最新报道:According to the security agency GoPlus, many recent contract attack cases have used EIP-7702 features to bypass the on-chain security check mechanism, including msg.sender == tx.origin and msg.sender == _owner, resulting in flash loan attacks and price manipulation, with losses reaching nearly one million US dollars. Case analysis shows that attackers used malicious delegator authorization to carry out attacks, affecting well-known DeFi projects including QuickConverter @QuickswapDEX and multiple CSM fund pools. The implementation of EIP-7702 enables EOA addresses to have smart contract capabilities, and traditional security logic is invalid. GoPlus recommends that project parties strengthen flash loan attack protection, reentry attack protection, reconstruct EOA inspection and permission management logic, and continue to pay attention to the delegator authorization of administrator addresses to prevent potential risks.