Careful when signing messages in Ethereum Pectra
By: protos|2025/05/08 03:00:04
0
Share
The Ethereum blockchain forked today for its Pectra code change and introduced a suite of new features, upgrades, and vulnerabilities.However, within an hour of the changeover, concerned users were warning about a new threat vector: message signing.“Be careful what you sign... It is enough to drain all tokens,” posted one user to Telegram. Another Ethereum user echoed the warning, saying, “You only have to sign a message to get completely drained!”Many other warnings flagged similar risks.Ethereum’s Pectra upgrade included Ethereum Improvement Proposal (EIP) 3074, which has introduced new AUTH and AUTHCALL Ethereum operation codes. These opcodes allow the holder of an Ethereum private key to delegate authorization to a smart contract.Developers called it an important step in achieving account abstraction. However, critics say it has introduced new phishing attacks that allow theft of all assets in a user’s wallet once they delegate control of their keys.pectra pros:>approve spend then swap is deadpectra cons:>signing messages just got a whole lot spicier— sloth (@0xSloth) May 7, 2025Signing Ethereum messages just got a whole lot spicier.Careful signing Ethereum transactions and messagesEIP-3074’s co-authors tried to calm fears with a post published on Binance claiming to be “unaware” of any wallet that allowed signing of improperly prefixed messages without a user warning.Transactions use the prefix 0x04, and the authors of the EIP hope that all major Ethereum wallets will flag 0x04 messages with prominent warnings to inform the user about their expansive power to authorize multiple withdrawals, including possible theft. “The caller field in the EIP-3074 signature is very important,” they wrote solemnly. “A bad caller could steal your funds.”Why ether underperformed bitcoin in 2024Read more: Seneca Protocol hack highlights dangers of Ethereum’s token approval mechanismToday’s Pectra fork also added EIP-7702, raising the stakes even higher. With the power of EIP-7702, a single malicious signature can temporarily delegate someone’s entire account to a third-party smart contract.If that contract is malicious, it could potentially drain all assets (ETH, tokens, NFTs) in one go. As opposed to pre-Pectra Ethereum transactions, the possible attack surface for victims is broader with EIP-7702 because externally owned accounts (EOAs) are now exposed to third-party temporary smart contract vulnerabilities.This temporary delegation of executable code was not a concern before Pectra.Although warnings are proliferating across social media, there are no reports yet of a successful theft of funds using the new Pectra-enabled attack vector.Most wallet providers like MetaMask were prepared for Pectra and added prominent warnings for EIP-3074 message signings.Got a tip? Send us an email securely via Protos Leaks. For more informed news, follow us on X, Bluesky, and Google News, or subscribe to our YouTube channel.The post Careful when signing messages in Ethereum Pectra appeared first on Protos.
You may also like

Quick Overview of Alliance ALL16 Demo Day: 18 New Projects Featuring Emerging Trends in Prediction Markets and AI Applications
ALL17 application deadline is March 25.

The Ethereum Foundation launches "Hardness," a dedicated team to safeguard the decentralized baseline
Hardness is a protocol-level commitment to the core attributes of Ethereum, including censorship resistance, privacy, security, and permissionlessness.

Morning News | Boya Interactive plans to invest no more than $70 million to purchase cryptocurrency; WeChat launches official lobster plugin; Bitcoin mining difficulty decreased by 7.76% to 133.79 T
Overview of Important Market Events on March 22

The competition for stablecoin yields, how has it stalled U.S. cryptocurrency regulatory legislation?
Congress has only a few weeks left to seek bank support for the CLARITY Act, or it may shelve the legislation due to the midterm elections.

This Week's News Preview | The joint cryptocurrency regulatory guidance document from the U.S. SEC and CFTC officially takes effect; Polymarket announces major news
Highlights of the week from March 23 to March 29.

What characteristics do the projects delisted by mainstream exchanges have?
Mainstream exchanges are, on one hand, massively delisting coins, and on the other hand, massively listing tokenized stock assets. Essentially, this is a supply-side reform aimed at "bad money." The quality of the asset targets and the compliance of the platforms will become the focus of competition...

Before the $75,000 Gamma level, both bulls and bears are waiting for a signal
The selling pressure is being digested, and the belief is still on the way.

Business Opportunities of Tokenized Stocks
In this article, we will outline the lifecycle of tokenized stocks, analyze the current market landscape, and highlight the emerging business opportunities.

In-depth research report on the Resolv protocol hacking incident, who is the final payer?
This incident reveals a fundamental weakness in Delta's stablecoin - the coupling point between the minting logic and off-chain signatures/oracles is the most vulnerable attack surface of the system. Any capital efficiency design of "1 dollar minted for 1 dollar" must be predicated on extremely rigo...

Crypto Market Sees Large Liquidations: $272 Million in Long Positions Affected
Key Takeaways In the last 24 hours, $272 million worth of contracts were liquidated across the entire crypto…

Whale Increases BTC Shorts and Bets on Crude Oil: A Strategic Crypto Move
Key Takeaways A prominent whale, known as “UnRektCapital,” has strategically escalated its short position in Bitcoin while simultaneously…

Hackers in Brazil Use Fake Google Play Store to Steal Cryptocurrency
Key Takeaways Hackers in Brazil are exploiting fake Google Play Store pages to spread Android malware. Infected devices…

Exchanging 200,000 for nearly 100 million, DeFi stablecoins face another attack
DeFi project teams cannot assume that the modules they control are necessarily secure.

The underlying business agreement of the trillion-dollar Agent economy: Understanding ERC-8183, it's not just about payments, but the future
This article systematically analyzes the technical principles and commercial value of the ERC-8183 protocol from the dimensions of technical architecture, core mechanisms, application scenarios, and ecological collaboration.

When Wall Street's ETH begins to "yield": Looking at the asset properties of Ethereum from BlackRock's ETHB
ETH is undergoing a paradigm shift from a "volatile asset" to a "yield-generating cash flow asset."

The Power of Agency: The Agentic Wallet and the Next Decade of Wallets
In 1984, Apple killed the command line with a mouse. In 2026, Agent is killing the mouse.

Understanding x402 and MPP in One Article: Two Routes for Agent Payments
x402 makes payments within the agreement, while MPP makes system-level payments.

Particle Founder: The entrepreneurial insights I have gained the most from in the past year
Stop lean startup, stop lightning entrepreneurship, and think carefully about what your product aspirations are.
Quick Overview of Alliance ALL16 Demo Day: 18 New Projects Featuring Emerging Trends in Prediction Markets and AI Applications
ALL17 application deadline is March 25.
The Ethereum Foundation launches "Hardness," a dedicated team to safeguard the decentralized baseline
Hardness is a protocol-level commitment to the core attributes of Ethereum, including censorship resistance, privacy, security, and permissionlessness.
Morning News | Boya Interactive plans to invest no more than $70 million to purchase cryptocurrency; WeChat launches official lobster plugin; Bitcoin mining difficulty decreased by 7.76% to 133.79 T
Overview of Important Market Events on March 22
The competition for stablecoin yields, how has it stalled U.S. cryptocurrency regulatory legislation?
Congress has only a few weeks left to seek bank support for the CLARITY Act, or it may shelve the legislation due to the midterm elections.
This Week's News Preview | The joint cryptocurrency regulatory guidance document from the U.S. SEC and CFTC officially takes effect; Polymarket announces major news
Highlights of the week from March 23 to March 29.
What characteristics do the projects delisted by mainstream exchanges have?
Mainstream exchanges are, on one hand, massively delisting coins, and on the other hand, massively listing tokenized stock assets. Essentially, this is a supply-side reform aimed at "bad money." The quality of the asset targets and the compliance of the platforms will become the focus of competition...