TLDR Hackers are using the EIP-7702 exploit to drain WLFI tokens from vulnerable wallets. The EIP-7702 exploit relies on private key leaks, enabling token theft during transactions. WLFI users have reported significant thefts in forums, with hackers quickly sweeping tokens. World Liberty Financial warns of phishing attacks and urges users to double-check official communication. World [...] The post WLFI Token Holders Targeted by EIP-7702 Exploit Following Token Launch appeared first on CoinCentral.TLDR Hackers are using the EIP-7702 exploit to drain WLFI tokens from vulnerable wallets. The EIP-7702 exploit relies on private key leaks, enabling token theft during transactions. WLFI users have reported significant thefts in forums, with hackers quickly sweeping tokens. World Liberty Financial warns of phishing attacks and urges users to double-check official communication. World [...] The post WLFI Token Holders Targeted by EIP-7702 Exploit Following Token Launch appeared first on CoinCentral.

WLFI Token Holders Targeted by EIP-7702 Exploit Following Token Launch

2025/09/02 14:18

TLDR

  • Hackers are using the EIP-7702 exploit to drain WLFI tokens from vulnerable wallets.
  • The EIP-7702 exploit relies on private key leaks, enabling token theft during transactions.

  • WLFI users have reported significant thefts in forums, with hackers quickly sweeping tokens.

  • World Liberty Financial warns of phishing attacks and urges users to double-check official communication.


World Liberty Financial’s (WLFI) token holders are falling victim to a known phishing exploit tied to Ethereum’s EIP-7702 upgrade. The exploit, which takes advantage of a feature introduced during Ethereum’s Pectra upgrade in May, allows external accounts to temporarily act like smart contract wallets. This can delegate execution rights and enable batch transactions, potentially making the user experience smoother. However, hackers are exploiting this to drain tokens from unsuspecting victims’ wallets.

Yu Xian, founder of the security firm SlowMist, identified the attack as a classic example of the EIP-7702 phishing exploit. In a recent X post, Xian explained that attackers pre-plant a hacker-controlled address into a victim’s wallet, often after the victim’s private key has been compromised. Once the victim deposits WLFI tokens into their wallet, the malicious contract quickly “snatches” the tokens.

Xian confirmed in the post that he had seen multiple WLFI holders report stolen tokens from their wallets, pointing to a consistent pattern of phishing attacks.

WLFI Exploit Details and How It Works

The EIP-7702 exploit works by exploiting private key leakage, typically through phishing attacks. Once an attacker has access to the victim’s private key, they can insert a delegate smart contract into the wallet. This allows the attacker to control the victim’s funds when they attempt to transfer them.

The issue occurs when a user attempts to move World Liberty Financial tokens that were stored in a Lockbox contract. Due to the exploit, any gas fees the victim inputs for transferring tokens are automatically transferred to the hacker-controlled address. The attacker is thus able to snatch the WLFI tokens before the victim can complete the transaction.

Xian advised users to cancel or replace the compromised EIP-7702 contract with their own to prevent further theft. Transferring tokens out of a compromised wallet as quickly as possible is another suggested mitigation method.

Phishing Attacks Spread Across WLFI Communities

The phishing attack is not isolated to a few cases. Multiple users have reported similar issues in WLFI forums, with one user named hakanemiratlas describing the difficulty in moving WLFI tokens to a new wallet after his wallet was compromised. Despite successfully transferring a portion of his tokens, the user’s wallet remained vulnerable, with 80% of his World Liberty Financial still stuck.

In another forum post, user Anton warned that the automated nature of the exploit meant that the tokens were quickly drained by “sweeper bots” as soon as they were deposited. He requested that the WLFI team implement a direct transfer option to prevent such thefts in the future. The WLFI community has been particularly concerned about the initial token drop mechanism, which requires a whitelisted wallet to participate in the presale.

The attack method has left many in the community anxious about the safety of their holdings, especially with the WLFI tokens still being locked and vulnerable to exploitation.

Warnings and Security Measures from World Liberty Financial Team

The World Liberty Financial team has warned users to be vigilant about phishing scams, particularly in the wake of the recent token launch. The team clarified that WLFI will never contact users through direct messages or social media platforms, and any such communication is likely to be fraudulent.

“Any email communication should be verified through official WLFI domains,” the team said, stressing that users should be cautious and avoid responding to suspicious inquiries.

Despite the ongoing security challenges, the WLFI team is actively addressing the issues, and security experts are recommending that token holders secure their private keys to prevent further attacks. The ongoing discourse within the community reflects growing concerns over the security of token assets following this exploit.

The post WLFI Token Holders Targeted by EIP-7702 Exploit Following Token Launch appeared first on CoinCentral.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

BFX Presale Raises $7.5M as Solana Holds $243 and Avalanche Eyes $1B Treasury — Best Cryptos to Buy in 2025

BFX Presale Raises $7.5M as Solana Holds $243 and Avalanche Eyes $1B Treasury — Best Cryptos to Buy in 2025

BFX presale hits $7.5M with tokens at $0.024 and 30% bonus code BLOCK30, while Solana holds $243 and Avalanche builds a $1B treasury to attract institutions.
Share
Blockchainreporter2025/09/18 01:07
Major Banks Rush to Get Crypto Charters in 2025

Major Banks Rush to Get Crypto Charters in 2025

The post Major Banks Rush to Get Crypto Charters in 2025 appeared on BitcoinEthereumNews.com. Key Highlights In the latest statement, the OCC revealed a major development that approves new federally chartered banks This might open the door for crypto and fintech companies to become regulated institutions An OCC official has raised his support for the authority of existing trust banks to hold digital assets for clients, stating that they have legally provided this custody service for decades and that crypto is not different  The U.S.’s leading banking regulator has revealed that many new federally chartered banks are going to be approved soon and stated that firms working with digital assets should have a clear regulatory framework to become regulated banks.  Our first public panel of the day: @USComptroller Jonathan Gould delivers a keynote and sits for a conversation to discuss the @USOCC’s modernization agenda and GENIUS Act implementation. Tune in to watch the livestream here: https://t.co/6gK6lZakdz — Blockchain Association (@BlockchainAssn) December 8, 2025 US Regulator Welcomes New Crypto-Friendly Banks Comptroller of the Currency’s head, Jonathan V. Gould, shared a statement at a Blockchain Association Summit on December 8, where he unveiled the regulator’s plan to integrate financial innovations into the existing financial infrastructure. In his official statement, he slammed the last 15 years of “completely stagnated” new bank formations by blaming regulators for discouraging applicants.  “Over the past 15 years, de novo chartering has completely stagnated. In the late 1990s, the OCC received over 100 de novo charter applications each year, and nearly 50 per year in the early 2000s. But from 2011 through 2024, the OCC received, on average, less than four charter applications per year,” he said. Jonathan V. Gould further added into his statement, “Following the financial crisis, there were years when the OCC received only one or two charter applications—as well as years when the OCC did not receive a…
Share
BitcoinEthereumNews2025/12/09 05:26