Foreign Code on Your Ethereum Address: How to Check Your EIP-7702 Delegation
Since the Pectra upgrade, a single signature can be enough for your Ethereum address to run the code of someone else's contract. Our own measurement across 200 blocks shows what these delegations mostly point to today, and how to check your own address in a few minutes.

Table of Contents
Table of Contents



Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
An Ethereum address that belongs to you has been able to execute someone else's program code since the Pectra upgrade, without its address, its balance or its key changing at all. EIP-7702 is what makes this possible: one signature from you is enough, and from that moment on your address behaves like a contract. This is the basis for many convenient wallet features, and it is also the route by which attackers keep a drained account permanently under their control. This article shows you how to check in two minutes whether your own address carries such a delegation, and what to do if the contract sitting there is one you do not recognise.
The basis for this is our own measurement on the Ethereum chain, taken today. It shows how widespread these delegations have become and what they mostly point to. The answer is more uncomfortable than wallet marketing suggests, but also more nuanced than a bare percentage implies.
What an EIP-7702 delegation does to your Ethereum address
EIP-7702 is an extension to Ethereum that lets an ordinary key-controlled account run the program code of a contract without becoming a contract itself. The account keeps its private key, its address, its balance and its nonce. All it gains is a pointer to a contract whose code runs on the account's behalf on every call.
The technical term for this is delegation. The pointer is written into the account's code field, which until then was empty for a key-controlled account. From that moment on, anyone calling the account calls the stored contract, and that contract reaches the account's storage and balance.
The benefit is obvious. A wallet can bundle several steps instead of asking you to sign three times. A provider can cover the fee on your behalf. An app can set up a tightly bounded spending permission that expires after an hour. These are exactly the features wallet makers have been selling under the Smart Account label since 2025.
The price sits in the same sentence: the stored contract acts with your account's full authority. It can move funds, grant approvals and trigger further calls. A delegation is therefore not a setting but a power of attorney, and it stays in place until you replace it or revoke it.
The 0xef0100 code prefix: how to spot a delegation in a block explorer
A delegated account carries exactly 23 bytes in its code field: the fixed marker 0xef0100 followed by the 20 bytes of the target address. That marker is the only reliable evidence. Everything else an interface shows you is interpretation.
In practice you see it in two places. A block explorer suddenly lists your address as a contract, or displays a note about a delegated account, even though you have never deployed a contract. And the code lookup that every explorer offers returns, instead of an empty value, a short string beginning with ef0100.
The 20 bytes that follow are the address you have to check. They decide everything. If your wallet maker's contract address is sitting there, the delegation is probably intended. If something unfamiliar is sitting there, you have a problem that goes well beyond a misplaced click.
One point matters for context: an empty code field is the good news. If you find nothing there, you have no active delegation, regardless of whether one existed in the past.
How to check an EIP-7702 delegation: four steps in this order
The check takes a few minutes and needs neither a tool nor an installation.
- Open the address in a block explorer. Enter your Ethereum address and look at whether the page lists it as an ordinary account or as a contract. A note about a delegated account is already the result.
- Look at the code field. Open the tab with the stored code. Empty means no delegation. A short string beginning with
ef0100means the delegation is active. - Read out the target address and look it up. The 20 bytes after the marker are the target address. Look it up and check whether verified source code is available and what name that source code carries.
- Interpret the result before you move anything. If you do not know the contract, send no further funds to the address, not even a fee. The next section explains why that is the most important rule on this list.
The same check works on every chain where EIP-7702 is live. An authorisation signed for chain ID zero is even valid on all chains at once. Anyone using several networks is better off checking more than once.

Our own measurement of September 13, 2026: 4,035 delegations in 40 minutes
This analysis was carried out by cryptoticker.io itself on September 13, 2026. Method: we pulled 200 consecutive blocks in full from a public Ethereum node, blocks 25,971,139 to 25,971,338, and evaluated every transaction of type 0x04 in them together with its authorisation list. The window runs from 21:14:35 to 21:54:23 UTC and covers 39.8 minutes of chain time.
The numbers from that window:
- 41,110 transactions in total, of which 1,229 were delegation transactions. That is 2.99 percent of total transaction volume.
- 4,035 individual authorisations, since a single transaction may carry any number of them. 889 transactions carried exactly one; the largest carried 110.
- 56 distinct target addresses. Of the 55 actual contracts among them, 15 had publicly verified source code and the remaining 40 did not.
- 140 authorisations, or 3.5 percent, pointed to the zero target address. Those are revocations, not new powers of attorney.
- The four most frequent targets account for 71.7 percent of all authorisations between them.
What we could not measure is how many accounts currently carry a delegation in total, because that would require a full state dump of the chain rather than a time window. Nor can these data show how much money was moved through the contracts we found. And a 40-minute window is a snapshot: another day may show a different distribution.
Poisoner and CrimeEnjoyor: what the verified source code of the largest targets says
In this measurement the names say more than the shares do. Publicly verified source code is available for two of the three most frequent targets, and both describe themselves as tools used by criminals.
The most frequent target, with 2,007 authorisations, or 49.7 percent of the window, carries the name Poisoner in its verified source code. The comment in the source names the purpose outright: the contract is used for address poisoning, that is, to trick inattentive users into sending funds to a wrong address that looks visually similar. As the party behind the publication, the source names the trading firm Wintermute, which says it rebuilt and disclosed the contract. The program code itself is short: it executes a list of arbitrary calls, but only if the transaction was triggered by exactly the address that created the contract.
The third most frequent target, with 170 authorisations, carries the name CrimeEnjoyor. Here too the explanation sits in the source code, and it is set in capital letters: anyone who finds this contract in an authorisation list has a compromised account; no further funds may be sent there, because they will be swept immediately. The code is shorter still than that of the first contract. It does precisely one thing: every incoming amount is forwarded straight away to a target address fixed at setup.
For comparison, the legitimate side of the same list: in eighth place sits a verified contract from a well-known wallet maker with 110 authorisations, alongside several contract accounts from the account-abstraction world with 10 to 49 authorisations each. Those contracts run to several thousand bytes, while the two conspicuous targets get by on 772 and 1,042 bytes. A contract that only sweeps needs little code.
Why a 49.7 percent share does not mean 2,007 victims
Care is needed here, because the percentage invites a false conclusion. So we looked at who actually sent these transactions.
The result: the 2,007 authorisations pointing at the top-ranked contract come from 186 transactions, and those 186 transactions came from a single sender. With 176 distinct senders across the whole window, almost half of all authorisations therefore trace back to one address that registers bundles of up to 110 powers of attorney at a time, minute after minute.
Our reading of this, and it is explicitly a reading rather than an established fact: the pattern does not fit 2,007 freshly harmed users, but rather an operator kitting out their own throwaway addresses. Besides the single sender, the design of the contract supports that view, since it only executes calls for its own creator. In address poisoning the attacker generates the deceptively similar addresses themselves and needs no one else's key to do so. What we are measuring in this case is infrastructure rather than loot.
The second conspicuous contract looks different. Its 170 authorisations are spread across 170 separate transactions from two senders, so one power of attorney per transaction. A collection contract that forwards incoming amounts immediately only makes sense for an account whose key is already in someone else's hands. For you as a reader the difference is decisive: the first case almost certainly does not concern you, the second concerns you directly if your account appears on that list.

Found a sweeper contract? Why revoking alone is not enough
A sweeper is a contract or program that forwards incoming amounts to an outside address automatically and within seconds. If you find a delegation to such a contract on your address, the delegation is not the cause but the consequence. Someone was able to sign in your name, and that requires your private key or your recovery words.
From this follows an order of operations that runs against the first reflex. The reflex says: revoke the power of attorney and move on. The correct view is this: the account is lost, and every amount you send there, including the fee for the revocation, will very likely go to the attacker. A revocation you pay for yourself funds the other side, in case of doubt.
So set up a new account first, ideally on a device whose key has never sat on a computer. Which designs come into question, and how the devices differ, is laid out in our software wallet comparison alongside the device selection. Only afterwards do you deal with whatever is left on the old account, and you do so with help.
For exactly this case there is a free point of contact, one that the sweeper contract's own source code names: the Flashbots whitehat hotline. It helps get remaining balances past a sweeper by settling the rescue and the fee in a single bundle that the sweeper cannot pick off separately. That is no guarantee, but it is the only serious route that requires no payment up front.
Revoking it properly: the zero target address as the only ending
If the account is clean and the delegation is merely unwanted, because you no longer use a wallet feature for instance, then revoking it is simple and still easy to misunderstand.
A delegation does not end because you delete the app, change device or withdraw an approval. It ends solely through a new authorisation pointing at the zero target address, that is, an address made up entirely of zeros. Only then does your account's code field become empty again. Our measurement shows that this step does occur in practice: 140 of the 4,035 authorisations in the window were revocations of this kind.
Check the code field once more after revoking. An interface reporting success to you is not evidence. The evidence is an empty code field in the explorer.
A second point is easily overlooked: a new delegation replaces the old one entirely. Anyone switching from one wallet provider to another ends up with the new provider's power of attorney in the account, not both. That is reassuring, but it does not remove the need to check, because which contract ends up sitting there is decided by the most recently registered authorisation.
Authorisation without gas: why a signature on someone else's site is enough
The most dangerous part of EIP-7702 is its price. An authorisation is a pure signature. It costs you nothing, it shows up in no fee summary, and you do not even have to submit it yourself: any third party may wrap it into a transaction of their own and cover the fee.
For honest providers that is an advantage, because a new account becomes usable straight away without holding funds. For a fraudulent site it is a gift. It needs no transfer from you, no approval and no balance on the account. A single signature in a window that looks like a login, a claim for free tokens or a security check is enough.
From this follows a rule for everyday use: treat every signature request whose content you cannot read as if it were a transfer. That applies in particular to requests asking you to update, migrate or secure an account. You already know this trick in its classic form from the world of manipulated payment recipients; how it plays out there was covered in our August analysis of address poisoning.
Legitimate delegations: how to recognise a genuine wallet account
It would be wrong to conclude from all this that every delegation is an attack. Alongside the conspicuous targets, our measurement also shows a number of clearly attributable wallet contracts, among them the contract of a large browser wallet provider and several account templates from the account-abstraction world.
Three characteristics separate the two groups fairly reliably in practice:
- The source code is publicly verified and carries a name that matches the provider. In our window that applied to 15 of 55 target addresses. Missing source code is no proof of anything malicious, but it is a reason not to proceed.
- The contract is substantial. Account templates weigh in at several thousand bytes, because they bring signature checking, permission management and interfaces with them. The conspicuous targets in our measurement came in under 1,100 bytes.
- You triggered the delegation yourself. A wallet switching to a smart account says so in advance and displays the target address. A delegation you do not remember is a finding.
Anyone working with several wallets regularly should note down their own provider's target address once. The check then becomes a comparison of twenty bytes next time, rather than a research task.
Hardware wallets and blind signing: why the device does not automatically protect you here
A common misconception holds that a hardware wallet makes this question moot. That is true for the key, but not for the power of attorney. An EIP-7702 authorisation is also signed with the private key, and in the worst case the device displays only a target address and a nonce, without being able to explain what follows from them.
What matters, then, is whether your device presents the content of a signature request in plain text and whether you have switched off the signing of unreadable data. What counts here was set out in our article on blind signing on hardware wallets. The recommendation from there applies unchanged: what the device cannot display, you do not sign.
The second protection is the separation of duties. One account for day-to-day dealings with applications, a second for holdings that stay put, and no signature from the second account on any website. A delegation on the everyday account is annoying; a delegation on the holdings account is expensive. If you need the technical wording of the specification, you can read it in the text of EIP-7702, in particular the rules for chain ID zero.
How to check an EIP-7702 delegation: what to take away
- Look at the code field of your main address today. Empty means you are fine. A string carrying the marker
ef0100means: read out the target address and look it up. Start with the addresses that actually hold something, and then set those holdings up on a device you pick from the hardware wallet comparison. - If you do not know the contract, send nothing further to that address. Not even a fee for a revocation. Treat the key as lost, set up a new account and handle the rest through the whitehat hotline. Whatever you want to move to safety in the short term is for now better placed in an account at a supervised trading platform than at an address whose power of attorney you do not control; the selection for that is in our overview of crypto exchanges.
- Actively revoke intended but unused delegations. Only an authorisation pointing at the zero target address ends one, and only an empty code field in the explorer proves it worked. Anyone running several wallets in parallel should note down their own providers' target addresses; which programs display this feature cleanly is covered in the software wallet comparison.
(As of September 13, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.
Related articles
- Check Your Safe Wallet Modules: How One Module Moved $7.7 Million Without a Signature
- Wallet Drainers: What You Really Approve When You Confirm, and How to Take It Back
- Adding a Network, Bridges and Explorers: Switching Blockchains in 2026
- Breaking: Trust Wallet Chrome Extension Hack Drains $7M, Full Reimbursements Promised
- Beware of New Ethereum Node Scam: USDT Fraud Exposed
Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
March 6, 2025 7:00 PM

What is Ethereum Pectra Upgrade?
Ethereum's Pectra upgrade is set to revolutionize the network with enhanced scalability, lower fees, and smart accounts. Here's all you need to know about the Ethereum Pectra upgrade.
February 24, 2026 4:28 PM

Can Ethereum Price Crash to $0? Analyzing Ethereum Blockchain
Ethereum's price is under pressure as the crypto market faces a downturn. We analyze if ETH can truly hit $0 and what its ecosystem value means for the future.
March 31, 2026 5:13 PM

Quantum Threat to Bitcoin? Google Research Sparks Urgent Crypto Security Debate
Google’s quantum breakthrough raises fears for Bitcoin security. Can crypto survive quantum attacks—or is an upgrade urgent?
May 22, 2024 7:27 PM

SEC 'APPROVES' Ethereum Spot ETF: Will It Happen TOMORROW?
May 23rd is the anticipated day for SEC to announce its decision concerning ETH spot ETF. In less than 24 hours, an approval, rejection, or postponement will be among the top headlines, but what do analysts foresee?
August 3, 2022 9:22 AM

What are the BEST Ethereum Wallets in 2022?
What are the best Ethereum wallets in 2022? In this article, we talk about the best Ethereum wallets for 2022 and help you pick the best.
March 12, 2020 1:12 PM

What Is A Cold Wallet? And Why Is It Important?
A cold wallet is a wallet which is completely offline and used for storing cryptocurrencies. It is also known as cold storage.
August 25, 2026 10:11 PM

Ledger Closes a Gap in the Ethereum App: When the Display Shows Something Other Than What You Sign
Ledger has closed a flaw in its Ethereum app that let a malicious application swap the reviewed transaction for a different one. Anyone holding Ether or ERC-20 tokens on the device should check the app version and clear out old token approvals.
July 8, 2023 2:55 PM

Which Crypto Network was the MOST Hacked? You’ll know the answer…
Which crypto network was the most hacked and why did this happen? In this article, we analyze why hackers targeted a specific network.
August 14, 2019 2:21 PM

What is Ethereum Virtual Machine?
The Ethereum Virtual Machine (EVM) is a robust, sandboxed virtual implicit enclosed within each complete Ethereum node, capable of performing contract bytecode. Contracts are normally inscribed in higher-level languages, like Solidity, then gathered to EVM bytecode. Virtual machines are actually […]
July 23, 2020 9:31 AM

Argent v1 Smart Wallet – 1-Click Comprehensive DeFi On The Go
The Argent team announced the release of the first version of their crypto wallet with built-in comprehensive DeFi functionality on May 18. According to the release notes – “Argent is now the easiest way to access DeFi, starting with TokenSets, […]
September 14, 2026 10:13 AM

Revoke Token Approvals on Ethereum: A Revocation Now Costs 0.52 Cents
Every decentralized exchange, every lending pool and every bridge asks for a token approval, and it keeps running after the swap is done. We counted 5,910 approvals and worked out what a revocation really costs today.
September 10, 2026 1:28 AM

End Blind Signing: What to Check on Your Hardware Wallet After the Trezor Update
Since September 7, Trezor has shown contract data in plain text on the device instead of a hexadecimal string alone. Our own count shows which share of Ethereum capital that reaches and where you keep signing blind.
August 30, 2026 1:22 AM

Ajna Exploit: $775,400 Drained and No Pause Button in the DeFi Lending Protocol
Between August 28 and 29, 2026 roughly $775,400 drained out of seven Ethereum pools of the lending protocol Ajna v2. Because the contract is immutable and has no governance, there is no pause button: users have to withdraw themselves.
February 19, 2024 4:41 PM

Web3 Security Essentials: A Guide to Web3 Security
This comprehensive guide delves into the aspects of Web3 security, offering in-depth insights for safely navigating this world.
January 12, 2024 12:27 PM

Guide to Choosing the Best Crypto Wallets in 2024
Explore the best crypto wallets of 2024 in our comprehensive guide. Discover top choices for security, convenience, and versatility in cryptocurrency management.
December 16, 2023 4:33 PM

BREAKING NEWS: NFT Trader Hit in Largest NFT Hack to Date?
NFT Trader Hit in Largest NFT Hack. Let's take a look at this in more detail as the NFT community is grappling with the profound impact.
October 29, 2023 1:47 AM

Exploring ERC-4337 on Etherscan: A Comprehensive Guide to Enhanced Ethereum Transactions
Unlock the potential of Ethereum with our comprehensive guide to ERC-4337 on Etherscan. Learn about smart contract wallets, User Ops, and Paymasters in this groundbreaking update.
May 17, 2023 7:40 PM

WARNING: Ledger can read Private keys – New Controversial Feature?
Ledger alternatives: Let's explores the details of the new private key extraction feature, and the reasons behind the concerns it has generated.
November 4, 2022 8:09 AM

How to add Avalance (AVAX) to MetaMask?
If you want to contribute to Avalanche's growth, you should look for a suitable wallet (MetaMask). This article is all about how to add Avalanche to MetaMask.
May 6, 2022 11:08 PM

What is the Internet of Things? Meet the Top 3 IoT Crypto Projects!
This article will take a detailed look into the Internet of Things, what to expect from it, and the top 3 projects in the IoT sector.
November 25, 2021 12:56 PM

Ethereum Rollups Will Be 5X Cheaper, Meet EIP4488!
Ethereum rollups will be 5x cheaper as Ethereum devs Ansgar Dietrichs and Vitalik Buterin have put forward a new proposal EIP-4488 on Nov 23.
October 17, 2021 3:57 PM

Top 5 Metamask Alternatives
The cryptocurrency world is full of innovations and exciting things. One such innovation is Metamask. But this post is all about the top 5 Metamask alternatives.
June 8, 2021 9:41 PM

How to send Ethereum from Metamask?
MetaMask was initially available in desktop web browser extensions for Google chrome and firefox. Later in 2020, they released its mobile app version which is available in Android and iOS. MetaMask was audited by legal authorities & found to be exceptionally secure and user-friendly.
January 7, 2021 11:10 PM

Ethereum Has Surpassed It’s Previous ATH Market Capitalization At $144B!
Ethereum - the largest smart contract platform in the world smashed a new record today by surpassing it's previous All Time High (ATH) market capitalization of $136B. The premier asset is currently trading in a range of $1250-$1270, which gives it a market capitalization of $144B. It's momentum appears intact and the previous ATH price record is also likely to be broken in the next couple of hour!
December 8, 2020 6:34 PM

Cryptocurrency ABC – The Crypto Dictionary
Crypto-ABC: The complete overview of the most important words in the cryptocurrency world
July 17, 2019 1:08 PM

Blockchain Trilemma: Explained
The blockchain Trilemma is one of the greatest hurdles for cryptocurrencies. The Trilemma is a situation which involves the three basic concepts of blockchain technology: security, scalability, and decentralization. The Blockchain trilemma states that you can always achieve the three […]
More from CryptoTicker



