Security Vulnerability Identified in Ethereum ERC-8424 Draft
A proposed standard for tokenized real-world assets contains a flaw that enables the unauthorized disclosure of account balances.
Updated on Sept. 25, 2026 in Cybersecurity

Live Poll
Do you trust that new technical standards will keep your digital asset balances private and secure?
Ethereum developers have identified a critical security vulnerability within the draft ERC-8424 standard designed for tokenized real-world assets. The flaw allows external parties to reveal an account's encrypted balance through targeted function calls.
Why it matters
This vulnerability threatens the privacy of users holding tokenized assets on the Ethereum network by potentially exposing sensitive financial information. It surfaced during the draft review process, highlighting the risks inherent in protocols that enable issuers to force-transfer assets without holder consent.
The draft ERC-8424, which builds on the existing ERC-7984 standard, includes two public checks and three private functions. Security analysis showed that these functions leak balance data via specific reverts during failed transactions, allowing for full 64-bit balance disclosure in just 64 calls.
The players
Ethereum
A decentralized, open-source blockchain platform that serves as the foundation for smart contracts and token standards.
zexoverz
The security reviewer who identified the balance disclosure vulnerability within the draft standard.
The details
The vulnerability stems from a lack of restricted caller permissions within the draft functions intended to manage transfer eligibility and balance limits. Because the protocol relies on specific error states when a transfer fails due to vesting or balance caps, an attacker can iterate through these reverts to determine an encrypted balance. The spendable-balance function is particularly exposed, reportedly revealing a user's total balance in a single call.
Timeline
September 25, 2026: The ERC-8424 standard was formally assigned and the review process began.
The Tech Race
This finding arrives as developers refine the EIP process to better secure protocols for tokenized real-world assets. It acts as a necessary check against the broader roadmap of established standards like ERC-7984, ensuring that privacy-preserving features are not bypassed by draft implementations.
The vulnerability remains a research-stage issue within a draft proposal and is not currently deployed in active production contracts. Users and developers should monitor the Ethereum Magicians thread for updates on whether the draft is patched or requires a complete redesign before final approval.
The takeaway
The ERC-8424 draft highlights the tension between issuer-controlled force transfers and individual asset privacy. Stakeholders should track the final Ethereum editor review to see if the vulnerability is resolved before any potential implementation.
Further reading
For more information on protocol security and development, visit the Cybersecurity section.
Live Poll
Do you trust that new technical standards will keep your digital asset balances private and secure?







