![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
Cryptocurrency News Articles
Pectra upgrade forks the Ethereum blockchain, introducing new features and vulnerabilities
May 08, 2025 at 02:43 am
The Ethereum blockchain forked today for its Pectra code change and introduced a suite of new features, upgrades, and vulnerabilities.
The Ethereum blockchain underwent a planned code change, known as Pectra, which brought a suite of new features, upgrades, and unfortunately, also some vulnerabilities.
This new set of opcodes will be used for an upcoming version of Ethereum Improvement Proposal (EIP) 3074. The proposal aims to introduce a new authorization pattern.
It is an important step towards account abstraction, which is being brought to Ethereum in later phases with further upgrades.
However, some critics say it will open up new phishing attack vectors that could allow an entire user’s account to be stolen if they accidentally delegate control of their key.
pectra pros:>approve spend then swap is deadpectra cons:>signing messages just got a whole lot spicier
Credit: EIP-3074 authors
The authors of EIP-3074, which is part of the Pectra upgrade, are introducing new AUTH and AUTHCALL Ethereum operation codes.
These opcodes will allow the holder of an Ethereum private key to delegate authorization to a smart contract.
The authors of the EIP, which is part of the Pectra upgrade, are introducing new AUTH and AUTHCALL Ethereum operation codes.
These opcodes will allow the holder of an Ethereum private key to delegate authorization to a smart contract.
It is an important step towards account abstraction, which is being brought to Ethereum in later phases with further upgrades.
However, some critics say it will open up new phishing attack vectors that could allow an entire user’s account to be stolen if they accidentally delegate control of their key.
pectra pros:+ approve spend then swap is deadpectra cons:signing messages just got a whole lot spicier
Careful signing Ethereum transactions and messages
According to a post on Binance, the authors of EIP-3074 are trying to calm fears. They claimed they are "unaware" of any wallet that would allow signing of improperly prefixed messages without a user warning.
Transactions use the prefix 0x04, and the authors of the EIP hope that all major Ethereum wallets will put 0x04 messages in a way that will alert the user about their expansive power to authorize multiple withdrawals.
“The caller field in the EIP-3074 signature is very important. A bad caller could steal your funds.”
Today's Pectra fork also added EIP-7702, which is increasing the stakes even higher.
With the power of EIP-7702, a single malicious signature can temporarily delegate someone’s entire account to a third-party smart contract.
If that contract is malicious, it could potentially drain all assets (ETH, tokens, NFTs) in one go.
As opposed to pre-Pectra Ethereum transactions, the possible attack surface for victims is broader with EIP-7702 because externally owned accounts (EOAs) are now exposed to third-party temporary smart contract vulnerabilities.
This temporary delegation of executable code was not a concern before Pectra.
Although warnings are proliferating across social media, there are no reports yet of a successful theft of funds using the new Pectra-enabled attack vector.
Most wallet providers like MetaMask were prepared for Pectra and added prominent warnings for EIP-3074 message signings.
Disclaimer:info@kdj.com
The information provided is not trading advice. kdj.com does not assume any responsibility for any investments made based on the information provided in this article. Cryptocurrencies are highly volatile and it is highly recommended that you invest with caution after thorough research!
If you believe that the content used on this website infringes your copyright, please contact us immediately (info@kdj.com) and we will delete it promptly.
-
-
- DOGE Does 38% Rebound and ADA Tests AI Integration: But Unstaked's Real AI Advantage Commands Attention!
- May 11, 2025 at 07:40 am
- Dogecoin (DOGE) has surged back into focus with a 38% rebound from its April lows, fueling talk of a potential rally toward $3.94. Meanwhile, Cardano (ADA) is turning heads with its AI-powered “Face Melting Net” testnet
-
- Analyst Sounds The Alarm: Buying This SHIB Killer Today Is Like Buying Dogecoin Right Before Elon Musk Started Promoting It
- May 11, 2025 at 07:35 am
- A top analyst warns that buying this SHIB killer, FloppyPepe (FPPE), now could mirror the explosive gains seen when Elon Musk first backed Dogecoin (DOGE).
-
-
-
- As SHIB Eyes a Bounce and Cardano Gains Developer Strength, Web3 ai's $2.6M Presale & 1747% ROI Steal the Spotlight
- May 11, 2025 at 07:30 am
- Guesswork often leads to missed chances and poor decisions. Right now, Shiba Inu is getting attention again with recovery signals. Cardano is also showing strength due to its rising developer activity.
-
-
- BlackRock Files Proposal to Allow In-Kind Creation and Redemption of Its iShares Ethereum Trust ETF (ETHA)
- May 11, 2025 at 07:25 am
- American investment firm BlackRock has filed a proposal with the US Securities and Exchange Commission that will allow the in-kind creation and redemption of its iShares Ethereum Trust ETF (ETHA).
-