Skip to main content
AVOID.NET

EIP-7702 CrimeEnjoyor Drainer Cluster

avoid.net/eip-7702-crimeenjoyor-drainer-cluster→2/100·72% conf.
[AI-DRAFTED · AWAITING FACT-CHECK]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·4wYBuV…QwXm
last updated 2026-10-05

Summary

Following Ethereum's Pectra hard fork (May 7, 2025), which activated EIP-7702 account-delegation functionality, a coordinated drainer campaign emerged that security researchers at Wintermute labeled 'CrimeEnjoyor.' Wintermute found that over 97% of all EIP-7702 delegations on-chain used near-identical sweeper bytecode designed to automatically drain ETH from compromised addresses, and one analysis citing Wintermute data placed the share of crime-tagged delegations at roughly 48% of total activations. Documented losses linked to EIP-7702 phishing range from a May 2025 incident of $146,551 to two August 2025 incidents totalling approximately $2.54 million, with a separate April 2026 protocol-level exploit removing 1,988.5 QNT (about 54.93 ETH) from a reserve pool through an access-control flaw in a delegated BatchExecutor contract.

Connected Entities

1 entity

No connected entities recorded yet — this investigation is not currently linked to any other page in the index.

Have evidence about EIP-7702 CrimeEnjoyor Drainer Cluster?

Timeline(6 events)

7 May 2025

Ethereum Pectra hard fork activates EIP-7702, enabling EOA-to-smart-contract delegation via transaction type 0x04.

Coin Edition / multiple

7 May 2025

Wintermute observes that within the first weeks post-Pectra, the first 11,000 EIP-7702 mainnet authorizations include a high proportion linked to sweeper bytecode.

Zelcore security analysis

23 May 2025

Scam Sniffer flags a $146,551 loss by a wallet upgraded to EIP-7702 through malicious batched transactions attributed to Inferno Drainer; SlowMist's Yu Xian confirms batch-authorization mechanics.

Bitget / Scam Sniffer

2 June 2025

Wintermute publicly discloses CrimeEnjoyor findings: over 97% of EIP-7702 delegations use near-identical sweeper bytecode; Wintermute injects on-chain warnings into verified malicious contracts. CoinDesk notes Wintermute's caveat that the sweepers are largely not profiting, as they target already-compromised wallets.

CoinDesk / CoinTelegraph

1 August 2025

Two EIP-7702 phishing incidents in August cause a combined approximately $2.54 million in losses: one victim loses $1.54 million through a fake Uniswap interface using malicious batch transactions; a second victim loses approximately $1 million in tokens and NFTs through the same attack pattern.

Cryptopolitan / Scam Sniffer

29 April 2026

SlowMist reports a protocol-level EIP-7702 exploit draining 1,988.5 QNT (approximately 54.93 ETH) from a QNT reserve pool. Root cause: admin EOA delegated to BatchExecutor, which authorized a BatchCall contract with no access controls, enabling arbitrary calls to transfer pool funds.

Crypto Times / SlowMist via Bitget
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (1 event). 16 of 20 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 10/4/2026, 11:24:00 PM

last updated: 10/5/2026, 6:29:52 AM

3 views

avoid.net — verified advice for a post-truth world