Skip to main content
AVOID.NET
← avoid.net

Verify a decision

Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.

How verification works

  1. We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction.
  2. We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
  3. You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>

Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.

Sequence
#1
Score
→
Cluster
mainnet-beta
Slot
453403201
Off-chain at
2026-10-04T23:24:09.772Z
Anchored at
2026-10-04T23:24:20.826Z
Block time
—

Independent verification

1. Database (off-chain)
c5nm7KePKDjNMzjxAoHHERHEfDuWJADnctzRouV4hnR
2. Recomputed (your browser)
computing…
3. On-chain (Solana memo)
fetching…
Canonical bytes hashed (22879 chars)
{"actor":"system:backfill","investigation_id":"e86fd241-f210-4d38-abaa-4204e408e3de","kind":"publish","page_slug":"eip-7702-crimeenjoyor-drainer-cluster","published_at":"2026-10-04T23:24:09.691Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"EIP-7702 CrimeEnjoyor Drainer Cluster","sections":[{"content":"EIP-7702 was activated on May 7, 2025, as part of Ethereum's Pectra hard fork. The proposal introduces transaction type 0x04, which allows an externally owned account (EOA) to temporarily attach smart-contract bytecode by signing an authorization message. The authorization writes a 23-byte pointer (0xef0100 followed by a target address) into the EOA's code slot, granting the designated contract execution rights against that wallet for the duration of the delegation. Intended use cases include batched transactions, gas sponsorship, and spending limits. Authorizations signed with chain_id = 0 are valid on every EVM-compatible chain, creating cross-chain replay risk. MetaMask added support within days of the fork; Trust Wallet followed through Q3 2025; Coinbase Wallet and Ledger added support by late 2025, according to the Zelcore security analysis.","heading":"Background: EIP-7702 and the Pectra Upgrade","severity":"low","sources":[{"credibility":2,"name":"Zelcore: EIP-7702 Delegation Phishing Risk","type":"research","url":"https://zelcore.io/academy/security/eip-7702-delegation-phishing-risk"},{"credibility":2,"name":"Coin Edition: Ethereum EIP-7702 Scammers Exploit Wallet Drain","type":"news_article","url":"https://coinedition.com/ethereum-eip7702-scammers-exploit-wallet-drain/"}]},{"content":"Wintermute's research team reverse-engineered on-chain EIP-7702 delegation contracts post-Pectra and found that over 97% of all observed EIP-7702 delegations were authorized to contracts sharing nearly identical bytecode. Wintermute converted the bytecode to human-readable Solidity, publicly verified it, and named the dominant contract 'CrimeEnjoyor.' The contract is described by Wintermute as 'short, simple, and widely reused,' functioning as an automated sweeper that drains any incoming ETH from wallets whose private keys have been compromised. Wintermute subsequently injected on-chain warnings into the verified contracts stating the contract 'is used by bad guys to automatically sweep all incoming ETH' and advising users 'NOT SEND ANY ETH.' By the time of Wintermute's public disclosure, the CrimeEnjoyor share of delegations had slightly decreased to 94.7%, but it remained the dominant delegation bytecode. According to reporting citing Wintermute data, of approximately 1.58 million EIP-7702 delegations activated after the Pectra launch, approximately 768,275 (roughly 48%) were tagged as crime-related, with more than 97% of those malicious delegations pointing to the same sweeper bytecode. The attackers were reported to have spent at least 2.88 ETH to authorize these sweeper contracts. Wintermute also noted that, despite the volume of malicious delegations, the sweepers were primarily targeting wallets already compromised by leaked private keys rather than newly defrauding previously secure users through delegation alone.","heading":"The CrimeEnjoyor Sweeper Contracts","severity":"high","sources":[{"credibility":2,"name":"Wintermute on X: EIP-7702 delegation sweeper findings","type":"social_media","url":"https://x.com/wintermute_t/status/1928501765865091400"},{"credibility":2,"name":"CoinTelegraph: Wintermute CrimeEnjoyor flags Ethereum wallet-draining contracts","type":"news_article","url":"https://cointelegraph.com/news/wintermute-crimeenjoyor-flags-malicious-ethereum-contracts"},{"credibility":2,"name":"Analytics Insight: Ethereum Pectra Upgrade Exposes 97% of EIP-7702 Wallets to Auto-Drain Risk","type":"news_article","url":"https://www.analyticsinsight.net/news/ethereum-pectra-upgrade-exposes-97-of-eip-7702-wallets-to-auto-drain-risk"},{"credibility":1,"name":"CoinDesk: Ethereum CrimeEnjoyors Aren't Making Money, Wintermute Says","type":"news_article","url":"https://www.coindesk.com/tech/2025/06/02/post-pectra-upgrade-malicious-ethereum-contracts-are-trying-to-drain-wallets-but-to-no-avail-wintermute"},{"credibility":3,"name":"hoge.gg: Crypto Phishing Campaigns 2026 Drainer Economy","type":"research","url":"https://hoge.gg/crypto-phishing-campaigns-2026-drainer-economy/"}]},{"content":"EIP-7702-based phishing campaigns collapse the traditional multi-step approval process into a single signature. When a victim signs a malicious authorization, the attacker's contract is written into the EOA's code slot, granting the contract full execution rights over the wallet. Scam Sniffer and SlowMist documented three primary lure types: fake gas-sponsorship and token-claim interfaces requesting 7702 signatures; pages impersonating MetaMask's smart-account onboarding flow with a substituted delegator address; and malicious dApp connectors that silently substitute type-0x04 authorizations during an expected signing interaction. Because EIP-7702 authorization messages are not compatible with the existing EIP-191 or EIP-712 standards, they often appear in wallets as opaque 32-byte hashes, bypassing normal wallet warnings. Hardware wallets are exposed to the same phishing risk as software wallets because the risk lies in what the user signs, not in key storage. Inferno Drainer exploited a MetaMask delegator wallet already authorized under EIP-7702 to execute a batch of token approvals and transfers in a single silent background call, according to reporting by Bitget News citing SlowMist researcher Yu Xian.","heading":"Phishing Attack Mechanics","severity":"critical","sources":[{"credibility":2,"name":"Zelcore: EIP-7702 Delegation Phishing Risk","type":"research","url":"https://zelcore.io/academy/security/eip-7702-delegation-phishing-risk"},{"credibility":2,"name":"Bitget: Inferno Drainer Exploits Ethereum EIP-7702 in Evolving Phishing Tactics","type":"news_article","url":"https://www.bitget.com/news/detail/12560604776647"},{"credibility":2,"name":"DeFi Hack Labs: Top 7702 Delegator Revealed as Phishing Scam","type":"research","url":"https://defihacklabs.substack.com/p/top-7702-delegator-revealed-as-phishing"},{"credibility":2,"name":"Mitrade: New Ethereum feature exploited just weeks after launch in $146K phishing heist","type":"news_article","url":"https://www.mitrade.com/insights/news/live-news/article-3-842092-20250526"}]},{"content":"The following individual incidents have been documented by on-chain security firms with specific figures. On May 23-24, 2025, Scam Sniffer flagged the loss of $146,551 by a wallet that had been upgraded to EIP-7702 through a malicious batched transaction attributed to Inferno Drainer; SlowMist researcher Yu Xian confirmed the mechanics involved batch-authorization operations on tokens. In August 2025, Scam Sniffer and Cryptopolitan reported two related incidents totalling approximately $2.54 million: one investor lost $1.54 million after signing malicious EIP-7702 batch transactions through a fake DeFi interface mimicking Uniswap; approximately two days prior, a second investor lost approximately $1 million in tokens and NFTs through the same attack pattern, with stolen funds bridged to mainnet via Relay Protocol. On April 29, 2026, blockchain security firm SlowMist reported that an attacker exploited a misconfigured EIP-7702 delegation in a QNT reserve pool, stealing 1,988.5 QNT (approximately 54.93 ETH at the time). The root cause was that the pool's admin EOA had delegated to a BatchExecutor contract which in turn authorized a BatchCall contract without access-control checks, allowing unauthorized calls to drain QNT tokens. The $2.3 million figure cited in some summaries appears to represent an approximation of documented phishing losses through mid-2025; separately reported August 2025 incidents pushed confirmed losses to at least $2.54 million from phishing alone, not counting the April 2026 protocol exploit.","heading":"Confirmed Incidents and Losses","severity":"critical","sources":[{"credibility":2,"name":"Bitget: EIP-7702 address loses $146,551 in phishing attack","type":"news_article","url":"https://www.bitget.com/news/detail/12560604775453"},{"credibility":2,"name":"Cryptopolitan: Security analysts warn about EIP-7702 flaw after user loses $1.54M","type":"news_article","url":"https://www.cryptopolitan.com/eip-7702-user-loses-1-54m-phishing-attack/"},{"credibility":2,"name":"Crypto Times: EIP-7702 Flaw Drains 1,988 QNT From Ethereum Pool","type":"news_article","url":"https://www.cryptotimes.io/2026/04/29/eip-7702-flaw-drains-1988-qnt-from-ethereum-pool/"},{"credibility":2,"name":"Bitget: SlowMist EIP-7702 account vulnerability exploited, 1,988.5 QNT stolen","type":"news_article","url":"https://www.bitget.com/amp/news/detail/12560605389679"},{"credibility":2,"name":"PANewsLab: SlowMist malicious EIP-7702 transaction, approximately 54.93 ETH loss","type":"news_article","url":"https://www.panewslab.com/en/articles/019dd769-5b5c-766d-beb4-9bb2e860e44d"}]},{"content":"Multiple established drainer-kit operations shipped EIP-7702-flavored modules after the Pectra upgrade. Inferno Drainer, which had previously announced retirement in November 2023 but resurfaced after Pink Drainer shut down in May 2024, was directly linked to the May 2025 $146,551 incident by Scam Sniffer and SlowMist. Zelcore's security analysis states that Inferno Drainer, Pink Drainer, and the Angel Kit all shipped 7702-flavored modules through 2025 and 2026; this claim has not been independently verified through Tier 1 sources for Pink Drainer and Angel Kit specifically and should be treated as medium-confidence. Pink Drainer had previously stolen approximately $85 million from over 21,000 victims before its announced May 2024 shutdown. The drainer-kit model operates on a commission basis: kit operators take a percentage (typically 20-30%) of funds drained by affiliates using their infrastructure.","heading":"Drainer-as-a-Service Kit Adoption","severity":"high","sources":[{"credibility":2,"name":"Zelcore: EIP-7702 Delegation Phishing Risk","type":"research","url":"https://zelcore.io/academy/security/eip-7702-delegation-phishing-risk"},{"credibility":2,"name":"Bitget: Inferno Drainer Exploits Ethereum EIP-7702 in Evolving Phishing Tactics","type":"news_article","url":"https://www.bitget.com/news/detail/12560604776647"},{"credibility":2,"name":"PA News: Inferno Drainer uses EIP-7702, single $150,000 loss","type":"news_article","url":"https://panews.io/articles/kyyu829k"}]},{"content":"DeFi Hack Labs identified the malicious delegator contract at address 0x930fcc37d6042c79211ee18a02857cb1fd7f0d0b and the fraudulent ETH recipient address at 0x000085bad5b016e5448a530cb3d4840d2cfd15bc. The phishing contract ranked prominently on bundlebear.com, a delegation-tracking tool, giving it apparent legitimacy. GoPlus Security and MetaMask both issued warnings stating that EIP-7702 authorization should only occur within official wallet applications and that any email or URL claiming to 'enable' smart-account features represents a phishing vector. Wintermute's counter-measure of injecting warning text into verified malicious contracts is an informational signal, not a block; it does not prevent the contracts from draining funds if a user has already authorized a delegation.","heading":"On-Chain Detection and Identified Addresses","severity":"high","sources":[{"credibility":2,"name":"DeFi Hack Labs: Top 7702 Delegator Revealed as Phishing Scam","type":"on_chain","url":"https://defihacklabs.substack.com/p/top-7702-delegator-revealed-as-phishing"},{"credibility":2,"name":"GoPlus Security Medium: Understanding EIP-7702 Phishing Attacks","type":"research","url":"https://goplussecurity.medium.com/understanding-eip-7702-phishing-attacks-a-comprehensive-guide-to-protection-strategies-for-wallets-8e8372e3d5ea"},{"credibility":2,"name":"Analytics Insight: Ethereum Pectra Upgrade Exposes 97% of EIP-7702 Wallets to Auto-Drain Risk","type":"news_article","url":"https://www.analyticsinsight.net/news/ethereum-pectra-upgrade-exposes-97-of-eip-7702-wallets-to-auto-drain-risk"}]},{"content":"CoinDesk reported in June 2025, citing Wintermute, that despite the large volume of malicious EIP-7702 delegations, the 'CrimeEnjoyors' were reportedly not generating significant revenue at that time. Wintermute's position was that the sweeper contracts predominantly targeted wallets already known to be compromised via leaked private keys, and that most of those wallets were already empty or had minimal funds. This does not mean the campaign posed no threat to users, but it contextualizes the 97% malicious-delegation statistic: a high proportion of malicious delegations does not automatically translate into an equivalent proportion of wallet drainings of active users. Subsequent August 2025 incidents causing $2.54 million in losses, however, demonstrated that the attack pattern evolved beyond automated sweeping of already-compromised wallets to active phishing of previously secure users.","heading":"Wintermute Assessment: Profitability Caveat","severity":"medium","sources":[{"credibility":1,"name":"CoinDesk: Ethereum CrimeEnjoyors Aren't Making Money From Exploiting Pectra's EIP-7702, Wintermute Says","type":"news_article","url":"https://www.coindesk.com/tech/2025/06/02/post-pectra-upgrade-malicious-ethereum-contracts-are-trying-to-drain-wallets-but-to-no-avail-wintermute"},{"credibility":2,"name":"Bitcoin Ethereum News: Ethereum CrimeEnjoyors Aren't Making Money, Wintermute Says","type":"news_article","url":"https://bitcoinethereumnews.com/ethereum/ethereum-crimeenjoyors-arent-making-money-from-exploiting-pectras-eip-7702-wintermute-says/"}]},{"content":"Security researchers and wallet providers have issued consistent guidance. Users should only authorize EIP-7702 delegations through official wallet interfaces, never through links in emails, social media messages, or unsolicited DApp connections. Before signing any delegation, users should verify the delegator contract's source code is publicly available and audited. The chain_id = 0 replay risk means a delegation signed on one network may be valid on all EVM chains; users should confirm the chain_id in any authorization. Existing EIP-7702 delegations can be revoked by submitting a new type-0x04 transaction with an empty authorization, but this requires gas and awareness that an active malicious delegation exists. Hardware wallets do not mitigate this risk, as the vulnerability is in what the user approves, not in how the private key is stored.","heading":"User Protection and Risk Mitigation","severity":"medium","sources":[{"credibility":2,"name":"Zelcore: EIP-7702 Delegation Phishing Risk","type":"research","url":"https://zelcore.io/academy/security/eip-7702-delegation-phishing-risk"},{"credibility":2,"name":"DeFi Hack Labs: Top 7702 Delegator Revealed as Phishing Scam","type":"research","url":"https://defihacklabs.substack.com/p/top-7702-delegator-revealed-as-phishing"},{"credibility":2,"name":"The Coin Republic: How Hackers Are Exploiting EIP-7702 To Drain Wallets","type":"news_article","url":"https://www.thecoinrepublic.com/2025/05/25/ethereum-news-how-hackers-are-exploiting-eip-7702-to-drain-wallets/"}]}],"sources_used":[{"credibility":1,"name":"CoinDesk: Ethereum CrimeEnjoyors Aren't Making Money From Exploiting Pectra's EIP-7702, Wintermute Says","type":"news_article","url":"https://www.coindesk.com/tech/2025/06/02/post-pectra-upgrade-malicious-ethereum-contracts-are-trying-to-drain-wallets-but-to-no-avail-wintermute"},{"credibility":1,"name":"CoinTelegraph: Wintermute CrimeEnjoyor flags malicious Ethereum contracts","type":"news_article","url":"https://cointelegraph.com/news/wintermute-crimeenjoyor-flags-malicious-ethereum-contracts"},{"credibility":1,"name":"The Block: Wintermute warns Pectra upgrade leaves Ethereum users at risk of automated attacks","type":"news_article","url":"https://www.theblock.co/post/356481/wintermute-warns-pectra-upgrade-leaves-ethereum-users-at-risk-of-automated-attacks"},{"credibility":2,"name":"Wintermute on X: EIP-7702 delegation sweeper findings","type":"social_media","url":"https://x.com/wintermute_t/status/1928501765865091400"},{"credibility":2,"name":"Coin Edition: Ethereum EIP-7702 Scammers Exploit Wallet Drain","type":"news_article","url":"https://coinedition.com/ethereum-eip7702-scammers-exploit-wallet-drain/"},{"credibility":2,"name":"Analytics Insight: Ethereum Pectra Upgrade Exposes 97% of EIP-7702 Wallets to Auto-Drain Risk","type":"news_article","url":"https://www.analyticsinsight.net/news/ethereum-pectra-upgrade-exposes-97-of-eip-7702-wallets-to-auto-drain-risk"},{"credibility":2,"name":"Cryptonews.com.au: Ethereum EIP-7702 Upgrade Exploited by CrimeEnjoyor Wallet-Sweeping Scam","type":"news_article","url":"https://cryptonews.com.au/news/ethereums-eip-7702-upgrade-exploited-by-crimeenjoyor-wallet-sweeping-scam-129271/"},{"credibility":2,"name":"Zelcore: EIP-7702 Delegation Phishing Risk","type":"research","url":"https://zelcore.io/academy/security/eip-7702-delegation-phishing-risk"},{"credibility":2,"name":"DeFi Hack Labs: Top 7702 Delegator Revealed as Phishing Scam","type":"on_chain","url":"https://defihacklabs.substack.com/p/top-7702-delegator-revealed-as-phishing"},{"credibility":2,"name":"Bitget: EIP-7702 address loses $146,551 in phishing attack","type":"news_article","url":"https://www.bitget.com/news/detail/12560604775453"},{"credibility":2,"name":"Bitget: Inferno Drainer Exploits Ethereum EIP-7702 in Evolving Phishing Tactics","type":"news_article","url":"https://www.bitget.com/news/detail/12560604776647"},{"credibility":2,"name":"Cryptopolitan: Security analysts warn about EIP-7702 flaw after user loses $1.54M","type":"news_article","url":"https://www.cryptopolitan.com/eip-7702-user-loses-1-54m-phishing-attack/"},{"credibility":2,"name":"Crypto Times: EIP-7702 Flaw Drains 1,988 QNT From Ethereum Pool","type":"news_article","url":"https://www.cryptotimes.io/2026/04/29/eip-7702-flaw-drains-1988-qnt-from-ethereum-pool/"},{"credibility":2,"name":"Bitget: SlowMist EIP-7702 account vulnerability exploited, 1,988.5 QNT stolen","type":"news_article","url":"https://www.bitget.com/amp/news/detail/12560605389679"},{"credibility":2,"name":"PANewsLab: SlowMist malicious EIP-7702 transaction, approximately 54.93 ETH loss","type":"news_article","url":"https://www.panewslab.com/en/articles/019dd769-5b5c-766d-beb4-9bb2e860e44d"},{"credibility":2,"name":"PA News: Inferno Drainer uses EIP-7702, single $150,000 loss","type":"news_article","url":"https://panews.io/articles/kyyu829k"},{"credibility":2,"name":"Mitrade: New Ethereum feature exploited just weeks after launch in $146K phishing heist","type":"news_article","url":"https://www.mitrade.com/insights/news/live-news/article-3-842092-20250526"},{"credibility":2,"name":"The Coin Republic: Ethereum News: How Hackers Are Exploiting EIP-7702 To Drain Wallets","type":"news_article","url":"https://www.thecoinrepublic.com/2025/05/25/ethereum-news-how-hackers-are-exploiting-eip-7702-to-drain-wallets/"},{"credibility":3,"name":"hoge.gg: Crypto Phishing Campaigns 2026 Drainer Economy","type":"research","url":"https://hoge.gg/crypto-phishing-campaigns-2026-drainer-economy/"},{"credibility":2,"name":"Bitcoin Ethereum News: Ethereum CrimeEnjoyors Aren't Making Money, Wintermute Says","type":"news_article","url":"https://bitcoinethereumnews.com/ethereum/ethereum-crimeenjoyors-arent-making-money-from-exploiting-pectras-eip-7702-wintermute-says/"}],"summary":"Following Ethereum's Pectra hard fork (May 7, 2025), which activated EIP-7702 account-delegation functionality, a coordinated drainer campaign emerged that security researchers at Wintermute labeled 'CrimeEnjoyor.' Wintermute found that over 97% of all EIP-7702 delegations on-chain used near-identical sweeper bytecode designed to automatically drain ETH from compromised addresses, and one analysis citing Wintermute data placed the share of crime-tagged delegations at roughly 48% of total activations. Documented losses linked to EIP-7702 phishing range from a May 2025 incident of $146,551 to two August 2025 incidents totalling approximately $2.54 million, with a separate April 2026 protocol-level exploit removing 1,988.5 QNT (about 54.93 ETH) from a reserve pool through an access-control flaw in a delegated BatchExecutor contract.","timeline":[{"date":"2025-05-07","event":"Ethereum Pectra hard fork activates EIP-7702, enabling EOA-to-smart-contract delegation via transaction type 0x04.","source":"Coin Edition / multiple","source_url":"https://coinedition.com/ethereum-eip7702-scammers-exploit-wallet-drain/"},{"date":"2025-05-07","event":"Wintermute observes that within the first weeks post-Pectra, the first 11,000 EIP-7702 mainnet authorizations include a high proportion linked to sweeper bytecode.","source":"Zelcore security analysis","source_url":"https://zelcore.io/academy/security/eip-7702-delegation-phishing-risk"},{"date":"2025-05-23","event":"Scam Sniffer flags a $146,551 loss by a wallet upgraded to EIP-7702 through malicious batched transactions attributed to Inferno Drainer; SlowMist's Yu Xian confirms batch-authorization mechanics.","source":"Bitget / Scam Sniffer","source_url":"https://www.bitget.com/news/detail/12560604775453"},{"date":"2025-06-02","event":"Wintermute publicly discloses CrimeEnjoyor findings: over 97% of EIP-7702 delegations use near-identical sweeper bytecode; Wintermute injects on-chain warnings into verified malicious contracts. CoinDesk notes Wintermute's caveat that the sweepers are largely not profiting, as they target already-compromised wallets.","source":"CoinDesk / CoinTelegraph","source_url":"https://www.coindesk.com/tech/2025/06/02/post-pectra-upgrade-malicious-ethereum-contracts-are-trying-to-drain-wallets-but-to-no-avail-wintermute"},{"date":"2025-08-01","event":"Two EIP-7702 phishing incidents in August cause a combined approximately $2.54 million in losses: one victim loses $1.54 million through a fake Uniswap interface using malicious batch transactions; a second victim loses approximately $1 million in tokens and NFTs through the same attack pattern.","source":"Cryptopolitan / Scam Sniffer","source_url":"https://www.cryptopolitan.com/eip-7702-user-loses-1-54m-phishing-attack/"},{"date":"2026-04-29","event":"SlowMist reports a protocol-level EIP-7702 exploit draining 1,988.5 QNT (approximately 54.93 ETH) from a QNT reserve pool. Root cause: admin EOA delegated to BatchExecutor, which authorized a BatchCall contract with no access controls, enabling arbitrary calls to transfer pool funds.","source":"Crypto Times / SlowMist via Bitget","source_url":"https://www.cryptotimes.io/2026/04/29/eip-7702-flaw-drains-1988-qnt-from-ethereum-pool/"}]},"v":1}