logo

Pectra’s EIP-7702: Redefining Trust Assumptions of Externally Owned Accounts (EOAs) in EVM

ID: c9488c07-a0ec-536d-aae4-1223f725c41c

STIX ID: report--c9488c07-a0ec-536d-aae4-1223f725c41c

Feed Name: CertiK Blog

Threat Score
70/100

Date Published: 2025-05-06

Date Updated: 2026-06-11

...
...

This advisory explains how EIP-7702 (Pectra) lets EOAs set delegated bytecode, invalidating common EVM assumptions (e.g., tx.origin == msg.sender and extcodesize-based EOA detection) and enabling new attack vectors such as reentrancy, flash-loan/atomic sandwich bypasses, and unexpected token/ETH transfer reverts; CertiK observed suspicious BSC transactions leveraging these changes, the report provides PoCs and recommends replacing tx.origin checks, using reentrancy guards/CEI patterns, and assuming any address may have code.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.