EIP-7702 CrimeEnjoyor Drainer Cluster
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·4wYBuV…QwXmSummary
Following Ethereum's Pectra hard fork (May 7, 2025), which activated EIP-7702 account-delegation functionality, a coordinated drainer campaign emerged that security researchers at Wintermute labeled 'CrimeEnjoyor.' Wintermute found that over 97% of all EIP-7702 delegations on-chain used near-identical sweeper bytecode designed to automatically drain ETH from compromised addresses, and one analysis citing Wintermute data placed the share of crime-tagged delegations at roughly 48% of total activations. Documented losses linked to EIP-7702 phishing range from a May 2025 incident of $146,551 to two August 2025 incidents totalling approximately $2.54 million, with a separate April 2026 protocol-level exploit removing 1,988.5 QNT (about 54.93 ETH) from a reserve pool through an access-control flaw in a delegated BatchExecutor contract.
Connected Entities
1 entityNo connected entities recorded yet — this investigation is not currently linked to any other page in the index.
Timeline(6 events)
7 May 2025
Ethereum Pectra hard fork activates EIP-7702, enabling EOA-to-smart-contract delegation via transaction type 0x04.
Coin Edition / multiple7 May 2025
Wintermute observes that within the first weeks post-Pectra, the first 11,000 EIP-7702 mainnet authorizations include a high proportion linked to sweeper bytecode.
Zelcore security analysis23 May 2025
Scam Sniffer flags a $146,551 loss by a wallet upgraded to EIP-7702 through malicious batched transactions attributed to Inferno Drainer; SlowMist's Yu Xian confirms batch-authorization mechanics.
Bitget / Scam Sniffer2 June 2025
Wintermute publicly discloses CrimeEnjoyor findings: over 97% of EIP-7702 delegations use near-identical sweeper bytecode; Wintermute injects on-chain warnings into verified malicious contracts. CoinDesk notes Wintermute's caveat that the sweepers are largely not profiting, as they target already-compromised wallets.
CoinDesk / CoinTelegraph1 August 2025
Two EIP-7702 phishing incidents in August cause a combined approximately $2.54 million in losses: one victim loses $1.54 million through a fake Uniswap interface using malicious batch transactions; a second victim loses approximately $1 million in tokens and NFTs through the same attack pattern.
Cryptopolitan / Scam Sniffer29 April 2026
SlowMist reports a protocol-level EIP-7702 exploit draining 1,988.5 QNT (approximately 54.93 ETH) from a QNT reserve pool. Root cause: admin EOA delegated to BatchExecutor, which authorized a BatchCall contract with no access controls, enabling arbitrary calls to transfer pool funds.
Crypto Times / SlowMist via BitgetDecision Log
- hash: c5nm7KePKDjNMzjxAoHHERHEfDuWJADnctzRouV4hnR
This investigation is cryptographically anchored to the Solana blockchain (1 event). 16 of 20 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 10/4/2026, 11:24:00 PM
last updated: 10/5/2026, 6:29:52 AM
3 viewsavoid.net — verified advice for a post-truth world