TLDR WLFI tokenholders are being targeted by hackers using an EIP-7702 phishing exploit The attack requires leaked private keys and pre-plants malicious contracts in victim wallets Many users reported losing tokens immediately after receiving them The Donald Trump-backed token launched with a 24.66 billion total supply WLFI team warns users to be cautious of scams [...] The post WLFI Token Holders Targeted by EIP-7702 Phishing Exploit appeared first on Blockonomi.TLDR WLFI tokenholders are being targeted by hackers using an EIP-7702 phishing exploit The attack requires leaked private keys and pre-plants malicious contracts in victim wallets Many users reported losing tokens immediately after receiving them The Donald Trump-backed token launched with a 24.66 billion total supply WLFI team warns users to be cautious of scams [...] The post WLFI Token Holders Targeted by EIP-7702 Phishing Exploit appeared first on Blockonomi.

WLFI Token Holders Targeted by EIP-7702 Phishing Exploit

2025/09/02 17:42
4 min read

TLDR

  • WLFI tokenholders are being targeted by hackers using an EIP-7702 phishing exploit
  • The attack requires leaked private keys and pre-plants malicious contracts in victim wallets
  • Many users reported losing tokens immediately after receiving them
  • The Donald Trump-backed token launched with a 24.66 billion total supply
  • WLFI team warns users to be cautious of scams and only use official email support

World Liberty Financial (WLFI) tokenholders are falling victim to a sophisticated phishing attack that exploits Ethereum’s recent EIP-7702 upgrade, according to security expert Yu Xian, founder of SlowMist.

The attack targets users who have had their private keys compromised through phishing attempts. Once hackers obtain these keys, they pre-plant malicious delegate smart contracts into victims’ wallets.

When users deposit funds or attempt to transfer tokens, the hackers quickly drain the accounts. This exploit takes advantage of features introduced in Ethereum’s Pectra upgrade from May, which allows external accounts to temporarily function like smart contract wallets.

“Encountered another player whose multiple addresses’ WLFI were all stolen. Looking at the theft method, it’s again the exploitation of the 7702 delegate malicious contract, with the prerequisite being private key leakage,” Xian posted on X.

The Donald Trump-backed World Liberty Financial token began trading Monday with a total supply of 24.66 billion tokens. In the days leading up to the launch, reports of token theft started emerging.

How the Exploit Works

One X user reported on August 31 that their friend had WLFI tokens drained after transferring Ether into their wallet. Xian confirmed this was a classic example of the EIP-7702 phishing exploit.

The attack works by first compromising a user’s private key through phishing. The hacker then plants a delegate smart contract in the victim’s wallet. When the user attempts to transfer tokens or receives new tokens, the malicious contract immediately redirects them to the hacker’s wallet.

“As soon as you try to transfer away the remaining tokens in it, such as these WLFI that were thrown into the Lockbox contract, the gas you input will be automatically transferred away,” Xian explained.

For users with compromised wallets, Xian suggests canceling or replacing the malicious EIP-7702 contract with their own and quickly transferring tokens to a new, secure wallet.

User Reports and Concerns

In WLFI forums, multiple users have shared similar experiences. One user named hakanemiratlas had their wallet hacked months ago and was only able to rescue 20% of their WLFI tokens.

“I managed to transfer only 20% of my WLFI tokens to a new wallet, but it was a stressful race against the hacker. Even sending ETH for gas fees felt dangerous, since it could have been stolen instantly as well,” they wrote.

Another user, Anton, pointed out a major issue with the token drop implementation. The wallet used to join the WLFI whitelist must also be used to participate in the presale.

“The instant the tokens arrive, they will be stolen by automated sweeper bots before we have a chance to move them to a secure wallet,” Anton warned. He requested the WLFI team implement a direct transfer option for tokens to bypass compromised wallets.

The problem affects users who joined the whitelist but later had their wallets compromised, putting them at risk of losing their tokens immediately upon receipt.

Analytics firm Bubblemaps has identified several “bundled clones” – look-alike smart contracts that imitate established crypto projects – targeting WLFI users.

The WLFI team has issued warnings about scams, emphasizing they never contact users via direct messages on any platform. Their only official support channels are through email, and users should verify that communications come from official domains.

The post WLFI Token Holders Targeted by EIP-7702 Phishing Exploit appeared first on Blockonomi.

Market Opportunity
OFFICIAL TRUMP Logo
OFFICIAL TRUMP Price(TRUMP)
$3.402
$3.402$3.402
+0.97%
USD
OFFICIAL TRUMP (TRUMP) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

SEC Adopts Final Rules Under HFIA Act to Boost Foreign Insider Transparency

SEC Adopts Final Rules Under HFIA Act to Boost Foreign Insider Transparency

TLDR: The HFIA Act was enacted on December 18, 2025, mandating SEC action within 90 days of enactment. FPI directors and officers must file Section 16 reports electronically
Share
Blockonomi2026/02/28 07:17
CME Group to Launch Solana and XRP Futures Options

CME Group to Launch Solana and XRP Futures Options

The post CME Group to Launch Solana and XRP Futures Options appeared on BitcoinEthereumNews.com. An announcement was made by CME Group, the largest derivatives exchanger worldwide, revealed that it would introduce options for Solana and XRP futures. It is the latest addition to CME crypto derivatives as institutions and retail investors increase their demand for Solana and XRP. CME Expands Crypto Offerings With Solana and XRP Options Launch According to a press release, the launch is scheduled for October 13, 2025, pending regulatory approval. The new products will allow traders to access options on Solana, Micro Solana, XRP, and Micro XRP futures. Expiries will be offered on business days on a monthly, and quarterly basis to provide more flexibility to market players. CME Group said the contracts are designed to meet demand from institutions, hedge funds, and active retail traders. According to Giovanni Vicioso, the launch reflects high liquidity in Solana and XRP futures. Vicioso is the Global Head of Cryptocurrency Products for the CME Group. He noted that the new contracts will provide additional tools for risk management and exposure strategies. Recently, CME XRP futures registered record open interest amid ETF approval optimism, reinforcing confidence in contract demand. Cumberland, one of the leading liquidity providers, welcomed the development and said it highlights the shift beyond Bitcoin and Ethereum. FalconX, another trading firm, added that rising digital asset treasuries are increasing the need for hedging tools on alternative tokens like Solana and XRP. High Record Trading Volumes Demand Solana and XRP Futures Solana futures and XRP continue to gain popularity since their launch earlier this year. According to CME official records, many have bought and sold more than 540,000 Solana futures contracts since March. A value that amounts to over $22 billion dollars. Solana contracts hit a record 9,000 contracts in August, worth $437 million. Open interest also set a record at 12,500 contracts.…
Share
BitcoinEthereumNews2025/09/18 01:39
SEC is seeking to regain crypto ground following ‘missed opportunity,’ Chairman Atkins says

SEC is seeking to regain crypto ground following ‘missed opportunity,’ Chairman Atkins says

The SEC is working to regain momentum on crypto after what Atkins described as a “big missed opportunity” under the prior administration.
Share
Coinstats2026/02/28 06:40