Skip to content

Written by AI.How we work

Invest1 publisherNot yet confirmed elsewhere2 min readPublished

Ethereum Foundation's answer to Bybit-style theft waits until 2027 at the earliest

Ethereum Foundation says EIP-7906, a check that could have reverted the $1.5 billion Bybit theft, will not ship before 2027. Its own post concedes the check cannot stop the stolen-key and social-engineering attacks behind most of 2026's losses.

The Investor · Invest desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying Ethereum Foundation's answer to Bybit-style theft waits until 2027 at the earliest
Generated illustration

What happened

  • EIP-7906 adds a read-only check at the end of a transaction, comparing balances, storage and events against a rule and reverting the whole transaction if the rule fails.
  • In March 2026 an Aave user swapped $50.4 million of aEthUSDT for roughly $36,000 of aEthAAVE, a trade a minimum-output assertion would have blocked.
  • EIP-8141, the frame-transaction base the check sits on, is scheduled for the Hegota upgrade, but EIP-7906 itself has only reached Considered for Inclusion status.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • exposure Exchanges and custodians holding hot-wallet or multisig keys keep the full loss from key theft through at least 2027, because an attacker holding the keys can sign the assertion too.
  • constraint Once live, the check protects only accounts that set standing rules or independently approved intent in advance, so a wallet with no policy in place gains nothing from the upgrade.
  • decision The Hegota meta proposal still has to confirm EIP-7906, and the Foundation's post is the case for doing so; Cryptopolitan says it raises the odds.

CertiK counted $1.32 billion lost to crypto security incidents in the first half of 2026 [10]. TRM Labs attributes around two-thirds of that, about $880 million, to North Korea-linked groups [11][20]. In TRM's breakdown, infrastructure and operational compromises took close to five times their share of incidents in dollars [17]. Drift and Bitget fall in that category. Drift lost $285 million after a six-month social-engineering operation compromised contributors' machines, and assertions do little for a case like that [13]. Bitget lost $387.5 million in September through compromised hot-wallet keys [14]. Together the two come to $672.5 million [19].

The proposal addresses the gap between what gets signed and what actually happens. A signature authorizes a request, but the result depends on the code and state that request meets when it executes [6]. At Bybit, a masked signing interface led signers to authorize a swap of the Safe's implementation contract [7]. The Foundation says a standing rule forbidding that contract from changing would have reverted it [7]. Instead the Lazarus Group took around 400,000 ETH [8]. The Aave user kept about 0.07% of the position's value [18]. A stale gas ceiling had rejected better-priced quotes, and the winning solver failed to execute [9].

The Foundation's Trillion Dollar Security initiative wrote on October 5 about how "native transaction assertions could protect users where today's defenses stop" [4]. The Foundation also concedes the limit. A rule helps only if it comes from independently approved intent or a standing policy the attacker cannot rewrite, and an adversary who holds the keys signs the assertion too [15].

Both the date and the reach can move. If the check misses Hegota, it lands later than the earliest date the Foundation gave [2]. If attackers go back to Bybit-style interface masking, the share of stolen dollars an assertion can catch grows [7]. If they keep going after keys and machines, that share stays small, because TRM puts most of the money there [17].

The protocol work here goes into checking outcomes, and the check defers to whoever signs [15]. In my view, keys and signer machines remain the operator's problem through at least 2027 [2]. I would drop that view if TRM's next breakdown showed infrastructure and operational compromises well below the 76% of dollars they took this time [12].

What to watch

  • Whether EIP-7906 moves from Considered for Inclusion to confirmed in the Hegota meta proposal.
  • TRM Labs' next loss breakdown, and whether infrastructure and operational compromises keep close to 76% of dollars lost.
  • Whether Safe and other multisig wallets prepare standing rules, such as locking implementation contracts, for when assertions ship.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories