• bitcoinBitcoin (BTC) $ 95,252.00
  • ethereumEthereum (ETH) $ 3,288.74
  • tetherTether (USDT) $ 0.999556
  • bnbBNB (BNB) $ 937.02
  • xrpXRP (XRP) $ 2.06
  • usd-coinUSDC (USDC) $ 1.00
  • tronTRON (TRX) $ 0.311748
  • staked-etherLido Staked Ether (STETH) $ 3,288.09
  • dogecoinDogecoin (DOGE) $ 0.137314
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.03
  • cardanoCardano (ADA) $ 0.395480
  • wrapped-stethWrapped stETH (WSTETH) $ 4,026.67
  • whitebitWhiteBIT Coin (WBT) $ 57.30
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 3,576.34
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 95,134.00
  • bitcoin-cashBitcoin Cash (BCH) $ 593.85
  • moneroMonero (XMR) $ 635.25
  • wrapped-eethWrapped eETH (WEETH) $ 3,567.74
  • usdsUSDS (USDS) $ 0.999585
  • chainlinkChainlink (LINK) $ 13.71
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
  • leo-tokenLEO Token (LEO) $ 9.00
  • wethWETH (WETH) $ 3,289.17
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 95,254.00
  • stellarStellar (XLM) $ 0.225431
  • suiSui (SUI) $ 1.80
  • zcashZcash (ZEC) $ 404.18
  • ethena-usdeEthena USDe (USDE) $ 0.999692
  • hyperliquidHyperliquid (HYPE) $ 24.94
  • avalanche-2Avalanche (AVAX) $ 13.57
  • litecoinLitecoin (LTC) $ 74.65
  • hedera-hashgraphHedera (HBAR) $ 0.118012
  • shiba-inuShiba Inu (SHIB) $ 0.000008
  • canton-networkCanton (CC) $ 0.125716
  • usdt0USDT0 (USDT0) $ 0.999402
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.168823
  • daiDai (DAI) $ 1.00
  • susdssUSDS (SUSDS) $ 1.08
  • the-open-networkToncoin (TON) $ 1.71
  • crypto-com-chainCronos (CRO) $ 0.101318
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • paypal-usdPayPal USD (PYUSD) $ 0.999602
  • polkadotPolkadot (DOT) $ 2.14
  • usd1-wlfiUSD1 (USD1) $ 0.998674
  • uniswapUniswap (UNI) $ 5.34
  • rainRain (RAIN) $ 0.009460
  • mantleMantle (MNT) $ 0.945820
  • memecoreMemeCore (M) $ 1.58
  • aaveAave (AAVE) $ 175.26
  • bittensorBittensor (TAO) $ 276.18
  • bitget-tokenBitget Token (BGB) $ 3.78
  • pepePepe (PEPE) $ 0.000006
  • okbOKB (OKB) $ 114.44
  • tether-goldTether Gold (XAUT) $ 4,593.28
  • nearNEAR Protocol (NEAR) $ 1.75
  • internet-computerInternet Computer (ICP) $ 4.04
  • falcon-financeFalcon USD (USDF) $ 0.997374
  • jito-staked-solJito Staked SOL (JITOSOL) $ 180.44
  • ethereum-classicEthereum Classic (ETC) $ 12.85
  • binance-peg-wethBinance-Peg WETH (WETH) $ 3,292.53
  • pax-goldPAX Gold (PAXG) $ 4,608.64
  • aster-2Aster (ASTER) $ 0.720183
  • ethenaEthena (ENA) $ 0.219765
  • pi-networkPi Network (PI) $ 0.205578
  • pump-funPump.fun (PUMP) $ 0.002926
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • solanaWrapped SOL (SOL) $ 143.84
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.91
  • htx-daoHTX DAO (HTX) $ 0.000002
  • global-dollarGlobal Dollar (USDG) $ 0.999716
  • binance-staked-solBinance Staked SOL (BNSOL) $ 157.35
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.145675
  • worldcoin-wldWorldcoin (WLD) $ 0.554096
  • hash-2Provenance Blockchain (HASH) $ 0.028307
  • kucoin-sharesKuCoin (KCS) $ 11.41
  • hashnote-usycCircle USYC (USYC) $ 1.11
  • skySky (SKY) $ 0.063965
  • ripple-usdRipple USD (RLUSD) $ 0.999542
  • aptosAptos (APT) $ 1.82
  • wbnbWrapped BNB (WBNB) $ 936.80
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,799.15
  • bfusdBFUSD (BFUSD) $ 0.999213
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 1.00
  • arbitrumArbitrum (ARB) $ 0.211781
  • cosmosCosmos Hub (ATOM) $ 2.52
  • ondo-financeOndo (ONDO) $ 0.386692
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,492.76
  • kaspaKaspa (KAS) $ 0.044782
  • gatechain-tokenGate (GT) $ 10.41
  • render-tokenRender (RENDER) $ 2.25
  • algorandAlgorand (ALGO) $ 0.131592
  • filecoinFilecoin (FIL) $ 1.51
  • official-trumpOfficial Trump (TRUMP) $ 5.37
  • midnight-3Midnight (NIGHT) $ 0.063016
  • ignition-fbtcFunction FBTC (FBTC) $ 94,849.00
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 95,506.00
  • vechainVeChain (VET) $ 0.011894
  • dashDash (DASH) $ 80.87
  • myx-financeMYX Finance (MYX) $ 5.20
  • nexoNEXO (NEXO) $ 0.990338
  • usddUSDD (USDD) $ 1.00
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 95,225.00
  • story-2Story (IP) $ 2.71
  • bonkBonk (BONK) $ 0.000011
  • flare-networksFlare (FLR) $ 0.011008
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 3,524.79
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,564.62
  • usdtbUSDtb (USDTB) $ 0.999047
  • xdce-crowd-saleXDC Network (XDC) $ 0.043956
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999602
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 10.96
  • sei-networkSei (SEI) $ 0.119083
  • wrappedm-by-m0WrappedM by M0 (WM) $ 0.999705
  • ousgOUSG (OUSG) $ 114.00
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 94,914.00
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.012128
  • clbtcclBTC (CLBTC) $ 96,264.00
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.12
  • morphoMorpho (MORPHO) $ 1.34
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 3,507.48
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.02
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 167.30
  • jupiter-exchange-solanaJupiter (JUP) $ 0.224562
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.11
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 3,489.59
  • optimismOptimism (OP) $ 0.344285
  • beldexBeldex (BDX) $ 0.087836
  • tezosTezos (XTZ) $ 0.617544
  • usdaiUSDai (USDAI) $ 1.00
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 3,287.82
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • blockstackStacks (STX) $ 0.369647
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.984982
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.278771
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999690
  • wrapped-flareWrapped Flare (WFLR) $ 0.011015
  • curve-dao-tokenCurve DAO (CRV) $ 0.431980
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.21
  • chilizChiliz (CHZ) $ 0.058265
  • usual-usdUsual USD (USD0) $ 0.998118
  • c8ntinuumc8ntinuum (CTM) $ 0.132410
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 25.20
  • tbtctBTC (TBTC) $ 95,368.00
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 3,285.83
  • injective-protocolInjective (INJ) $ 5.38
  • spx6900SPX6900 (SPX) $ 0.570822
  • gtethGTETH (GTETH) $ 3,287.75
  • ether-fiEther.fi (ETHFI) $ 0.748060
  • lido-daoLido DAO (LDO) $ 0.603527
  • aerodrome-financeAerodrome Finance (AERO) $ 0.558801
  • celestiaCelestia (TIA) $ 0.587346
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.999100
  • msolMarinade Staked SOL (MSOL) $ 194.65
  • ghoGHO (GHO) $ 0.999550
  • true-usdTrueUSD (TUSD) $ 0.999495
  • a7a5A7A5 (A7A5) $ 0.012592
  • flokiFLOKI (FLOKI) $ 0.000051
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 3,521.96
  • fasttokenFasttoken (FTN) $ 1.09
  • doublezeroDoubleZero (2Z) $ 0.135750
  • the-graphThe Graph (GRT) $ 0.043381
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.09
  • stader-ethxStader ETHx (ETHX) $ 3,546.24
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,681.97
  • riverRiver (RIVER) $ 22.92
  • lighterLighter (LIT) $ 1.83
  • wrapped-apecoinWrapped ApeCoin (WAPE) $ 0.224748
  • starknetStarknet (STRK) $ 0.085235
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • staked-aaveStaked Aave (STKAAVE) $ 175.35
  • sbtc-2sBTC (SBTC) $ 95,231.00
  • decredDecred (DCR) $ 24.45
  • newton-projectAB (AB) $ 0.004360
  • syrupMaple Finance (SYRUP) $ 0.362507
  • bittorrentBitTorrent (BTT) $ 0.00000042
  • usdbUSDB (USDB) $ 0.996767
  • cap-usdCap USD (CUSD) $ 0.999905
  • jasmycoinJasmyCoin (JASMY) $ 0.008095
  • conflux-tokenConflux (CFX) $ 0.077365
  • iotaIOTA (IOTA) $ 0.094094
  • sun-tokenSun Token (SUN) $ 0.020682
  • trust-wallet-tokenTrust Wallet (TWT) $ 0.949804
  • ethereum-name-serviceEthereum Name Service (ENS) $ 10.35
  • bitcoin-svBitcoin SV (BSV) $ 19.37
  • dogwifcoindogwifhat (WIF) $ 0.385178
  • gnosisGnosis (GNO) $ 145.44
  • pyth-networkPyth Network (PYTH) $ 0.066144
  • fartcoinFartcoin (FARTCOIN) $ 0.373972
  • wrapped-stx-velarWrapped STX (Velar) (WSTX) $ 0.370267
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 3,290.33
  • crvusdcrvUSD (CRVUSD) $ 0.999456
  • resolv-usrResolv USR (USR) $ 0.999722
  • telcoinTelcoin (TEL) $ 0.003836
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 95,162.00
  • the-sandboxThe Sandbox (SAND) $ 0.135229
  • chain-2Onyxcoin (XCN) $ 0.008485
  • justJUST (JST) $ 0.040822
  • pendlePendle (PENDLE) $ 2.12
  • apenftAINFT (NFT) $ 0.00000036

Hackers are using the ‘classic EIP-7702’ exploit to snatch WLFI

0 61

Hackers are using the ‘classic EIP-7702’ exploit to snatch WLFI

World Liberty Financial’s (WLFI) governance tokenholders are being hit with a known phishing wallet exploit using Ethereum’s EIP-7702 upgrade, SlowMist founder Yu Xian says.

Ethereum’s Pectra upgrade in May introduced EIP-7702, which allows external accounts to temporarily act like smart contract wallets, delegating execution rights and allowing batch transactions, which are aimed at streamlining a user’s experience.

Xian said in an X post on Monday that hackers are exploiting the upgrade to pre-plant a hacker-controlled address in victim wallets, then, when a deposit is made, they quickly “snatch” the tokens, which in this case, is affecting WLFI tokenholders.

“Encountered another player whose multiple addresses’ WLFI were all stolen. Looking at the theft method, it’s again the exploitation of the 7702 delegate malicious contract, with the prerequisite being private key leakage,” Xian said.

Hackers are using the ‘classic EIP-7702’ exploit to snatch WLFI

Source: Yu Xian

The Donald Trump–backed World Liberty Financial (WLFI) token began trading Monday morning, with a total supply of 24.66 billion tokens.

How it works

In the lead-up to the official launch, an X user reported on Aug. 31 that a friend had their WLFI tokens drained after transferring Ether (ETH) into their wallet.

In a reply, Xian said it was clearly an example of the “Classic EIP-7702 phishing exploit,” where the private key was leaked, and the bad actor then pre-plants a delegate smart contract into the victim’s wallet address connected to the key.

In a previous post, Xian said the private keys are usually stolen through phishing.

Hackers are using the ‘classic EIP-7702’ exploit to snatch WLFI

Source: Yu Xian

“As soon as you try to transfer away the remaining tokens in it, such as these WLFI that were thrown into the Lockbox contract, the gas you input will be automatically transferred away,” he said.

Xian suggested to “cancel or replace the ambushed EIP-7702 with your own,” and transferring away tokens from the compromised wallet as a possible solution.

Crypto users discuss thefts on WLFI forums

Some have been reporting similar issues in the WLFI forums. One posting under the handle hakanemiratlas said his wallet was hacked in October last year and now worries his WLFI tokens are at risk.

“I managed to transfer only 20% of my WLFI tokens to a new wallet, but it was a stressful race against the hacker. Even sending ETH for gas fees felt dangerous, since it could have been stolen instantly as well,” they said.

“Currently, 80% of my WLFI tokens are still stuck in the compromised wallet. I am extremely worried that once they unlock, the hacker might immediately transfer them away.”

Another user under the handle Anton said many other people are facing a similar issue because of how the token drop was implemented. The wallet used to join the WLFI whitelist needs to be used to participate in the presale.

“The instant the tokens arrive, they will be stolen by automated sweeper bots before we have a chance to move them to a secure wallet,” he said.

Anton is also requesting the WLFI Team to consider implementing a direct transfer option for the tokens.

Hackers are using the ‘classic EIP-7702’ exploit to snatch WLFI

A user under the handle Anton said people who signed up for the WLFI whitelist and have since had their wallets compromised are in danger of losing their tokens. Source: World Liberty Financial

Scammers targeting token launch

Numerous WLFI scams have appeared in the lead-up and post token launch. Analytics firm Bubblemaps identified several “bundled clones” look-alike smart contracts that imitate established crypto projects.

Meanwhile, the WLFI team has warned that it doesn’t contact via direct message on any platform, with the only official support channels through email.

“If you receive a DM claiming to be from us, it is fraudulent and should be ignored. If you receive an email, always double-check that it is coming from one of these official domains before responding,” the WLFI team said.

Source

Leave A Reply

Your email address will not be published.