Ethereum's proposed safety checks may still permit harmful trades. The $ETH Foundation's new Trillion Dollar Security initiative is examining native transaction assertions through EIP-7906; however, this enhancement will not prevent all bad trades.
Published on October 5, the idea is that Ethereum currently executes what is authorized rather than what is expected.
Clear Signing shows the request but cannot ensure the outcome. EIP-7906 introduces a POST_TX frame that follows execution, utilizing three new opcodes: `TXT RACE`, `TXDIFF`, and `EVENTDATACOPY`.
A wallet could enforce rules like "receive at least X tokens" or "no unexpected approval"; if the requirement fails, the entire transaction reverts, although gas fees are still incurred.
This could have potentially addressed incidents like the $1.5 billion Bybit heist and the $50 million Aave swap issue, where a user exchanged $50.4 million aEthUSDT for merely 329 aEthAAVE ($36,000) after ignoring a significant price impact warning.
However, if the safety rule stems from a compromised frontend, an attacker can provide an overly permissive rule with the malicious request.
Furthermore, the system will not protect against stolen-key or social-engineering attacks, which accounted for most losses in 2026, and the deployment is not expected to occur until 2027, as part of the Hegota upgrade.
While safety measures are advancing, having a signature does not guarantee safety.
#ETH #Ethereum
Published on October 5, the idea is that Ethereum currently executes what is authorized rather than what is expected.
Clear Signing shows the request but cannot ensure the outcome. EIP-7906 introduces a POST_TX frame that follows execution, utilizing three new opcodes: `TXT RACE`, `TXDIFF`, and `EVENTDATACOPY`.
A wallet could enforce rules like "receive at least X tokens" or "no unexpected approval"; if the requirement fails, the entire transaction reverts, although gas fees are still incurred.
This could have potentially addressed incidents like the $1.5 billion Bybit heist and the $50 million Aave swap issue, where a user exchanged $50.4 million aEthUSDT for merely 329 aEthAAVE ($36,000) after ignoring a significant price impact warning.
However, if the safety rule stems from a compromised frontend, an attacker can provide an overly permissive rule with the malicious request.
Furthermore, the system will not protect against stolen-key or social-engineering attacks, which accounted for most losses in 2026, and the deployment is not expected to occur until 2027, as part of the Hegota upgrade.
While safety measures are advancing, having a signature does not guarantee safety.
#ETH #Ethereum