Ivo 7702/acc

7.2K posts

Ivo 7702/acc banner
Ivo 7702/acc

Ivo 7702/acc

@Ivshti

CEO & founder @Ambire; Entrepreneur and coder for 15 years, started with gamedev, cofounded @heyAura, now building the future of web3 UX

Katılım Ocak 2010
1.1K Takip Edilen3.3K Takipçiler
Ivo 7702/acc
Ivo 7702/acc@Ivshti·
posting this every day until i stop seeing slop
Ivo 7702/acc tweet media
English
1
0
11
199
Ivo 7702/acc
Ivo 7702/acc@Ivshti·
@Marczeller @ambire did you try using it with revoke btw? Last time I checked Ambire was the only one that could multi-revoke seemlessly in one actual txn
English
0
0
4
107
Ivo 7702/acc retweetledi
Marc Zeller
Marc Zeller@Marczeller·
I'm updating the Golden trio of onchain safety: 1) Own a hardware wallet, with the new clear signing framework, screen output will go from gibberish to human-readable. 2) Import your hw into @ambire, they cooked, I migrated to it and it's now the best wallet for the EVM experience, check their simulation. 3) create a @safe, even if 1/1 at first, use tenderly simulation. Bonus: generate a hotwallet without any funds, make it a proposer on your safe and give the private key to your agent to generate the transactions and batchs for you, no more clicking buttons, no more clunky UIs, just prompt then verify simulations at each layer and sign at the end. Voila, this setup makes you safe, 100x your crypto UX and makes unc Kim sad.
English
37
37
540
78.5K
Arik Galansky
Arik Galansky@arik_g·
Different wallets have different positioning, it's very cool to see the @ambire approach of diving head first into new technologies, like account abstraction and clear signing. ERC-7984 confidential token support next? @zama can help...
English
4
0
24
655
Ivo 7702/acc
Ivo 7702/acc@Ivshti·
@Trecc_finance @Xylon_lew i assume this is AI slop but i'll address it anyway - there are plenty of legitimate cases, it's not exactly an open design space - ambire uses it and almost all txns use 7702 - nobody notices things when they work, people only notice them when they're hacks/exploits
English
2
0
2
36
Trecc
Trecc@Trecc_finance·
@Xylon_lew @Ivshti honestly? none yet. that's the problem. legitimate ux for 7702 delegation is still an open design space. whoever ships it first and makes it intuitive wins wallet market share by default.
English
1
0
4
37
Ivo 7702/acc
Ivo 7702/acc@Ivshti·
EIP-7702 is the greatest marketing disaster in Ethereum history... - no mainstream (or any that I know of) wallet implements a flow for signing an arbitrary delegation - attackers use EIP-7702 once they have the user's private key, to make draining easier - user sees EIP-7702 on chain and immediately thinks "I got phished into signing a delegation", not "my private key is compromised" For anyone in this situation who doesn't believe me, just send funds to your compromised address on a DIFFERENT chain. You will see a NEW delegation appear, without your involvement, and your funds get drained.
TailTop Re:Born🌙@tail_top_re

EIP-7702委任が設定される原因は、主に2つあると思っています。 1つ目は、悪質サイトでEIP-7702 Authorizationに署名してしまうケース。 見た目は「Claim」「Verify」「Connect」「Gasless」「Enable smart account」など普通の操作に見えても、実際には自分のEOAを不明なコントラクトへ委任する署名になっている可能性があります。 2つ目は、シードフレーズや秘密鍵の漏洩。 この場合、犯人がこちらの代わりに各チェーンで委任を設定できるため、委任を解除しても根本的には安全とは言えません。 今回、自分のウォレットではBaseだけでなく、Ethereum / BNB / PolygonにもEIP-7702委任が入っていました。 なので、EIP-7702をRevokeできたとしても、そのウォレットをメイン利用に戻すのは危険だと判断しています。 旧ウォレットはロック資産回収・監視専用。 今後のメイン利用は新しいウォレットへ移行。 これが安全だと思います。 「Approveを消せばOK」ではなく、RabbyのApprovalsで「EIP-7702」タブも必ず確認してください。 見慣れないDelegated Addressがあれば、かなり危険です。

English
4
16
74
10.6K
Ivo 7702/acc
Ivo 7702/acc@Ivshti·
Delegations ARE for a particular chain. But this is exactly what I'm saying. If you send money to a new chain on the same acc, the attacker will sign a NEW delegation, proving that they have the private key. (technically, there is a cross-chain delegation but in practice it can't work because its tied to the account nonce; this only works if you're starting from a new acc)
English
0
0
2
146
Ivo 7702/acc
Ivo 7702/acc@Ivshti·
@hanni_abu read my post again I'm saying it's a marketing disaster, not a disaster it's a fantastically designed and executed EIP that had huge potential, only to be ruined by bad rep and adopted pretty much only by ambire and metamask
English
1
0
11
487
hanniabu.eth (Ξ, α)
hanniabu.eth (Ξ, α)@hanni_abu·
@Ivshti If I'm not mistaken, doesn't Ambire recommend using 7702? If it's so bad then isn't it not great we're exposing users to this?
English
2
0
0
539
Ivo 7702/acc retweetledi
alphacruze.eth(Hate Cabal Warlord)
People keep making misleading posts and articles about 7702 delegations and it's genuinely just hurting AA at the end of the day All wallets handle their own AA, and a wallet would not drain you
Ivo 7702/acc@Ivshti

Once again, absolutely misleading. Wallets don't let you sign arbitrary EIP-7702 delegations. There simply is no flow for this. Your private key got compromised, and THEN an attacker made a malicious delegation to make their life easier. It's not "via" the EIP-7702 delegation

English
1
1
7
381
Ivo 7702/acc
Ivo 7702/acc@Ivshti·
first of all, sorry for your loss - I shouldn't have focused on the technical parts first, considering the state of our industry and how error prone it is. Second - which wallet did you sign this with? I've never heard of any wallet that allows arbitrary 7702 delegations, this should be investigated
English
1
0
1
209
TailTop Re:Born🌙
TailTop Re:Born🌙@tail_top_re·
【注意喚起】EIP-7702委任で資産を抜かれました。 今回、SoSoValueでロックしていたUSSI/USDCのLPをクールダウン後にWithdrawしようとしたところ、資産がウォレットに戻った直後に抜かれました。 最初はApprove被害かと思いましたが、Basescanを確認すると、自分のアドレスに 「Delegated to: 不明なアドレス」 という表示が出ていました。 これは通常のERC-20 Approveとは別で、EIP-7702による委任状態です。 EIP-7702は、EOA(普通のウォレット)にスマートウォレットのような機能を持たせるための仕組みです。 便利な機能である一方、悪意あるコントラクトに委任されていると、ウォレットに入ってきた資産が自動で抜かれるような挙動につながる可能性があります。 実際、自分の場合はBaseだけでなく、Ethereum、BNB、PolygonにもEIP-7702委任が残っていました。 確認・解除はRabbyでできます。 手順👇 1️⃣ Rabbyを開く 2️⃣ Approvalsへ 3️⃣ 上部タブの「EIP-7702」を確認 4️⃣ 不明なDelegated Addressがあれば選択 5️⃣ Revokeを実行 6️⃣ 各チェーンのExplorerで「Delegated to」が消えたか確認 自分の場合、EthereumではEtherscan上の「Delegated to」表示が消えたので、解除できた可能性が高いです。 ただし、委任を解除できても、そのウォレットを完全に安全扱いするのは危険です。 なぜ委任されたのかが不明な場合、秘密鍵漏洩・悪質署名・偽サイト接続・端末汚染などの可能性も残ります。 なので基本方針は、 ✅ EIP-7702委任を確認 ✅ 不明な委任はRevoke ✅ Explorerでも確認 ✅ 旧ウォレットは監視・回収専用 ✅ 今後のメイン利用は新ウォレットへ移行 これが安全だと思います。 特に、ステーキングやロック資産がある人は本当に注意してください。 ロック解除後に資産が戻った瞬間、委任先に抜かれる可能性があります。 SoSoValueが悪いという話ではなく、危険な委任状態のウォレットでWithdrawしてしまったことが原因だと見ています。 自分のように実際に抜かれるまで気づかない人も多いと思うので、今すぐRabbyのApprovalsで「EIP-7702」を確認してみてください。 これはApproveとは別枠です。 見慣れないDelegated Addressがあったら、かなり危険です。 #EIP7702 #WalletSecurity
TailTop Re:Born🌙 tweet media
日本語
14
105
363
61.1K
Ivo 7702/acc
Ivo 7702/acc@Ivshti·
@tail_top_re false, not possible. There's no flow in mainstream wallets (metamask, rabby, ambire, etc) for this to happen with a request from a website. Your PK got leaked.
English
1
1
3
406
TailTop Re:Born🌙
TailTop Re:Born🌙@tail_top_re·
EIP-7702委任が設定される原因は、主に2つあると思っています。 1つ目は、悪質サイトでEIP-7702 Authorizationに署名してしまうケース。 見た目は「Claim」「Verify」「Connect」「Gasless」「Enable smart account」など普通の操作に見えても、実際には自分のEOAを不明なコントラクトへ委任する署名になっている可能性があります。 2つ目は、シードフレーズや秘密鍵の漏洩。 この場合、犯人がこちらの代わりに各チェーンで委任を設定できるため、委任を解除しても根本的には安全とは言えません。 今回、自分のウォレットではBaseだけでなく、Ethereum / BNB / PolygonにもEIP-7702委任が入っていました。 なので、EIP-7702をRevokeできたとしても、そのウォレットをメイン利用に戻すのは危険だと判断しています。 旧ウォレットはロック資産回収・監視専用。 今後のメイン利用は新しいウォレットへ移行。 これが安全だと思います。 「Approveを消せばOK」ではなく、RabbyのApprovalsで「EIP-7702」タブも必ず確認してください。 見慣れないDelegated Addressがあれば、かなり危険です。
日本語
2
7
25
13.6K
Ivo 7702/acc
Ivo 7702/acc@Ivshti·
@J222ad lmao we have a warning for non-ascii character tokens but not for this yet
English
0
0
1
87
#jad
#jad@J222ad·
A gang of drainers deployed a malicious contract hiding behind the $ token symbol, tricking transaction simulators into showing fake balance gains in $ 🤣while quietly siphoning real ETH to their wallet.
#jad tweet media
English
2
2
9
545
Ivo 7702/acc retweetledi
Josh Payne
Josh Payne@jnpayne·
Second-time founders be like… > GTM > PMF > Go fully remote > Profitability is king > Must have a Big TAM > Outsource non-core tasks > Have great advisors/investors > Prioritize customer conversations > Focused on retention over growth > Hire fewer, more experienced people > Document everything on Notion/Slack > Thinking in decades and acting in days None of this stuff came from a book. It came from living through the first company. The price of admission was worth it.
English
60
74
1K
83.2K
Ivo 7702/acc retweetledi
۟
۟@MINHxDYNASTY·
if mfs defended crypto as much as they did peptides, wed be at $250k bitcoin lock in
English
1
1
13
1.7K
Ivo 7702/acc retweetledi
Snapshot.eth
Snapshot.eth@SnapshotLabs·
@ambire voted to close Rewards Season 2 with no payout after users hit $1.27M of a $2M swap and bridge volume target, about 63% of the goal. The season had already been extended once. With the target still out of reach, the team framed the close as "rewards follow real volume, not promises." 58% of voting power backed the clean close. 42% pushed for a 50% partial payout worth $50K in $WALLET, arguing participants earned something for getting two-thirds of the way there. The largest no-payout voter argued the market itself was the problem: "statistically speaking, most of the previously claimed tokens were sold... the market is way too tired and value-extracting for this to work in favor of $WALLET." One partial-payout backer pushed a broader rethink: pause the rewards program entirely and redirect $WALLET toward onboarding power users and mobile download incentives instead of volume targets. Closed with 53 wallets participating and a ~9M token margin. Proposal: snapshot.box/#/s:ambire.eth…
Snapshot.eth tweet media
English
1
4
11
602