Ethereum Foundation research published Oct. 5 reveals that proposed transaction assertions under EIP-7906 could still allow bad trades to execute if transaction builders configure weak protection floors. As of Oct. 9, the draft proposal depends on EIP-8141 frame transactions, which are scheduled for inclusion in Ethereum's upcoming Hegotá upgrade, while EIP-7906 remains under consideration.
How EIP-7906 Evaluates Net State Changes
First created on Feb. 21, 2025, EIP-7906 introduces read-only POST_TX frames that execute at the end of a transaction to evaluate outcomes before finalization. The specification introduces three main operations: TXTRACE to enumerate net changes and events, TXDIFF to retrieve storage values by key, and EVENTDATACOPY to pass event data into assertion logic. The scope of these checks includes native ETH balances, contract storage changes, newly deployed contracts, and code hashes.
However, these assertion checks only inspect net execution results. Multiple writes to a single storage slot collapse into initial and final values, while a storage slot restored to its original value disappears from the net-change list entirely. Existing tools like Uniswap v3's amountOutMinimum parameter or the Ethereum Working Group's May 12, 2026 Clear Signing standard already enforce minimum thresholds, but a minimum receipt quantity cannot guarantee a trade is a good financial bargain if derived from a bad quote.
Security Guidelines and Failed Transaction Costs
To prevent exploits, EIP-7906 security guidance requires assertion targets to be immutable and non-upgradeable so an execution body cannot alter enforcement logic mid-transaction. The draft recommends fixing reference values at signing or drawing them from state at the start of execution to prevent transactions from shifting the price metrics used to judge their own outputs.
If an assertion check fails, the POST_TX frame reverts the execution body, but the transaction remains in the block. The gas payer is still charged for all consumed gas, and state modifications made during the initial validation prefix stay committed on-chain. Amid ongoing discussions around Ethereum protocol architecture, developers must carefully balance protection against execution costs.
Key Takeaways
- EIP-7906 proposes POST_TX frames using TXTRACE, TXDIFF, and EVENTDATACOPY to inspect net execution effects.
- Scheduled EIP-8141 frame transactions are required for EIP-7906, which is considered for the Hegotá upgrade.
- Failed assertion checks revert execution, but gas fees remain charged and validation prefix changes stay committed.
Why It Matters
While EIP-7906 provides smart accounts and protocols with post-execution verification, it highlights a fundamental limitation of automated on-chain guards. If an app, solver, or transaction builder sets a permissive threshold, an assertion will successfully execute a poor trade while strictly following its rules. For decentralized finance developers, this demonstrates that on-chain assertions cannot replace secure off-chain price discovery and trusted order routing.



