Holders of the World Liberty Financial (WLFI) governance token are currently falling victim to a sophisticated phishing exploit that leverages Ethereum's EIP-7702 upgrade. This vulnerability allows malicious actors to pre-plant compromised addresses in victim wallets, enabling them to quickly seize newly deposited tokens, including WLFI.
Key Takeaways
-
Hackers are exploiting Ethereum's EIP-7702 upgrade, introduced with the Pectra upgrade, to steal WLFI tokens.
-
The exploit involves pre-planting a hacker-controlled address in victim wallets, often after private key leakage through phishing.
-
Victims report losing significant amounts of WLFI, with some struggling to transfer remaining tokens due to the risk of immediate theft.
The EIP-7702 Exploit Explained
Ethereum's EIP-7702, designed to streamline user experience by allowing external accounts to temporarily act as smart contract wallets for batch transactions, has an exploitable flaw. Security experts, including SlowMist founder Yu Xian, have identified that hackers are using this upgrade to their advantage. The process typically begins with the leakage of a victim's private key, often through phishing attempts. Once the private key is compromised, the attacker can pre-plant a malicious delegate smart contract into the victim's wallet. When the victim deposits tokens, such as WLFI, into this compromised wallet, the hacker's contract can automatically transfer the assets away, often before the user can react.
WLFI Token Holders Under Attack
The World Liberty Financial (WLFI) token, which recently began trading, has become a target for these attacks. Reports indicate that users who participated in the WLFI presale, which required using the same wallet that joined the whitelist, are particularly vulnerable. Some users have described a frantic race against hackers to move their WLFI tokens to secure wallets, even finding that the gas fees for transactions could be instantly stolen. Many are left with a significant portion of their WLFI trapped in compromised wallets, fearing immediate loss once any remaining tokens are accessible.
Broader Scam Landscape and Warnings
Beyond the EIP-7702 exploit, the WLFI launch has also seen numerous other scam attempts, including fake smart contracts designed to mimic legitimate projects. The WLFI team has issued warnings, emphasizing that they do not contact users via direct messages on any platform and that official support is only available through designated email channels. They urge users to be vigilant against fraudulent communications claiming to be from the WLFI team.
Sources
-
WLFI Holders Targeted as Hackers Use Ethereum’s EIP-7702 Exploit, Cointelegraph.
This article was created with support from AI-driven technology, drawing on multiple reputable sources. The final content has been thoroughly reviewed and edited by BlockzHub's editorial team to ensure accuracy, clarity, and coherence. Original reporting sources are credited whenever appropriate and as required. The opinions expressed in this article do not necessarily represent the official views or positions of BlockzHub. This article is intended for informational purposes only and should not be considered financial or professional advice. Investing involves risk, and you should consult a qualified financial advisor before making any investment decisions.