Ethereal news

Ethereal news weekly #20

6 min read
Subscribe to Ethereal news

Etherealize: ETH is productive money, DeFi united effort to restore rsETH backing, Arbitrum security council froze exploiter ETH

Ecosystem


MetaMask Community Call April

Join us next week for the April MetaMask Community Call.

We’ll cover:

  • How to build trustful agents
  • The latest MetaMask Connect updates
  • x402 + Advanced Permissions

Thursday, April 30, 11:30 AM ET
RSVP


Enterprise

Applications

  • Apoorv dapp3.eth (browser extension): ENS websites via Helios light client & local IPFS node
  • Nouns DAO voted to set auction reserve price to 2.8 ETH
  • Shutter perpetual endowment network (PEN): proposal for DAO alternative, quarterly voting on yield distribution, soulbound voting seats
  • Stomp (game): monster battle, turn-based, 1v1

Developers

  • OpenZeppelin Contracts CLI: generate contracts using OpenZeppelin contract libraries
  • Foundry (dev framework):
    • Forge-std v1.16.0 (helpers): adds expectAndMockCall, console.table & currentFilePath
  • Weiroll (operation-chaining/scripting language) migrated to Foundry
  • Backseats wagmi-swift & viem-swift (client libraries): wagmi/viem ported to Swift
  • ZeroDev Omni SDK (ERC4337 SDK): written in Zig, native Swift binding, alpha
  • Ross: Onchain html example, html app returned by a contract
  • Application layer standards (ERCs):
    • ERC8236: Deferred-settlement fungible tokens
    • Revived ERC1404: Simple restricted token
    • ERC8238: Coercion-resistant vault
    • ERC8239: Agent skill registry
    • ERC8240: Trust infrastructure for agents & assets

Security

  • Kelp ~$292M exploit on April 18, rsETH drained from bridging adapter via forged crosschain message, 1/1 DVN (Decentralized Verifier Networks) setup, subsequent attempt for ~$95M was mitigated
    • LayerZero: quorum of RPCs LayerZero Labs DVN relied upon were compromised (2 RPCs compromised, DDoS attacks on uncompromised RPCs)
    • Arbitrum security council froze 30,766 ETH held by exploiter on Arbitrum One
    • DeFi united: coordinated relief effort to restore rsETH backing
  • eth.limo DNS hijack post-mortem, EasyDNS account compromised via social engineering
  • Pashov X-Ray: generates protocol overview, threat model, test gaps, Git history, readiness verdict, entry points, invariant map & architecture diagram
  • TheDAO Security Fund: Ethereum Security quadratic funding round live on Giveth, 500 ETH matching pool, 2x impact for ETHSecurity badges

All core devs (main protocol calls)

All core devs - execution (ACDE) #235

  • Nixo co-leading All Core Devs going forward
  • Glamsterdam upgrade (targeting mid-2026):
    • bal-devnet-3 running well, 100M gas limit
    • glamsterdam-devnet-0 (spec) targeting launch this week
    • EIP8037 state creation gas cost increase: complexity concerns
    • Mascot needed, last call for suggestions
  • Hegotá upgrade (targeting late-2026):
    • Non-headliner EIPs Proposed for Inclusion:

All core devs - testing (ACDT) #78

Layer 1

Research

Staking

  • Pintail: staking ratio tipping point, one third of ETH is staked & ratio continues to grow, case for issuance curve adjustment
  • Remote-signer-dirk-interop: use Dirk with validator clients that support remote-signer API
  • Reminder: EthStaker staking survey
  • Client diversity:
    • Consensus layer: Lighthouse ~53% (data may not be accurate)
  • Staking marketshare: Lido 23.1% [Note: dual governance]
  • Validators: 914k active (target 128k), 12k accumulating (0x02 withdrawal credentials)
  • Client releases:
    • Execution layer:
      • Besu 26.4.0: adds eth/70 partial block receipt lists, eth/71 block access list exchange & snap/2 block access list exchange, max blobs options, IPv6 dual stack support for DiscV5 & txpool RPCs
      • Lambda ethrex v10.0.0: Glamsterdam upgrade prep, new P2P stack & snap sync hardening
      • Paradigm Reth v2.1.0 (medium): migrate to v2 storage command without a full resync, alloy-evm fix for gas refunds for custom precompiles

Layer 2

  • Sunnyside Labs privacy boost: private transfers, live on OP Mainnet
  • Optimism: op-geth being deprecated May 31
  • L2Beat interoperability: view volume, routes & transfers between chains

Regulation

  • US CFTC charged Army service member with insider trading on Polymarket
  • UK Financial Conduct Authority (FCA): 8 premises suspected of peer-to-peer crypto trading issued with cease & desist letters

General


Editor: @abcoathup
Permalink: ethereal.news/ethereal-news-weekly-20/
Markdown: ethereal.news/ethereal-news-weekly-20.md