Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Gold Bitcoin BTC coin standing vertically in front of a rising green financial candlestick chart
    Inside Bitcoin’s September 2026 Rally: BTC Reclaiming $87K, $2B in ETF Inflows and a Short Squeeze
    CLARITY Act Fails 49-50 in US Senate as SEC & CFTC Move Ahead on Crypto Rules Within 48 Hours
    CLARITY Act Fails 49-50 in US Senate as SEC & CFTC Move Ahead on Crypto Rules Within 48 Hours
    Illustrated collage featuring diverse people surrounded by crypto symbols and a corporate boardroom backdrop.
    Quiet Racism in Crypto Gets “Obvious” During Circle’s Arc Mainnet Launch
    3D Liquid Network logo with a hooded hacker shadow and computer code overlays in the background
    Liquid Network Exploit Explained: Unbacked L-BTC and the $320M Peg-Out
    Clarity Act bill with a September 15 calendar and Senate chamber in the background.
    Can the Senate Pass the CLARITY Act on September 15? Here’s the Vote Math
  • Opinion
    OpinionShow More
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

EIP-7702 Flaw Drains 1,988 QNT From Ethereum Pool

Ethereum’s EIP-7702 upgrade adds flexibility to wallets by letting them temporarily act like smart contracts, but it also introduces new security risks.

Written By Kenrodgers Fabian
Fact Checked by Divya Mistry
Published 2026-04-29
Make The Crypto Times preferred on GoogleGoogle
EIP-7702 Flaw Drains 1,988 QNT From Ethereum Pool

Key Highlights

  • Ethereum’s EIP-7702 delegation flaw enabled a QNT reserve drain, exposing weak access control in smart contract setups.
  • Misconfigured admin delegation let attackers bypass checks and execute unauthorized batch transactions on Ethereum.
  • Post-Pectra exploits show rising abuse of delegation features, with attackers combining phishing and contract weaknesses.

A critical flaw in Ethereum’s EIP-7702 standard has led to the theft of 1,988.5 QNT from a token reserve pool. According to blockchain security firm SlowMist, the stolen funds, worth about 54.93 ETH, highlight risks in how delegated accounts are being configured.

In a recent incident breakdown, SlowMist traced the attack back to a misconfigured account, where admin control was tied to an externally owned address. This exposed a batch execution contract that lacked proper access checks. 

🚨SlowMist TI Alert🚨

We have detected a malicious transaction exploiting a flawed EIP-7702 account, resulting in a loss of 1,988.5 $QNT (approx. 54.93 $ETH).

The root cause is that the admin identity of a QNT reserve pool is held by an EOA… pic.twitter.com/KREgwKtFOq

— SlowMist (@SlowMist_Team) April 29, 2026

As a result, the attacker was able to run unauthorized transactions and move the funds. The incident on the Ethereum network highlights ongoing concerns around the safety of newer delegation features.

Delegation design opens critical gaps

Ethereum’s EIP-7702 upgrade, rolled out as part of the Pectra network upgrade, was meant to revolutionize user experience. The proposal allows standard wallets (EOAs) to temporarily attach smart contract code to themselves during a transaction. This enables powerful features like gas sponsorship, transaction batching, and social recovery without requiring users to permanently migrate to a separate smart contract wallet. 

However, as this QNT exploit demonstrates, the temporary “superpowers” granted to EOAs can create catastrophic security gaps if the attached code is flawed. When an account upgrades to a smart account and delegates logic, the embedded contract code executes with full account privileges. If the target contract is misconfigured, the traditional security assumptions of the wallet are bypassed entirely.

Rising pattern of post-Pectra exploits

The QNT drain incident is part of a wider, alarming pattern following Ethereum’s Pectra upgrade, where attackers are taking advantage of delegated account features alongside weak contract design. Security researchers say scams are also evolving, with phishing tactics now using approval signatures to hide malicious actions.

Similar instances that occurred in May 2025 demonstrated the potential of such an attack. For instance, a group named InfernoDrainer was able to use batch transactions to fool users into giving access to tokens, resulting in the loss of over $146,000. Furthermore, attackers on the BNB Smart Chain managed to circumvent transaction validations via delegations.

Researchers at Wintermute have also warned about the scale of the issue. They found that most EIP-7702 delegations were tied to contracts using the same code, many of them built to automate fund theft.

While EIP-7702 brings new convenience, it also introduces new risks

Our Research team found that over 97% of all EIP-7702 delegations were authorized to multiple contracts using the same exact code. These are sweepers, used to automatically drain incoming ETH from compromised… pic.twitter.com/xHp7zr4hC9

— Wintermute (@wintermute_t) May 30, 2025

The pattern is raising the pressure on DeFi developers to tighten their security postures. As the boundaries between standard wallets and smart contracts blur, rigorous access control checks, explicit permission parameters, and clear UI warnings for users engaging with EIP-7702 authorizations have become mandatory for survival on the network.

Also Read: WLFI Partnered With Crypto Project Linked to Alleged Scam Network

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:Ethereum (ETH)
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

Jumper Announces JUMP Token Sale Starting September 29
Binance Sees Biggest Bitcoin Outflow Since 2023 as Analyst Flags FOMO
Binance Sees Biggest Bitcoin Outflow Since 2023 as Analyst Flags FOMO
Ethena Begins Equity Basis Trade on Binance With Tokenized Stocks
Ethena Begins Equity Basis Trade on Binance With Tokenized Stocks
NEAR Protocol Surges 13.9% Following Bitwise NEAR ETF Updates
NEAR Protocol Surges 13.9% Following Bitwise NEAR ETF Updates
3D orange text spelling "Strategy" ending with an integrated Bitcoin symbol, set against a dark wall and marble surface.
Michael Saylor’s Strategy Proposes Daily Dividends on Preferred Stocks

Find Us on Socials

You may also like

A gloved hand holding a smartphone displaying the Limit Break logo, with the Yuga Labs logo illuminated on the wall behind it.

Limit Break NFT Exploit: Yuga Labs’ Quit Rescues 23,155 NFTs, Says 660 WETH Lost

Magic Eden Ethereum Flaw Whitehat 0xQuit Secures 3,832 NFTs, Users Told to Revoke Approvals

Magic Eden Ethereum Flaw: Whitehat 0xQuit Secures 3,832 NFTs, Users Told to Revoke Approvals

Bryan Pellegrino, CEO of LayerZero, positioned between the Kelp DAO and LayerZero logos on a cracked background.

KelpDAO Sues LayerZero and CEO Bryan Pellegrino in Canada Over $292M rsETH Exploit

Bitget Hacked for $351.6M Withdrawals Frozen as CEO Points to North Korea

Bitget Hacked for $351.6M: Withdrawals Frozen as CEO Points to North Korea

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information