Ethereum’s fix for Bybit-style theft is a year out, and misses most 2026 hacks

- Ethereum’s proposed transaction assertions could have blocked the $1.5 billion Bybit hack and $50.4 million Aave incident.
- EIP-7906 would enforce post-transaction rules, but it is not expected to ship before 2027.
- The defense cannot stop attacks involving stolen keys or compromised signers who can rewrite the rules.
The Ethereum Foundation has identified protocol-level defense that could have caught the $1.5 billion Bybit heist and the $50 million Aave swap disaster.
However, the Foundation says that the solution will not ship before 2027. It also added that even though it was already available, it would not have stopped the stolen-key and social-engineering attacks that drove most of 2026’s losses.
A rule the chain enforces after the transaction runs
In a blog published on Monday, October 5, the Foundation’s Trillion Dollar Security initiative discussed how “native transaction assertions could protect users where today’s defenses stop, and the design choices behind them.”
The Trillion Dollar Security initiative was set up in May as an ecosystem effort to upgrade Ethereum’s security.
The existing practice is that a signature authorizes a request; however, the result depends on the code and the state that the request meets when it executes.
What this means for Ethereum is that it runs what is authorized without checking whether the outcome is what was desired.
This is the gap that the Foundation wants to close, and it sees assertion as the solution. What it does is that it allows an account to inspect what a transaction actually did. It will compare balances, that is, both the starting and final, storage and events, against a rule. It will then revert the whole transaction if the rule fails.
The Foundation has identified EIP-7906 as a possible solution to the problem. They say that it adds a read-only check at the end of a transaction and sits on top of the frame-transaction model in EIP-8141.
Intent mismatch versus outcome mismatch
The Foundation splits signing losses into two kinds. The first is an intent mismatch, where a user approves something other than what they believed they were approving.
An example that fits here is the Bybit incident, where the signing interface was masked. This caused Bybit’s signers to authorize a swap of the Safe’s implementation contract.
The bad actors identified behind the attack, the North Korea-linked Lazarus Group, stole around 400,000 ETH.
The Ethereum Foundation stated that a standing rule forbidding that contract from changing would have reverted it.
The second kind of signing loss that was flagged is the one where the signed request is honest, but the result still goes wrong.
The case study that the Foundation used to describe this kind of loss is the Aave incident, where a user converted $50.4 million of aEthUSDT into roughly $36,000 of aEthAAVE through the CoW Swap widget on Aave’s interface in March 2026.
A stale gas ceiling rejected better-priced quotes, and a winning solver failed to execute. This left the worst route as the only option. An assertion setting a minimum acceptable output would have blocked the trade regardless of the interface’s warning.
Where does the defense stop?
CertiK reported that $1.32 billion was lost to crypto security incidents in the first half of 2026. According to TRM Labs, North Korea-linked groups are behind around two-thirds of these losses.
TRM Labs also found that infrastructure and operational compromises made up about 15% of incidents, but close to 76% of the money lost.
Assertions do little for these cases. An example is the Drift exploit that saw the loss of $285 million. The cause of that exploit was a six-month social-engineering operation that compromised contributors’ machines.
Another one is Bitget’s $387.5 million September loss, which came from compromised hot-wallet keys. The Foundation concedes the limit itself: a rule only helps if it comes from independently approved intent or a standing policy the attacker cannot rewrite. An adversary who holds the keys signs the assertion too.
Hegotá, and a timeline that may slip
EIP-8141, which is the frame-transaction base, is scheduled for the Hegotá upgrade. However, EIP-7906 has only reached “Considered for Inclusion” in the Hegotá meta proposal. So far, it is yet to be confirmed.
The latest article by the foundation increases the possibility of EIP-7906 getting confirmed.
If you're reading this, you’re already ahead. Stay there with our newsletter.
FAQs
What are native transaction assertions?
They are a proposed Ethereum feature, drafted as EIP-7906, that lets on-chain code inspect a transaction's full set of net state changes after it runs and revert the transaction if those changes break a signed rule, such as a minimum amount received or a ban on new approvals.
Would assertions have prevented the Bybit hack?
According to the Ethereum Foundation, yes in principle: a rule requiring Bybit's Safe implementation contract to stay unchanged would have reverted the transaction that Lazarus used to steal about 400,000 ETH on February 21, 2025, provided the rule came from a source the attacker could not alter.
When could EIP-7906 go live?
Not before 2027 at the earliest. EIP-7906 is only "Considered for Inclusion" in the Hegotá upgrade and not yet confirmed, and may be deferred to the following upgrade, while its base layer EIP-8141 is already scheduled for Hegotá.
Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Hannah Collymore
Hannah is a writer and editor with nearly a decade of blog writing and event reporting experience in the crypto space. At Cryptopolitan, Hannah contributes to the news page, reporting and analyzing the latest developments in DeFi, RWA, crypto regulation, AI and frontier tech industries. She graduated from Arcadia university with a degree in Business Administration.
















