← EIP-7702 CrimeEnjoyor Drainer Cluster1 decision on this page
Audit log
Every state-changing event for EIP-7702 CrimeEnjoyor Drainer Cluster: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-10-04 23:24:09ZScore: ? → ? (no score change)anchoranchored
- chain
- ●mainnet-betaslot 453,403,201
- sig
4wYBuV2g2xe3…6DCRQwXmexplorer ↗- hash
c5nm7KePKDjN…RouV4hnRsha256 → base58
verifying row…full verify ↗canonical bytes (22879 B) ▸
{"actor":"system:backfill","investigation_id":"e86fd241-f210-4d38-abaa-4204e408e3de","kind":"publish","page_slug":"eip-7702-crimeenjoyor-drainer-cluster","published_at":"2026-10-04T23:24:09.691Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"EIP-7702 CrimeEnjoyor Drainer Cluster","sections":[{"content":"EIP-7702 was activated on May 7, 2025, as part of Ethereum's Pectra hard fork. The proposal introduces transaction type 0x04, which allows an externally owned account (EOA) to temporarily attach smart-contract bytecode by signing an authorization message. The authorization writes a 23-byte pointer (0xef0100 followed by a target address) into the EOA's code slot, granting the designated contract execution rights against that wallet for the duration of the delegation. Intended use cases include batched transactions, gas sponsorship, and spending limits. Authorizations signed with chain_id = 0 are valid on every EVM-compatible chain, creating cross-chain replay risk. MetaMask added support within days of the fork; Trust Wallet followed through Q3 2025; Coinbase Wallet and Ledger added support by late 2025, according to the Zelcore security analysis.","heading":"Background: EIP-7702 and the Pectra Upgrade","severity":"low","sources":[{"credibility":2,"name":"Zelcore: EIP-7702 Delegation Phishing Risk","type":"research","url":"https://zelcore.io/academy/security/eip-7702-delegation-phishing-risk"},{"credibility":2,"name":"Coin Edition: Ethereum EIP-7702 Scammers Exploit Wallet Drain","type":"news_article","url":"https://coinedition.com/ethereum-eip7702-scammers-exploit-wallet-drain/"}]},{"content":"Wintermute's research team reverse-engineered on-chain EIP-7702 delegation contracts post-Pectra and found that over 97% of all observed EIP-7702 delegations were authorized to contracts sharing nearly identical bytecode. Wintermute converted the bytecode to human-readable Solidity, publicly verified it, and named the dominant contract 'CrimeEnjoyor.' The contract is described by Wintermute as 'short, simple, and widely reused,' functioning as an automated sweeper that drains any incoming ETH from wallets whose private keys have been compromised. Wintermute subsequently injected on-chain warnings into the verified contracts stating the contract 'is used by bad guys to automatically sweep all incoming ETH' and advising users 'NOT SEND ANY ETH.' By the time of Wintermute's public disclosure, the CrimeEnjoyor share of delegations had slightly decreased to 94.7%, but it remained the dominant delegation bytecode. According to reporting citing Wintermute data, of approximately 1.58 million EIP-7702 delegations activated after the Pectra launch, approximately 768,275 (roughly 48%) were tagged as crime-related, with more than 97% of those malicious delegations pointing to the same sweeper bytecode. The attackers were reported to have spent at least 2.88 ETH to authorize these sweeper contracts. Wintermute also noted that, despite the volume of malicious delegations, the sweepers were primarily targeting wallets already compromised by leaked private keys rather than newly defrauding previously secure users through delegation alone.","heading":"The CrimeEnjoyor Sweeper Contracts","severity":"high","sources":[{"credibility":2,"name":"Wintermute on X: EIP-7702 delegation sweeper findings","type":"social_media","url":"https://x.com/wintermute_t/status/1928501765865091400"},{"credibility":2,"name":"CoinTelegraph: Wintermute CrimeEnjoyor flags Ethereum wallet-draining contracts","type":"news_article","url":"https://cointelegraph.com/news/wintermute-crimeenjoyor-flags-malicious-ethereum-contracts"},{"credibility":2,"name":"Analytics Insight: Ethereum Pectra Upgrade Exposes 97% of EIP-7702 Wallets to Auto-Drain Risk","type":"news_article","url":"https://www.analyticsinsight.net/news/ethereum-pectra-upgrade-exposes-97-of-eip-7702-wallets-to-auto-drain-risk"},{"credibility":1,"name":"CoinDesk: Ethereum CrimeEnjoyors Aren't Making Money, Wintermute Says","type":"news_article","url":"https://www.coindesk.com/tech/2025/06/02/post-pectra-upgrade-malicious-ethereum-contracts-are-trying-to-drain-wallets-but-to-no-avail-wintermute"},{"credibility":3,"name":"hoge.gg: Crypto Phishing Campaigns 2026 Drainer Economy","type":"research","url":"https://hoge.gg/crypto-phishing-campaigns-2026-drainer-economy/"}]},{"content":"EIP-7702-based phishing campaigns collapse the traditional multi-step approval process into a single signature. When a victim signs a malicious authorization, the attacker's contract is written into the EOA's code slot, granting the contract full execution rights over the wallet. Scam Sniffer and SlowMist documented three primary lure types: fake gas-sponsorship and token-claim interfaces requesting 7702 signatures; pages impersonating MetaMask's smart-account onboarding flow with a substituted delegator address; and malicious dApp connectors that silently substitute type-0x04 authorizations during an expected signing interaction. Because EIP-7702 authorization messages are not compatible with the existing EIP-191 or EIP-712 standards, they often appear in wallets as opaque 32-byte hashes, bypassing normal wallet warnings. Hardware wallets are exposed to the same phishing risk as software wallets because the risk lies in what the user signs, not in key storage. Inferno Drainer exploited a MetaMask delegator wallet already authorized under EIP-7702 to execute a batch of token approvals and transfers in a single silent background call, according to reporting by Bitget News citing SlowMist researcher Yu Xian.","heading":"Phishing Attack Mechanics","severity":"critical","sources":[{"credibility":2,"name":"Zelcore: EIP-7702 Delegation Phishing Risk","type":"research","url":"https://zelcore.io/academy/security/eip-7702-delegation-phishing-risk"},{"credibility":2,"name":"Bitget: Inferno Drainer Exploits Ethereum EIP-7702 in Evolving Phishing Tactics","type":"news_article","url":"https://www.bitget.com/news/detail/12560604776647"},{"credibility":2,"name":"DeFi Hack Labs: Top 7702 Delegator Revealed as Phishing Scam","type":"research","url":"https://defihacklabs.substack.com/p/top-7702-delegator-revealed-as-phishing"},{"credibility":2,"name":"Mitrade: New Ethereum feature exploited just weeks after launch in $146K phishing heist","type":"news_article","url":"https://www.mitrade.com/insights/news/live-news/article-3-842092-20250526"}]},{"content":"The following individual incidents have been documented by on-chain security firms with specific figures. On May 23-24, 2025, Scam Sniffer flagged the loss of $146,551 by a wallet that had been upgraded to EIP-7702 through a malicious batched transaction attributed to Inferno Drainer; SlowMist researcher Yu Xian confirmed the mechanics involved batch-authorization operations on tokens. In August 2025, Scam Sniffer and Cryptopolitan reported two related incidents totalling approximately $2.54 million: one investor lost $1.54 million after signing malicious EIP-7702 batch transactions through a fake DeFi interface mimicking Uniswap; approximately two days prior, a second investor lost approximately $1 million in tokens and NFTs through the same attack pattern, with stolen funds bridged to mainnet via Relay Protocol. On April 29, 2026, blockchain security firm SlowMist reported that an attacker exploited a misconfigured EIP-7702 delegation in a QNT reserve pool, stealing 1,988.5 QNT (approximately 54.93 ETH at the time). The root cause was that the pool's admin EOA had delegated to a BatchExecutor contract which in turn authorized a BatchCall contract without access-control checks, allowing unauthorized calls to drain QNT tokens. The $2.3 million figure cited in some summaries appears to represent an approximation of documented phishing losses through mid-2025; separately reported August 2025 incidents pushed confirmed losses to at least $2.54 million from phishing alone, not counting the April 2026 protocol exploit.","heading":"Confirmed Incidents and Losses","severity":"critical","sources":[{"credibility":2,"name":"Bitget: EIP-7702 address loses $146,551 in phishing attack","type":"news_article","url":"https://www.bitget.com/news/detail/12560604775453"},{"credibility":2,"name":"Cryptopolitan: Security analysts warn about EIP-7702 flaw after user loses $1.54M","type":"news_article","url":"https://www.cryptopolitan.com/eip-7702-user-loses-1-54m-phishing-attack/"},{"credibility":2,"name":"Crypto Times: EIP-7702 Flaw Drains 1,988 QNT From Ethereum Pool","type":"news_article","url":"https://www.cryptotimes.io/2026/04/29/eip-7702-flaw-drains-1988-qnt-from-ethereum-pool/"},{"credibility":2,"name":"Bitget: SlowMist EIP-7702 account vulnerability exploited, 1,988.5 QNT stolen","type":"news_article","url":"https://www.bitget.com/amp/news/detail/12560605389679"},{"credibility":2,"name":"PANewsLab: SlowMist malicious EIP-7702 transaction, approximately 54.93 ETH loss","type":"news_article","url":"https://www.panewslab.com/en/articles/019dd769-5b5c-766d-beb4-9bb2e860e44d"}]},{"content":"Multiple established drainer-kit operations shipped EIP-7702-flavored modules after the Pectra upgrade. Inferno Drainer, which had previously announced retirement in November 2023 but resurfaced after Pink Drainer shut down in May 2024, was directly linked to the May 2025 $146,551 incident by Scam Sniffer and SlowMist. Zelcore's security analysis states that Inferno Drainer, Pink Drainer, and the Angel Kit all shipped 7702-flavored modules through 2025 and 2026; this claim has not been independently verified through Tier 1 sources for Pink Drainer and Angel Kit specifically and should be treated as medium-confidence. Pink Drainer had previously stolen approximately $85 million from over 21,000 victims before its announced May 2024 shutdown. The drainer-kit model operates on a commission basis: kit operators take a percentage (typically 20-30%) of funds drained by affiliates using their infrastructure.","heading":"Drainer-as-a-Service Kit Adoption","severity":"high","sources":[{"credibility":2,"name":"Zelcore: EIP-7702 Delegation Phishing Risk","type":"research","url":"https://zelcore.io/academy/security/eip-7702-delegation-phishing-risk"},{"credibility":2,"name":"Bitget: Inferno Drainer Exploits Ethereum EIP-7702 in Evolving Phishing Tactics","type":"news_article","url":"https://www.bitget.com/news/detail/12560604776647"},{"credibility":2,"name":"PA News: Inferno Drainer uses EIP-7702, single $150,000 loss","type":"news_article","url":"https://panews.io/articles/kyyu829k"}]},{"content":"DeFi Hack Labs identified the malicious delegator contract at address 0x930fcc37d6042c79211ee18a02857cb1fd7f0d0b and the fraudulent ETH recipient address at 0x000085bad5b016e5448a530cb3d4840d2cfd15bc. The phishing contract ranked prominently on bundlebear.com, a delegation-tracking tool, giving it apparent legitimacy. GoPlus Security and MetaMask both issued warnings stating that EIP-7702 authorization should only occur within official wallet applications and that any email or URL claiming to 'enable' smart-account features represents a phishing vector. Wintermute's counter-measure of injecting warning text into verified malicious contracts is an informational signal, not a block; it does not prevent the contracts from draining funds if a user has already authorized a delegation.","heading":"On-Chain Detection and Identified Addresses","severity":"high","sources":[{"credibility":2,"name":"DeFi Hack Labs: Top 7702 Delegator Revealed as Phishing Scam","type":"on_chain","url":"https://defihacklabs.substack.com/p/top-7702-delegator-revealed-as-phishing"},{"credibility":2,"name":"GoPlus Security Medium: Understanding EIP-7702 Phishing Attacks","type":"research","url":"https://goplussecurity.medium.com/understanding-eip-7702-phishing-attacks-a-comprehensive-guide-to-protection-strategies-for-wallets-8e8372e3d5ea"},{"credibility":2,"name":"Analytics Insight: Ethereum Pectra Upgrade Exposes 97% of EIP-7702 Wallets to Auto-Drain Risk","type":"news_article","url":"https://www.analyticsinsight.net/news/ethereum-pectra-upgrade-exposes-97-of-eip-7702-wallets-to-auto-drain-risk"}]},{"content":"CoinDesk reported in June 2025, citing Wintermute, that despite the large volume of malicious EIP-7702 delegations, the 'CrimeEnjoyors' were reportedly not generating significant revenue at that time. Wintermute's position was that the sweeper contracts predominantly targeted wallets already known to be compromised via leaked private keys, and that most of those wallets were already empty or had minimal funds. This does not mean the campaign posed no threat to users, but it contextualizes the 97% malicious-delegation statistic: a high proportion of malicious delegations does not automatically translate into an equivalent proportion of wallet drainings of active users. Subsequent August 2025 incidents causing $2.54 million in losses, however, demonstrated that the attack pattern evolved beyond automated sweeping of already-compromised wallets to active phishing of previously secure users.","heading":"Wintermute Assessment: Profitability Caveat","severity":"medium","sources":[{"credibility":1,"name":"CoinDesk: Ethereum CrimeEnjoyors Aren't Making Money From Exploiting Pectra's EIP-7702, Wintermute Says","type":"news_article","url":"https://www.coindesk.com/tech/2025/06/02/post-pectra-upgrade-malicious-ethereum-contracts-are-trying-to-drain-wallets-but-to-no-avail-wintermute"},{"credibility":2,"name":"Bitcoin Ethereum News: Ethereum CrimeEnjoyors Aren't Making Money, Wintermute Says","type":"news_article","url":"https://bitcoinethereumnews.com/ethereum/ethereum-crimeenjoyors-arent-making-money-from-exploiting-pectras-eip-7702-wintermute-says/"}]},{"content":"Security researchers and wallet providers have issued consistent guidance. Users should only authorize EIP-7702 delegations through official wallet interfaces, never through links in emails, social media messages, or unsolicited DApp connections. Before signing any delegation, users should verify the delegator contract's source code is publicly available and audited. The chain_id = 0 replay risk means a delegation signed on one network may be valid on all EVM chains; users should confirm the chain_id in any authorization. Existing EIP-7702 delegations can be revoked by submitting a new type-0x04 transaction with an empty authorization, but this requires gas and awareness that an active malicious delegation exists. Hardware wallets do not mitigate this risk, as the vulnerability is in what the user approves, not in how the private key is stored.","heading":"User Protection and Risk Mitigation","severity":"medium","sources":[{"credibility":2,"name":"Zelcore: EIP-7702 Delegation Phishing Risk","type":"research","url":"https://zelcore.io/academy/security/eip-7702-delegation-phishing-risk"},{"credibility":2,"name":"DeFi Hack Labs: Top 7702 Delegator Revealed as Phishing Scam","type":"research","url":"https://defihacklabs.substack.com/p/top-7702-delegator-revealed-as-phishing"},{"credibility":2,"name":"The Coin Republic: How Hackers Are Exploiting EIP-7702 To Drain Wallets","type":"news_article","url":"https://www.thecoinrepublic.com/2025/05/25/ethereum-news-how-hackers-are-exploiting-eip-7702-to-drain-wallets/"}]}],"sources_used":[{"credibility":1,"name":"CoinDesk: Ethereum CrimeEnjoyors Aren't Making Money From Exploiting Pectra's EIP-7702, Wintermute Says","type":"news_article","url":"https://www.coindesk.com/tech/2025/06/02/post-pectra-upgrade-malicious-ethereum-contracts-are-trying-to-drain-wallets-but-to-no-avail-wintermute"},{"credibility":1,"name":"CoinTelegraph: Wintermute CrimeEnjoyor flags malicious Ethereum contracts","type":"news_article","url":"https://cointelegraph.com/news/wintermute-crimeenjoyor-flags-malicious-ethereum-contracts"},{"credibility":1,"name":"The Block: Wintermute warns Pectra upgrade leaves Ethereum users at risk of automated attacks","type":"news_article","url":"https://www.theblock.co/post/356481/wintermute-warns-pectra-upgrade-leaves-ethereum-users-at-risk-of-automated-attacks"},{"credibility":2,"name":"Wintermute on X: EIP-7702 delegation sweeper findings","type":"social_media","url":"https://x.com/wintermute_t/status/1928501765865091400"},{"credibility":2,"name":"Coin Edition: Ethereum EIP-7702 Scammers Exploit Wallet Drain","type":"news_article","url":"https://coinedition.com/ethereum-eip7702-scammers-exploit-wallet-drain/"},{"credibility":2,"name":"Analytics Insight: Ethereum Pectra Upgrade Exposes 97% of EIP-7702 Wallets to Auto-Drain Risk","type":"news_article","url":"https://www.analyticsinsight.net/news/ethereum-pectra-upgrade-exposes-97-of-eip-7702-wallets-to-auto-drain-risk"},{"credibility":2,"name":"Cryptonews.com.au: Ethereum EIP-7702 Upgrade Exploited by CrimeEnjoyor Wallet-Sweeping Scam","type":"news_article","url":"https://cryptonews.com.au/news/ethereums-eip-7702-upgrade-exploited-by-crimeenjoyor-wallet-sweeping-scam-129271/"},{"credibility":2,"name":"Zelcore: EIP-7702 Delegation Phishing Risk","type":"research","url":"https://zelcore.io/academy/security/eip-7702-delegation-phishing-risk"},{"credibility":2,"name":"DeFi Hack Labs: Top 7702 Delegator Revealed as Phishing Scam","type":"on_chain","url":"https://defihacklabs.substack.com/p/top-7702-delegator-revealed-as-phishing"},{"credibility":2,"name":"Bitget: EIP-7702 address loses $146,551 in phishing attack","type":"news_article","url":"https://www.bitget.com/news/detail/12560604775453"},{"credibility":2,"name":"Bitget: Inferno Drainer Exploits Ethereum EIP-7702 in Evolving Phishing Tactics","type":"news_article","url":"https://www.bitget.com/news/detail/12560604776647"},{"credibility":2,"name":"Cryptopolitan: Security analysts warn about EIP-7702 flaw after user loses $1.54M","type":"news_article","url":"https://www.cryptopolitan.com/eip-7702-user-loses-1-54m-phishing-attack/"},{"credibility":2,"name":"Crypto Times: EIP-7702 Flaw Drains 1,988 QNT From Ethereum Pool","type":"news_article","url":"https://www.cryptotimes.io/2026/04/29/eip-7702-flaw-drains-1988-qnt-from-ethereum-pool/"},{"credibility":2,"name":"Bitget: SlowMist EIP-7702 account vulnerability exploited, 1,988.5 QNT stolen","type":"news_article","url":"https://www.bitget.com/amp/news/detail/12560605389679"},{"credibility":2,"name":"PANewsLab: SlowMist malicious EIP-7702 transaction, approximately 54.93 ETH loss","type":"news_article","url":"https://www.panewslab.com/en/articles/019dd769-5b5c-766d-beb4-9bb2e860e44d"},{"credibility":2,"name":"PA News: Inferno Drainer uses EIP-7702, single $150,000 loss","type":"news_article","url":"https://panews.io/articles/kyyu829k"},{"credibility":2,"name":"Mitrade: New Ethereum feature exploited just weeks after launch in $146K phishing heist","type":"news_article","url":"https://www.mitrade.com/insights/news/live-news/article-3-842092-20250526"},{"credibility":2,"name":"The Coin Republic: Ethereum News: How Hackers Are Exploiting EIP-7702 To Drain Wallets","type":"news_article","url":"https://www.thecoinrepublic.com/2025/05/25/ethereum-news-how-hackers-are-exploiting-eip-7702-to-drain-wallets/"},{"credibility":3,"name":"hoge.gg: Crypto Phishing Campaigns 2026 Drainer Economy","type":"research","url":"https://hoge.gg/crypto-phishing-campaigns-2026-drainer-economy/"},{"credibility":2,"name":"Bitcoin Ethereum News: Ethereum CrimeEnjoyors Aren't Making Money, Wintermute Says","type":"news_article","url":"https://bitcoinethereumnews.com/ethereum/ethereum-crimeenjoyors-arent-making-money-from-exploiting-pectras-eip-7702-wintermute-says/"}],"summary":"Following Ethereum's Pectra hard fork (May 7, 2025), which activated EIP-7702 account-delegation functionality, a coordinated drainer campaign emerged that security researchers at Wintermute labeled 'CrimeEnjoyor.' Wintermute found that over 97% of all EIP-7702 delegations on-chain used near-identical sweeper bytecode designed to automatically drain ETH from compromised addresses, and one analysis citing Wintermute data placed the share of crime-tagged delegations at roughly 48% of total activations. Documented losses linked to EIP-7702 phishing range from a May 2025 incident of $146,551 to two August 2025 incidents totalling approximately $2.54 million, with a separate April 2026 protocol-level exploit removing 1,988.5 QNT (about 54.93 ETH) from a reserve pool through an access-control flaw in a delegated BatchExecutor contract.","timeline":[{"date":"2025-05-07","event":"Ethereum Pectra hard fork activates EIP-7702, enabling EOA-to-smart-contract delegation via transaction type 0x04.","source":"Coin Edition / multiple","source_url":"https://coinedition.com/ethereum-eip7702-scammers-exploit-wallet-drain/"},{"date":"2025-05-07","event":"Wintermute observes that within the first weeks post-Pectra, the first 11,000 EIP-7702 mainnet authorizations include a high proportion linked to sweeper bytecode.","source":"Zelcore security analysis","source_url":"https://zelcore.io/academy/security/eip-7702-delegation-phishing-risk"},{"date":"2025-05-23","event":"Scam Sniffer flags a $146,551 loss by a wallet upgraded to EIP-7702 through malicious batched transactions attributed to Inferno Drainer; SlowMist's Yu Xian confirms batch-authorization mechanics.","source":"Bitget / Scam Sniffer","source_url":"https://www.bitget.com/news/detail/12560604775453"},{"date":"2025-06-02","event":"Wintermute publicly discloses CrimeEnjoyor findings: over 97% of EIP-7702 delegations use near-identical sweeper bytecode; Wintermute injects on-chain warnings into verified malicious contracts. CoinDesk notes Wintermute's caveat that the sweepers are largely not profiting, as they target already-compromised wallets.","source":"CoinDesk / CoinTelegraph","source_url":"https://www.coindesk.com/tech/2025/06/02/post-pectra-upgrade-malicious-ethereum-contracts-are-trying-to-drain-wallets-but-to-no-avail-wintermute"},{"date":"2025-08-01","event":"Two EIP-7702 phishing incidents in August cause a combined approximately $2.54 million in losses: one victim loses $1.54 million through a fake Uniswap interface using malicious batch transactions; a second victim loses approximately $1 million in tokens and NFTs through the same attack pattern.","source":"Cryptopolitan / Scam Sniffer","source_url":"https://www.cryptopolitan.com/eip-7702-user-loses-1-54m-phishing-attack/"},{"date":"2026-04-29","event":"SlowMist reports a protocol-level EIP-7702 exploit draining 1,988.5 QNT (approximately 54.93 ETH) from a QNT reserve pool. Root cause: admin EOA delegated to BatchExecutor, which authorized a BatchCall contract with no access controls, enabling arbitrary calls to transfer pool funds.","source":"Crypto Times / SlowMist via Bitget","source_url":"https://www.cryptotimes.io/2026/04/29/eip-7702-flaw-drains-1988-qnt-from-ethereum-pool/"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision b78bd74e-6ddd-4244-b2f9-c04b7d5f3629
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.