Ethereum phishing scams – $12M lost in August as EIP-7702 exploits surge!

ambcrypto发布于2025-09-07更新于2025-09-08

Key Takeaways

Phishing scams drained over $12M from 15,000+ wallets in August 2025, largely exploiting Ethereum’s EIP-7702 standard. Experts warn that even major projects like Trump’s WLFI token are being targeted.


Phishing scams in the crypto sector surged to alarming levels in August 2025, stripping investors of more than $12 million across 15,000+ wallets.

According to blockchain security firm Scam Sniffer, the losses marked a 72% jump from July – With the number of victims climbing by 67% month-over-month.

Phishing attacks go beyond heights

Phishing attacks in August showed how quickly scammers have adapted to Ethereum [ETH]’s latest innovations.

In fact, Scam Sniffer revealed that three whale wallets accounted for nearly 46% of the $12 million in losses that month, with one wallet alone losing $3.08 million. The firm identified Ethereum’s new EIP-7702 standard as the primary tool scammers exploited in these schemes.

For those unaware, Ethereum introduced EIP-7702 to improve wallet functionality, enabling externally owned accounts (EOAs) to temporarily operate like smart contract wallets. The upgrade added convenient features such as batching transactions, setting spending caps, integrating passkeys, and recovering wallets without changing addresses.

However, attackers soon weaponized these same features, using them to accelerate thefts and trick users into signing malicious approvals.

Details of the attack

Wintermute’s Dune Analytics dashboard showed that over 80% of delegate contracts tied to EIP-7702 have displayed malicious behavior, compromising more than 450,000 wallet addresses since the standard’s rollout.

Security experts also believe that most users remain dangerously unaware of these risks.

Yu Xian, founder of blockchain security firm SlowMist, also emphasized that organized criminal groups have eagerly exploited EIP-7702, extending the attacks across Ethereum Virtual Machine (EVM) ecosystems.

Hence, to counter these threats, Scam Sniffer is urgingnvestors to exercise greater caution when interacting with wallet prompts.

The firm recommended verifying domains, avoiding rushed approvals, and rejecting signatures that grant unlimited or overly broad permissions.

As suspicious prompts tied to contract upgrades and mismatched transaction simulations continue to spread, Ethereum users should stay vigilant. Especially since even breakthrough features can double as attack vectors in the wrong hands.

Share

热门币种推荐

你可能也喜欢

美国大模型走向封闭,以安全之名

2026年6月,美国政府以安全为由,对前沿AI模型的发布实施管制。Anthropic的最强网络安全模型Mythos 5被要求下架后,仅获准有限恢复至约100家美国机构,其公众版Fable 5恢复时间未定。同时,OpenAI发布的新模型GPT-5.6系列也只对经政府审批的合作伙伴开放API。此事标志着美国政府首次成功介入商业AI模型的发布审批。 然而,涉事公司的安全评估显示,模型并未越过其自设的风险红线。OpenAI评估其模型不具备自主实施端到端网络攻击的能力;Anthropic则反驳政府的担忧基于一个狭窄、非通用的漏洞。行业批评政府的决策缺乏清晰的技术标准和透明的流程。有观点认为,管制行动的背后是模型能力的“可演示性”引发了政治担忧、竞争对手的举报以及新AI行政令寻求执法案例的需求。 文章回顾了上世纪90年代的“密码战争”,当时美国政府试图管制强加密技术的出口,最终因技术扩散无法遏制、损害美国企业竞争力而失败。历史镜鉴提示,对前沿AI的类似管制可能阻碍技术创新与产业投资,并将市场优势让位于以开源开放策略发展的竞争者。 评论指出,一个没有明确标准和时间表的审批流程,可能动摇前沿AI产业的商业逻辑,并将强大工具的访问权集中于少数特权机构,反而可能增加风险。全球开发者社区开始怀念模型自由发布、快速创新的时代,并将更多期待转向持续开放的中国大模型。

链捕手1小时前

美国大模型走向封闭,以安全之名

链捕手1小时前

交易

现货

热门文章

加密市场宏观研报:美国“加密货币周”来袭,ETH开启机构军备赛高潮

本周,加密市场迎来两股重磅催化——华盛顿“加密货币周”的立法攻势与以太坊机构布局的密集爆发,共同构成加密行业2025年下半年的“政策拐点”与“资金拐点”。这一轮加密周期的深层逻辑,正从比特币转向以太坊、稳定币及链上金融基础设施。我们认为:美国的政策明朗化+以太坊的机构化扩展,标志着加密行业正进入结构性转正阶段,市场配置的重心亦应逐步从“价格博弈”过渡至“规则+基础设施的制度红利捕捉”。

1.8k人学过发布于 2025.07.17更新于 2025.07.17

加密市场宏观研报:美国“加密货币周”来袭,ETH开启机构军备赛高潮

相关讨论

欢迎来到HTX社区。在这里,您可以了解最新的平台发展动态并获得专业的市场意见。以下是用户对ETH(ETH)币价的意见。

活动图片