As of October 2026, you check for an EIP-7702 delegation by opening your address on a block explorer such as Etherscan and reading the 'Delegated Address' field: 'Null' means no active delegation, a labeled contract from a wallet you knowingly upgraded is expected, and an unknown contract should be revoked. If your key is safe, revoke by sending a type 0x04 transaction that delegates the address to the zero address from a wallet that supports it, then confirm the field reads 'Null' again. If deposits vanish seconds after they arrive, assume your private key or seed phrase is leaked, or that you signed a malicious delegation: treat the address as burned and move what remains to a new seed phrase, since revoking is not enough if the key is leaked and the attacker can delegate again.
What is an EIP-7702 delegation, and why might your address have one?
An EIP-7702 delegation is a setting that makes an ordinary seed-phrase address (an EOA) run the code of a smart contract. EIP-7702 shipped in Ethereum's Pectra upgrade, which activated on mainnet on 7 May 2025 at 10:05 UTC (epoch 364032), according to ethereum.org. You sign an authorization, it travels in a new transaction type, 0x04 (the set-code transaction), and the account's code becomes 0xef0100 followed by the 20-byte contract address (23 bytes in total), per the EIP-7702 specification.
A delegation is persistent: Linea's documentation says it stays active until you change it. It is per chain, unless the authorization was signed with chain ID 0, which the Security Alliance (SEAL) warns can be replayed on other networks. So check every EVM network you use.
A legitimate delegation usually comes from a "switch to smart account" upgrade you accepted in your own wallet; a malicious one comes from a phishing authorization you signed or from an attacker holding your key. Every authorization needs the account key's signature, so an unknown delegation you never signed suggests the key is compromised. See our EIP-7702 explainer for the mechanics.
How do you check if your address has a delegation?
You check by reading the 'Delegated Address' field on your address page in a block explorer. Follow these steps:
- Copy your address from your wallet.
- Type the network's official explorer URL yourself (Etherscan for Ethereum) and never click explorer links from DMs or ads. See reading a block explorer.
- Find 'Delegated Address' on the overview. Etherscan's knowledge base (13 June 2025) says the field shows 'Null' once a delegation is reverted, which means no active delegation.
- Repeat on each EVM network's official explorer. Other explorers may label the field differently or omit it, so check the account's code or the Delegations tab below.
Revoke.cash offers a second read-only view: a Delegations tab on its account page. Avoid "delegation checker" sites from ads: reading a delegation never needs your seed phrase or a signature.
What does the result mean?
The explorer result falls into one of five cases.
| What you see on the explorer | What it usually means | What to do |
|---|---|---|
| 'Null' | No active delegation on this network (the state Etherscan's knowledge base describes after a revert) | Nothing to revoke; check your other networks |
| A labeled contract from your own wallet that you enabled (Etherscan labels MetaMask's as 'MetaMask: EIP-7702 Delegator') | Expected smart-account upgrade | Keep it, or revert it in that wallet |
| An unfamiliar contract you do not remember enabling | Suspicious | If your key is safe, revoke now |
| A contract with a phishing or scam label | Assume compromise | Move assets to a new seed phrase |
| Any delegation, and funds leave within seconds | Leaked key (or a signed phishing delegation) plus a sweeper | See the sweeper section; revoking alone will not protect a leaked key |
How do you revoke an EIP-7702 delegation if your key is safe?
You revoke by signing a new authorization that points your address to the zero address (0x000...000), which the EIP-7702 specification says clears the account's code and returns it to a normal EOA. It needs your key's signature and costs gas on that network.
- Open a wallet that supports type 0x04 transactions and lets you change or clear the delegation. MetaMask documents a revert flow for its own Smart Account: account menu, Account details, Smart account, toggle the network off, then confirm and pay the network fee (extension and mobile).
- Repeat on every network where a delegation exists.
- Re-check the explorer: 'Delegated Address' should read 'Null'.
One caveat: MetaMask's help center says it only supports smart-account functionality for its own contract, and Curvegrid (13 February 2026) reports that revoking arbitrary delegations varies by wallet. MetaMask's documentation does not say its revert flow clears a delegation to a third-party contract, so do not assume it does. If your wallet cannot send an authorization to the zero address, treat the address as retired and move your assets to a new address from a fresh seed phrase.
Why do deposits vanish seconds after they arrive?
Deposits vanish right away because something, often a sweeper contract your address was delegated to, forwards anything that lands, which usually means your private key or seed phrase is compromised or you signed a malicious delegation. Revoke.cash says a sweeper delegation is only possible if the seed phrase is already compromised, but phishing research shows users can also be tricked into signing a malicious authorization. Either way, stop funding the address. Cointelegraph reported on 2 September 2025 that WLFI token holders with leaked keys found pre-planted malicious delegations taking the gas they deposited, according to SlowMist founder Yu Xian.
- Stop sending gas to that address; a sweeper or a bot watching the key can take it.
- Create a new wallet with a new seed phrase on a clean device.
- First check each chain's explorer for a delegation. Move native assets first, because gas you add for other transfers can be taken, and consider a gas-sponsored or bundled transfer from an experienced responder.
- Follow our first-hour checklist after a wallet is drained.
If the key is leaked, revoking does not fix this, because the attacker holds the same key and can re-delegate or transfer funds right after you revoke. If you only signed a phishing delegation and the key is safe, revoking removes it, but you cannot easily tell the two cases apart, so treat the address as burned. Treat "rescue" offers in DMs as scams.
Does revoking token approvals, or revoke.cash, remove a delegation?
No. A token approval is a permission stored on each token contract, while a delegation is code attached to your own account, so each layer is separate. See how to revoke token approvals for that side.
Revoke.cash shows delegations but cannot revoke them. A malicious delegate contract can be written to move any asset in the account, including native ETH, with no token approval, so it can be worse than a single unlimited allowance, and phishing kits such as wallet drainers can ask for such authorizations too.
How do you avoid a malicious delegation in the first place?
Accept a smart-account upgrade only when it appears inside your own wallet app. MetaMask said in May 2025 that it only prompts users to switch inside the wallet itself, and that an email or link asking you to "upgrade" is a phishing scam (reported by DeFiHackLabs, 26 May 2025).
- Treat any signing request that mentions authorization, delegation, set code or chain ID 0 as suspect.
- Delegate only to well-known, audited contracts, per SEAL.
- Keep long-term holdings on an address you never use for dapp signing; revoke.cash suggests enabling 7702 only on day-to-day hot addresses.
This figure describes early post-Pectra activity, not today's share. Wintermute said in late May 2025 that over 97% of delegations were linked to scams (cited by Etherscan's knowledge base, 13 June 2025).
How does WATS Wallet relate to EIP-7702?
WATS Wallet is a non-custodial wallet (Chrome extension and iOS/Android app) where you hold your own keys and seed phrase, so this page's rules apply to WATS users too. WATS never holds a key, and if a seed phrase leaks, no wallet can undo it: the fix is a new seed phrase.
On EVM networks, WATS Wallet charges every action in ATS through an ERC-4337 paymaster, debited from one ATS balance on BNB Chain, a different account-abstraction mechanism from EIP-7702. See what ERC-4337 is and our EIP-7702 explainer for the difference, and how the ATS fee works: it tracks the live network cost and is not a discount.
Frequently asked questions
Can revoke.cash remove an EIP-7702 delegation?
No. Revoke.cash lists delegations in a Delegations tab on your account page, but its own learn page says you cannot revoke them there, because most wallets do not let outside dapps set or clear them. Revoke inside a wallet that supports type 0x04 transactions by delegating to the zero address, then re-check the explorer.
Should I accept a 'switch to smart account' prompt in my wallet?
Only if it appears inside your own official wallet app and you understand what you gain, such as batching. Never sign a delegation or authorization requested through a website, email or DM; the Security Alliance calls those phishing. A legitimate in-wallet upgrade can be reverted later (MetaMask documents this for its own Smart Account, and it costs gas), and an address holding long-term savings is better left as a plain EOA.
If I revoke the delegation, will the sweeper stop stealing my deposits?
Not if your key is leaked. A sweeper delegation usually exists because an attacker already has your private key or seed phrase, so they can re-delegate or transfer funds right after you revoke. If you instead signed a malicious delegation and the key is safe, revoking removes it, but you cannot easily tell the two cases apart, so stop sending gas, move what you can to a new seed phrase on a clean device, and treat the old address as burned. Ignore paid 'rescue' offers in DMs.

