracts. 

The upgrade, which went live on 7 May, introduced EIP-7702, an improvement proposal allowing Externally Owned Accounts (EOAs) to temporarily act as smart contracts. However, this innovation has been filled with malicious copy-pasted code and it has put a significant amount of Ethereum users at risk. 

In a latest X post, the Wintermute team revealed that 97% of EIP-7702 wallet delegations are tied to malicious “sweeper” contracts, designed to automatically drain ETH from compromised addresses. These contracts, dubbed “CrimeEnjoyor” by Wintermute, target wallets with leaked private keys, siphoning funds without user intervention. 

While EIP-7702 brings new convenience, it also introduces new risks

Our Research team found that over 97% of all EIP-7702 delegations were authorized to multiple contracts using the same exact code. These are sweepers, used to automatically drain incoming ETH from compromised… pic.twitter.com/xHp7zr4hC9

— Wintermute (@wintermute_t) May 30, 2025

Wintermute’s Dune dashboard highlights over 79,000 addresses linked to these sweepers, with attackers spending 2.88 ETH to authorize them. 

To find exact details, the research firm reversed the malicious bytecode into Solidity, verifying it as CrimeEnjoyor to expose its intent and warn users. Despite the large scale of the operation, no such exploits have been confirmed yet. 

The Pectra upgrade aimed to streamline transactions through features like transaction batching and gas sponsorship. It was considered beneficial for early adopters like Uniswap and JumperExchange, which account for 95% of EIP-7702 flows on Ethereum. However, the lack of transparency in unverified contracts has enabled exploitation. 

This finding has sparked concern in the crypto community, with experts urging users to exercise caution. As Ethereum evolves, the need for robust verification and transparency tools has never been more critical to protect users from such auto-drain threats.

Also read: Institutional Investors Shift to Ethereum From Bitcoin & XRP: Data

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News
Google News Banner

TAGGED:Ethereum (ETH)
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link
Gopal Solanky - Crypto Research Analyst at The Crypto Times
By Gopal Solanky Sr. Crypto Journalist
Follow:
Gopal Solanky is a Research Analyst and Reporter with over 5 years of experience in DeFi, blockchain, crypto, IT, and financial markets. With a Bachelor's in Computer Applications, he brings a strong technical foundation to his analysis and reporting. Gopal focuses on breaking down complex topics for both seasoned investors and curious readers. His work has been referenced by publications like Business Insider and Vulture.com, highlighting his contributions to industry stories around topics like Huwak Tuah Memecoin and the FTX collapse.

Latest News

Bessent Pushes US Bitcoin Reserve as CLARITY Act Bill Gains Steam
Bessent Pushes US Bitcoin Reserve as CLARITY Act Bill Gains Steam
Axelar Pushes Cross-Chain Messaging and Asset Transfers With Solana Integration
Axelar Pushes Cross-Chain Messaging and Asset Transfers With Solana Integration
£5M Crypto Gift Scandal: U.K PM Starmer Puts Nigel Farage on the Spot
£5M Crypto Gift Scandal: U.K PM Starmer Puts Nigel Farage on the Spot
Alephium Burns Unauthorized wALPH After Bridge Attack
Alephium Burns Unauthorized wALPH After Bridge Attack
Bitcoin Rally Collapses as ETF Outflows and Selling Pressure Mount: Glassnode
Bitcoin Rally Collapses as ETF Outflows and Selling Pressure Mount: Glassnode

Find Us on Socials

You may also like

Coinbase Launches ETH-INR and SOL-INR Pairs in India

Coinbase Launches ETH-INR and SOL-INR Pairs in India

Crypto Market Today BTC Falls to $66K as Liquidations Hit $1.65B

Crypto Market Today: BTC Falls to $66K as Liquidations Hit $1.65B

BitMine Faces $8.66B Paper Loss Amid ETH Price Decline — Inside Tom Lee’s ‘Alchemy of 5%’ Strategy

BitMine Faces $8.66B Paper Loss Amid ETH Price Decline — Inside Tom Lee’s ‘Alchemy of 5%’ Strategy

Ethereum to Build Its “Quantum Shield” for Next Era of Crypto

Ethereum to Build Its “Quantum Shield” for Next Era of Crypto

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Podcasts

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information