USENIX Security2026Top-tier venue
Revealing the Dark Side of Smart Accounts: An Empirical Study of EIP-7702 Incurred Risks in Blockchain Ecosystem
Mingyuan Huang, Han Liu, Shuo Yang, Daoyuan Wu, Shuai Wang
Abstract
The introduction of smart accounts by EIP-7702 represents a major advancement for blockchain account abstraction, enabling externally owned accounts (EOAs) to be upgraded into programmable accounts while still preserving their original addresses. This advancement significantly enhances both account functionality and usability, but also redefines blockchain trust boundaries between EOAs and smart contract accounts (CAs), thereby altering security assumptions and creating opportunities for novel types of attack.
To systematically examine these risks, we classify smart account-based risks into three categories according to the type of victim accounts: EOA-targeted, CA-targeted, and composite attacks. We then develop specialized detection tools that combine large-scale transaction analysis with cross-contract static analysis to identify malicious behaviors. Applying these tools across seven blockchains that support EIP-7702, we detect 924 malicious contract accounts, including several previously unreported zero-day cases. These attacks have led to more than 10 million to potential compromise. We uncover multiple key insights into attacker behaviors. Specifically, we find that over 63% of EIP-7702 authorization transactions are associated with malicious EOA-targeted attacks, and nearly half of the most frequently authorized contracts are controlled by attackers. In addition, we identify existing evasion tactics that attackers use to circumvent detection, attack impacts observed in realworld incidents, and potential risks that may emerge in future deployments, underscoring the urgency of addressing smart account security in blockchain ecosystems.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 9905bed0-a8cc-4adf-88d7-db63208ec29dBuilds on13
- Making Smart Contracts SmarterLoi Luu, Duc-Hiep Chu, Hrishi Olickel, Prateek Saxena et al.CCS 2016 · 2,306 citations
- Securify: Practical Security Analysis of Smart ContractsPetar Tsankov, Andrei Marian Dan, Dana Drachsler-Cohen, Arthur Gervais et al.CCS 2018 · 1,108 citations
- VERISMART: A Highly Precise Safety Verifier for Ethereum Smart ContractsSunbeom So, Myungho Lee, Jisu Park, Heejo Lee et al.S&P 2020 · 133 citations
- Evil Under the Sun: Understanding and Discovering Attacks on Ethereum Decentralized ApplicationsLiya Su, Xinyue Shen, Xiangyu Du, Xiaojing Liao et al.USENIX Security 2021 · 74 citations
- Elipmoc: advanced decompilation of Ethereum smart contractsNeville Grech, Sifis Lagouvardos, Ilias Tsatiris, Yannis SmaragdakisOOPSLA 2022 · 40 citations
Related papers
- Lost in Blockchain Address Misuse: Hidden Cross-Platform Risks and Their Security ImpactZhenzhe Shao, Jiashuo Zhang, Zihao Li, Daoyuan Wu et al.USENIX Security 2026
- Ethainter: a smart contract security analyzer for composite vulnerabilitiesLexi Brent, Neville Grech, Sifis Lagouvardos, Bernhard Scholz et al.PLDI 2020 · 163 citations
- Demystifying Exploitable Bugs in Smart ContractsZhuo Zhang, Brian Zhang, Wen Xu, Zhiqiang LinICSE 2023 · 80 citations
- ETHBMC: A Bounded Model Checker for Smart ContractsJoel Frank, Cornelius Aschermann, Thorsten HolzUSENIX Security 2020
- Dissecting Payload-based Transaction Phishing on EthereumZhuo Chen, Yufeng Hu, Bowen He, Dong Luo et al.NDSS 2025
