{"id":9020,"date":"2025-02-26T06:24:24","date_gmt":"2025-02-26T05:24:24","guid":{"rendered":"https:\/\/wsj-crypto.com\/?p=9020"},"modified":"2025-02-26T06:24:24","modified_gmt":"2025-02-26T05:24:24","slug":"beware-smart-contract-wallets-in-frontier-exposed-to-phishing-threats","status":"publish","type":"post","link":"https:\/\/wsj-crypto.com\/index.php\/2025\/02\/26\/beware-smart-contract-wallets-in-frontier-exposed-to-phishing-threats\/","title":{"rendered":"Beware: Smart Contract Wallets in Frontier Exposed to Phishing Threats"},"content":{"rendered":"<p><\/p>\n<div id=\"\">\n<p class=\"chakra-text css-gi02ar\"><b>Impacted configurations:<!-- --><\/b><span style=\"font-weight:400\"> All smart contract wallets established using <!-- --><em class=\"chakra-text css-0\">Ethereum Wallet \u00a0Frontier, version 0.4.0 (Beta 7) or earlier<!-- --><\/em>. Wallets created with Ethereum Wallet 0.5.0 and all subsequent releases after March 3, 2016, are unaffected.<!-- --><\/span><\/p>\n<p><!-- --><\/p>\n<p class=\"chakra-text css-gi02ar\"><b>Probability<!-- --><\/b><span style=\"font-weight:400\">: Low<!-- --><\/span><\/p>\n<p><!-- --><\/p>\n<p class=\"chakra-text css-gi02ar\"><b>Impact Level<!-- --><\/b><span style=\"font-weight:400\">: High<!-- --><\/span><\/p>\n<p><!-- --><\/p>\n<h2 class=\"chakra-heading css-1w54o5f\" id=\"summary\">Overview:<!-- --><\/h2>\n<p><!-- --><span style=\"font-weight:400\">Refrain from utilizing wallet contracts or the owner accounts of wallets that were generated by Ethereum Wallet 0.4.0 or earlier. Engaging with a malicious contract may result in loss of ownership of your wallet contract. Establish a new wallet and transfer your assets.<!-- --><\/span><br \/>\n<!-- --><\/p>\n<h3 class=\"chakra-heading css-145upk7\" id=\"how-to-be-super-safe\">How to ensure maximum security??<!-- --><\/h3>\n<p><!-- --><strong>Avoid using compromised wallet contracts, AND\u00a0the associated owner\u00a0accounts of these wallets when sending ether or interacting with unfamiliar contracts!<br \/>\nIf you refrain from using these accounts and wallets, and upgrade your wallet as\u00a0<!-- --><\/strong><b>outlined <!-- --><a target=\"_blank\" rel=\"noopener\" class=\"chakra-link css-ug8vf0\" href=\"https:\/\/github.com\/ethereum\/mist\/releases\/tag\/0.7.6\">here<!-- --><\/a>, you will be safe!<!-- --><\/b><br \/>\n<!-- --><\/p>\n<h2 class=\"chakra-heading css-1w54o5f\" id=\"details\">Details:<!-- --><\/h2>\n<p><!-- --><span style=\"font-weight:400\">A vulnerability was identified that influences smart contract wallets created before the Homestead release (Frontier phase). The risk arises if an affected wallet engages with a malicious contract OR if the owner account of a compromised wallet connects with a malicious contract that is aware of their wallet address. An attacker can then mimic the owner, allowing them to misappropriate funds or tokens and alter the ownership of the wallet.<!-- --><\/span><br \/>\n<!-- --><\/p>\n<p class=\"chakra-text css-gi02ar\"><strong>As long as you do not use your wallet and owner accounts with unfamiliar contracts, you are secure!<!-- --><\/strong><\/p>\n<p><!-- --><\/p>\n<p class=\"chakra-text css-gi02ar\"><span style=\"font-weight:400\">Receiving Ether and sending Ether to non-contract accounts is permissible.<!-- --><\/span><\/p>\n<p><!-- --><\/p>\n<p class=\"chakra-text css-gi02ar\"><span style=\"font-weight:400\">Moreover, if your wallet is set up with multisig, your security is enhanced, as the attacker would need to compel all owners to send to malicious contract(s).<!-- --><\/span><\/p>\n<p><!-- --><\/p>\n<p class=\"chakra-text css-gi02ar\">\u00a0<!-- --><\/p>\n<p><!-- --><\/p>\n<h2 class=\"chakra-heading css-1w54o5f\" id=\"proposed-solution\">Recommended solution:<!-- --><\/h2>\n<p><!-- --><span style=\"font-weight:400\">We advise that if you established a wallet using the affected versions, you undertake one of these measures:<!-- --><\/span><br \/>\n<!-- --><\/p>\n<ul role=\"list\" class=\"css-1onhfjo\">\n<li class=\"css-cvpopp\"><b>Establish a new wallet<!-- --><\/b><span style=\"font-weight:400\"> using the most recent version of Ethereum Wallet (any version from 0.5.0 or later) and <!-- --><\/span><b>transfer your assets<!-- --><\/b><span style=\"font-weight:400\"> there. <!-- --><a target=\"_blank\" rel=\"noopener\" class=\"chakra-link css-ug8vf0\" href=\"https:\/\/github.com\/ethereum\/mist\/releases\/tag\/0.7.6\">You can follow these instructions<!-- --><\/a>.<!-- --><\/span><\/li>\n<li class=\"css-cvpopp\"><i><span style=\"font-weight:400\">Until you complete the above<!-- --><\/span><\/i><span style=\"font-weight:400\">, <!-- --><\/span><b>do not utilize any account<!-- --><\/b><span style=\"font-weight:400\"> that is an <!-- --><\/span><b><i>owner <!-- --><\/i><\/b><b>of an affected wallet, or the affected wallet itself<!-- --><\/b><span style=\"font-weight:400\"> to interact with closed source or otherwise unknown contracts that might invoke arbitrary actions (including rerouting Ether). <!-- --><\/span><b>Only send\/interact with addresses you own, or recognize!<!-- --><\/b><\/li>\n<li class=\"css-cvpopp\">Create a secondary account for daily usage. This account should not be linked to your contract wallets<!-- --><\/li>\n<\/ul>\n<p>\u00a0<br \/>\n<!-- --><br \/>\n<!-- --><span style=\"font-weight:400\">We have introduced a new Ethereum Wallet release 0.7.6, which will recognize your vulnerable wallets.<!-- --><\/span><br \/>\n<!-- --><\/p>\n<p class=\"chakra-text css-gi02ar\"><a target=\"_blank\" rel=\"noopener\" class=\"chakra-link css-ug8vf0\" href=\"https:\/\/github.com\/ethereum\/mist\/releases\/tag\/0.7.6\">Download the latest release and follow the instructions provided in the release notes to update your vulnerable wallets!<!-- --><\/a><\/p>\n<p><!-- --><\/p>\n<p class=\"chakra-text css-gi02ar\"><a target=\"_blank\" rel=\"noopener\" class=\"chakra-link css-ug8vf0\" href=\"https:\/\/github.com\/ethereum\/mist\/releases\/tag\/0.7.6\"\/><a target=\"_blank\" rel=\"noopener\" class=\"chakra-link css-ug8vf0\" href=\"https:\/\/github.com\/ethereum\/mist\/releases\/tag\/0.7.6\">https:\/\/github.com\/ethereum\/mist\/releases\/tag\/0.7.6<!-- --><\/a><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/blog.ethereum.org\/en\/2016\/06\/24\/security-alert-smart-contract-wallets-created-in-frontier-are-vulnerable-to-phishing-attacks\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Impacted configurations: All smart contract wallets established using Ethereum Wallet \u00a0Frontier, version 0.4.0 (Beta 7) or earlier. Wallets created with Ethereum Wallet 0.5.0 and all subsequent releases after March 3, 2016, are unaffected. Probability: Low Impact Level: High Overview: Refrain from utilizing wallet contracts or the owner accounts of wallets that were generated by Ethereum<\/p>\n","protected":false},"author":3,"featured_media":8282,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[23],"tags":[1456],"class_list":["post-9020","post","type-post","status-publish","format-standard","has-post-thumbnail","category-ethereum","tag-return-a-list-of-comma-separated-tags-from-this-title-security-alert-smart-contract-wallets-created-in-frontier-are-vulnerable-to-phishing-attacks"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.3 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Beware: Smart Contract Wallets in Frontier Exposed to Phishing Threats - WSJ-Crypto<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/wsj-crypto.com\/index.php\/2025\/02\/26\/beware-smart-contract-wallets-in-frontier-exposed-to-phishing-threats\/\" \/>\n<meta property=\"og:locale\" content=\"it_IT\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Beware: Smart Contract Wallets in Frontier Exposed to Phishing Threats - WSJ-Crypto\" \/>\n<meta property=\"og:description\" content=\"Impacted configurations: All smart contract wallets established using Ethereum Wallet \u00a0Frontier, version 0.4.0 (Beta 7) or earlier. Wallets created with Ethereum Wallet 0.5.0 and all subsequent releases after March 3, 2016, are unaffected. Probability: Low Impact Level: High Overview: Refrain from utilizing wallet contracts or the owner accounts of wallets that were generated by Ethereum\" \/>\n<meta property=\"og:url\" content=\"https:\/\/wsj-crypto.com\/index.php\/2025\/02\/26\/beware-smart-contract-wallets-in-frontier-exposed-to-phishing-threats\/\" \/>\n<meta property=\"og:site_name\" content=\"WSJ-Crypto\" \/>\n<meta property=\"article:published_time\" content=\"2025-02-26T05:24:24+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/wsj-crypto.com\/wp-content\/uploads\/2025\/02\/eth-org.jpeg\" \/>\n\t<meta property=\"og:image:width\" content=\"2100\" \/>\n\t<meta property=\"og:image:height\" content=\"900\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"wsjcrypto\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Scritto da\" \/>\n\t<meta name=\"twitter:data1\" content=\"wsjcrypto\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tempo di lettura stimato\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minuti\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/wsj-crypto.com\/index.php\/2025\/02\/26\/beware-smart-contract-wallets-in-frontier-exposed-to-phishing-threats\/\",\"url\":\"https:\/\/wsj-crypto.com\/index.php\/2025\/02\/26\/beware-smart-contract-wallets-in-frontier-exposed-to-phishing-threats\/\",\"name\":\"Beware: Smart Contract Wallets in Frontier Exposed to Phishing Threats - WSJ-Crypto\",\"isPartOf\":{\"@id\":\"https:\/\/wsj-crypto.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/wsj-crypto.com\/index.php\/2025\/02\/26\/beware-smart-contract-wallets-in-frontier-exposed-to-phishing-threats\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/wsj-crypto.com\/index.php\/2025\/02\/26\/beware-smart-contract-wallets-in-frontier-exposed-to-phishing-threats\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/wsj-crypto.com\/wp-content\/uploads\/2025\/02\/eth-org.jpeg\",\"datePublished\":\"2025-02-26T05:24:24+00:00\",\"author\":{\"@id\":\"https:\/\/wsj-crypto.com\/#\/schema\/person\/88a93723b30416db1a352d5a0096c4a7\"},\"breadcrumb\":{\"@id\":\"https:\/\/wsj-crypto.com\/index.php\/2025\/02\/26\/beware-smart-contract-wallets-in-frontier-exposed-to-phishing-threats\/#breadcrumb\"},\"inLanguage\":\"it-IT\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/wsj-crypto.com\/index.php\/2025\/02\/26\/beware-smart-contract-wallets-in-frontier-exposed-to-phishing-threats\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"it-IT\",\"@id\":\"https:\/\/wsj-crypto.com\/index.php\/2025\/02\/26\/beware-smart-contract-wallets-in-frontier-exposed-to-phishing-threats\/#primaryimage\",\"url\":\"https:\/\/wsj-crypto.com\/wp-content\/uploads\/2025\/02\/eth-org.jpeg\",\"contentUrl\":\"https:\/\/wsj-crypto.com\/wp-content\/uploads\/2025\/02\/eth-org.jpeg\",\"width\":2100,\"height\":900},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/wsj-crypto.com\/index.php\/2025\/02\/26\/beware-smart-contract-wallets-in-frontier-exposed-to-phishing-threats\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/wsj-crypto.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Beware: Smart Contract Wallets in Frontier Exposed to Phishing Threats\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/wsj-crypto.com\/#website\",\"url\":\"https:\/\/wsj-crypto.com\/\",\"name\":\"WSJ-Crypto\",\"description\":\"Just Another Crypto News Website\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/wsj-crypto.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"it-IT\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/wsj-crypto.com\/#\/schema\/person\/88a93723b30416db1a352d5a0096c4a7\",\"name\":\"wsjcrypto\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"it-IT\",\"@id\":\"https:\/\/wsj-crypto.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/86fe8af82ea089646d6639ca2f87e0243d8688d957bd8e3ec22ec3c457cc16d4?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/86fe8af82ea089646d6639ca2f87e0243d8688d957bd8e3ec22ec3c457cc16d4?s=96&d=mm&r=g\",\"caption\":\"wsjcrypto\"},\"url\":\"https:\/\/wsj-crypto.com\/index.php\/author\/wsjcrypto\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Beware: Smart Contract Wallets in Frontier Exposed to Phishing Threats - WSJ-Crypto","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/wsj-crypto.com\/index.php\/2025\/02\/26\/beware-smart-contract-wallets-in-frontier-exposed-to-phishing-threats\/","og_locale":"it_IT","og_type":"article","og_title":"Beware: Smart Contract Wallets in Frontier Exposed to Phishing Threats - WSJ-Crypto","og_description":"Impacted configurations: All smart contract wallets established using Ethereum Wallet \u00a0Frontier, version 0.4.0 (Beta 7) or earlier. Wallets created with Ethereum Wallet 0.5.0 and all subsequent releases after March 3, 2016, are unaffected. Probability: Low Impact Level: High Overview: Refrain from utilizing wallet contracts or the owner accounts of wallets that were generated by Ethereum","og_url":"https:\/\/wsj-crypto.com\/index.php\/2025\/02\/26\/beware-smart-contract-wallets-in-frontier-exposed-to-phishing-threats\/","og_site_name":"WSJ-Crypto","article_published_time":"2025-02-26T05:24:24+00:00","og_image":[{"width":2100,"height":900,"url":"https:\/\/wsj-crypto.com\/wp-content\/uploads\/2025\/02\/eth-org.jpeg","type":"image\/jpeg"}],"author":"wsjcrypto","twitter_card":"summary_large_image","twitter_misc":{"Scritto da":"wsjcrypto","Tempo di lettura stimato":"2 minuti"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/wsj-crypto.com\/index.php\/2025\/02\/26\/beware-smart-contract-wallets-in-frontier-exposed-to-phishing-threats\/","url":"https:\/\/wsj-crypto.com\/index.php\/2025\/02\/26\/beware-smart-contract-wallets-in-frontier-exposed-to-phishing-threats\/","name":"Beware: Smart Contract Wallets in Frontier Exposed to Phishing Threats - WSJ-Crypto","isPartOf":{"@id":"https:\/\/wsj-crypto.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/wsj-crypto.com\/index.php\/2025\/02\/26\/beware-smart-contract-wallets-in-frontier-exposed-to-phishing-threats\/#primaryimage"},"image":{"@id":"https:\/\/wsj-crypto.com\/index.php\/2025\/02\/26\/beware-smart-contract-wallets-in-frontier-exposed-to-phishing-threats\/#primaryimage"},"thumbnailUrl":"https:\/\/wsj-crypto.com\/wp-content\/uploads\/2025\/02\/eth-org.jpeg","datePublished":"2025-02-26T05:24:24+00:00","author":{"@id":"https:\/\/wsj-crypto.com\/#\/schema\/person\/88a93723b30416db1a352d5a0096c4a7"},"breadcrumb":{"@id":"https:\/\/wsj-crypto.com\/index.php\/2025\/02\/26\/beware-smart-contract-wallets-in-frontier-exposed-to-phishing-threats\/#breadcrumb"},"inLanguage":"it-IT","potentialAction":[{"@type":"ReadAction","target":["https:\/\/wsj-crypto.com\/index.php\/2025\/02\/26\/beware-smart-contract-wallets-in-frontier-exposed-to-phishing-threats\/"]}]},{"@type":"ImageObject","inLanguage":"it-IT","@id":"https:\/\/wsj-crypto.com\/index.php\/2025\/02\/26\/beware-smart-contract-wallets-in-frontier-exposed-to-phishing-threats\/#primaryimage","url":"https:\/\/wsj-crypto.com\/wp-content\/uploads\/2025\/02\/eth-org.jpeg","contentUrl":"https:\/\/wsj-crypto.com\/wp-content\/uploads\/2025\/02\/eth-org.jpeg","width":2100,"height":900},{"@type":"BreadcrumbList","@id":"https:\/\/wsj-crypto.com\/index.php\/2025\/02\/26\/beware-smart-contract-wallets-in-frontier-exposed-to-phishing-threats\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/wsj-crypto.com\/"},{"@type":"ListItem","position":2,"name":"Beware: Smart Contract Wallets in Frontier Exposed to Phishing Threats"}]},{"@type":"WebSite","@id":"https:\/\/wsj-crypto.com\/#website","url":"https:\/\/wsj-crypto.com\/","name":"WSJ-Crypto","description":"Just Another Crypto News Website","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/wsj-crypto.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"it-IT"},{"@type":"Person","@id":"https:\/\/wsj-crypto.com\/#\/schema\/person\/88a93723b30416db1a352d5a0096c4a7","name":"wsjcrypto","image":{"@type":"ImageObject","inLanguage":"it-IT","@id":"https:\/\/wsj-crypto.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/86fe8af82ea089646d6639ca2f87e0243d8688d957bd8e3ec22ec3c457cc16d4?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/86fe8af82ea089646d6639ca2f87e0243d8688d957bd8e3ec22ec3c457cc16d4?s=96&d=mm&r=g","caption":"wsjcrypto"},"url":"https:\/\/wsj-crypto.com\/index.php\/author\/wsjcrypto\/"}]}},"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/wsj-crypto.com\/index.php\/wp-json\/wp\/v2\/posts\/9020","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wsj-crypto.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wsj-crypto.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wsj-crypto.com\/index.php\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/wsj-crypto.com\/index.php\/wp-json\/wp\/v2\/comments?post=9020"}],"version-history":[{"count":2,"href":"https:\/\/wsj-crypto.com\/index.php\/wp-json\/wp\/v2\/posts\/9020\/revisions"}],"predecessor-version":[{"id":9022,"href":"https:\/\/wsj-crypto.com\/index.php\/wp-json\/wp\/v2\/posts\/9020\/revisions\/9022"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/wsj-crypto.com\/index.php\/wp-json\/wp\/v2\/media\/8282"}],"wp:attachment":[{"href":"https:\/\/wsj-crypto.com\/index.php\/wp-json\/wp\/v2\/media?parent=9020"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wsj-crypto.com\/index.php\/wp-json\/wp\/v2\/categories?post=9020"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wsj-crypto.com\/index.php\/wp-json\/wp\/v2\/tags?post=9020"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}