# Pectra lets hackers drain wallets with just an offchain signature Source: https://cointelegraph.com/news/pectra-wallet-exploit-offchain-signature-risk ## Summary Security researchers Rudytsia and Usman warn that Ethereum's Pectra upgrade opened a new attack vector that lets hackers drain user wallets using only an offchain signature. Rudytsia says hardware wallets are now at the same risk as hot wallets for signing malicious messages, and that if a malicious signature is completed, "all the funds are gone in a moment." Usman says EIP-7702 delegation messages may appear as 32-byte hashes that bypass normal wallet warnings, and that EIP-7702 signatures with chain_id = 0 can be replayed on any Ethereum-compatible chain. ## Article Ethereum’s latest network upgrade, Pectra, introduced powerful new features aimed at improving scalability and smart account functionality — but it also opened a dangerous new attack vector that could allow hackers to drain funds from user wallets using only an offchain signature. Under the Pectra upgrade, which Hardware wallets are no longer inherently safer, Rudytsia said. He added that hardware wallets from now on are at the same risk as hot wallets from the perspective of signing malicious messages. “If done, all the funds are gone in a moment.” There are ways to stay safe, but they require awareness. “Users should not sign the messages they do not understand,” Rudytsia advised. He also urged wallet developers to provide clear warnings when users are asked to sign a delegation message. Special caution should be taken with new delegation signature formats introduced by EIP-7702, which are not compatible with existing EIP-191 or EIP-712 standards. These messages often appear as simple 32-byte hashes and may bypass normal wallet warnings. “If a message includes your account nonce, it’s probably affecting your account directly,” Usman warned. “Normal sign-in messages or offchain commitments don’t usually involve your nonce.” Adding to the risk, EIP-7702 allows for signatures with chain_id = 0, meaning the signed message can be replayed on any Ethereum-compatible chain. “Understand it can be used anywhere,” Usman said. While multisignature wallets remain more secure under this upgrade, thanks to their requirement for multiple signers, single-key wallets — hardware or otherwise — must adopt new signature parsing and red-flagging tools to prevent potential exploitation. Alongside EIP-7702, Pectra also included EIP-7251, which raised Ethereum’s validator staking limit from 32 to 2,048 ETH, and EIP-7691, which increases the number of data blobs per block for better layer-2 scalability. ## Comments **mishaderidder.eth**: Ok great, well from now on only multi-sig safes for high value assets 😥 **macbudkowski.eth**: > hardware wallets from now on are at the same risk as hot wallets from the perspective of signing malicious messages. Mmmm okay. Who the fuck designed this kind of change? How making millions of users more vulnerable to losing all their money is the UX improvement? I understand the push for EIP-7702, as some benefits are clear, but can we just stop executing like a hackathon project, and start acting like a $200B network? **macbudkowski.eth**: And I'm not saying that Eth core devs are to blame, maybe it's on the wallets to be ready with protections, idk. But can you imagine your bank shipping an UX improvement and saying "Ah btw if you click the wrong button you can lose all your money, hope you won't click it!"