Pectra lets hackers drain wallets with just an offchain signature
Pectra lets hackers drain wallets with just an offchain signature by timdaub.eth12379 ๐ฅ โข 1y โข 0 views โข 0 clicks | |
AI summary of the linked articleSecurity researchers Rudytsia and Usman warn that Ethereum's Pectra upgrade opened a new attack vector that lets hackers drain user wallets using only an offchain signature. Rudytsia says hardware wallets are now at the same risk as hot wallets for signing malicious messages, and that if a malicious signature is completed, "all the funds are gone in a moment." Usman says EIP-7702 delegation messages may appear as 32-byte hashes that bypass normal wallet warnings, and that EIP-7702 signatures with chain_id = 0 can be replayed on any Ethereum-compatible chain. | |
Recommended by 2 curators | |
hardware wallets from now on are at the same risk as hot wallets from the perspective of signing malicious messages. Mmmm okay. Who the fuck designed this kind of change? How making millions of users more vulnerable to losing all their money is the UX improvement? I understand the push for EIP-7702, as some benefits are clear, but can we just stop executing like a hackathon project, and start acting like a $200B network? And I'm not saying that Eth core devs are to blame, maybe it's on the wallets to be ready with protections, idk. But can you imagine your bank shipping an UX improvement and saying "Ah btw if you click the wrong button you can lose all your money, hope you won't click it!" | |
Characters remaining: 10,000 comment guidelines | |
More from cointelegraph.com on Kiwi News
| |
