Ethereum’s 2027 Security Fix Misses Most 2026 Hacks
The Ethereum Foundation has proposed a protocol-level solution to prevent high-profile thefts like the $1.5 billion Bybit heist and the $50 million Aave swap disaster. However, the fix will not be available until 2027, and even then, it will not address most of the hacks that occurred in 2026.
The Foundation's Trillion Dollar Security initiative outlined the need for native transaction assertions, which would allow accounts to inspect transactions and revert them if they violate predefined rules. This approach aims to close the gap between user intent and transaction outcomes. The proposed solution, EIP-7906, would add a read-only check at the end of a transaction, building on the frame-transaction model in EIP-8141.
The Foundation distinguishes between two types of signing losses: intent mismatch and outcome mismatch. Intent mismatch occurs when users authorize something different from what they intended, as seen in the Bybit attack. Outcome mismatch happens when the signed request is honest, but the result still goes wrong, as in the Aave incident where a user lost $50.4 million due to a flawed swap.
However, the solution has limitations. Assertions would not have prevented attacks involving stolen keys or social engineering, such as the $285 million Drift exploit or Bitget’s $387.5 million loss. The Foundation acknowledges that rules are only effective if they come from independently approved intent or standing policies that attackers cannot rewrite.
EIP-8141 is scheduled for the Hegotá upgrade, but EIP-7906 has only reached the 'Considered for Inclusion' stage. The latest article by the Foundation increases the likelihood of EIP-7906 being confirmed, though the timeline may still slip.