According to SlowMist monitoring, a QNT reserve pool suffered an attack due to a design flaw in the EIP-7702 account, resulting in the loss of 1988.5 QNT, worth approximately 54.93 ETH. The root cause of the attack lies in the fact that the administrator of the reserve pool was held by an address that delegated its code to the BatchExecutor contract through EIP-7702. Because BatchExecutor authorized the BatchCall contract, which lacked permission control, as the caller, and the BatchCall.batch function lacked permission checks, the attacker exploited an arbitrary call vulnerability to extract tokens from the pool.