Breaking
October 5, 2026

Ethereum’s fix for Bybit-style heists is still a year away, and it won’t stop most of 2026’s hacks Hannah Collymore | usagoldmines.com

The Ethereum Foundation has identified protocol-level defense that could have caught the $1.5 billion Bybit heist and the $50 million Aave swap disaster. 

However, the Foundation says that the solution will not ship before 2027. It also added that even though it was already available, it would not have stopped the stolen-key and social-engineering attacks that drove most of 2026’s losses.

A rule the chain enforces after the transaction runs

In a blog published on Monday, October 5, the Foundation’s Trillion Dollar Security initiative discussed how “native transaction assertions could protect users where today’s defenses stop, and the design choices behind them.”

The Trillion Dollar Security initiative was set up in May as an ecosystem effort to upgrade Ethereum’s security.

The existing practice is that a signature authorizes a request; however, the result depends on the code and the state that the request meets when it executes.

What this means for Ethereum is that it runs what is authorized without checking whether the outcome is what was desired.

This is the gap that the Foundation wants to close, and it sees assertion as the solution. What it does is that it allows an account to inspect what a transaction actually did. It will compare balances, that is, both the starting and final, storage and events, against a rule. It will then revert the whole transaction if the rule fails. 

The Foundation has identified EIP-7906 as a possible solution to the problem. They say that it adds a read-only check at the end of a transaction and sits on top of the frame-transaction model in EIP-8141.

Intent mismatch versus outcome mismatch

The Foundation splits signing losses into two kinds. The first is an intent mismatch, where a user approves something other than what they believed they were approving. 

An example that fits here is the Bybit incident, where the signing interface was masked. This caused Bybit’s signers to authorize a swap of the Safe’s implementation contract. 

The bad actors identified behind the attack, the North Korea-linked Lazarus Group, stole around 400,000 ETH.

The Ethereum Foundation stated that a standing rule forbidding that contract from changing would have reverted it.

The second kind of signing loss that was flagged is the one where the signed request is honest, but the result still goes wrong. 

The case study that the Foundation used to describe this kind of loss is the Aave incident, where a user converted $50.4 million of aEthUSDT into roughly $36,000 of aEthAAVE through the CoW Swap widget on Aave’s interface in March 2026. 

A stale gas ceiling rejected better-priced quotes, and a winning solver failed to execute. This left the worst route as the only option. An assertion setting a minimum acceptable output would have blocked the trade regardless of the interface’s warning.

Where does the defense stop?

CertiK reported that $1.32 billion was lost to crypto security incidents in the first half of 2026. According to TRM Labs, North Korea-linked groups are behind around two-thirds of these losses.

TRM Labs also found that infrastructure and operational compromises made up about 15% of incidents, but close to 76% of the money lost.

Assertions do little for these cases. An example is the Drift exploit that saw the loss of $285 million. The cause of that exploit was a six-month social-engineering operation that compromised contributors’ machines.

Another one is Bitget’s $387.5 million September loss, which came from compromised hot-wallet keys. The Foundation concedes the limit itself: a rule only helps if it comes from independently approved intent or a standing policy the attacker cannot rewrite. An adversary who holds the keys signs the assertion too.

Hegotá, and a timeline that may slip

EIP-8141, which is the frame-transaction base, is scheduled for the Hegotá upgrade. However, EIP-7906 has only reached “Considered for Inclusion” in the Hegotá meta proposal. So far, it is yet to be confirmed.

The latest article by the foundation increases the possibility of EIP-7906 getting confirmed.

The smartest crypto minds already read our newsletter. Want in? Join them.

 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.