Wintermute, a prominent crypto market maker, has launched "CrimeEnjoyor," a new tool designed to enhance security for Ethereum users. This innovative code injects warnings directly into malicious Ethereum contracts, specifically those exploiting the EIP-7702 feature to automatically drain wallets with compromised private keys, thereby safeguarding users from potential financial losses.
Key Takeaways
-
Enhanced Security: "CrimeEnjoyor" directly warns users about malicious contracts, preventing wallet drains.
-
EIP-7702 Exploitation: Malicious actors are exploiting EIP-7702 to create "sweeper" contracts.
-
Transparency: Wintermute's method of reversing bytecode and public verification increases transparency.
-
User Protection: The tool aims to protect users, especially new ones, from sophisticated exploits.
-
Pectra Upgrade Context: EIP-7702 is part of the broader Pectra upgrade, which also includes EIP-725 (increased validator staking limit) and EIP-7691 (increased data blobs per block for scalability).
Wintermute's "CrimeEnjoyor" Safeguards Ethereum Users
Wintermute has developed "CrimeEnjoyor," a crucial tool that embeds warnings within malicious Ethereum contracts. These contracts are designed to automatically sweep funds from wallets with leaked private keys. The warning, prominently displayed, states that the contract "is used by bad guys to automatically sweep all incoming ETH" and advises users to "NOT SEND ANY ETH."
Exploiting EIP-7702
The malicious contracts leverage Ethereum Improvement Proposal-7702 (EIP-7702), a feature introduced in Ethereum's Pectra upgrade. EIP-7702 allows users to temporarily delegate control of their wallets to smart contracts. Wintermute's research revealed that over 97% of EIP-7702 delegations were authorized to multiple contracts using identical code, identifying them as "sweepers" designed to drain incoming ETH from compromised addresses.
To ensure the "CrimeEnjoyor" warnings appear, Wintermute reversed the Ethereum Virtual Machine bytecode of these malicious contracts into human-readable Solidity code and publicly verified it. This action ensures transparency and alerts users to the inherent dangers.
The Importance of Transparency
While EIP-7702 is an opt-in feature and not essential for basic Ethereum operations, Wintermute emphasizes that its expanded capabilities necessitate robust verification tools. The lack of such tools makes it challenging to differentiate legitimate infrastructure from malicious exploits, particularly for new users. By tagging more compromised contracts, "CrimeEnjoyor" aims to surface more malicious activity and protect a greater number of users. An example of such an exploit occurred on May 23, when an Ethereum user lost $146,550 by signing malicious batched transactions utilizing EIP-7702.
Since the Pectra upgrade went live on May 7, a total of 12,329 EIP-7702 transactions have been recorded. The Pectra upgrade also introduced EIP-7251, which increased the validator staking limit from 32 ETH to 2,048 ETH, and EIP-7691, which boosts the number of data blobs per block to improve scalability on Ethereum layer 2s and reduce transaction fees.
Sources
-
Wintermute’s ‘CrimeEnjoyor’ to flag Ethereum’s wallet-draining contracts — TradingView News, TradingView.
-
Wintermute’s ‘CrimeEnjoyor’ to flag Ethereum’s wallet-draining contracts, Cointelegraph.
This article was created with support from AI-driven technology, drawing on multiple reputable sources. The final content has been thoroughly reviewed and edited by BlockzHub's editorial team to ensure accuracy, clarity, and coherence. Original reporting sources are credited whenever appropriate and as required. The opinions expressed in this article do not necessarily represent the official views or positions of BlockzHub. This article is intended for informational purposes only and should not be considered financial or professional advice. Investing involves risk, and you should consult a qualified financial advisor before making any investment decisions.
