TechFlow Logo
Login/ Sign up
ETH Gas
Gwei
Fear
gas
7x24hNews

SlowMist: EIP-7702 Account Vulnerability Exploited, 1,988.5 QNT Stolen

2026.04.29 - 04:09
Share

7x24h News

SlowMist: EIP-7702 Account Vulnerability Exploited, 1,988.5 QNT Stolen

According to SlowMist, the attacker exploited a flawed EIP-7702 account to steal 1,988.5 QNT (approximately 54.93 ETH) from the QNT reserve pool. The root cause lies in the fact that the reserve pool’s administrator EOA delegated code to the BatchExecutor contract via EIP-7702, and this BatchExecutor contract authorized the permissionless BatchCall contract as an authorized caller. Since the BatchCall.batch() function lacks any access control checks, any external caller can invoke it—ultimately resulting in the complete depletion of the reserve pool’s assets.

2026.04.29 - 04:09:56

TechFlow News: On April 29, according to SlowMist, an attacker exploited a flawed EIP-7702 account to steal 1,988.5 QNT (approximately 54.93 ETH) from the QNT reserve pool.

The root cause lies in the fact that the reserve pool’s administrator EOA delegated code execution to the BatchExecutor contract via EIP-7702, and this BatchExecutor contract authorized the permissionless BatchCall contract as a caller. Since the BatchCall.batch() function lacks any access control checks, any external caller can invoke it—ultimately resulting in the complete depletion of assets in the reserve pool.

Add to Favorites
Share to Social Media

7x24h News

TechFlow Logo

Navigating Web3 tides with focused insights

Contribute An Articleemail
Media Requestsmsg

Risk Disclosure: This website's content is not investment advice and offers no trading guidance or related services. Per regulations from the PBOC and other authorities, users must be aware of virtual currency risks. Contact us / [email protected] ICP License: 琼ICP备2022009338号