Careful when signing messages in Ethereum Pectra
By: bitcoin ethereum news|2025/05/08 03:30:02
0
Share
The Ethereum blockchain forked today for its Pectra code change and introduced a suite of new features, upgrades, and vulnerabilities. However, within an hour of the changeover, concerned users were warning about a new threat vector: message signing. “Be careful what you sign... It is enough to drain all tokens,” posted one user to Telegram. Another Ethereum user echoed the warning, saying, “You only have to sign a message to get completely drained!” Many other warnings flagged similar risks . Ethereum’s Pectra upgrade included Ethereum Improvement Proposal (EIP) 3074, which has introduced new AUTH and AUTHCALL Ethereum operation codes. These opcodes allow the holder of an Ethereum private key to delegate authorization to a smart contract. Developers called it an important step in achieving account abstraction. However, critics say it has introduced new phishing attacks that allow theft of all assets in a user’s wallet once they delegate control of their keys. pectra pros: >approve spend then swap is dead pectra cons: >signing messages just got a whole lot spicier — sloth (@0xSloth) May 7, 2025 Careful signing Ethereum transactions and messages EIP-3074’s co-authors tried to calm fears with a post published on Binance claiming to be “unaware” of any wallet that allowed signing of improperly prefixed messages without a user warning. Transactions use the prefix 0x04, and the authors of the EIP hope that all major Ethereum wallets will flag 0x04 messages with prominent warnings to inform the user about their expansive power to authorize multiple withdrawals, including possible theft. “The caller field in the EIP-3074 signature is very important,” they wrote solemnly. “A bad caller could steal your funds.” Read more: Seneca Protocol hack highlights dangers of Ethereum’s token approval mechanism Today’s Pectra fork also added EIP-7702, raising the stakes even higher. With the power of EIP-7702, a single malicious signature can temporarily delegate someone’s entire account to a third-party smart contract . If that contract is malicious, it could potentially drain all assets (ETH, tokens, NFTs) in one go. As opposed to pre-Pectra Ethereum transactions, the possible attack surface for victims is broader with EIP-7702 because externally owned accounts (EOAs) are now exposed to third-party temporary smart contract vulnerabilities. This temporary delegation of executable code was not a concern before Pectra. Although warnings are proliferating across social media, there are no reports yet of a successful theft of funds using the new Pectra-enabled attack vector. Most wallet providers like MetaMask were prepared for Pectra and added prominent warnings for EIP-3074 message signings. Got a tip? Send us an email securely via Protos Leaks . For more informed news, follow us on X , Bluesky , and Google News , or subscribe to our YouTube channel. Source: https://protos.com/careful-when-signing-messages-in-ethereum-pectra/
You may also like

RootData: February 2026 Cryptocurrency Exchange Transparency Research Report
This month's cumulative spot trading volume on cryptocurrency exchanges has decreased slightly by 4.7% compared to January, which is the result of multiple factors including market conditions, the macro environment, and the Spring Festival holiday in Chinese-speaking regions.

「One and Done SEA」, so OpenSea chooses to wait a little longer
It's already Q1 2026, and we're still waiting for OpenSea to launch its token.

Ray Dalio: The Resolution of the US-Iran Conflict Is In the Strait of Hormuz
In war, the ability to endure pain is often more important than the ability to inflict pain.

In just 70 days, Polymarket easily raked in tens of millions in fees
The money printer is running, and the future ceiling only depends on two main variables.

Matrixdock is launching the Silver Token XAGm, built on the FRS standard as an on-chain silver-backed asset.
In the future, Matrixdock will continue to expand to include more high-quality real-world assets, driving the development of a more transparent and robust on-chain reserve asset system.

a16z: The Hardest Enterprise Software, and the Greatest Opportunity in AI
The world will continue to run on SAP, but AI will reshape it

Polymarket Market-Making Bible: Pricing Spread Formula
This article presents a comprehensive market-making pricing framework that will elevate you from "guesstimate pricing spread" to "formula-based pricing spread."

Ray Dalio: If the United States loses Hormuz, it will lose more than just a war
In war, who can endure pain better is often more important than who can inflict pain better.
How to Earn Up to 40% Rebates on Crypto Futures Trading (WEEX Trade to Earn IV Guide)
WEEX Trade to Earn IV lets traders earn up to 40% fee rebates in real time through a tiered miner system tied to trading activity. With additional boosts from referrals, it offers a more reliable alternative to airdrops as the crypto market gains momentum.

NVIDIA Plays Trillion-Dollar Chess Game | Rewire News Morning Edition
DGX Station, a desktop workstation capable of running trillion-parameter models

Real-time Update | NVIDIA GTC 2026 Conference Highlights Galore
The most anticipated annual event in the AI field, NVIDIA's GTC 2026 Conference, kicked off today in San Jose, California, USA.

People Behind Pokémon Go: Started with CIA's Money, Now Mapping the World for the Military AI
The security of data depends on whose hands it ends up in.

Huang Renxun GTC Speech Full Text: By 2027, Market Demand Will Exceed $1 Trillion; Everyone Should Develop an OpenClaw Strategy
The underlying business logic driving future growth will be the "Tokenomics of a Platform Factory."

Stratechery Debunks the AI Bubble Myth: What Should We Do with AI?
LLM Third Normal Form Jump drives the Agent from Tool to Execution System, current AI investment is closer to demand-driven rather than hype

Three Charts to Watch at NVIDIA's GTC: Cheaper Compute, Spend More
Mining Cost Down 94%, Capex Up 170%

BTC Eight Green Candles Reach $76K, What Is the Logic Behind Outperforming Gold in the Midst of Battle?
War Cooling Off, Oil Pullback, Stock Market Rebound: Where Is Bitcoin Headed This Time?

Morning Report | Strategy invested $1.57 billion last week to increase its holdings by 22,337 bitcoins; Abra plans to go public through a SPAC merger; Metaplanet aims to raise approximately $765 million to increase its bitcoin holdings
Overview of Important Market Events on March 16

CB Insights: Nine Predictions for the Fintech Sector in 2026, with Asset Tokenization Already Becoming a Trend
AI agents initiate autonomous trading, crypto giants directly challenge traditional banks: an article revealing 9 disruptive predictions that will reshape the financial landscape in 2026.
RootData: February 2026 Cryptocurrency Exchange Transparency Research Report
This month's cumulative spot trading volume on cryptocurrency exchanges has decreased slightly by 4.7% compared to January, which is the result of multiple factors including market conditions, the macro environment, and the Spring Festival holiday in Chinese-speaking regions.
「One and Done SEA」, so OpenSea chooses to wait a little longer
It's already Q1 2026, and we're still waiting for OpenSea to launch its token.
Ray Dalio: The Resolution of the US-Iran Conflict Is In the Strait of Hormuz
In war, the ability to endure pain is often more important than the ability to inflict pain.
In just 70 days, Polymarket easily raked in tens of millions in fees
The money printer is running, and the future ceiling only depends on two main variables.
Matrixdock is launching the Silver Token XAGm, built on the FRS standard as an on-chain silver-backed asset.
In the future, Matrixdock will continue to expand to include more high-quality real-world assets, driving the development of a more transparent and robust on-chain reserve asset system.
a16z: The Hardest Enterprise Software, and the Greatest Opportunity in AI
The world will continue to run on SAP, but AI will reshape it