Pectra upgrade was created to speed up the Ethereum ecosystem through a series of improvements like native account abstraction, single slot finality, seamless validator withdrawals and using minimal on-chain data to make operations economical. But in the process, Pectra has left one blind spot, security. The SetCode Transaction Type, or type 0x04, would allow an adversary to sign transactions with just a message, and not AUTHCodes. That said, if an attacker lures through a phishing site to write a message, they can take control of the wallet.
