Overview:
Funds drained not via compromised private keys, classic token approvals, or an obvious malicious transfer at the moment of loss. The root cause was a single EIP-7702 authorization signed during what appeared to be a routine bridge or payment flow.
