A phishing attack exploiting EIP-7702 has resulted in the theft of $1 million, involving five different tokens. The attack leveraged the EIP-7702 Delegator to authorize user EOA addresses to MetaMask, executing transactions through the Uniswap Universal Router. Victims were lured to a phishing site where they were prompted to sign a wallet transaction. Upon confirmation, all valuable assets in their wallet were instantly transferred away. The technical complexity of the exploit involves using the execute function (0xe9ae5c53) to facilitate token transfers, leaving users with empty wallets after a single interaction.