The Ethereum Foundation has outlined a protocol-level security framework designed to close the gap between what users authorize in transactions and what actually happens onchain. Published on October 5, 2026, under the Trillion Dollar Security initiative, the research focuses on native transaction assertions that could have prevented the $1.5 billion Bybit heist and a $50.4 million Aave swap failure.
The foundation explained that Ethereum currently executes authorized requests without checking whether the final outcome matches the user's expectations. To address this, the proposed mechanism would let an account inspect a transaction after execution, comparing starting and final balances, storage changes and events against a predefined rule. If the rule fails, the entire transaction would be reverted.
The foundation divided signing losses into two main categories. The first is intent mismatch, where signers approve something different from what they believe they are approving. The Bybit incident is cited as a key example: signing interfaces were masked, causing signers to authorize a change to a Safe implementation contract. The attackers, linked to the North Korea-based Lazarus Group, stole approximately 400,000 ETH.
The second category is outcome mismatch, where a signed request is honest but the result is damaging. The foundation pointed to a March 2026 Aave incident in which a user converted $50.4 million of aEthUSDT into roughly $36,000 of aEthAAVE through the CoW Swap widget on Aave's interface. A stale gas ceiling rejected better-priced quotes, leaving the worst route as the only option. According to the foundation, an assertion enforcing a minimum acceptable output would have blocked the trade.
Technically, the proposal is linked to EIP-7906, which introduces a read-only POST_TX execution frame after the main transaction payload. It adds three new opcodes: TXTRACE, TXDIFF and EVENTDATACOPY. EIP-7906 builds on the frame-transaction model defined by EIP-8141. EIP-8141 is scheduled for the Hegotá upgrade, but EIP-7906 has so far only been marked as "Considered for Inclusion."
The foundation also acknowledged limits: native assertions would not stop attacks driven by stolen keys or social engineering. It cited the Drift exploit, which caused a $285 million loss after a six-month social-engineering operation compromised contributors' machines, and Bitget's $387.5 million September loss from compromised hot-wallet keys. CertiK reported $1.32 billion lost to crypto security incidents in the first half of 2026, with TRM Labs linking North Korea-affiliated groups to about two-thirds of those losses.
"Ethereum executes what you authorize. But does what you authorize correspond to what you expect? Not always," the Ethereum Foundation stated. The proposed native transaction assertions aim to fix that mismatch, though the foundation says the solution will not ship before 2027.