|

Trump’s Crypto Project WLFI Under Attack as Ethereum Upgrade Backfires – What Went Wrong?

😶‍🌫️

Hackers are systematically exploiting Ethereum’s EIP-7702 upgrade to steal World Liberty Financial tokens from Donald Trump’s crypto project, in accordance with SlowMist safety researchers.

The assaults leverage a vulnerability within the May Pectra improve that enables externally owned accounts to delegate management to sensible contracts, enabling attackers to plant malicious code that immediately drains all incoming ETH and tokens.

World Liberty Financial Becomes Latest Victim of Ethereum Exploit

According to SlowMist, a number of WLFI token holders have misplaced their belongings after hackers mixed non-public key theft with malicious delegate contract deployment.

The exploit approach has matured quickly since Ethereum’s Pectra upgrade launched May 7, with over 97% of EIP-7702 delegations linked to an identical wallet-draining contracts designed to routinely sweep funds.

Security agency SlowMist warned that victims whose non-public keys are compromised face full asset loss by pre-planted malicious delegates.

When customers switch ETH for fuel or obtain tokens like WLFI, the malicious contracts instantly redirect all funds to attacker-controlled addresses, leaving wallets completely compromised.

The vulnerability stems from EIP-7702’s design, which permits EOAs to borrow execution logic from designated sensible contracts quickly.

Trump's Crypto Project Under Attack as Ethereum Upgrade Backfires – What Went Wrong?
Source: Blockchain Academy

Attackers exploit this vulnerability by putting in delegate contracts that use the DELEGATECALL perform to execute malicious code throughout the sufferer’s pockets context, thereby gaining full management over the storage and funds.

Ethereum’s Account Abstraction Dream Becomes Security Nightmare

EIP-7702 was designed to reinforce Ethereum’s consumer expertise by enabling wallets to execute sensible contracts with out completely turning into contract-based addresses.

The improve aimed to scale back fuel charges by bundled transactions and permit settlement utilizing cryptocurrencies apart from ETH, supporting Vitalik Buterin’s vision of seamless Web3 adoption.

However, the implementation created vital safety dangers when mixed with non-public key compromise.

Hackers pre-install malicious delegate addresses that achieve full pockets management by DELEGATECALL operations, successfully turning sufferer wallets into attacker-controlled sensible contracts whereas sustaining the unique handle.

Notable incidents embody a $1.54 million phishing attack in August, the place victims signed disguised batch transactions, and Inferno Drainer’s $146,000 MetaMask wallet drain by malicious delegation authorization.

The phishing group netted over $9 million throughout chains in 2025 by convincing customers to authorize attacker-controlled delegate contracts.

Earlier in June, Wintermute’s analysis revealed that automated sweeper contracts account for the overwhelming majority of EIP-7702 delegations, creating a scientific menace to Ethereum customers.

The market maker developed CrimeEnjoyor, a software that injects warnings into verified malicious contracts stating they’re “utilized by dangerous guys to routinely sweep all incoming ETH.”

Multiple Attack Vectors Emerge From Flawed Upgrade Implementation

Beyond World Liberty Financial token theft, EIP-7702 exploitation has enabled numerous assault strategies focusing on completely different vulnerability factors.

Phishing campaigns impersonate trusted DeFi platforms to trick customers into signing harmful batch transactions and delegate approvals, resulting in quick fund drainage upon authorization.

Particularly, off-chain signature attacks pose one other vital menace with this vulnerability, as it allows hackers to remotely set up malicious code in wallets utilizing signed messages somewhat than on-chain transactions.

This technique bypasses conventional safety measures and operates stealthily, requiring solely a compromised signature to grant whole pockets management.

Similarly, flash loan and reentrancy exploits leverage EIP-7702 options to bypass on-chain safety logic, enabling worth manipulation assaults towards DeFi protocols.

Recent contract assaults prompted losses approaching a million {dollars} in established DeFi initiatives by compromised delegated authorizations.

The technical root trigger lies in EIP-7702’s delegation mechanism mixed with DELEGATECALL operations that execute within the sufferer’s pockets context.

When non-public keys are compromised by phishing or different means, attackers can set malicious delegate contracts that routinely steal any incoming worth.

Security consultants advocate avoiding suspicious delegation requests, verifying all transaction permissions, and canceling compromised delegate contracts when attainable.

However, the basic design that enables EOAs to delegate execution creates an assault floor that criminals proceed to take advantage of as the approach matures.

Notably, the improve elevated validator staking limits from 32 ETH to 2,048 ETH whereas introducing auto-compounding options designed to draw conservative institutional capital.

While the improve aimed to enhance consumer expertise and scale back prices, the safety trade-offs have overshadowed these advantages as customers face wallet-draining threats. The safety vulnerabilities have created new assault vectors that criminals quickly weaponized.

The publish Trump’s Crypto Project WLFI Under Attack as Ethereum Upgrade Backfires – What Went Wrong? appeared first on Cryptonews.

Similar Posts

  • Cathie Wood Loads Up $93M More in Crypto Stocks — Circle, Coinbase, Block and Bullish

    Cathie Wood’s ARK Invest pushed deeper into the crypto sector this week, including one other wave of purchases throughout a number of beaten-down digital-asset-linked shares because the broader market continued to slip. The funding agency spent greater than $93 million on Tuesday alone, extending a month-long sample of shopping for into weak spot as crypto…

  • Trump Fights Court Order Protecting Fed Governor Cook’s Seat Ahead of Rate Cut Decision

    President Trump is difficult a federal court docket injunction that stops him from eradicating Federal Reserve (Fed) Governor Lisa Cook, submitting appeals arguing his “for trigger” elimination energy extends past misconduct dedicated whereas in workplace. The authorized battle intensifies as economists count on a 25 basis-point price minimize on September 17, with Trump demanding aggressive…

  • Elon Musk再點燃狗狗幣話題 市場資金轉向下個爆炸性百倍迷因幣Bitcoin Hyper

    埃隆·馬斯克Elon Musk的一句「是時候了」再度攪動迷因幣世界,也使沈寂數週的狗狗幣敘事重返社群焦點。與2021年火熱行情相比,當前的市場環境更偏向保守,宏觀壓力、清算連鎖與流動性不足,使得馬斯克效應不再能單獨推動整體市場反轉。 但正因如此,資金的移動方向變得格外值得觀察:一邊是馬斯克帶起的迷因情緒,另一邊是Bitcoin Hyper這類功能型Layer2項目快速吸納巨量資金,形成鮮明對比,也揭示出資金偏好的變化。 馬斯克訊號引發迷因幣追逐,DOGE–1成短線焦點 本周馬斯克在X上留下簡短訊息,使整個狗狗幣社群瞬間活躍起來。雖然Dogecoin本身並未如預期般強勢反彈,價格一度落至0.16美元附近,但模因板塊內部的輪動卻異常激烈。特別是與SpaceX計畫同名的DOGE-1代幣,受到投機者追捧,短時間飆升約三倍,甚至吸引到重量級鏈上交易者的參與。 其中最受矚目的,是god.sol這位以高速輪動著稱的模因交易員,花費百枚SOL購得1627萬枚DOGE-1。他的過往交易記錄累積超過兩百八十萬美元利潤,任何動作都會被視為短線情緒的指標。雖然DOGE-1隨後因獲利回吐而回落,但這種急漲急跌的節奏呈現出迷因資產特有的投機定律,也反映市場在疲弱環境下更依賴瞬間情緒,而非長線資金。 同時,DOGE-1背後的真實衛星任務尚在排程之中,預計於2025年底發射,這也讓部分交易者押注未來可能出現新的消息催化。隨著宏觀環境持續波動,迷因生態仍維持活力,只是參與者普遍採取短線策略,速度優先於耐心。 市場在波動中尋找更可靠敘事 比特幣十一月初的急跌,使市場進一步走向避險結構。美聯儲偏鷹的語氣、全球經濟不明朗、清算高潮帶來的恐慌情緒,使交易者對高風險資產更加謹慎。即使馬斯克重新提起狗狗幣,也未能像前幾年那般直接引發全面式狂潮。迷因幣的升勢迅速被獲利盤壓制,反映出當前資金對流動性與退出速度的高敏感度。 在此背景下,市場開始出現另一條清晰軌跡:具備技術基礎、敘事完整且進度可追蹤的項目更容易成為資金目的地。這正是Bitcoin Hyper崛起的核心原因。當迷因敘事提供的是情緒刺激,Layer2的功能性則提供可衡量的未來價值,兩者在此刻形成鮮明對照。 Bitcoin Hyper吸金超過2600萬美元,Layer2革命成新主軸 Bitcoin Hyper在預售階段迅速累計超過2,600萬美元資金,連續多日保持大額買單,最引人矚目的,是日前一筆來自單一地址的鯨魚級大額交易,單筆金額高達31萬美元,刷新該項目預售以來的單日個人買入紀錄,而於10月6日也錄得一筆巨鯨購入超過26萬美元,引發廣泛關注。 這種級別的買盤往往象徵市場對項目方向的強烈認同,也代表比特幣Layer2敘事正在成為本輪市場的新焦點。 Bitcoin Hyper的核心,是讓比特幣真正具備可編程能力。項目架構基於Solana虛擬機,使BTC能以低延遲方式參與DeFi、遊戲、NFT與高頻支付。非託管橋接的設計讓資產能自由進出,不需犧牲原鏈安全性。這種能力突破了比特幣一直以來只能作為儲值工具的限制,也讓BTC邁向更大的應用場景。 HYPER代幣的價格每三日自動調整,使預售階段形成自然的進場節奏。質押回報率接近44%,交易費、治理與所有Layer2活動均使用HYPER,使代幣本身成為整個網路的核心動力。在2025年第四季主網上線後,完整的應用層將逐步曝光,市場預期這將會是比特幣生態中罕見的功能性躍升。 對許多長線投資者而言,Bitcoin Hyper的吸引力不只在於預售增長空間,更來自其解決了比特幣十五年來最具爭議的瓶頸:速度、可編程性與跨應用能力。 官網購買Bitcoin Hyper 結論:迷因與Layer2雙軸並行,新敘事正在形成 馬斯克重新點燃迷因熱度,使狗狗幣與DOGE-1短線活絡,但宏觀壓力讓投資者更謹慎,迷因行情呈現快速往返的結構。相較之下,Bitcoin Hyper代表的是另一類市場需求:在波動之下找到具備技術深度、結構清晰、增長空間實際可量化的項目。 一邊是情緒流動,一邊是功能革新;一邊追求短線爆發,一邊構築中期價值。當兩條敘事同時進行,2025年的市場將可能迎來截然不同的投資節奏。而Bitcoin Hyper在此格局下,已成為最受關注的比特幣Layer2新核心,並有機會在山寨幣季真正開啟時佔據關鍵位置。

  • Andrew Tate Gets Liquidated for $67K on WLFI, Immediately Bets Again With a Long Position

    Andrew Tate misplaced $67,500 on a leveraged WLFI place on Tuesday, then instantly opened one other lengthy guess on Trump’s crypto token. The controversial influencer’s liquidation on Hyperliquid extends his buying and selling losses to just about $700,000 throughout 80 trades with simply a 36% win charge. Tate reopened his WLFI place inside minutes of…

  • Consensys Taps Aave to Launch Stablecoin Yield in MetaMask Wallets

    Consensys, the Ethereum-focused software firm, has partnered with Aave to integrate a new feature into MetaMask wallets, allowing users to earn yield on stablecoins like USDC, USDT, and DAI. In a press release shared with CryptoNews, the firm said the new feature called “Stablecoin Earn” will be powered by Aave’s lending protocol and will give…

  • SEC Opens Door for More Crypto ETFs—But There’s a Catch

    The US Securities and Exchange Commission (SEC) is inching closer to broader crypto ETF approvals, thanks to new listing standards centered on derivatives markets. This comes only days after the securities regulator approved in-kind ETF redemptions, allowing investors to swap tokens directly with issuers. Crypto ETFs Get Derivatives-Driven Framework Under New SEC Standards According to…