BTC ETH SOL BNB XRP Fear & Greed
AltcoinGordon
Research & Intelligence

Report: Attackers Behind 63% of Early Transactions Using Ethereum’s New Wallet Feature

Two outlets say malicious actors dominated initial use of Ethereum's account delegation upgrade

Original AltcoinGordon illustration for: Report: Attackers Behind 63% of Early Transactions Using Ethereum’s New Wallet Feature
Original illustration, drawn for this story by AltcoinGordon.

Ethereum's newest smart wallet feature has drawn scrutiny after reports found attackers accounted for the majority of its early activity. According to CryptoSlate and The Cryptonomist, 63% of transactions using the feature in its initial period were linked to malicious actors rather than everyday users.

The feature in question allows standard Ethereum wallets, known as externally owned accounts, to temporarily gain smart contract capabilities. This type of account delegation is part of a broader push toward account abstraction, a long-discussed goal for the Ethereum network. The upgrade lets users batch transactions, sponsor gas fees for others, and add programmable logic to wallets that previously lacked such flexibility.

Account abstraction has been pitched as a way to simplify the user experience on Ethereum. Supporters argue it can reduce friction for newcomers and unlock more sophisticated wallet designs. But the same mechanism that grants a simple wallet temporary smart contract powers can also be exploited, if attackers find ways to trick users into granting delegation to malicious code.

The reported 63% figure suggests that bad actors moved quickly to test and exploit the feature before typical users adopted it at scale. Early adoption periods for new blockchain functionality often see this pattern, as attackers probe for weaknesses before broader security awareness catches up. The concentration of malicious activity in the feature's earliest days points to a narrow window in which safeguards may not have kept pace with capability.

Neither CryptoSlate nor The Cryptonomist detailed the exact nature of the attacks or the total transaction volume involved. Both outlets focused on the proportion of early transactions tied to attackers rather than absolute figures. This distinction matters for interpreting the scale of the issue, since a high percentage of a small early sample can look more alarming than it would against a larger, matured dataset.

The timing of the reports, both published in August 2026, places the finding squarely in the feature's rollout phase. Ethereum's account abstraction efforts have evolved over several years, with multiple proposals contributing incremental steps toward wallets that can act more like programmable accounts. Each step has historically introduced new attack surfaces even as it expanded functionality.

Market Impact

The finding is unlikely to move Ethereum's price directly, but it could influence how quickly wallet providers and users adopt the new delegation feature. Security concerns around early account abstraction tools may slow integration among exchanges, custodians, and retail wallet apps that would otherwise move fast to support new standards.

For the broader Ethereum ecosystem, the episode underscores a recurring pattern: new capabilities that expand what wallets can do also expand what attackers can attempt. Developers and auditors will likely watch subsequent transaction data closely to see whether the share of malicious activity declines as the feature matures and defenses improve.

The reported dominance of attackers in early use of Ethereum's smart wallet delegation feature highlights the tension between innovation and security in blockchain upgrades. How quickly the ecosystem addresses these risks may shape trust in future account abstraction tools.

Frequently Asked Questions

What is Ethereum's new smart wallet feature?

It allows standard Ethereum wallets to temporarily gain smart contract capabilities, part of the network's ongoing account abstraction efforts.

What did the reports find?

CryptoSlate and The Cryptonomist both reported that 63% of early transactions using the feature were linked to attackers rather than typical users.

Why would attackers target a new wallet feature?

New blockchain functionality often attracts attackers early, since security tooling and user awareness typically take time to catch up with new capabilities.

Does this mean the feature is unsafe for all users?

The reports describe activity during the feature's early rollout period and did not detail total transaction volumes, so the long-term risk profile remains to be seen.