EIP-7702 “Upgrade Your Wallet” Scams and Batched-Call Drains During Airdrop Claims: 2026 Checklist
Since Ethereum’s Pectra upgrade, a normal wallet address can be “upgraded” into a smart account through EIP-7702. Wallets use this for useful things: batching an approval and a swap into one confirmation, or letting someone else pay the gas. Scammers have adapted too. Fake claim pages now tell you to “upgrade your wallet to claim,” and batched requests can bundle several token approvals or transfers behind a single button. This 2026 checklist explains what an EIP-7702 delegation actually does, which upgrade and batch prompts are red flags during airdrop claims, how to read a batched request, and what to do if you already approved one. It builds on our blind signing vs clear signing checklist and the fake gas token and approval drain checklist. Educational safety information only. It is not financial, legal, or investment advice, and there is no recovery guarantee.
What EIP-7702 changes for your wallet
Pectra activated on Ethereum mainnet on 2025-05-07, according to the Ethereum Foundation’s Pectra mainnet announcement. One of its changes, EIP-7702: Set Code for EOAs, lets a regular account (an “externally owned account,” controlled by your seed phrase) point to a smart contract and run that contract’s code as if it were its own.
The mechanics matter for safety:
- You sign an authorization that names a chain ID, a contract address, and your account nonce. Once it is included on-chain, your address carries a “delegation indicator” pointing at that contract.
- Your address, balance, and seed phrase stay the same. MetaMask’s What is a smart account page stresses that funds don’t move and the account is still governed by your recovery phrase.
- The delegation persists until you replace it or reset it by delegating to the null (zero) address.
- The delegated contract has full reach. The EIP itself warns that the code an authorization points to “has unrestricted access to the account,” and that a poorly implemented delegate can let an attacker take near-complete control.
In other words, the authorization is the most powerful thing an Ethereum account can sign. A token approval exposes one token. A delegation to a malicious contract exposes everything the address holds.
Why claim season makes this risky
The EIP’s authors say applications should not ask users to sign authorizations directly, and that wallets should not offer an interface for it. ethereum.org’s EIP-7702 guidelines repeat the point: dApps should go through standard wallet interfaces such as batched calls instead of requesting delegations, and hardware wallets should only allow a list of trusted delegation contracts. Mainstream wallets follow that model. MetaMask, for example, only upgrades accounts to its own audited delegator contract, and only from inside the wallet.
That gives you a simple rule, but scammers work around it in three ways:
- The fake “upgrade to claim” page. A cloned claim site says your wallet is “not eligible until upgraded” and sends you to an off-wallet tool. That tool either asks for your seed phrase or private key, or asks you to sign through a wallet or script that exposes raw authorization signing. Either way, the target is a contract the attacker controls.
- Malicious batched calls. If your account already is a legitimate smart account, a dApp can request several calls at once using the ERC-5792 wallet_sendCalls standard. That is convenient for honest apps, but a phishing claim page can bundle “claim” with approvals or transfers of your other tokens behind one confirmation.
- Cross-chain authorizations. ethereum.org warns that an authorization signed with
chain_id = 0applies on every EVM chain. A single bad signature can expose the same address on networks you rarely check.
MetaMask’s smart accounts announcement says it plainly: ignore anyone trying to get you to upgrade outside the wallet. Real upgrade prompts come from the wallet’s own banner, its account details screen, or a compatible dApp transaction inside the wallet.
Red flags before you click “Upgrade” or “Confirm”
- A claim page or DM says you must upgrade your wallet to receive an airdrop. Eligibility is decided by the project’s snapshot or contract, not by your account type.
- The upgrade happens anywhere other than your wallet’s own settings, for example on a website, in a browser extension you just installed, or through a “support agent.”
- The delegation target is a contract you can’t identify as your wallet vendor’s published delegator. ethereum.org keeps a table of known audited implementations for reference.
- Anyone asks for your seed phrase or private key to “activate,” “sync,” or “validate” a smart account. That is always a scam. See our DM impersonation checklist.
- A batched request includes approvals, permits, or transfers out when all you expected was to receive tokens.
- The wallet shows a simulation where any token leaves your account during a “claim.”
How to read a batched claim request
When a wallet shows a batched transaction, it usually lists each call and often a simulated balance change. Take thirty seconds and work through it:
- Count the calls. A typical claim is one call, sometimes two (claim, then stake or delegate votes). A batch of many calls during a claim is a reason to stop and ask why.
- Read each call. Is it a receive, an approval, or a transfer? Approvals should name a spender you can match against the project’s official docs.
- Check the outflows. Look at the simulated balance changes. If anything other than gas leaves your account, cancel.
- Watch for “unlimited.” An unlimited allowance to an unknown spender is the classic drainer pattern, batched or not.
- If the wallet can’t decode a call, treat it like blind signing. Cancel unless you can verify it independently.
Set up your accounts before claim season
- Keep a vault account that never connects to claim sites. Decide deliberately whether it needs smart account features at all.
- Use a separate claim account with only the gas it needs. If you use smart account features there, enable them only through your wallet’s own settings.
- Know your current status. MetaMask shows smart account status per network under account details. Block explorers also mark addresses that carry a delegation. Check the networks you use, not just mainnet.
- Bookmark claim pages from the project’s official website or docs instead of using search results or replies. Our claim-site phishing checklist covers that routine.
- Keep firmware and wallet apps updated from official sources only, since delegation warnings and batch decoding arrive through updates.
If you already approved a suspicious upgrade or batch
Speed matters, but so does order. If your account is delegated to a malicious contract, the attacker’s code can act on your address whenever it is called.
- If you typed your seed phrase or private key anywhere, assume the account is lost. Move what you can to a brand-new wallet with a new seed phrase. Resetting a delegation does not help if the attacker has your key, because they can sign a new one.
- Move remaining assets from the affected address to a fresh account you control. Be aware that some malicious delegates sweep incoming ETH automatically, so don’t keep sending gas into an address that keeps emptying itself.
- Reset the delegation on every affected network. In MetaMask, follow How to switch to or revert from a smart account. Under the hood, a reset is an authorization to the zero address, as described in the EIP.
- Revoke token approvals separately. Removing a delegation does not cancel approvals you granted. Use ethereum.org’s guide on revoking smart contract access.
- Document and report. Save transaction hashes, addresses, and the site URL. Report to the FBI’s IC3 cryptocurrency page or ReportFraud.ftc.gov in the U.S., or your national cybercrime service elsewhere.
- Ignore recovery offers. The FTC’s cryptocurrency scams guidance notes that crypto payments usually lack the protections of cards. “Recovery services” that charge upfront are a known follow-up scam.
Safety checklist (YMYL)
- No airdrop requires you to “upgrade” your wallet. Treat that demand as a drainer red flag.
- Upgrade to a smart account only from your wallet’s own settings, to the wallet vendor’s published delegator.
- Never share a seed phrase or private key, for any reason.
- Read every call in a batch. Any outflow or unlimited approval during a claim means cancel.
- Check delegation status on each network you use, not just Ethereum mainnet.
- After a mistake: move funds, reset the delegation, revoke approvals, then report.
Key takeaways
- An EIP-7702 delegation gives a contract control over your whole address, so it is far more powerful than a single token approval.
- Legitimate upgrades happen inside your wallet. Websites asking you to upgrade are a scam signal.
- Batched calls make good apps smoother and bad apps more dangerous, so read the whole batch.
- Delegations can be reset, but approvals and a leaked seed phrase need separate fixes.
Sources and further reading
- EIP-7702: Set Code for EOAs and ERC-5792: Wallet Call API
- ethereum.org: Pectra EIP-7702 guidelines
- Ethereum Foundation: Pectra Mainnet Announcement
- MetaMask Help Center: What is a smart account
- MetaMask Help Center: Signature phishing
- FTC: What To Know About Cryptocurrency and Scams
Related CoinDrop guides: fake “Connect Wallet to verify eligibility” drains, address poisoning after claims, and cryptocurrency airdrop safety considerations.
Not financial, legal, or investment advice. This article is general educational information about a common crypto risk. Wallet smart account features, supported networks, and delegation settings change with updates; confirm current guidance in your wallet vendor’s official documentation. CoinDrop does not endorse any wallet vendor or recovery service and cannot recover funds. Last verified 2026-10-07.